NIST SP 800-171 is the standard behind DFARS 252.204-7012 and behind CMMC Level 2: 110 security requirements that any contractor handling Controlled Unclassified Information (CUI) must implement, self-assess, and, for most contracts, have certified by a third party. Search the document for “penetration test” and you will not find it. Search an assessor’s evidence request list and you usually will.
This guide explains that gap. It lists the practices a penetration test evidences directly, shows how the results feed the System Security Plan, the Plan of Action and Milestones, and the SPRS score, and explains where enclave scoping makes or breaks the whole effort.
Which version applies
NIST published SP 800-171 Revision 3 in May 2024, restructuring the requirements into 97 with organization-defined parameters. For contract purposes, however, DFARS 7012 and the CMMC program continue to assess against Revision 2 (110 requirements in 14 families), and the Department of Defense has said any move to Revision 3 will come through a later rulemaking. Everything below uses the Revision 2 numbering, which is what a C3PAO uses today.
Does NIST SP 800-171 require a penetration test?
No practice says “conduct penetration testing.” Several practices, though, require you to assess whether controls work, to find and fix vulnerabilities, and to prove that boundaries hold, and for those a penetration test is the most direct evidence available. The higher-level companion standard, NIST SP 800-172, does require penetration testing explicitly for the enhanced requirements behind CMMC Level 3, which is a useful signal about where NIST thinks the practice belongs.
The practices a penetration test evidences
The table below lists the requirements most directly evidenced by testing, what each asks for, how a test satisfies it, and its weight under the DoD Assessment Methodology used to calculate the SPRS score.
| Practice | What it requires | How a penetration test evidences it | SPRS weight |
|---|---|---|---|
| 3.12.1 Security control assessment | Periodically assess the security controls to determine if they are effective | The test is the assessment: controls exercised under attack, with results documented | 5 |
| 3.11.2 Vulnerability scanning | Scan for vulnerabilities periodically and when new vulnerabilities are identified | Authenticated scanning across the CUI environment, validated by analysts | 5 |
| 3.11.3 Remediate vulnerabilities | Remediate vulnerabilities in accordance with risk assessments | Findings ranked by exploitability, fixed, and confirmed by retest | 1 |
| 3.13.1 Boundary protection | Monitor, control, and protect communications at external and key internal boundaries | External testing of the boundary and internal testing of the enclave segmentation | 5 |
| 3.13.5 Public-access subnetworks | Implement subnetworks for publicly accessible components separated from internal networks | Testing whether the DMZ actually separates public services from the CUI enclave | 5 |
| 3.13.6 Deny by default | Deny network traffic by default and allow by exception | Attempts to reach services that should be blocked, from inside and outside | 5 |
| 3.1.1 and 3.1.2 Access control | Limit system access to authorized users, and to authorized transactions and functions | Authentication and authorization testing across applications and systems that hold CUI | 5 each |
| 3.1.5 Least privilege | Employ the principle of least privilege | Privilege escalation attempts from a standard user account | 3 |
| 3.5.3 Multifactor authentication | MFA for local and network access to privileged accounts and network access to non-privileged accounts | Attempts to reach CUI systems without MFA, and MFA bypass testing | 5 |
| 3.14.1 Flaw remediation | Identify, report, and correct system flaws in a timely manner | Missing patches found and exploited, then confirmed fixed | 5 |
| 3.14.6 Monitoring | Monitor systems to detect attacks and indicators of potential attacks | Whether the test’s activity was detected and alerted on | 5 |
| 3.3.1 Audit logging | Create and retain audit logs to enable monitoring and investigation | Whether the test’s actions appear in logs with enough detail to reconstruct them | 5 |
Weights are from the DoD Assessment Methodology (version 1.2.1): each unimplemented requirement deducts 1, 3, or 5 points from a maximum score of 110. The practices above account for a large share of the 5-point deductions, which is why testing evidence matters for the score and not only for the assessment.
Enclave scoping: the test that decides everything
Most contractors reduce cost by scoping CMMC to an enclave, a segmented environment where CUI lives, so that the 110 requirements apply to a few dozen systems instead of the whole company. The approach is sound and assessors accept it, on one condition: the segmentation has to be real. If a user on the corporate network can reach a file share inside the enclave, or if CUI has drifted onto a SharePoint site outside it, the boundary in the System Security Plan is fiction and the assessment scope expands to everything the CUI touches.
A penetration test is the only reliable way to know before the assessor does. It tests the boundary from the internet and from an assumed foothold inside the corporate network (3.13.1, 3.13.5, 3.13.6), hunts for CUI outside the defined boundary, and documents exactly what was reachable. Our CMMC Level 2 penetration testing service treats this as the highest-value part of the engagement, because a failed enclave discovered on assessment day costs far more than a test.
How the results feed your documents
System Security Plan (SSP). Each finding names the practice it touches. Where the control held, the report is evidence of implementation and can be cited in the SSP’s implementation statement. Where it did not, the SSP entry gets a truthful status, which assessors respect far more than an optimistic one.
Plan of Action and Milestones (POA&M). Unimplemented practices go into the POA&M with a remediation plan and date. CMMC allows a limited POA&M at Level 2 for lower-weighted practices, but 5-point practices and certain others (including MFA) cannot be open at the time of certification. A test run early enough turns those into closed items before the assessment rather than disqualifying gaps during it.
SPRS score. The self-assessment score submitted to the Supplier Performance Risk System is calculated from the same practices. A score based on tested controls is defensible; a score based on assumptions is a liability for the senior official who affirms it, since affirmations carry personal accountability and the False Claims Act has already been applied to inaccurate cybersecurity representations.
What a NIST 800-171 penetration test covers
A typical engagement combines:
- An external penetration test of the internet-facing boundary of the CUI environment: VPN, email, remote access, and any public application that touches CUI (3.13.1, 3.13.5, 3.14.1).
- An internal penetration test from an assumed foothold in the corporate network: enclave segmentation, Active Directory abuse paths, lateral movement, and CUI discovery outside the boundary (3.13.1, 3.13.6, 3.1.5, 3.5.3).
- Web application or cloud testing where CUI is stored or processed in an application or a cloud environment such as GCC High (3.1.1, 3.1.2, 3.13.1).
- Validated vulnerability scanning across the environment, which evidences 3.11.2 and 3.11.3 on its own and feeds the periodic cadence the practice expects.
- A detection review: which of the test’s activities your logging and monitoring caught (3.3.1, 3.14.6), documented so the assessor sees the practices operating rather than merely configured.
Findings are mapped to practice numbers, written as objective evidence a C3PAO can read directly, and retested for free so the report shows closure.
Where the CMMC rollout stands
The CMMC program rule (32 CFR Part 170) took effect in December 2024, and the acquisition rule that puts CMMC clauses into contracts took effect on November 10, 2025, beginning a phased rollout. In July 2026 the Department paused the third-party (C3PAO) and government-led assessment requirements pending a program review, allowing only self-assessment designations while the review runs. Two things did not pause: DFARS 7012’s requirement to implement SP 800-171, and the SPRS self-assessment. Primes are still asking suppliers for Level 2 evidence. Confirm the current phase with your contracting officer, and use the interval to close gaps, because self-assessments filed now will be examined when certification resumes.
Frequently asked questions
Can our internal IT team run the test? For 3.12.1 the assessment should be objective, and assessors give far more weight to an independent tester’s report than to a self-run scan. An external firm also supplies the documented tester qualifications assessors ask about.
How often should we test? Annually at minimum, after significant changes to the enclave or its boundary, and before any scheduled C3PAO assessment. Vulnerability scanning (3.11.2) runs more often, typically monthly or quarterly.
Do we need Level 3 style testing? Not for Level 2. SP 800-172, which underlies Level 3, requires penetration testing explicitly and with more adversarial depth. A Level 2 contractor that tests annually is well positioned if Level 3 requirements arrive in a future contract.
How much does it cost? Most engagements combine our external test (from $4,200) and internal test (from $6,000) scoped to the CUI environment, with application or cloud testing added where CUI lives there, quoted as one fixed price in writing from your scope details. Starting prices for every service are on our pricing page.
Preparing an SPRS submission or a C3PAO assessment? Scope a CMMC assessment and we will map the test to your enclave boundary and the practices your assessor will ask about.
Written by
Invadel Team
Senior penetration testers writing from real engagements, the same team that scopes, tests, and reports for our clients. About Invadel →