Skip to content

NIST Penetration Testing Requirements: 800-53 CA-8, CSF 2.0, 800-171, 800-115 and CIS Controls Compared

What NIST requires for penetration testing: SP 800-53 control CA-8, CSF 2.0, SP 800-171 and CMMC, the SP 800-115 method, and how CIS Control 18 compares.

Invadel TeamSeptember 14, 20267 min read

“NIST requires penetration testing” is true, but the requirement lives in several documents that do different jobs. SP 800-53 is the control catalog that federal systems and most enterprise frameworks draw from; it has a control for penetration testing by name. The Cybersecurity Framework 2.0 is an outcome-based framework that expects testing without prescribing it. SP 800-171 and CMMC carry NIST controls into defense contracting. SP 800-115 is the method: how to run the test. And the CIS Controls, which many organizations use instead of or alongside NIST, have a whole control family for it. This guide takes each in turn and ends with a comparison table.

SP 800-53: control CA-8, Penetration Testing

SP 800-53 Revision 5, in the Assessment, Authorization and Monitoring family, defines control CA-8: conduct penetration testing on organization-defined systems or system components at an organization-defined frequency. The discussion text describes penetration testing as a specialized assessment that goes beyond automated scanning: testers attempt to circumvent security features, using tools and techniques adversaries would use, based on a defined scope and rules of engagement, with the goal of finding vulnerabilities that would otherwise not be found.

The control has three enhancements:

  • CA-8(1), Independent Penetration Testing Agent or Team. The test is performed by an agent or team independent of the system’s owners and developers, so that the results are not shaped by who built it.
  • CA-8(2), Red Team Exercises. Adversary simulation exercises against the organization’s protections, run under defined rules of engagement, to test the whole defensive capability rather than a single system. See red teaming vs penetration testing.
  • CA-8(3), Facility Penetration Testing. Physical testing of facilities, announced or unannounced.

Where CA-8 is selected: the NIST baselines include CA-8 at the High impact level, and CA-8(1) with it. FedRAMP requires penetration testing annually for Moderate and High systems and publishes its own penetration test guidance describing the attack vectors that must be covered. Many private-sector frameworks that map to 800-53 (including state regulations and insurer questionnaires) inherit the control regardless of impact level.

CA-8 works together with RA-5, Vulnerability Monitoring and Scanning (scan at a defined frequency and when new vulnerabilities are identified), which is the scanning counterpart, and with CA-2, Control Assessments. The distinction is the same one PCI DSS draws between scans and tests: RA-5 is frequent and automated, CA-8 is periodic and manual.

Cybersecurity Framework 2.0

The CSF does not contain a penetration testing control. It is an outcome framework, and several of its outcomes are hard to demonstrate without a test:

  • ID.RA (Risk Assessment): vulnerabilities in assets are identified, validated and recorded. A penetration test is the validation step.
  • ID.IM (Improvement): improvements are identified from evaluations, including security tests and exercises. The CSF 2.0 text explicitly names tests and exercises as sources of improvement.
  • DE.CM (Continuous Monitoring) and DE.AE (Adverse Event Analysis): a test that records whether detection fired is direct evidence for both.
  • PR.PS (Platform Security) and PR.IR (Technology Infrastructure Resilience): configuration and segmentation outcomes that a test checks from the attacker’s side.

The CSF’s Informative References map each outcome back to SP 800-53 controls, so an organization “following NIST CSF” ends up at CA-8 and RA-5 when it asks what evidence the outcome needs. Our security risk assessment guide covers the risk assessment side.

SP 800-171 and CMMC

SP 800-171 protects Controlled Unclassified Information in non-federal systems and is the basis of CMMC Level 2. Its Security Assessment family requires periodically assessing the security controls (3.12.1), developing and implementing plans of action (3.12.2), and monitoring controls on an ongoing basis (3.12.3). Revision 3 of SP 800-171 aligns the requirements more closely with SP 800-53, and its Risk Assessment family requires scanning for vulnerabilities in the system and remediating them (3.11.2 and 3.11.3 in Revision 2).

The standard does not require penetration testing by name. Assessors under CMMC Level 2 expect evidence that the assessment in 3.12.1 was real and that vulnerabilities were found and fixed, and a penetration test report is the strongest form of that evidence. Contractors handling CUI generally run an annual test for that reason. See NIST 800-171 penetration testing and our CMMC Level 2 page.

SP 800-115: how NIST says to test

SP 800-115, the Technical Guide to Information Security Testing and Assessment, is the methodology document. It defines the three assessment techniques (review, identification and analysis, and target vulnerability validation, which includes penetration testing), describes the four phases of a penetration test (planning, discovery, attack, reporting), and covers rules of engagement, data handling and reporting. It is the document PCI DSS assessors and federal agencies expect a penetration testing methodology to reference, and it is one of the two standards our methodology is built on, alongside PTES. See the Penetration Testing Execution Standard explained.

CIS Controls v8: Control 18

The Center for Internet Security’s Controls are the other common baseline, and they are more prescriptive about testing than NIST is. Control 18, Penetration Testing, has five safeguards:

  • 18.1 Establish and maintain a penetration testing program, with scope, frequency, rules of engagement and remediation requirements documented.
  • 18.2 Perform periodic external penetration tests, based on program requirements, at least annually.
  • 18.3 Remediate penetration test findings based on the enterprise’s policy for remediation scope and prioritization.
  • 18.4 Validate security measures after each penetration test: if findings were addressed by a control change, confirm the change is effective.
  • 18.5 Perform periodic internal penetration tests, at least annually.

18.1 through 18.3 apply from Implementation Group 2; 18.4 and 18.5 at Implementation Group 3. The CIS Controls also map every safeguard to NIST CSF and SP 800-53, so Control 18 is, in effect, CA-8 with the frequency filled in.

NIST vs CIS on penetration testing

Question NIST SP 800-53 (CA-8) NIST CSF 2.0 NIST SP 800-171 / CMMC L2 CIS Controls v8 (Control 18)
Requires a penetration test by name Yes No, expects tests as evidence for outcomes No, requires control assessment; test is expected evidence Yes
Frequency Organization-defined; annual under FedRAMP Not specified “Periodically” At least annually, external (18.2) and internal (18.5)
Independence of tester CA-8(1) Not specified Not specified; assessors expect it Not specified; program defines rules
Red team CA-8(2) Exercises named as improvement input Not specified Not in Control 18
Scanning counterpart RA-5 ID.RA, DE.CM 3.11.2 Control 7 (Continuous Vulnerability Management)
Remediation and validation Via CA-5 (plans of action) ID.IM 3.12.2 18.3, 18.4
Method reference SP 800-115 Informative references SP 800-115 Program document

The practical reading: if you follow NIST, write a penetration testing program that sets the frequency to annual, requires an independent tester, references SP 800-115 or PTES, and includes internal, external and retest, and you have satisfied CA-8, the CSF outcomes that depend on it, 800-171’s assessment requirement, and CIS Control 18 at once.

What the report has to show

For a NIST-aligned reader (a federal agency, a CMMC assessor, a customer’s third-party risk team using the CSF):

  • scope and rules of engagement, tied to the system boundary or asset inventory;
  • the methodology, referencing SP 800-115 and PTES;
  • tester independence from the system’s owners (CA-8(1));
  • findings with severity, the control each one implicates (CA-8, RA-5, or the CSF outcome), and remediation;
  • the retest, as the input to plans of action (CA-5) and to CIS 18.3 and 18.4;
  • whether detection responded, as evidence for DE.CM.

Our report includes a framework mapping section written for these readers; the format is on the sample report page.

Frequently asked questions

Does NIST require annual penetration testing? SP 800-53 leaves the frequency to the organization; FedRAMP sets it at annual; CIS Control 18 sets it at annual. Annual is the defensible answer under all of them. See how often you should do a penetration test.

Is a vulnerability scan enough for NIST? RA-5 requires scanning and CA-8 requires penetration testing. They are different controls. See penetration testing vs vulnerability scanning.

Does the tester need a specific certification? NIST does not name one. CA-8(1) requires independence, and assessors look for demonstrated experience.

Which should we follow, NIST or CIS? They map to each other. CIS is more prescriptive and easier to start with; NIST is what regulators and federal customers cite. Following CIS Control 18 satisfies CA-8 in practice.

The short version

NIST’s penetration testing requirement is SP 800-53 control CA-8, tested the way SP 800-115 describes, at a frequency you define and FedRAMP sets at annual, by a team independent of the system’s builders. The CSF expects the same test as evidence, 800-171 and CMMC assessors expect it as proof of control assessment, and CIS Control 18 writes the annual internal and external cadence down. One well-scoped annual engagement covers all of them. Scope a test to get it in writing.

Written by

Invadel Team

Senior penetration testers writing from real engagements, the same team that scopes, tests, and reports for our clients. About Invadel →

Find out what an attacker sees.

Tell us what to test and see your fixed price.

Prefer the full scoping questionnaire? 
Start the conversation