Skip to content

Compliance

CMMC Level 2
Penetration Testing

The DoD certification program for contractors handling Controlled Unclassified Information.

Component tests from $4,200, one fixed quote for your scope, free retest included. See all pricing →

Get a Fixed Quote

Three fields. A senior tester reads it and replies within one business day.

Prefer the full scoping questionnaire? 
OSCP & OSCE3 certified testers150+ years combined experienceOnboarding within 24 hoursFree retest includedOur methodology

When you need it

When you need CMMC level 2 penetration testing

The situations that bring teams to this engagement, and where it fits alongside the rest of your program.

  • A prime contractor asked for your CMMC status, or a solicitation you want to bid on carries a CMMC Level 2 requirement.
  • Your self-assessment SPRS score is due and you want technical evidence behind the practices you marked implemented.
  • A C3PAO assessment is scheduled and you want to find the gaps before the assessor does.
  • You scoped CMMC to a CUI enclave and nobody has tested whether the enclave boundary actually holds.
  • Level 3 is on the horizon, where NIST SP 800-172 makes penetration testing explicit, and you want the baseline now.

Levels

CMMC Level 1, 2, and 3: where penetration testing fits

Who

Level 1
Contractors handling Federal Contract Information (FCI) only
Level 2
Contractors handling Controlled Unclassified Information (CUI)
Level 3
Contractors supporting the most critical programs

Requirements

Level 1
15 basic safeguarding practices from FAR 52.204-21
Level 2
The 110 practices of NIST SP 800-171
Level 3
Level 2 plus 24 enhanced practices from NIST SP 800-172

Assessment

Level 1
Annual self-assessment
Level 2
Third-party C3PAO certification every three years for most contracts; self-assessment for a limited set
Level 3
Government-led assessment by DIBCAC

Penetration testing

Level 1
Not required. An external test is still the fastest way to confirm the basics hold.
Level 2
Not named, but CA.L2-3.12.1 control assessment and RA.L2-3.11.2 and 3.11.3 vulnerability practices are best evidenced by one
Level 3
Explicit. SP 800-172 requires penetration testing and threat-informed assessment

What we assess

What your CMMC pentest covers

A CMMC Level 2 assessment checks that 110 NIST SP 800-171 practices are implemented. A penetration test checks that they actually hold up against an attacker, and finds the gaps assessors and adversaries both look for: flat networks, weak segmentation, and CUI outside the enclave.

External Penetration Testing

Testing the internet-facing boundary of your CUI environment the way a foreign adversary targeting the defense supply chain would.

We test for

  • Internet-facing host and service discovery
  • Exploitation of exposed services
  • VPN, email, and remote-access testing
  • Boundary protection (SC.L1-3.13.1) evidence

Internal & Enclave Testing

Testing from inside the network to prove the CUI enclave boundary you scoped is the boundary an attacker experiences.

We test for

  • Segmentation testing around the CUI enclave
  • Lateral movement and privilege escalation
  • Active Directory abuse paths
  • CUI discovery outside the defined boundary

Control Validation

Objective evidence that key 800-171 control families work in practice, not just on paper.

We test for

  • Access control and least privilege (AC family)
  • MFA and identification (IA.L2-3.5.3)
  • Vulnerability management (RA.L2-3.11.2, 3.11.3)
  • Audit and monitoring visibility of our activity

Assessment Evidence

The documentation your C3PAO, your SPRS submission, and your prime actually ask to see.

We test for

  • Report mapped to exercised practices
  • Remediation tracking and retest evidence
  • Tester qualifications
  • Input for your SSP and POA&M

Assessment route

C3PAO certification vs self-assessment

C3PAO certification

A Certified Third-Party Assessment Organization examines each of the 110 practices against objective evidence, interviews, and testing, and the result is recorded in the DoD’s systems for three years with annual affirmations. Most Level 2 contracts involving CUI require this route. A penetration test report is the kind of objective evidence that shortens the assessor’s questions and shows the controls operating under attack.

Self-assessment

Permitted for a limited set of Level 2 contracts where the CUI is less sensitive. The contractor scores itself against SP 800-171, submits the score to SPRS, and affirms it annually, with the senior official personally accountable for its accuracy. A penetration test turns an honest self-assessment into a defensible one, because the score rests on tested controls rather than assumptions.

Timeline

The rollout timeline and what primes are asking now

The CMMC program rule (32 CFR Part 170) took effect on December 16, 2024, and the acquisition rule that puts CMMC clauses into contracts (48 CFR, DFARS 252.204-7021) took effect on November 10, 2025, starting a four-phase rollout. Phase 1 introduced self-assessment requirements into new solicitations; Phase 2 was scheduled to begin on November 10, 2026 and bring C3PAO certification requirements to most Level 2 contracts, with Phases 3 and 4 following through 2028.

In July 2026 the Department paused the C3PAO and DIBCAC assessment requirements pending a program review, allowing only Level 1 and Level 2 self-assessment designations in requirement documents while the review runs. What has not paused is the underlying obligation: DFARS 252.204-7012 has required NIST SP 800-171 implementation for years, SPRS scores are still due, and primes are still asking their supply chain for Level 2 evidence. Confirm the current phase status with your contracting officer, and treat the pause as time to close gaps rather than a reason to wait.

Scoping

Enclave scoping: the test that saves the most money

Most contractors cut CMMC cost by scoping the assessment to an enclave: a segmented environment where CUI lives, so the 110 practices apply to it rather than the whole company. That only works if segmentation genuinely separates the enclave from the corporate network, and assessors look for exactly that. We test the boundary from the outside and from an assumed foothold inside the corporate network, hunt for CUI on file shares and mailboxes outside the enclave, and document what was reachable. If the enclave holds, you have proof; if it does not, you have found out before the assessor did, at a fraction of the cost of a failed assessment.

Methodology

How we test

Full methodology →

Every engagement follows the Penetration Testing Execution Standard and the relevant OWASP guides.

These are the phases your compliance test runs through.

  1. 01

    Scope the boundary

    The systems your framework actually covers, and nothing you would pay to test twice.

  2. 02

    Test

    The component penetration tests run to PTES and OWASP standards by senior testers.

  3. 03

    Map to controls

    Every finding tied to the requirement or control it evidences.

  4. 04

    Report for the auditor

    Evidence formatted the way your assessor, examiner, or QSA expects to read it.

  5. 05

    Fix & retest

    A free retest so the audit shows closed findings, not open ones.

How it works

How your engagement runs

From scope through the final retest, your team stays in the loop at every step, with findings tracked live in our platform.

  1. 01

    Scope the enclave

    We map your CMMC assessment boundary: CUI assets, security protection assets, and the segmentation between them.

  2. 02

    Test the controls

    External and internal testing that exercises your 800-171 controls the way a real adversary would.

  3. 03

    Assessor-ready report

    Findings mapped to the practices they touch, formatted as objective evidence for your C3PAO.

  4. 04

    Fix & retest

    Close the findings, then a free retest so remediation is documented before assessment day.

Proof

Proof in the field

Every engagement is confidential, so the work below is anonymized to sector and engagement type. The findings and outcomes are real.

All case studies →

Free

Retest on every penetration test

150+

Years combined experience

13

Senior in-house specialists

24h

Onboarding after signing

Fintech · Payments

Web Application Penetration Test

High risk

Critical: a remote code execution flaw in the application’s web framework that could have given an attacker full control of the server. We escalated it to the development team while the test was still running.

Outcome. The critical RCE was reported and remediated during the engagement via an emergency framework upgrade, which also closed the server-side request forgery, and the remaining findings were retested to confirmation.

1

Critical (RCE)

Mid-test

Critical remediated

2

High

Read the case study

HR & Payroll SaaS

Web Application Penetration Test

High risk

Critical: a file-inclusion flaw that let an attacker read sensitive files from the server through the application itself. High: stored cross-site scripting capable of session theft, insecure direct object references, and an authorization bypass that let an administrator create or delete organization owners.

Outcome. Delivered a remediation plan sequenced by real business impact, critical and high findings first, with a complimentary retest to verify every fix.

28

Findings

1

Critical

5

High

Read the case study

FAQ

Frequently asked questions

What teams most often ask before CMMC Level 2 testing.

Still have questions? 
01Does CMMC Level 2 require penetration testing?

Level 2 does not name penetration testing as one of its 110 practices, but CA.L2-3.12.1 requires you to periodically assess your security controls for effectiveness, and RA.L2-3.11.2 and 3.11.3 require you to scan for and remediate vulnerabilities. A penetration test is the strongest objective evidence for those practices, and it is how mature contractors prove the controls work before a C3PAO checks. At Level 3, NIST SP 800-172 makes penetration testing an explicit requirement, so testing at Level 2 also positions you for that step.

02Who needs CMMC Level 2?

Defense contractors and subcontractors that handle Controlled Unclassified Information (CUI). The CMMC program rule took effect in December 2024, and since late 2025 CMMC requirements have been phasing into new DoD solicitations, so primes are already asking their supply chain for Level 2 status. Most Level 2 contractors need a certification assessment by a C3PAO every three years; a smaller set of contracts allows self-assessment.

03How does a penetration test help our C3PAO assessment?

Assessors verify each practice against objective evidence, and interviews plus screenshots only go so far. A penetration test report shows the controls operating under real attack: MFA that resists bypass, segmentation that actually contains movement, and logging that catches the activity. It also finds the problems you want to fix before assessment day rather than during it, such as CUI on file shares outside your enclave.

04Can you test our CUI enclave scoping?

Yes, and it is usually the highest-value part of the test. Most contractors reduce cost by scoping CMMC to an enclave, but that only works if segmentation genuinely separates the enclave from the rest of the network. We test the boundary from the outside and from an assumed foothold inside your corporate network, so you know before the assessor asks whether the enclave holds.

05How much does CMMC penetration testing cost?

Most CMMC engagements combine our external network test (from $4,200) and internal network test (from $6,000) scoped to the CUI environment, with web application testing (from $5,200) added when a CUI-handling application is in scope. You get one fixed price in writing from your scope details, and starting prices for every service are on our pricing page.

06Can you help with our System Security Plan and POA&M?

The report is written to feed both. Each finding names the NIST SP 800-171 practice it touches, so it slots into the System Security Plan as evidence of implementation or into the Plan of Action and Milestones as a documented gap with a remediation date. We do not write the SSP for you, and we do not act as your C3PAO, which keeps the test independent, but we will walk your compliance lead through where each finding lands.

Ready to test your defenses?

Talk to our team about what your CMMC Level 2 compliance requires.

Prefer the full scoping questionnaire? 

Get a Fixed-Scope Quote

Tell us what you need tested. We reply within one business day.