CMMC 2.0 Pentest Requirements
CMMC 2.0 penetration testing requirements for defense contractors — Level 1 vs Level 2, what C3PAO assessors expect, and how to prepare for certification.
2026-08-24
CMMC 2.0 is the Department of Defense's certification program for contractors who handle Controlled Unclassified Information (CUI). Penetration testing is a core requirement for Level 2 certification.
CMMC 2.0 overview
CMMC 2.0 simplified the original five-level framework into three levels:
- Level 1 (Foundational). 17 basic practices for contractors who handle Federal Contract Information (FCI). No pentest required.
- Level 2 (Advanced). 110 practices aligned with NIST SP 800-171. Requires annual penetration testing for all CUI assets.
- Level 3 (Expert). 110+ practices plus selected controls from NIST SP 800-172. Requires annual penetration testing.
Most defense contractors need Level 2 certification.
Pentesting requirements for Level 2
Under CMMC 2.0 Level 2, the penetration testing requirements flow from NIST SP 800-171 control 3.11.2 (risk assessment) and 3.11.3 (vulnerability monitoring):
- Annual testing minimum. Your pentest must be current (within 12 months) at the time of your C3PAO assessment.
- Scope must cover CUI assets. Every system that processes, stores, or transmits CUI must be in scope.
- Remediation is required. High and critical findings must be remediated before certification.
- Retesting evidence. Your C3PAO will want to see evidence that findings were fixed and retested.
How to prepare for a CMMC 2.0 pentest
- Identify your CUI boundary. Know exactly which systems handle CUI. This defines your pentest scope.
- Document your asset inventory. Your C3PAO will cross-reference your asset inventory with your pentest scope.
- Fix known issues first. Run internal scans and remediate low-hanging fruit before the pentest.
- Choose a compliant provider. Ensure your pentest provider delivers reports mapped to NIST 800-171 controls.
The assessment timeline
| Phase | Timeline |
|---|---|
| Pre-assessment pentest | 2-4 weeks before C3PAO assessment |
| Remediation period | After pentest report delivered |
| Retesting | After remediation complete |
| C3PAO assessment | Pentest report must be current (< 12 months) |
What Affordable Pentesting delivers
Our pentests are mapped to NIST 800-171 controls and include the evidence package your C3PAO needs. Start a pentest for your defense contracting environment or view pricing.
Related reading: NIST 800-171 Pentest Requirements
