Affordable Pentesting Logo
CMMC 2.0 Pentest Requirements

CMMC 2.0 Pentest Requirements

CMMC 2.0 penetration testing requirements for defense contractors — Level 1 vs Level 2, what C3PAO assessors expect, and how to prepare for certification.

2026-08-24

CMMC 2.0 is the Department of Defense's certification program for contractors who handle Controlled Unclassified Information (CUI). Penetration testing is a core requirement for Level 2 certification.

CMMC 2.0 overview

CMMC 2.0 simplified the original five-level framework into three levels:

  • Level 1 (Foundational). 17 basic practices for contractors who handle Federal Contract Information (FCI). No pentest required.
  • Level 2 (Advanced). 110 practices aligned with NIST SP 800-171. Requires annual penetration testing for all CUI assets.
  • Level 3 (Expert). 110+ practices plus selected controls from NIST SP 800-172. Requires annual penetration testing.

Most defense contractors need Level 2 certification.

Pentesting requirements for Level 2

Under CMMC 2.0 Level 2, the penetration testing requirements flow from NIST SP 800-171 control 3.11.2 (risk assessment) and 3.11.3 (vulnerability monitoring):

  • Annual testing minimum. Your pentest must be current (within 12 months) at the time of your C3PAO assessment.
  • Scope must cover CUI assets. Every system that processes, stores, or transmits CUI must be in scope.
  • Remediation is required. High and critical findings must be remediated before certification.
  • Retesting evidence. Your C3PAO will want to see evidence that findings were fixed and retested.

How to prepare for a CMMC 2.0 pentest

  1. Identify your CUI boundary. Know exactly which systems handle CUI. This defines your pentest scope.
  2. Document your asset inventory. Your C3PAO will cross-reference your asset inventory with your pentest scope.
  3. Fix known issues first. Run internal scans and remediate low-hanging fruit before the pentest.
  4. Choose a compliant provider. Ensure your pentest provider delivers reports mapped to NIST 800-171 controls.

The assessment timeline

PhaseTimeline
Pre-assessment pentest2-4 weeks before C3PAO assessment
Remediation periodAfter pentest report delivered
RetestingAfter remediation complete
C3PAO assessmentPentest report must be current (< 12 months)

What Affordable Pentesting delivers

Our pentests are mapped to NIST 800-171 controls and include the evidence package your C3PAO needs. Start a pentest for your defense contracting environment or view pricing.

Related reading: NIST 800-171 Pentest Requirements