Blog · M.21 · Compliance

CMMC penetration testing requirements explained

CMMC - the US Department of Defense's Cybersecurity Maturity Model Certification - exists to verify that the defense supply chain actually protects sensitive government information, not just claims to. Built on NIST SP 800-171, its intent is to confirm safeguards work, not merely exist. It doesn't shout “pentest” in one universal control, but its higher levels and 800-171 basis include security-assessment requirements that testing satisfies. Here's the model, the levels, who must comply, and how testing supports certification.

CMMCNIST SP 800-171CUIDefense Supply ChainUS DoD
CMMC: US DoD Supply-chain Certification · Protects CUI / FCI · Built on NIST SP 800-171 · Tiered Levels · Independent Assessment · Testing Validates Controls CMMC: US DoD Supply-chain Certification · Protects CUI / FCI · Built on NIST SP 800-171 · Tiered Levels · Independent Assessment · Testing Validates Controls
// TL;DR

CMMC (Cybersecurity Maturity Model Certification) is the US Department of Defense framework verifying that the defense industrial base - contractors and subcontractors - protects Controlled Unclassified Information (CUI) and Federal Contract Information (FCI). It's built largely on NIST SP 800-171 (plus advanced practices at the top level) and uses tiered maturity levels, with independent third-party assessment at higher levels. It doesn't state “penetration test” as one universal mandate, but its security-assessment requirements and the intent to verify controls actually work mean testing is a standard, expected way to demonstrate control effectiveness. Who complies: any DIB business handling that information under DoD contracts - the requirement flows down through subcontracts. Confirm your target level; it dictates the controls and the validation depth. Detail below; related is NIST CSF.

// 01 What CMMC is

CMMC stands for Cybersecurity Maturity Model Certification - a framework created by the US Department of Defense to verify that companies in the defense industrial base (the contractors and subcontractors that make up the defense supply chain) adequately protect sensitive government information, in particular Controlled Unclassified Information (CUI) and Federal Contract Information (FCI). The key shift: rather than relying on a company's own self-attestation alone, CMMC introduces defined levels of maturity and, for higher levels, independent third-party assessment against a set of security practices drawn largely from NIST SP 800-171. The point is to give the DoD assurance that its suppliers meet a consistent, verifiable standard as a condition of holding relevant contracts - moving cybersecurity from a promise to a checked prerequisite.

// 02 The NIST SP 800-171 basis & where testing fits

CMMC is built on the security requirements in NIST SP 800-171 (with additional practices at the highest level), and its whole intent is to verify that safeguards actually work, not just exist on paper - the same “prove it” philosophy behind the NIST CSF. So while CMMC doesn't contain a single universal control that says the words “penetration test,” its higher levels and 800-171 basis include security-assessment requirements that testing is used to satisfy, and organisations pursuing certification commonly use penetration testing to validate that their controls protect CUI effectively. An organisation should confirm the exact requirement for its target level - but in practice penetration testing is a standard and expected way to demonstrate the assessed controls are effective, and is widely treated as part of preparing for and maintaining certification, exactly as with other framework requirements.

// 03 The levels & who complies

L1

Foundational

Basic safeguarding of Federal Contract Information - a set of foundational practices.

L2

Advanced

Aligns with the full NIST SP 800-171 requirements for CUI; involves independent assessment.

L3

Expert

Adds further advanced practices against the most capable threats.

DIB

Who complies

Any DIB contractor/subcontractor handling CUI/FCI - the requirement flows down through subcontracts.

CMMC is structured into maturity levels of increasing rigour: the lowest covers basic FCI safeguarding, the middle aligns with the full 800-171 requirements for CUI and involves independent assessment, and the highest adds advanced practices against the most capable threats. The higher the level, the more comprehensive the practices and the more formal the assessment. It applies across a very wide range of businesses - from large prime contractors to small specialist suppliers deep in the chain - because the requirement flows down through subcontracts. The level a company must meet depends on the sensitivity of the information it handles; any business wanting to win or keep defense-related contracts involving that information must achieve and maintain the required level.

// 04 How testing supports certification

Because the level dictates both the controls to implement and the depth of validation, the practical path is: determine your target level, implement the corresponding 800-171-based practices, and then validate that they actually protect CUI. Penetration testing does the validation work - it demonstrates that the safeguards resist real attack rather than merely appearing in a policy document, generating the evidence assessors and the certification process expect. Findings feed a remediation plan and are retested to closure, and the report can be mapped to the relevant practices to make the evidence explicit. Non-US readers should note CMMC is US-DoD-specific, but the pattern - a maturity model built on a control catalogue, validated by testing - mirrors how GCC regulators like the NCA operate. Engagements follow our methodology; scope carefully around the CUI environment as our scoping guide describes.

// 05 Frequently asked questions

Does CMMC require penetration testing?

There's no single universal control that says the words "penetration test," but CMMC's higher levels and its NIST SP 800-171 basis include security-assessment requirements that testing is used to satisfy, and organisations pursuing certification commonly use testing to validate that controls protect CUI effectively. The intent is to verify safeguards actually work, not just exist. Confirm the exact requirement for your target level, but testing is a standard, expected way to demonstrate control effectiveness.

What is CMMC?

Cybersecurity Maturity Model Certification - a US Department of Defense framework verifying that companies in the defense industrial base (contractors and subcontractors) adequately protect sensitive government information, especially Controlled Unclassified Information and Federal Contract Information. Rather than self-attestation alone, it uses defined maturity levels and, at higher levels, independent third-party assessment against practices drawn largely from NIST SP 800-171, as a condition of holding relevant contracts.

Who needs to comply with CMMC?

Organisations in the US defense industrial base - contractors and subcontractors handling sensitive DoD information such as CUI or FCI on defense contracts. It spans large primes to small suppliers deep in the chain, because the requirement flows down through subcontracts. The level a company must meet depends on the sensitivity of the information it handles. Any business wanting to win or keep such contracts must achieve and maintain the required level.

What are the CMMC levels?

Maturity levels of increasing rigour: the lowest covers basic safeguarding of Federal Contract Information with foundational practices; the middle aligns with the full NIST SP 800-171 requirements for protecting CUI and involves independent assessment; the highest adds advanced practices against the most capable threats. The higher the level, the more comprehensive the practices and formal the assessment. Determine which level your contracts demand - it dictates both controls and validation depth.

// 06 Related reading

UG

Usama Gul

Founder & Penetration Testing Lead, CyberFortify

Delivers penetration tests that validate NIST SP 800-171-based controls around Controlled Unclassified Information — generating the control-effectiveness evidence CMMC certification expects.

Pursuing CMMC certification?

We deliver penetration tests that validate your NIST SP 800-171-based controls around CUI — proving safeguards resist real attack, not just exist on paper, and generating the evidence certification expects.

Scope a CMMC-support test → Requirements by framework →