Selling into US Defence? The Penetration Testing in Your CMMC Evidence Pack

Selling into US Defence? The Penetration Testing in Your CMMC Evidence Pack

By EJN Labs · 11 Aug 2026 · 8 min read

CMMC does not name penetration testing as a Level 2 control, but NIST SP 800-171 requires vulnerability scanning and periodic security assessments, and US defence buyers routinely ask for penetration test reports as assurance evidence. A CREST-accredited test of the systems handling Controlled Unclassified Information, typically 4 to 6 days at £4,400 to £8,400, gives UK suppliers evidence that satisfies assessors and primes.

Why CMMC / NIST 800-171 security assurance now reaches UK suppliers

CMMC obligations flow down through contracts, which is why NIST 800-171 assurance now reaches UK suppliers. The Cybersecurity Maturity Model Certification is the US Department of Defense’s mechanism for verifying that its supply chain protects Controlled Unclassified Information (CUI), regardless of where a supplier sits.

If a UK engineering firm, software vendor or MSP supplies a US prime contractor, the prime’s DFARS clauses and CMMC obligations arrive in the subcontract. A Manchester machining shop or a London defence software house can find itself asked to evidence 110 NIST SP 800-171 controls before a purchase order is signed.

The commercial stakes are simple. CMMC is mandatory where the contract requires it: no certification or credible self-assessment score, no contract. Penetration testing sits inside that evidence pack as one of the strongest technical proofs a supplier can offer, which is why bid leads and security controllers keep asking the same question: what testing do we actually need, and what will an assessor accept?

What CMMC and NIST 800-171 actually require, honestly

CMMC Level 2 requires implementation of the 110 security requirements in NIST SP 800-171 Revision 2: 32 CFR 170.14(c)(3) states that the Level 2 security requirements are identical to the requirements in NIST SP 800-171 R2. Whether that is verified by self-assessment (32 CFR 170.16) or by a certification assessment from a third-party assessment organisation (C3PAO, 32 CFR 170.17) depends on the CMMC status DoD sets for the procurement (32 CFR 170.3(d)). None of those requirements says “carry out a penetration test” in so many words.

Precision matters here, because your claims will be read closely. What the 110 requirements do demand is periodic vulnerability scanning, remediation of identified vulnerabilities, and periodic assessment of whether your security controls are effective in operation.

That is where penetration testing earns its place. A scan tells you a patch is missing; a penetration test demonstrates whether your access controls, segmentation, monitoring and incident response actually hold up against a skilled attacker. For the security assessment requirements, an independent test report is far more persuasive evidence of control effectiveness than a self-attestation. At CMMC Level 3, which draws on the enhanced requirements of NIST SP 800-172, penetration testing and adversary-simulation style exercises become an explicit expectation rather than supporting evidence. Most UK suppliers will face Level 2, where the honest position is: testing is contractually driven and assessor-expected, not named in the control text.

Primes add their own layer. Many issue supplier security questionnaires that ask directly for the date and summary of your last penetration test, and a blank answer triggers a follow-up call at best and a scoring penalty at worst.

What penetration testing belongs in the evidence pack

Testing of the CUI boundary belongs in the evidence pack: the systems that store, process or transmit Controlled Unclassified Information, plus anything that can reach them. That boundary is what CMMC assessments care about, not a generic test of your marketing website.

For a typical UK supplier we would prioritise:

  • External infrastructure: the internet-facing perimeter of the environment holding CUI, including VPN endpoints, remote access and mail routing.
  • Cloud configuration: many UK suppliers build a CUI enclave in Microsoft 365 GCC-adjacent or Azure environments; misconfigured identity and conditional access is the most common finding class we see.
  • Internal segmentation: proof that the CUI enclave is genuinely separated from the general corporate network, tested from an assumed-breach position on the corporate side.
  • Applications and APIs: any software you develop that handles CUI or integrates with a prime’s systems.

When EJN Labs scopes a CMMC-driven engagement, we start from the supplier’s System Security Plan and asset inventory, walk the declared CUI boundary, and then deliberately test the assumption that the boundary is real. In practice that means attempting to reach enclave assets from the corporate LAN, from a compromised standard user account, and from the internet. Boundary failures are exactly what a C3PAO will probe, so finding them before the assessor does is the whole point of the exercise. Our penetration testing checklist covers the preparation steps that make this run smoothly.

How a CMMC-driven engagement runs

A CMMC-driven engagement starts from your System Security Plan, network diagrams and CUI data flows, agreeing the boundary, the test windows and any systems that need careful handling. Testing then follows CREST methodology, delivered by UK-based testers under UK contracts.

The methodology runs through reconnaissance, vulnerability identification, controlled exploitation and post-exploitation analysis of what an attacker could reach, so the work maps cleanly onto the evidence you need.

Reporting is where CMMC engagements differ from a standard test. Assessors and primes want three things: an executive summary a commercial officer can forward, findings mapped to the NIST SP 800-171 control families they touch, and a remediation log showing that issues were fixed and retested. We write reports with that audience in mind, and a free retest of critical and high findings is included so your pack ends with closure.

What it costs and how scope drives the price

Expect UK day rates of £1,100 to £1,400 for CREST-accredited testing, with total cost driven by the size of your CUI boundary. A supplier with a tight, well-segmented enclave pays materially less than one whose CUI is scattered across the whole corporate estate.

Penetration testing is priced by effort, and that effort translates into ranges like these:

ScopeTypical effortTypical UK cost
External infrastructure of the CUI environment3 to 5 days£3,300 to £7,000
Web application or API handling CUI4 to 6 days£4,400 to £8,400
Internal and cloud enclave assessment5 to 8 days£5,500 to £11,200
Combined evidence pack across all layers8 to 12 days£8,800 to £16,800

Most single-scope CMMC evidence engagements land in the 4 to 6 day band at £4,400 to £8,400. These are typical UK ranges rather than a quotation; the exact price depends on your boundary, and our UK penetration testing cost guide breaks down the drivers in more depth. For a figure specific to your estate, the quote form takes two minutes.

How EJN Labs approaches CMMC and NIST 800-171 testing

EJN Labs is a CREST-accredited UK penetration testing firm, certified to ISO 27001 and Cyber Essentials Plus, working entirely with UK-based testers. That combination matters for defence supply chains: your test data, findings and report never leave UK jurisdiction, and the accreditations give primes and assessors an independent basis to trust the work. Our CREST penetration testing service is the anchor for CMMC evidence engagements.

We treat the assessment as the customer. Scoping is anchored to your declared CUI boundary, findings are mapped to the control families an assessor will examine, and the report is structured so a bid lead can lift the executive summary straight into a supplier questionnaire response. The same discipline applies in other regulated sectors we test, from financial services to law firms: understand what the reviewer of the evidence needs, then test and write for that reviewer.

Frequently Asked Questions

Does CMMC require a penetration test?

Not by name at Level 2, where the 110 NIST SP 800-171 Revision 2 requirements mandate vulnerability scanning (3.11.2), remediation of what the scans find (3.11.3) and periodic assessment of whether controls are effective (3.12.1) rather than a named test. The words penetration testing do not appear anywhere in NIST SP 800-171 Revision 2. At Level 3, which draws on NIST SP 800-172, penetration testing style exercises become an explicit expectation.

A penetration test is the strongest common evidence for that periodic assessment, and in practice primes and assessors ask for test reports regardless of level.

What penetration test evidence do US primes actually ask for?

Five things: the date of your last independent penetration test, who performed it, the scope, a summary of findings and confirmation that critical issues were remediated. That is what supplier questionnaires from US primes typically ask for, whatever wording they use.

A report from a CREST-accredited firm covering the systems that handle CUI, plus a retest letter closing the serious findings, answers all of these in one pack.

What does penetration testing for CMMC / NIST 800-171 cost?

Budget £4,400 to £8,400 for most single-scope CMMC evidence engagements, which take 4 to 6 days at UK CREST-accredited day rates of £1,100 to £1,400. A combined pack covering external, internal, cloud and application layers runs 8 to 12 days at £8,800 to £16,800.

Exact pricing depends on your CUI boundary, so request a scoped quote.

Can a UK firm test our environment for a US defence contract?

Yes, a UK firm can test your environment for a US defence contract. CMMC does not require the tester to be US-based, it requires the supplier’s controls to be implemented and assessed, and for a UK supplier a UK testing firm is often the preferable choice.

The advantages are practical: testing runs in your time zone, contracts sit under English law, and findings about your CUI environment stay within UK jurisdiction, which simplifies your own data-handling story to the prime.

How often should we retest to keep the evidence pack current?

Retest annually, the working norm defence buyers expect, and after any significant change to the CUI environment, such as a new remote access route, a cloud migration or a new application handling CUI. A report older than twelve months tends to attract questionnaire follow-ups.

The underlying standard points the same way: NIST SP 800-171 expects assessment to be periodic rather than one-off.

Build the testing evidence your CMMC pack is missing

If a US prime or a C3PAO assessment is on your horizon, the fastest move is to scope a test against your CUI boundary now, so remediation and retesting are complete before anyone asks. Tell us about your environment through our CREST penetration testing quote form and we will come back with a fixed scope and price from UK-based testers.

Leave a Reply

Your email address will not be published. Required fields are marked *