
Table of contents
27
By Salman Khan, OSCP+, Founder of XHack, SRT (Synack Red Team member)
Read this in 30 seconds: FedRAMP penetration testing looks like one settled rule, but 2026 quietly split it into a stricter question of timing and a bigger question of where it fits in your program.
- FedRAMP’s own Rev5 control catalog now says penetration testing sits inside a continuous Vulnerability Detection and Response duty, but almost nobody covering this topic has caught it. The catalog page for control CA-8, sourced from a control catalog last modified May 11, 2026, states plainly that penetration testing “is part of vulnerability detection and is subject to the Vulnerability Detection and Response rules,” and that callout sits on the Rev5 control page, not on a 20x-only reference, with the underlying rule reaching Rev5 certification classes B, C and D.
- Only Moderate and High baselines carry a hard FedRAMP penetration testing obligation, but Low and LI-SaaS do not. FedRAMP’s own baseline workbooks show CA-8 marked “x” in Moderate and High, and absent entirely from Low and LI-SaaS.
- The Penetration Test Guidance sets a timing window most teams discover too late, and missing it invalidates the package. Version 3 requires the initial test “no more than 6 months prior to the submission of the SAR,” then “at least every 12 months” during continuous monitoring.
- Only an accredited 3PAO can run the official test, but “accredited” here means one specific body and one specific standard. A2LA accredits the assessment firms themselves against ISO/IEC 17020, and FedRAMP says it only accepts assessments from the recognized services listed in its own Marketplace.
- Every sourced FedRAMP penetration testing price is a bundle, never a pentest-only line item. stackArmor puts a Moderate-level 3PAO assessment at $125,000 to $195,000, and that number covers the test, the SAR, and the full assessment together.
FedRAMP penetration testing is the one compliance requirement in this whole space that does not leave you guessing. There is a named control, a dedicated guidance document, a named accreditation body for the tester, and a seven-section template for how the test itself gets planned.
That specificity is also why getting it wrong is expensive. Hire the wrong tester, miss the timing window, or misread the 2026 rule changes, and you can burn months waiting on an authorization that was never going to move.
This guide walks through where FedRAMP penetration testing is required, who is allowed to run it, what a compliant report looks like, what happens to the findings afterward, and what actually changed in 2026 that almost nothing else online has caught yet.
It sits inside our wider look at penetration testing for compliance, which compares how ten major frameworks, FedRAMP included, actually treat penetration testing side by side.

FedRAMP penetration testing is the manual, expert-led security test that a cloud service provider’s system has to pass before, and after, it earns a federal authorization to operate. It is not a scan, and FedRAMP is explicit about that distinction.
FedRAMP’s own Penetration Test Guidance, Version 3, dated 06/30/2022, defines it plainly: a penetration test is “a combination of automated and manual testing of technical security controls.” The same document adds that “the penetration test should not be strictly limited to automated scanning techniques, but manual techniques as well.”
In practice, FedRAMP penetration testing means a credentialed tester actively trying to break into the cloud service offering, chaining weaknesses the way a real attacker would, not just running a scanner and handing over a CVE list. The result feeds directly into the Security Assessment Report, or SAR.
Two things set FedRAMP penetration testing apart from most other compliance frameworks. The control that requires it is specific and numbered, not a vague “test your controls” clause, and the tester has to be accredited by name, not just “qualified” in the abstract.
Every FedRAMP system is, by definition, a cloud service offering, so the technical approach draws on standard cloud infrastructure penetration testing methodology, layered with FedRAMP’s own reporting and timing rules.
Organizations chasing SOC 2 or PCI DSS alongside FedRAMP will find those frameworks structure and price penetration testing differently; see our SOC 2 penetration testing and PCI DSS penetration testing requirements guides for the comparison.
The legal hook for FedRAMP penetration testing is NIST SP 800-53 Revision 5, control CA-8, titled simply “Penetration Testing.” Its base text reads: “Conduct penetration testing [Assignment: organization-defined frequency] on [Assignment: organization-defined system(s) or system components],” leaving frequency and scope open for FedRAMP to define.
CA-8’s supplemental guidance already separates it from a scan: penetration testing “goes beyond automated vulnerability scanning” and needs testers “with demonstrable skills and experience.” A related enhancement, CA-8(1), “Independent Penetration Testing Agent or Team,” requires the tester to be independent of the system being tested, and it is selected alongside CA-8 in FedRAMP’s stricter baselines.
FedRAMP closes those open parameters with its own operative document, the FedRAMP Penetration Test Guidance, Version 3, dated 06/30/2022. This is still the live, binding version as of today. A draft Version 4.0 has existed since March 2024, but it remains watermarked DRAFT throughout, with no finalization date announced, and its load-bearing content on timing, staffing, and tester credentials is essentially unchanged from v3.
Everything that follows in this guide on FedRAMP penetration testing, from timing to tester credentials to reporting structure, comes from that still-operative v3 document, cross-checked against CA-8 and CA-8(1) themselves.
Not every FedRAMP system carries a penetration testing obligation, and the difference is worth checking before you budget for one. FedRAMP publishes separate baseline-control workbooks for Low, LI-SaaS, Moderate, and High impact systems, and CA-8 does not appear in all four.
CA-8 is absent from the Low baseline, and from LI-SaaS, the lightweight baseline built for low-impact software-as-a-service. Neither baseline’s control-selection workbook marks CA-8 with an “x.”
Moderate and High are a different story. Both select CA-8 and its independence enhancement, CA-8(1), and Moderate’s workbook fills in the frequency CA-8 leaves open. The parameter cell reads, in full, “CA-8-1 [at least annually].”
That “CA-8-1” label trips people up, so it is worth separating. CA-8 is the control. CA-8(1) is the separate enhancement requiring an independent tester. “CA-8-1” is just how the spreadsheet tags CA-8’s own parameter cell, and the only thing it tells you is the frequency inside the brackets.
| Baseline | CA-8 selected? | What this means |
|---|---|---|
| Low | No | No FedRAMP penetration testing obligation under CA-8 |
| LI-SaaS | No | FedRAMP penetration testing is not required for a lightweight SaaS assessment either |
| Moderate | Yes, plus CA-8(1) | FedRAMP penetration testing required, at least annually, by an independent tester |
| High | Yes, plus CA-8(1) | Same requirement as Moderate, carried up from the Moderate baseline per the workbook’s own note |
Worth knowing where that comes from. Those workbooks are Rev4-era files, and they are still the baseline documents FedRAMP links from its own site. The Rev5 catalog page for CA-8 does not publish a replacement baseline grid at all, so the workbooks remain the only per-baseline answer FedRAMP currently gives you.
Either way, the practical takeaway holds. A cloud service offering targeting Low or LI-SaaS does not face FedRAMP penetration testing under CA-8, while one targeting Moderate or High faces a hard, recurring annual requirement once in continuous monitoring.

The Penetration Test Guidance does three jobs CA-8 leaves open: it sets a timing window, defines who can be the tester, and dictates what the report has to contain.
Section 7.0 is unambiguous about when FedRAMP penetration testing has to happen. For an initial authorization, “a penetration test must be completed by a 3PAO as a part of the assessment process described in the SAP,” and it “must be performed no more than 6 months prior to the submission of the SAR.”
Once a system enters continuous monitoring, the clock resets to an annual cycle: “additional penetration testing activities must be performed at least every 12 months, unless otherwise approved by an authorizing body with documented rationale.” Miss that six-month pre-SAR window and your assessment package is effectively stale before it is submitted.
Appendix D covers the Rules of Engagement and Test Plan, which must exist before testing starts. Its own language is direct: the ROE and TP documents “describe the target systems, scope, constraints, and proper notifications and disclosures of the Penetration Test,” and must be “developed in accordance with NIST SP 800-115, Appendix B, and be approved by an AO prior to testing.”
3PAOs must attach a copy of the ROE to the Security Assessment Plan they submit to FedRAMP, and must justify in writing if they skip any of the attack vectors the guidance enumerates in its own Section 3. That justification has to appear in both the ROE and the final report, so an unexplained gap in coverage is visible to whoever reviews the package. Here are all seven sections, with what each one has to cover.
| Section | What it covers |
|---|---|
| 1. System Scope | Boundaries, IPs, URLs, devices, components, software and hardware in scope |
| 2. Assumptions and Limitations | Dependencies, legal constraints, and any access assumed going in |
| 3. Testing Schedule | Phases, plus initiation and completion dates |
| 4. Testing Methodology | The approach and techniques the 3PAO will use |
| 5. Relevant Personnel | System Owner, Trusted Agent, Penetration Test Team Lead, Team Members, and escalation contacts on both sides |
| 6. Incident Response Procedures | The chain of communication if something goes wrong mid-test |
| 7. Evidence Handling Procedures | How evidence is transmitted and stored afterward |
That fifth section names five distinct roles, not one point of contact: a System Owner and Trusted Agent on the CSP side, a Team Lead and Team Member on the 3PAO side, plus escalation contacts for both.
Section 6.0 lays out what a compliant FedRAMP penetration testing report must contain: system scope, attack vectors assessed, a testing timeline, tests performed and results, findings and evidence (description, impact, recommendation, risk rating, evidence), and chained attack paths. A report missing any of these is not really FedRAMP penetration testing documentation, and a 3PAO worth hiring will not hand you one that skips a section.
This is where FedRAMP genuinely diverges from most other compliance frameworks. It does not say “a qualified tester,” it names the exact accreditation body and standard, and almost no article on FedRAMP penetration testing explains what that means or how to check it.
FedRAMP’s own “3PAO Obligations and Performance Standards,” Version 3.3, dated 04/06/2023, states it directly: “FedRAMP created a conformity assessment process to recognize third party assessment organizations (3PAOs) through accreditation by the American Association for Laboratory Accreditation (A2LA).”
The standard those 3PAOs are accredited against is ISO/IEC 17020. The same document states organizations “becoming FedRAMP recognized 3PAOs must be accredited by A2LA, which follows International Standardization Organization/International Electrotechnical Commission (ISO/IEC) 17020 (as revised).” A firm cannot self-declare itself qualified to run FedRAMP penetration testing; it has to hold a specific, checkable accreditation against a named standard.
Before hiring anyone to run FedRAMP penetration testing on your cloud service offering, check the FedRAMP Marketplace assessors listing. FedRAMP’s CR26-era assessors page sends you there without hedging: “FedRAMP only accepts independent assessments that have been performed by FedRAMP Recognized independent assessment services,” which “can be found in the FedRAMP Marketplace.”
That one check separates FedRAMP penetration testing work that counts toward your authorization from work that does not. Our guide to choosing a pentest provider is a useful cross-check too, though it covers vetting any tester, not the FedRAMP-specific 3PAO accreditation covered here.
Section 8.0 points to a separate document, A2LA’s R311 “Specific Requirements” for FedRAMP, to define who can lead the work. R311 names three personnel types, and the one that matters most here is the Penetration Tester role itself.
R311 requires a penetration tester who “has the technical competence to be able to complete a penetration test in accordance with FedRAMP Penetration Test Guidance and requirements,” plus two years of penetration testing experience as the lead penetration tester, plus one certification from a named list that includes CISSP, GPEN, CEH, CompTIA PenTest+, OSCP, OSWE, OSEP, eCPPT, and Burp Suite Certified Practitioner, among others.
Staffing has a floor too: High, Moderate, and Low assessments need at least three 3PAO team members, while Readiness and LI-SaaS assessments can run with a minimum of two.
| Role | Minimum requirement |
|---|---|
| Senior Assessor | 5+ years assessment experience, CISSP plus one additional listed credential |
| Penetration Tester | 2+ years as lead tester, plus one certification from a named list (OSCP, GPEN, CEH, CompTIA PenTest+, and others) |
| Junior Assessor | One certification from a separate, shorter list |
R311 was last updated on 07/27/2026, adding a new credential option and expanding the penetration tester list, so it is a recently maintained document, not a stale reference.
FedRAMP penetration testing does not end when the report ships. What happens to the findings afterward is where a lot of authorization timelines quietly stall.
The Penetration Test Guidance itself contains no standalone “retest” clause, in the live v3 or in the v4.0 draft. That does not mean findings just sit there.
Pentest findings get carried into the SAR’s Risk Exposure Table, then into the Plan of Action and Milestones, or POA&M, where FedRAMP’s real remediation clock lives, explicit and quantified.
FedRAMP’s own POA&M Template Instructions state the clock in plain numbers: “High and critical risk findings must be remediated within 30 days of discovery,” “Moderate findings must be remediated within 90 days of discovery,” and low-risk findings get 180 days. Closing a finding out requires “evidence of remediation… verified by a 3PAO during periodic assessments.”
That 3PAO verification step is, functionally, the retest the guidance never explicitly names. The Penetration Test Guidance never uses the word “retest,” but a 3PAO confirming your fix during a periodic assessment does the same job.
Dragging your feet on that clock has teeth. FedRAMP’s Continuous Monitoring Playbook, Version 1.0, dated 11/17/2025, ties overdue POA&M items to formal escalation: five or more high-impact findings aged past 30 days trigger one level, past 60 days a stricter one, and ten or more moderate findings aged past 90 or 120 days escalate the same way.
Those thresholds are the part worth writing down. An unresolved FedRAMP penetration testing finding does not just sit on a list looking bad, it ages into a formal escalation on a schedule nobody has to remember to trigger.

This is the part of FedRAMP penetration testing that almost every other guide has missed, and it comes straight off FedRAMP’s own control catalog rather than out of a press release.
FedRAMP’s Consolidated Rules for 2026, known as CR26, formally launched on June 25, 2026. FedRAMP’s own announcement describes it as “the central reference point for how FedRAMP will evaluate certification submissions,” not a minor administrative update.
FedRAMP’s current Rev5 control-catalog page for CA-8, which draws the control from NIST SP 800-53 Revision 5.2.0 with a catalog last modified May 11, 2026, carries its own “FedRAMP Guidance” callout stating: “Penetration testing is part of vulnerability detection and is subject to the Vulnerability Detection and Response rules.”
That sentence sits on the Rev5 page, explicitly labeled for Rev5 cloud service providers, not tucked away on a 20x-only reference page. The neighboring control, CA-7, “Continuous Monitoring,” carries a parallel callout pointing to the same family of rules.
The Vulnerability Detection and Response rule set, VDR, applies across both FedRAMP tracks by certification class: “20x Framework: Classes A, B, and C” and “Rev5 Framework: Classes B, C, and D.” So this is not a narrow, 20x-exclusive change. The rule names three of the four Rev5 certification classes, which is what puts it in front of CSPs who never touched the 20x track.
The rule itself, VDR-CSO-DET, requires providers to “systematically, persistently, and promptly discover and identify vulnerabilities… using appropriate techniques such as assessment, scanning, threat intelligence, vulnerability disclosure mechanisms, bug bounties, penetration testing, incident response, automated control testing, supply chain monitoring, and other relevant capabilities.” Inside that rule, penetration testing is one listed technique among several, not a separately named mandatory control of its own.
The rollout has its own dates. Optional adoption opened on July 4, 2026, the obtain and maintain deadlines both land on December 7, 2026, and the grace period ends on March 7, 2027.
So what does this actually change for FedRAMP penetration testing. The annual 3PAO test is still there. The Penetration Test Guidance v3 is still live, the R311 tester rules are still in force, and the Rules of Engagement template is still operative.
What has changed is how FedRAMP frames the test: one input feeding a bigger, continuous obligation, not a once-a-year checkbox on its own, a meaningful shift even though the annual cadence has not been formally retired.
One more document worth a brief mention: RFC-0012, FedRAMP’s “Continuous Vulnerability Management Standard,” remains a draft. Its own text says plainly, “This is a draft standard released for public comment; it does not apply to any FedRAMP authorization and MUST NOT be used in draft form.” It does not name penetration testing at all, so keep its numbers separate from the POA&M’s 30/90/180-day clock above.
If you take one thing from this section, take this: if your advisor is still describing FedRAMP penetration testing as a standalone annual control with no connection to continuous vulnerability work, their mental model predates June 2026.

Every FedRAMP penetration testing figure with a real source behind it is bundled. The pentest-only numbers that float around are vendor estimates with nothing underneath them, because the test does not get bought or delivered on its own, only as part of a full 3PAO assessment alongside the SAR.
stackArmor, a FedRAMP advisory and consulting firm (not itself a 3PAO), publishes some of the more concrete numbers available. It puts a Moderate-level 3PAO assessment, bundling the penetration test and SAR submission together, at $125,000 to $195,000. An LI-SaaS-level assessment runs $30,000 to $45,000, using the same bundled structure.
| Engagement type | Bundled cost range | What is included |
|---|---|---|
| Initial 3PAO assessment, general | $100,000 to $300,000 | Labelled by stackArmor as assessment-specific, with no breakdown published |
| Moderate-level 3PAO assessment | $125,000 to $195,000 | FedRAMP penetration testing plus SAR submission |
| LI-SaaS-level 3PAO assessment | $30,000 to $45,000 | Bundled assessment, lighter scope (note: LI-SaaS carries no CA-8 obligation, so this figure is not really pricing FedRAMP penetration testing at all) |
| Annual 3PAO reassessment | $75,000 to $125,000 per year on the page cited above, $50,000 to $150,000 per year on stackArmor’s other FedRAMP cost page | Ongoing continuous monitoring assessment |
Named 3PAOs themselves stay quiet about pricing. Coalfire, a 3PAO, publishes no cost figures on either of its public FedRAMP pages, only a general return-on-investment claim, which is fairly typical: FedRAMP penetration testing pricing tends to come from advisory firms quoting ranges, not from 3PAOs publishing rate cards.
A-LIGN, Fortreum, Kratos, and Schellman are the other names that come up when a CSP shops for FedRAMP penetration testing, and none of them put a number on a public page. One vendor, Qualysec, publishes a granular Low/Moderate/High breakdown with no sources or methodology behind it, so treat it as an unsupported estimate.
What actually drives the number is impact level, the number of in-scope systems, whether it is an initial assessment or an annual reassessment, and how much SSP work the 3PAO bundles in alongside the test.
FedRAMP publishes no official list of rejection reasons, so what follows is practitioner and vendor consensus rather than a government-issued list. It is still worth having, because the same handful of FedRAMP penetration testing problems keep turning up in the accounts of people who run these engagements.
Every one of these is avoidable with the same fix: scope the boundary precisely, coordinate the ROE properly, insist on evidence-backed findings, retest before submission, and watch the POA&M clock like any other deadline with real consequences.
These three terms get used almost interchangeably in casual conversation, and that looseness causes real confusion when a CSP is scoping work.
A vulnerability scan is automated and tool-driven. It checks for known weaknesses at speed and scale, but on its own it does not satisfy CA-8, no matter how thorough the scanner’s coverage claims are.
FedRAMP penetration testing is the CA-8-specific exercise this whole guide has covered: manual plus automated testing, performed by a 3PAO’s credentialed tester, following the timing and reporting structure the guidance lays out.
A full 3PAO assessment is the entire package: SSP review, control testing across the whole baseline, FedRAMP penetration testing as one component inside it, and the resulting SAR. FedRAMP penetration testing is a piece of the assessment, never the whole thing, which is exactly why every cost figure you will find quotes “the assessment,” not the test alone.
Keeping these three straight matters when you are budgeting or scoping work. A vendor quoting you a number for FedRAMP penetration testing that looks unusually low may actually be quoting the scan, not the manual testing CA-8 actually requires.
For what a full engagement looks like outside FedRAMP’s specific rules, our penetration testing checklist walks through the general process phase by phase, and our VAPT services buyer guide covers how to scope and compare providers more broadly.
So yeah, here’s where we talk about what XHack brings to the table.
Let’s be direct: XHack is not a 3PAO, and XHack is not A2LA-accredited. XHack cannot perform the official FedRAMP penetration testing engagement that CA-8 requires, whether initial or annual. That test has to come from an accredited 3PAO, full stop.
What XHack actually does is different and still useful: human-led penetration testing, with XHack AI agents working alongside our testers only when a client explicitly permits it and at no extra cost, run on a cloud service offering before it ever reaches a 3PAO’s desk. Think of it as a pre-assessment readiness test: a CSP runs it on the same application and infrastructure that will eventually go in front of a 3PAO, fixes what it finds, and walks into the official engagement with a cleaner baseline.
Our Comprehensive tier, starting at $12,000, is the closest fit by scale: up to 20 unauthenticated web apps or 3 authenticated web apps, or up to 200 host IPs, across internal and external scope. Enterprise, custom-quoted, fits ongoing hygiene between annual 3PAO reassessments, with continuous or quarterly cadence, red team work, SOC coverage, and incident response layered in.
Both tiers are practice, not evidence. Neither goes into a SAR, and neither satisfies CA-8 in any form. What both do is catch the scope gaps and missing evidence the common-mistakes list above describes, before your 3PAO finds them.
Privacy matters here too: XHack does not store user data and is privacy-focused by design. Pentest chats and session data stay on your own local computer, and you can delete them any time.
Want a fixed-price quote scoped to your pre-assessment needs? Request one.
Prefer to talk it through first? Book a free consultation, even if it ends with you deciding a 3PAO relationship is all you need right now. Brutal honesty is kind of our thing.
FedRAMP penetration testing is the manual, expert-led security test required under NIST SP 800-53 control CA-8 for Moderate and High baseline cloud systems. It combines automated and manual techniques, has to be performed by an accredited 3PAO, and follows the timing and reporting rules set out in FedRAMP’s Penetration Test Guidance, Version 3.
Any cloud service provider pursuing a Moderate or High baseline must complete it, because CA-8 and its independence enhancement, CA-8(1), are both selected there. Low and LI-SaaS baselines do not carry the CA-8 obligation, so it is not required at those lighter tiers.
The initial test must happen no more than 6 months before the SAR is submitted. After that, once continuous monitoring begins, FedRAMP penetration testing repeats at least every 12 months, unless an authorizing body approves a different schedule.
Only a 3PAO accredited by A2LA against ISO/IEC 17020, with a team lead holding a credential such as OSCP, GPEN, or CEH from A2LA’s R311 document, can run FedRAMP penetration testing. Check the FedRAMP Marketplace’s assessors listing before hiring anyone.
Findings flow into the SAR’s Risk Exposure Table and then the POA&M, where FedRAMP’s remediation clock applies: high and critical within 30 days, moderate within 90 days, low within 180 days. A 3PAO must verify the fix during a periodic assessment before closure.
It changes how the requirement is framed rather than removing it. FedRAMP’s current Rev5 control catalog states that penetration testing is now part of a continuous Vulnerability Detection and Response obligation, a reframing that applies to Rev5 classes as well as 20x classes, while the Penetration Test Guidance, the 3PAO tester rules, and the annual cadence stay active and unchanged.
There is no credibly sourced standalone price for the test itself, because every figure with a real source behind it bundles it with the SAR and the full 3PAO assessment. stackArmor quotes a Moderate-level bundled assessment at $125,000 to $195,000, and an LI-SaaS-level bundled assessment at $30,000 to $45,000, with annual reassessments quoted between $75,000 and $150,000 across stackArmor’s two FedRAMP cost pages.
No, not for the official authorization or continuous-monitoring test. A company can run a pre-assessment readiness test beforehand, which is what XHack offers, but that is practice, not compliance evidence, and it cannot substitute for the accredited 3PAO’s engagement. See does AI-run penetration testing satisfy compliance requirements? for the broader question of AI-run testing.
FedRAMP penetration testing is one of the most clearly defined requirements in the compliance landscape: a named control, an operative guidance document, an accredited tester, and a documented remediation clock. Moderate and High baselines require it every year, and Low and LI-SaaS do not require it at all.
The part that has not filtered through yet is the 2026 shift. FedRAMP’s own current control catalog now frames the test as one piece of a continuous Vulnerability Detection and Response obligation, not a once-a-year siloed event, spanning both the 20x and Rev5 tracks. The annual 3PAO test has not gone away, but the way FedRAMP talks about it has changed.
If you are heading into a 3PAO engagement and want your cloud service offering to walk in with a cleaner baseline, a pre-assessment readiness test is worth scoping before the official clock starts. Book a free consultation and we will walk through where that kind of testing fits around your 3PAO timeline, honestly, including if the answer is that you do not need us yet.
Categories
Related articles