Penetration testing · CMMC
How much does a pen test cost, and does CMMC require one?
Most professional penetration tests land between about $5,000 and $40,000, and scope drives almost all of the difference. CMMC Level 2 doesn't require one. Level 3 does, at least annually.
Published September 30, 2026 · Cyberuptive, Honolulu
The short answer
Plan on roughly $5,000 to $40,000 for a professional penetration test of a small to mid-sized environment, and more for multi-application, cloud-heavy, or red team work. CMMC Level 2 doesn't require a pen test. CMMC Level 3 does, at least once a year.
What pen tests cost in 2026
Published 2026 price guides line up closely:
- Synack puts typical pentest costs at "$5,000 to $100,000+, with web app tests averaging $5,000 to $30,000 and red team engagements reaching $30,000 to $150,000 or more" (Synack).
- BD Emerson says "most professional penetration tests in 2026 cost between $8,000 and $30,000 per engagement, with small external network tests starting around $4,000" (BD Emerson).
- Stingrai lists network tests at about $5,000 to $40,000 and API tests at about $6,000 to $30,000 (Stingrai).
| Test type | Typical 2026 range |
|---|---|
| Small external network | From about $4,000 to $5,000 |
| Network (external and internal) | About $5,000 to $40,000 |
| Web application | About $5,000 to $30,000 |
| API | About $6,000 to $30,000 |
| Red team | About $30,000 to $150,000+ |
Ranges from the guides cited above. They're vendor-published, not independent surveys, so treat them as a sanity check.
What drives the price
- Scope. Number of external IPs, internal subnets, applications, APIs, and cloud accounts. This is most of the variance.
- Depth. Unauthenticated versus authenticated testing, and whether testers go after lateral movement and Active Directory abuse once inside.
- Microsoft 365 and identity. Conditional access, Entra ID roles, and mail flow are common attack paths and are worth scoping explicitly.
- Social engineering. Phishing and phone pretexting add time and coordination.
- Retesting. Some quotes include a retest of fixed findings. Many don't. Ask.
- Reporting. A report mapped to CMMC, PCI DSS, or HIPAA takes more work than a raw findings list.
A quote far below the ranges above is usually an automated scan with a pen test label. That has value, but it's a different product.
Does CMMC require a pen test?
Levels 1 and 2: no. Level 2 is built on the 110 requirements of NIST SP 800-171 Rev. 2, which don't include penetration testing. Level 2 does require vulnerability scanning (3.11.2), periodic security assessments (3.12.1), and continuous monitoring (3.12.3). A pen test is one practical way to produce evidence for 3.12.1 and to find the gaps your self-assessment didn't.
Level 3: yes. DoD's CMMC model lists requirement CA.L3-3.12.1e, Penetration Testing: "Conduct penetration testing at least annually or when significant security changes are made to the system, leveraging automated scanning tools and ad hoc tests using subject matter experts" (DoD CIO CMMC Model Overview). It comes from NIST SP 800-172 requirement 3.12.1e (NIST SP 800-172).
Level 3 is on hold with the rest of the CMMC phases after the July 13, 2026 suspension (Inside Government Contracts). If your programs are likely Level 3 candidates, an annual test now gives you a baseline and a year of remediation history.
Who else asks for one
Even when CMMC doesn't, other parties may: PCI DSS Requirement 11.4 requires penetration testing (Stingrai), and cyber insurers and prime contractors sometimes ask for a recent report. If you're doing one anyway, scope it so the same report serves every audience.
Fixed scope, fixed price
Get a pen test quote you can compare
Send us your external IP count, number of apps, and whether you want internal and Microsoft 365 testing. We'll return a fixed-scope quote with retesting included.
How to get an accurate quote
Have these ready before you call anyone:
- Count of external IPs and domains.
- Number of web apps and APIs, and whether you can give testers credentials.
- Internal network size and whether testers get a VPN or an on-site drop box.
- Microsoft 365 or Google Workspace tenant in scope, yes or no.
- Social engineering, yes or no.
- Which frameworks the report needs to map to.
- Whether retesting is included.
Where Cyberuptive fits
We run manual penetration tests across external and internal networks, web applications, cloud, and Microsoft 365, following PTES with NIST SP 800-115 alignment, with findings mapped to CMMC, PCI, HIPAA, and NCUA and retesting of fixed findings included. See penetration testing services. If your immediate goal is a better SPRS score, start with how to raise it during the Phase 2 pause.
Frequently asked questions
How much does a penetration test cost in 2026?
Most professional tests run roughly $5,000 to $40,000 per engagement, with complex multi-application, cloud, or red team work reaching $100,000 or more. Published 2026 guides put a standard web application test around $5,000 to $30,000 and small external network tests starting around $4,000 to $5,000.
Does CMMC Level 2 require a penetration test?
No. CMMC Level 2 is based on the 110 requirements of NIST SP 800-171 Rev. 2, which don't include penetration testing. A pen test can still be useful evidence for periodic security assessments (3.12.1) and risk assessment (3.11.1), and it often finds gaps your self-assessment missed.
Does CMMC Level 3 require a penetration test?
Yes. CMMC Level 3 requirement CA.L3-3.12.1e requires penetration testing at least annually or when significant security changes are made, using automated scanning tools and ad hoc tests by subject matter experts.
Is a vulnerability scan the same as a pen test?
No. A vulnerability scan is automated and lists known weaknesses. A penetration test uses people to exploit and chain weaknesses to show what an attacker could actually reach. CMMC Level 2 requires vulnerability scanning (3.11.2); it doesn't require pen testing.
What makes a pen test cost more?
Scope (number of IPs, apps, APIs, and cloud accounts), depth (black box versus authenticated, internal versus external), social engineering, retesting, compliance-specific reporting, and the skill of the testers. Tests quoted well under $4,000 are often automated scans labeled as pen tests.