Compliance

CMMC Level 2 Penetration Testing.

NIST SP 800-171-aligned penetration testing for DoD primes and subcontractors. CUI boundary, supply chain, and identity in scope.

File · Where CMMC

Where CMMC touches penetration testing

CMMC Level 2 inherits NIST SP 800-171 control families covering access control, identification and authentication, incident response, system and communications protection, and system and information integrity. Several of those families are practically impossible to assess without manual, adversarial testing of the CUI environment.

Operator Note

CMMC fails on the chains, not the CVEs

A CMMC-flavored pentest is not a CVE checklist. The CUI boundary lives across endpoints, identity, cloud, and supply chain, and the failure modes that get DoD primes into trouble are the chains that cross those layers. The question that should keep a prime up at night is not did we patch, it is whether a subcontractor identity can reach CUI from a system the assessor will never look at. Manual operators reason about those chains; scanners do not.

File · Scope coverage

Scope coverage

  • [01] CUI boundary mapping across endpoints, network, identity, and cloud.
  • [02] Access control and identification testing against the 800-171 control set.
  • [03] Supply chain and shared-tenancy testing where CUI flows through subcontractors.
  • [04] Reporting mapped to NIST SP 800-171 controls, each finding cited to the control it implicates so C3PAOs and primes can drop it straight into the assessment.

File · FAQ

Frequently Asked Questions

Q1 Is Alacrinet a C3PAO?

We are not a C3PAO; we are the offensive testing vendor that C3PAOs and primes use for evidence inputs to the CMMC assessment.

Q2 What about DFARS 7012?

Our reports support DFARS 252.204-7012 evidence requirements for adequate security.

Q3 Can you test classified environments?

We work on CUI/CDI in compliant unclassified environments. For classified work, scope is handled case by case.

Talk to an Operator

Ready to See Your Environment the Way Attackers Do?

Real operators. Real attack paths. Real business impact. Talk to us about your security goals.