Which frameworks require a third-party penetration test?
Three do: FedRAMP, the CSA Cloud Controls Matrix, and DORA. PCI DSS and NYDFS require a penetration test but explicitly accept an internal tester. SOC 2 and ISO 27001 require no penetration test at all. Almost every vendor page you will read on this gets it wrong in the same direction.
On this page: the matrix · the three that mean it · required but not external · not required at all · independence · what is changing · what to do
The matrix
Read “requires a pentest” and “must the tester be external” as two separate questions. Almost all of the confusion in this market comes from collapsing them into one.
| Framework | Requires a pentest? | Must the tester be external? | Interval |
|---|---|---|---|
| FedRAMP (Moderate, High) | Yes | Yes, a recognized 3PAO | Initial, then every 12 months |
| CSA CCM v4 / STAR | Yes | Yes, “independent third parties" | "Periodic”, undefined |
| DORA (EU financial) | Yes, threat-led | Effectively, internal needs regulator approval | At least every 3 years |
| PCI DSS 4.0.1 | Yes | No, internal allowed if independent | Annually and after significant change |
| NYDFS Part 500 | Yes | No, “internal or external” | At least annually |
| NIST SP 800-53 / FISMA | Yes (CA-8) | Only if CA-8(1) is selected | Organization-defined |
| SOC 2 (AICPA TSC) | No | n/a | n/a |
| ISO/IEC 27001:2022 | No | n/a | n/a |
| GDPR Article 32 | No, “testing” only | No | ”Regularly” |
The three that actually require an outside tester
FedRAMP is the strictest, and says so plainly
The FedRAMP Penetration Test Guidance sets the schedule in Section 7.0:
For each initial security authorization, a penetration test must be completed by a 3PAO as a part of the assessment process described in the SAP. This initial penetration test must be performed no more than 6 months prior to the submission of the SAR. Once within the continuous monitoring phase of the FedRAMP process, additional penetration testing activities must be performed at least every 12 months.
Section 8.0 adds that all penetration test activities must be performed by a 3PAO with demonstrated proficiency and a defined methodology, and that the team lead must hold an industry-recognized penetration testing credential. There is one nuance worth knowing before you buy: a FedRAMP-recognized 3PAO is required for systems with a JAB provisional authorization, while for an Agency authorization the guidance says this “may refer to any assessment organization designated by the agency AO.”
CSA STAR inherits it from one CCM control
The Cloud Controls Matrix is the control set behind the CSA STAR registry, and control TVM-06 in CCM v4.0 is unambiguous about who tests:
Define, implement and evaluate processes, procedures and technical measures for the periodic performance of penetration testing by independent third parties.
Note what is missing: an interval. “Periodic” is doing a lot of work, and in practice the assessor decides whether your cadence is defensible against your own risk profile.
DORA requires it, then makes internal testing hard on purpose
Regulation (EU) 2022/2554 requires in-scope financial entities to “carry out at least every 3 years advanced testing by means of TLPT” on live production systems. Article 27 is where externality bites. Internal testers are permitted only where the competent authority has approved their use, has verified that conflicts of interest are avoided, and where “the threat intelligence provider is external to the financial entity.” That is a third-party requirement written as a conditional.
Required but not external
PCI DSS names the tester’s qualities, not their employer
Requirement 11.4 asks for a tester qualified by experience or training with organizational independence from the systems being tested. The parenthetical
(not required to be a QSA or ASV)
appears repeatedly through Requirement 11.4 and the SAQs. A qualified internal resource is explicitly acceptable. The full requirement breakdown is here, including the retest clause in 11.4.4 that most firms bill separately at 10% to 25% of the original fee.
NYDFS spells out both options in one sentence
The 2023 amendment to 23 NYCRR Part 500 retitled Section 500.5 as vulnerability management and requires covered entities to conduct
penetration testing of their information systems from both inside and outside the information systems’ boundaries by a qualified internal or external party at least annually
Two directions of testing, one annual interval, either kind of tester. Anyone telling a New York covered entity that Part 500 forces them to hire an outside firm has not read the clause.
NIST makes independence an optional enhancement
This one surprises people, because FISMA and FedRAMP both build on it. The base control CA-8 in NIST SP 800-53 Rev 5 says only to conduct penetration testing at an organization-defined frequency, and its discussion states that testing “can be conducted internally or externally” and that “risk assessments guide the decisions on the level of independence required.” Externality arrives only when the CA-8(1) enhancement is selected on top:
Employ an independent penetration testing agent or team to perform penetration testing on the system or system components.
The ones that do not require a test at all
SOC 2 and ISO 27001 are the two most requested frameworks in startup procurement and neither one requires a penetration test. We have written the long version for both: SOC 2 never names it, and ISO 27001 never names it either, though A.8.8 and A.8.29 make a test the cheapest defensible evidence.
GDPR belongs in this group too. Article 32(1)(d) requires “a process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures” and stops there. No method, no tester, no interval.
The current HIPAA Security Rule is the same shape. The Evaluation standard at 45 CFR 164.308(a)(8) asks a covered entity to “perform a periodic technical and nontechnical evaluation” and never mentions penetration testing.
Independence is the real constraint
Once you stop asking “is an outside test required” and start asking “is this tester independent of what they built”, most of the matrix collapses into one practical rule. NIST defines the bar as freedom “from perceived or actual conflicts of interest with respect to the development, operation, or management of the systems that are the targets of the penetration testing.”
Perceived is the operative word. Your platform lead may be the most rigorous tester in the building, and an assessor can still discount the evidence because a reasonable reader could suspect otherwise. At ten engineers, there is generally no internal resource who satisfies that test, which is why the internal option that PCI and NYDFS allow on paper is unavailable to most startups in practice.
What each rung costs
The bands below are market prices for a single web application, taken from our penetration testing cost breakdown. The point of the table is that rung 2 is the expensive one, even though it looks free.
| Rung | Who tests | What it costs | What it unlocks |
|---|---|---|---|
| 1 | The team that built it | engineering time only | nothing that names independence |
| 2 | A separate internal team | a dedicated headcount, the largest number here | PCI 11.4, NYDFS 500.5, CA-8(1) |
| 3 | An external boutique firm | $5,000 to $30,000 per engagement | adds CSA CCM TVM-06 and DORA |
| 3 | HackZero, continuous | $299 or $499 a month, plus $2,999 per human-validated engagement | the same as any external firm |
| 4 | An accredited or recognized assessor | quoted per system; the pentest is one line inside a larger assessment | adds FedRAMP Moderate and High |
What is changing
Two moves are worth watching, because both push in the same direction.
HHS proposed a rewritten HIPAA Security Rule in January 2025 that would require vulnerability scanning every six months and penetration testing at least once every 12 months, turning the framework in the “not required” column into one in the “required” column. It does not, as proposed, require an outside tester.
DORA’s TLPT regime has been live since January 2025, and it is the first major regime to write externality as a default with internal testing as a supervised exception rather than the reverse.
What to do with this
Pick the strictest framework you are genuinely in scope for and test once to that bar. Coverage and independence both flow downhill: a test that satisfies FedRAMP’s mandatory attack vectors satisfies PCI Requirement 11.4 and any SOC 2 control you wrote about testing. Running one engagement per framework is how companies end up paying three times for evidence a single well-scoped test would have produced, and the cost breakdown for a single engagement shows what each duplicate is worth.
Then check what your buyer wants, because it is usually stricter than your framework. A report from your own team clears an auditor and stalls in a security questionnaire, and the real cost of a compliance program is mostly determined by which of those two audiences you were optimising for.
Frequently asked questions
Which frameworks actually require a third-party penetration test?
Three, in the ordinary sense of the phrase. FedRAMP requires a test performed by a FedRAMP-recognized third party assessment organization for Moderate and High systems. The CSA Cloud Controls Matrix asks for penetration testing by independent third parties in control TVM-06, which flows into CSA STAR. DORA requires threat-led penetration testing of EU financial entities and permits internal testers only if the regulator has approved them and the threat intelligence still comes from outside. Everything else either requires a test without requiring externality, or does not require a test at all.
Does SOC 2 require a third-party penetration test?
No, and it does not require a penetration test at all. The Trust Services Criteria never use the phrase, so no clause can require a particular tester. What creates the expectation is your auditor deciding what evidence satisfies your own stated controls, plus buyers asking for a report during procurement. A test performed by your own engineers can satisfy an auditor. It routinely fails to satisfy the enterprise customer reading your security package, which is the real reason companies buy an outside one.
Is an internal penetration test ever good enough?
Under most frameworks, yes, provided the tester is independent of what they are testing. PCI DSS accepts a qualified internal resource and states the tester is not required to hold a QSA or ASV credential. NYDFS accepts a qualified internal or external party. NIST SP 800-53 only requires independence when the CA-8(1) enhancement is selected on top of the base control. The catch is organizational, not regulatory: at ten engineers there is usually nobody who did not build the thing.
What does organizational independence actually mean?
That the tester has no stake in the result and did not build, run, or maintain the target. NIST puts it as freedom from perceived or actual conflicts of interest with respect to the development, operation, or management of the systems being tested. Note perceived. An assessor does not have to prove your platform lead went easy on their own code, only that a reasonable reader could suspect it, and that is enough to challenge the evidence.
How can HackZero test every month for 299 dollars when one outside test costs thousands?
Stack ownership. The attack agents, the exploitation toolchain and the reporting are built in-house, so the marginal cost of a run is compute plus senior review rather than tester-weeks, and the day-rate arithmetic that sets consultancy prices stops applying. AI does the continuous coverage no human team could afford monthly, and hackers stay in the loop to confirm findings actually exploit and to write the report an auditor reads. Prices are published, not quoted: 299 dollars a month under ten people, 499 at ten or more. If a framework or a customer wants hackers driving a named engagement, that is 2,999 dollars per engagement on top.
Which framework should decide my testing scope?
The strictest one you are actually in scope for, then test once to that bar. A test that satisfies the FedRAMP mandatory attack vectors also satisfies PCI Requirement 11.4 and any SOC 2 control you wrote about testing, because externality and coverage both flow downhill. Running one engagement per framework is the most common way companies pay three times for evidence a single well-scoped test would have produced.