FedRAMP Penetration Testing & Red Team Exercises

Testing across the six mandatory attack vectors, plus the CA-8(2) red team exercise required at Moderate and High. Deliverables built to survive 3PAO validation.
Contact us
Definition

What does FedRAMP require for penetration testing?

Two distinct obligations that are frequently conflated. First, an annual penetration test conducted per the FedRAMP Penetration Test Guidance, which prescribes six mandatory attack vectors rather than leaving scope to the tester. Second, control CA-8(2), added to the FedRAMP Moderate and High baselines with the move to NIST SP 800-53 Revision 5, which requires a red team exercise simulating adversary attempts to compromise organizational systems under agreed rules of engagement. The penetration test measures exposure. The red team exercise measures whether your organization detects and responds. Both are assessed at initial authorization and at each annual assessment, and red team exercises are not required for LI-SaaS.

Services

The six mandatory FedRAMP attack vectors

1. External to Corporate
2. External to CSP Target System
3. Tenant to CSP Management System
4. Tenant to Tenant
5. Mobile Application to Target System
6. Client-side Application and Agents

1. External to Corporate

The vector that tests your people. It requires a social engineering campaign against corporate personnel, including an email phishing campaign and a non-credential-based phishing attack, then pursues what that access reaches. This is where the enterprise nature of FedRAMP testing becomes concrete: your corporate environment is in scope because it is the path an adversary uses to reach the service.

2. External to CSP Target System

Simulates and tests vulnerabilities reachable from the internet against the service offering itself: exposed interfaces, authentication, session handling, injection classes, and the supporting infrastructure inside the authorization boundary. This is the vector most providers already test well, and the one reviewers scrutinize least.

3. Tenant to CSP Management System

Tested as both a privileged and an unprivileged tenant user attempting to escape the tenant context and reach the management plane. Multi-tenant SaaS providers fail here more often than anywhere else, usually through an administrative function that trusts a tenant-supplied identifier or a support tool with more reach than its users need.

4. Tenant to Tenant

Isolation testing from untrusted internal threats and trusted tenant positions. The objective is to reach another tenant's data or influence their environment. Broken object-level authorization, shared cache or queue keys, and identifier-guessable exports are the recurring causes, and the impact is almost always High or Critical because it breaches the core promise of multi-tenancy.

5. Mobile Application to Target System

Required where the service ships a mobile client. Testing emulates the mobile application against the target system and covers local credential and token storage, transport protection including certificate pinning and its bypass, and the server-side authorization the client assumes but does not enforce. iOS and Android are assessed as binaries and in live traffic.

6. Client-side Application and Agents

Applies where you distribute client-side components or agents that run in customer environments. The test treats the agent as an untrusted foothold: what it stores, what it trusts, how it updates, and whether a compromised host can turn the agent's channel back into your infrastructure. Agent update mechanisms deserve particular attention as a supply-chain path.

Our approach

Our approach

01

Scope, boundary, and rules of engagement

We reconcile the authorization boundary against the six vectors, identify which apply to your architecture, and produce rules of engagement covering authorized targets, testing windows, prohibited techniques, evidence handling, hosting-provider notification, deconfliction, and the named authorizing official.

02

Threat-informed red team objectives

The guidance expects the assessment organization to leverage your threat intelligence to establish agreed objectives for the exercise. We run that session with your security team, so the exercise emulates adversaries plausibly interested in your service rather than a generic attacker, and the objectives are documented in the test plan.

03

Execute, evidence, and measure response

Penetration testing produces exploitable findings with CVSS vectors and evidence. The red team exercise runs current real-world tactics, techniques, and procedures and measures detection, defense, and response at each stage. Critical findings are reported on discovery. A deconfliction contact can attribute activity to the exercise within minutes.

04

RTTP, RTTR, and 3PAO handoff

You receive a Red Team Test Plan documenting scope, methodology, planned activities, schedule, the resources performing the test, and your authorizations, plus a Red Team Test Report summarizing results, alongside the penetration test report. We package them for your 3PAO to validate and attest, and we take reviewer questions directly.

contact us

Preparing for an initial authorization or annual assessment?

Talk to BD Emerson about your baseline, boundary, and assessment timing, and we will tell you what the six vectors and CA-8(2) mean for your architecture.

Our Advantage

Why BD Emerson for FedRAMP offensive testing

Separation from your attesting 3PAO

The exercise may be performed by the 3PAO, a separate third party, or internally, but the 3PAO must validate and attest to the plan and report either way. Keeping execution and attestation in separate hands is a stronger evidence posture and avoids asking one firm to review its own offensive work.

Deliverables written for the reviewer

Our RTTP and RTTR are structured against what the guidance actually asks for, so your 3PAO is validating a document that already contains the required elements. We write for someone reading cold with authority to send it back, because that is who reads it.

Compliance and security in one firm

We run FedRAMP advisory, SOC 2, and ISO programs alongside offensive security, so findings arrive already mapped to the controls they affect and the POA&M entries they create. Your assessor conversation and your remediation plan come from the same team.

Reviews

What our customers say

Great consulting firms for scaling security, compliance, and appsec.

Outstanding partner in Technical and Cyber Due Diligence

Appsec maturity and application hardening.

BD Emerson helped us simplfiy our compliance management.

BD Emerson did such a phenomenal job. What started as privacy support quickly became a full partnership across compliance, engineering, and even business operations. They’re embedded with our team. They understand our product. They move fast. They’re simply invaluable.

Adam Ben Jacobs

CTO @ OneStep GPS

Great consulting firms for scaling security, compliance, and appsec.

Outstanding partner in Technical and Cyber Due Diligence

Appsec maturity and application hardening.

BD Emerson helped us simplfiy our compliance management.

BD Emerson did such a phenomenal job. What started as privacy support quickly became a full partnership across compliance, engineering, and even business operations. They’re embedded with our team. They understand our product. They move fast. They’re simply invaluable.

Adam Ben Jacobs

CTO @ OneStep GPS

We had a hard time finding the right company to partner with in support of our compliance journey. Some vendors sell the idea that they do the work, but then you end up doing everything. The ambiguity is what killed our last project. BD Emerson’s team has such great technical knowledge and understands the standard so well that they made us comfortable with moving fast. This has led to us closing major enterprise customers that were previously out of reach because of security and compliance.

Tom Watkins

CEO @ AMI AssetTrack

Lead an enterprise initiative to overhaul the organization's technology stack from ecommerce, corporate tech, and corporate security.

Supported ISO 42001 exercise and served as internal auditor.

Rubrik's privacy and compliance team began with the backbone of BD Emerson. BD Emerson supported building out the privacy program, GRC (ISO 27001, SOC 2, CMMC, FedRAMP), and the appsec function.

We needed a partner who could move quickly, without sacrificing precision. BD Emerson brought the expertise, structure, and speed we were looking for. Their team became an extension of ours, embedding themselves across the organization, guiding us step by step, and giving us confidence in areas we hadn’t tackled before. The internal audit they conducted was so detailed that even the external auditors called it out. Achieving ISO 27001 with zero nonconformities says everything you need to know about the quality of the partnership.

Walid Souilem

CTO @ FGI Worldwide

We had a hard time finding the right company to partner with in support of our compliance journey. Some vendors sell the idea that they do the work, but then you end up doing everything. The ambiguity is what killed our last project. BD Emerson’s team has such great technical knowledge and understands the standard so well that they made us comfortable with moving fast. This has led to us closing major enterprise customers that were previously out of reach because of security and compliance.

Tom Watkins

CEO @ AMI AssetTrack

Lead an enterprise initiative to overhaul the organization's technology stack from ecommerce, corporate tech, and corporate security.

Supported ISO 42001 exercise and served as internal auditor.

Rubrik's privacy and compliance team began with the backbone of BD Emerson. BD Emerson supported building out the privacy program, GRC (ISO 27001, SOC 2, CMMC, FedRAMP), and the appsec function.

We needed a partner who could move quickly, without sacrificing precision. BD Emerson brought the expertise, structure, and speed we were looking for. Their team became an extension of ours, embedding themselves across the organization, guiding us step by step, and giving us confidence in areas we hadn’t tackled before. The internal audit they conducted was so detailed that even the external auditors called it out. Achieving ISO 27001 with zero nonconformities says everything you need to know about the quality of the partnership.

Walid Souilem

CTO @ FGI Worldwide

BD Emerson didn’t just help us meet our compliance goals; they integrated security and privacy into the core of our operations. I highly recommend BD Emerson to anyone seeking SOC 2 or GDPR compliance, or simply looking to enhance their security team and boost customer trust in their product and services. Their dedication and expertise have been invaluable to our success.

Padraig Reilly

CEO, Boxcore

BD Emerson understood our business requirements and worked side-by-side with us. The policies and controls we developed together not only meet compliance standards but improve how we operate day to day.

Matt Meierdierks

IT Manager, Lincoln Industries

From day one, BD Emerson brought urgency, clarity, and a sharp understanding of what truly matters to our business — earning and keeping customer trust. They went beyond helping us meet compliance requirements; they helped build a foundation for secure, scalable growth. That kind of partnership is rare.

Jason Marker

CEO @ LifeLenz

BD Emerson didn’t just help us pass an audit—they helped us build a sustainable culture of security.

Alexey Indeev

CTO Spare

BD Emerson was essential in helping our company navigate the daunting process of leveling up our security infrastructure. BD Emerson’s impressive expertise and confidence throughout the process helped our team exceed HIPAA and SOC 2 Type 1 standards quickly, distilling what can be an overwhelming process into a streamlined, organized effort. From day one they began adding value and getting us on course. With their help we delivered on a massive security overhaul with both extreme efficiency and thorough attention to details. Because of BD Emerson’s support, we’ve increased our clients’ trust in Titan Intake and the life-changing work it accomplishes for those seeking specialist referrals.

Patrick Bruce

CEO, Titan Intake

BD Emerson didn’t just help us meet our compliance goals; they integrated security and privacy into the core of our operations. I highly recommend BD Emerson to anyone seeking SOC 2 or GDPR compliance, or simply looking to enhance their security team and boost customer trust in their product and services. Their dedication and expertise have been invaluable to our success.

Padraig Reilly

CEO, Boxcore

BD Emerson understood our business requirements and worked side-by-side with us. The policies and controls we developed together not only meet compliance standards but improve how we operate day to day.

Matt Meierdierks

IT Manager, Lincoln Industries

From day one, BD Emerson brought urgency, clarity, and a sharp understanding of what truly matters to our business — earning and keeping customer trust. They went beyond helping us meet compliance requirements; they helped build a foundation for secure, scalable growth. That kind of partnership is rare.

Jason Marker

CEO @ LifeLenz

BD Emerson didn’t just help us pass an audit—they helped us build a sustainable culture of security.

Alexey Indeev

CTO Spare

BD Emerson was essential in helping our company navigate the daunting process of leveling up our security infrastructure. BD Emerson’s impressive expertise and confidence throughout the process helped our team exceed HIPAA and SOC 2 Type 1 standards quickly, distilling what can be an overwhelming process into a streamlined, organized effort. From day one they began adding value and getting us on course. With their help we delivered on a massive security overhaul with both extreme efficiency and thorough attention to details. Because of BD Emerson’s support, we’ve increased our clients’ trust in Titan Intake and the life-changing work it accomplishes for those seeking specialist referrals.

Patrick Bruce

CEO, Titan Intake

Certificates

Our accreditations

At BD Emerson, we believe that our team's extensive certifications not only set us apart but also ensure that we provide the highest level of service to our clients.
FAQ

Frequently asked questions

What are the six FedRAMP penetration test attack vectors?

Is a red team exercise required at every impact level?

Who is allowed to perform the CA-8(2) red team exercise?

What is the difference between the RTTP and the RTTR?

How does the red team exercise differ from the penetration test?

Does the red team exercise stay inside the authorization boundary?

How often does this have to happen?

Blog

Related Articles

Insights on strategy, transactions, technology, security, and compliance from BD Emerson's practitioners