NIST Penetration Testing Providers

National Institute of Standards and Technology SP 800-115 · Published by National Institute of Standards and Technology

NIST Special Publication 800-115, the Technical Guide to Information Security Testing and Assessment, provides a structured methodology for planning and conducting security assessments developed by the United States National Institute of Standards and Technology. This publication establishes a framework for organisations to evaluate the effectiveness of their security controls through testing techniques including vulnerability scanning, penetration testing, and social engineering.

NIST SP 800-115 defines four phases of security testing: planning, discovery, attack, and reporting. The planning phase covers scope definition, rules of engagement, and approval processes. The discovery phase includes information gathering, vulnerability scanning, and analysis. The attack phase covers exploitation, privilege escalation, and lateral movement. The reporting phase defines how findings should be documented, prioritised, and communicated to stakeholders.

As a US government publication, NIST SP 800-115 is authoritative for federal agencies and contractors, and is widely referenced in private sector security testing programmes. It aligns with the broader NIST Cybersecurity Framework (CSF) and NIST SP 800-53 security controls, making it particularly relevant for organisations that use NIST as their primary security framework. The methodology's emphasis on thorough planning and clear reporting makes it a strong foundation for regulatory-driven penetration testing programmes.

Key Features

  • Four-phase testing framework
  • US government authoritative standard
  • Aligns with NIST CSF and SP 800-53
  • Covers planning through reporting
  • Social engineering testing guidance

Best For

  • US federal agency testing
  • FedRAMP assessments
  • CMMC compliance
  • NIST CSF aligned organisations
  • Regulatory-driven testing programmes

Providers using NIST (18)

18 providers
Top UK ProviderElite TestersResearch-Driven
SECFORCE logo

SECFORCE

Leading UK offensive security consultancy based in Canary Wharf, delivering CREST-accredited penetration testing and adversary simulation to organisations with the most demanding security requirements.

95
Score
LOCLondon, United Kingdom
Web ApplicationNetworkMobile App+9
CRESTISO 27001Cyber Essentials
Best for Mid-MarketBest for Financial Services
NetSPI logo

NetSPI

Leading penetration testing firm with the Resolve platform for continuous attack surface management, trusted by nine of the top ten US banks.

60
Score
LOCMinneapolis, Minnesota, United States
Web ApplicationNetworkCloud+8
SOC 2ISO 27001CREST
Trustwave logo

Trustwave

Global managed security provider with the elite SpiderLabs penetration testing team and deep PCI DSS compliance expertise.

57
Score
LOCChicago, Illinois, United States
Web ApplicationNetworkMobile App+7
PCI QSAISO 27001SOC 2+1
Bridewell logo

Bridewell

Fast-growing CREST and CHECK-accredited UK cybersecurity consultancy with deep expertise in critical national infrastructure sectors.

56
Score
LOCBristol, United Kingdom
Web ApplicationNetworkCloud+7
CRESTCHECKISO 27001+1
Mandiant logo

Mandiant

World-renowned cybersecurity firm now part of Google Cloud, delivering threat intelligence-led penetration testing and red teaming informed by front-line incident response experience.

53
Score
LOCReston, Virginia, United States
Red TeamingPurple TeamingNetwork+6
SOC 2ISO 27001FedRAMP 3PAO
Best OverallElite TestersResearch Pioneers
Bishop Fox logo

Bishop Fox

Premier US-based offensive security firm known for elite penetration testers, cutting-edge research, and the Cosmos continuous attack surface management platform.

50
Score
LOCTempe, Arizona, United States
Web ApplicationNetworkMobile App+8
SOC 2OSCP Employer
Rapid7 logo

Rapid7

Creators of Metasploit offering enterprise penetration testing integrated with their comprehensive vulnerability management and security operations platform.

50
Score
LOCBoston, Massachusetts, United States
Web ApplicationNetworkMobile App+7
SOC 2ISO 27001
Coalfire logo

Coalfire

Compliance-focused cybersecurity advisory firm and FedRAMP 3PAO specializing in penetration testing that meets stringent regulatory requirements.

50
Score
LOCWestminster, Colorado, United States
Web ApplicationNetworkCloud+5
SOC 2FedRAMP 3PAOPCI QSA+1
Black Hills Information Security logo

Black Hills Information Security

Community-driven penetration testing firm known for free security education, open-source tools, Wild West Hackin' Fest, and practical offensive security services.

44
Score
LOCSpearfish, South Dakota, United States
NetworkWeb ApplicationSocial Engineering+5
SOC 2
CrowdStrike logo

CrowdStrike

Global cybersecurity leader leveraging world-class threat intelligence from the Falcon platform to deliver intelligence-led penetration testing and red teaming.

43
Score
LOCAustin, Texas, United States
Red TeamingNetworkWeb Application+5
SOC 2ISO 27001
IOActive logo

IOActive

Elite boutique security consultancy specializing in IoT, SCADA/ICS, embedded systems, and hardware security research with world-renowned researchers.

42
Score
LOCSeattle, Washington, United States
Web ApplicationNetworkIoT+7
OSCP Employer
Secureworks logo

Secureworks

Dell Technologies-backed cybersecurity firm with elite Counter Threat Unit intelligence informing enterprise penetration testing and adversary simulation.

41
Score
LOCAtlanta, Georgia, United States
Web ApplicationNetworkCloud+7
SOC 2ISO 27001
Rhino Security Labs logo

Rhino Security Labs

Cloud security penetration testing specialists known for the Pacu AWS exploitation framework and deep expertise across AWS, Azure, and GCP environments.

41
Score
LOCSeattle, Washington, United States
CloudWeb ApplicationNetwork+4
SOC 2
Praetorian logo

Praetorian

Offensive security firm founded by former DoD professionals, offering elite penetration testing and the Chariot continuous attack surface management platform.

40
Score
LOCAustin, Texas, United States
Web ApplicationNetworkCloud+7
SOC 2
Synack logo

Synack

FedRAMP-authorized crowdsourced penetration testing platform combining vetted elite hackers with AI-powered Hydra technology for continuous security testing.

39
Score
LOCRedwood City, California, United States
Web ApplicationNetworkAPI+4
FedRAMP 3PAOSOC 2
Aon Cyber Solutions logo

Aon Cyber Solutions

Cybersecurity consulting division of global insurance leader Aon, uniquely combining penetration testing with cyber risk quantification and insurance expertise.

36
Score
LOCLondon, United Kingdom
Web ApplicationNetworkCloud+5
ISO 27001SOC 2
Securin logo

Securin

Vulnerability intelligence-driven penetration testing firm providing contextual security assessments informed by threat actor exploitation data and ransomware tracking.

34
Score
LOCAlbuquerque, New Mexico, United States
Web ApplicationNetworkAPI+3
SOC 2
BreachLock logo

BreachLock

Cloud-based Penetration Testing as a Service platform combining AI-driven automation with expert manual testing at accessible price points.

33
Score
LOCNew York, New York, United States
Web ApplicationNetworkAPI+4
SOC 2ISO 27001

NIST FAQs

Is NIST SP 800-115 mandatory for US federal agencies?+

While not universally mandatory, NIST SP 800-115 is the authoritative technical guide for federal security testing and is widely adopted across US government agencies and their contractors. FedRAMP and CMMC reference NIST testing standards.

How does NIST SP 800-115 relate to the NIST Cybersecurity Framework?+

SP 800-115 provides the technical testing methodology that supports the NIST CSF's Identify and Protect functions. It helps organisations assess whether the security controls defined by NIST SP 800-53 are effectively implemented.

Can non-US organisations use NIST testing methodology?+

Absolutely. While developed for US government use, NIST SP 800-115 is freely available and widely adopted internationally. Many organisations outside the US use it alongside other frameworks like OWASP and PTES.