5 October 2026 · 9 min read · By Michael van Mameren, Lead Penetration Tester (OSCP)
NIST SP 800-115 Penetration Testing: The Methodology, Where It Is Required, and How to Apply It
NIST Special Publication 800-115 is the reference most auditors have in mind when they ask whether your penetration test followed an industry-accepted methodology. This guide explains what it says and how a compliant test is run.
What is NIST SP 800-115?
NIST Special Publication 800-115, the Technical Guide to Information Security Testing and Assessment, was published by the US National Institute of Standards and Technology in September 2008. It is a methodology document, not a compliance standard: it describes how to plan, run and report security assessments, including penetration tests, in a repeatable way. Despite its age it remains the most-cited penetration testing methodology in audit requirements worldwide, alongside OWASP and PTES.
The guide organises assessment techniques into three families: review techniques (documentation, logs, rulesets, system configurations, network sniffing, file integrity), target identification and analysis techniques (network discovery, port and service identification, vulnerability scanning, wireless scanning), and target vulnerability validation techniques (password cracking, penetration testing, social engineering). Penetration testing is the validation step: it proves whether an identified weakness can actually be exploited.
The four phases of a NIST SP 800-115 penetration test
Section 5.2 of the guide defines the penetration testing process in four phases. Auditors look for evidence of each.
1. Planning
Rules of engagement are agreed: scope, targets, timing, allowed techniques, escalation contacts, legal authorisation and how sensitive data found during the test is handled. No testing happens before this is signed. The planning record is the first thing an assessor asks for.
2. Discovery
Information gathering and scanning: network discovery, port and service identification, operating system and application fingerprinting, and vulnerability analysis that compares findings against known vulnerabilities. Discovery produces the attack surface map the next phase works from.
3. Attack
The core of the test. The tester attempts to gain access, escalate privileges, browse the system and install tools to pivot further, feeding new discoveries back into the loop. This is where manual skill separates a penetration test from a scan: chaining low-severity issues into a high-impact compromise.
4. Reporting
Runs in parallel with the other phases and ends with a report that lists findings with severity, evidence, root cause and remediation guidance, plus the methodology and scope so the result can be reproduced and audited.
Where NIST SP 800-115 is required or referenced
The guide is rarely mandated by name, but several frameworks require a methodology and name it as the accepted example.
| Framework | Requirement | How 800-115 applies |
|---|---|---|
| NIST SP 800-53 (Rev. 5) | Control CA-8 Penetration Testing: independent testing of systems at an organisation-defined frequency | 800-115 is the companion methodology; federal and defence suppliers are expected to follow it |
| FedRAMP | Annual penetration test per the FedRAMP Penetration Test Guidance for cloud service providers | The guidance builds on 800-115 phases and attack vectors |
| PCI DSS v4.0.1 | Requirement 11.4.1: a documented methodology based on industry-accepted approaches | 800-115 is named as an example of an accepted approach |
| CMMC / NIST SP 800-171 | CA.L2-3.12.1 periodic assessment of security controls | 800-115 provides the assessment method |
| ISO 27001 / SOC 2 | Evidence of control effectiveness, methodology stated | Citing 800-115 satisfies the methodology question |
What a NIST-aligned penetration test report contains
If your test needs to satisfy an auditor who references 800-115, make sure the report shows these elements.
- Rules of engagement and written authorisation (planning phase evidence)
- Scope definition with in-scope and out-of-scope systems, test window and test positions (external, internal, authenticated)
- Discovery results: the asset and service inventory the test worked from
- Attack narrative: what was attempted, what succeeded, how access was gained and escalated
- Findings with severity rating (CVSS), reproducible evidence, affected assets, root cause and remediation
- Data-handling statement: how sensitive data encountered during testing was protected and destroyed
- Retest section after remediation, dated separately
NIST SP 800-115 versus OWASP and PTES
The three are complementary, not competing. NIST SP 800-115 defines the overall assessment process and the phases. The Penetration Testing Execution Standard (PTES) adds detail on pre-engagement, threat modelling and post-exploitation. The OWASP Testing Guide and OWASP Top 10 define what to test in web applications and APIs. A mature penetration test cites all three: 800-115 for process, PTES for engagement structure, OWASP for application coverage.
When an RFP or auditor asks for a NIST-based penetration test, they are asking for the four-phase process, documented rules of engagement and a report in the format above. They are not asking you to limit the test to the techniques listed in a 2008 document; the attack phase should use current tooling and tradecraft.
How we run NIST-aligned tests
Every HackersHub penetration test follows the 800-115 phases with signed rules of engagement, a discovery inventory, a manual attack phase by OSCP-certified testers, and a report structured so a US federal assessor, a PCI QSA or an ISO auditor can map it to their framework. For FedRAMP and NIST 800-53 environments we add the attack vectors the FedRAMP guidance requires, including social engineering and the trusted-insider position.
The report cites NIST SP 800-115, PTES and OWASP explicitly, which closes the methodology question before it is asked.
Frequently asked questions
Need a NIST-aligned penetration test?
Signed rules of engagement, four-phase methodology, OSCP-certified testers and a report your assessor can map to NIST 800-53, FedRAMP or PCI DSS. Talk to an expert.