What Microsoft asks for
Microsoft's certification requirements say penetration testing is mandatory for any app that connects to services not hosted or managed by Microsoft. The test must:
- Take place every 12 months
- Be conducted by "a reputable independent company"
- Cover web application testing, both authenticated and unauthenticated
- Cover external infrastructure, and internal infrastructure where it applies
- Run against the live production environment that supports the app
- Include your full external footprint, such as IP addresses, URLs, and API endpoints, documented in the report
What a matching test looks like
- Standard external penetration test, $3,495 for a 30-day window: 10 external IPs or domains, with authenticated web application testing included. This is the usual fit for an app that has a login.
- Automated internal penetration test, from $2,995 for a 30-day window (up to 25 internal hosts), if your environment has internal infrastructure in scope.
You set the scope yourself in the portal, so your full external footprint can be listed and appears in the report.
Fix, retest, then submit
The test runs inside a 30-day window. Fix what it finds, retest inside the same window, and submit the report that shows the issues closed.
If the reviewer wants an engineer-led test
Microsoft's certification analysts decide whether the evidence meets their requirements. If they ask for a test led by a named engineer, our managed penetration testing team does that.
Microsoft, Microsoft 365, Teams, and Outlook are trademarks of the Microsoft group of companies. Clone Systems is not affiliated with Microsoft.
See pen test pricing and buy online · Talk to a specialist
Related: SOC 2, HIPAA, ISO 27001, PCI DSS 11.4, FTC Safeguards Rule, cyber insurance, penetration test cost
