Microsoft 365 Certification Penetration Testing
Certification is blocked until an independent penetration test covers your live production environment, and the report has to answer sixteen controls one by one. You are either starting certification, renewing the annual test, or sitting on a submission that came back for evidence. The scope, the published price and the timeline are on this page, before you talk to us.
Four things about this certification that get buyers oversold
Publisher Attestation is not this. It is the prerequisite step, a self-assessment questionnaire in Partner Center, and it carries no penetration testing requirement at all. If someone quoted you a pentest to complete Attestation, they quoted you the wrong thing.
Microsoft set no accreditation bar for the tester. The control says a reputable independent penetration testing company. On the same page Microsoft requires ISO 27001, SOC 2 and PCI DSS evidence to come from accredited auditors, and a PCI DSS attestation to be signed by a QSA. It wrote that requirement twice and did not write one here.
Nobody can promise you a pass. Controls 7 to 15 are automatic failure criteria and each is phrased as an absence. Whether your report can evidence those absences depends on your application and on what your engineers fix. A vendor promising a clean result is telling you they will either not look hard or not write down what they find.
You may not be able to book the test yet. Microsoft states that an ISV "must submit evidence and receive approval for 50% of in-scope controls before scheduling the penetration test". That sits in the delivery section written around the test Microsoft arranges through its own partner, so confirm with your certification analyst how it applies to a test you commission yourself. Either way it is the sequencing step most teams meet first, and it decides when testing can actually start.
The retest is part of the requirement, not an upsell. Control 16 requires the company that found the issue to verify the fix, inside the final report. A retest sold as a separate engagement, or delivered as a note appended to the original document, is weaker evidence than a reissued report.
What our reports have had to satisfy elsewhere
Microsoft's controls ask for a report that a reviewer can work through line by line: scope documented, findings evidenced, remediation verified. That is the same structure we already produce: every finding carries a CVSS score with its full vector string, a CWE identifier, reproduction steps, evidence, business impact and a specific remediation, and the retest reissues the report with the fixed state evidenced rather than asserted.
The point is narrower and more useful to you than a claim about other frameworks: the report is built to be checked line by line, which is the only property that matters when a reviewer has the authority to reject it.
What Microsoft puts in scope, and what we test against each
Web application, authenticated and unauthenticated
Both surfaces, as the control requires. Authentication and session handling, authorisation across every role you expose, business logic, and the injection and traversal classes that sit inside the automatic failure list.
The complete external attack surface
All public IP addresses, URLs, domains, API endpoints and other internet-facing services, enumerated and documented in the report because the control requires the report to document them.
The internal production network
In scope wherever the environment is not fully PaaS, meaning you manage infrastructure. Where segmentation isolates the in-scope environment, the report validates that the segmentation actually holds rather than asserting it.
Every production component that could affect the in-scope environment
Microsoft requires testing to cover the entire live production environment, including any additional production environments, systems or services that interact with or support the application. Scope is agreed against that wording rather than against a list of environment names.
What a certification engagement costs
The plan is the Growth Pentest, which covers two scopes at INR 1,79,999, with each additional scope at INR 74,999. A certification engagement is normally two or three scopes: the web application, the external attack surface, and the internal production network where you manage infrastructure. A fully PaaS environment often comes to two.
Two scopes INR 1,79,999 · 10 business days
Three scopes INR 2,54,998 · 15 business days
Prices exclude taxes. Scopes run sequentially at five business days each. The retest is included in the plan and is not a separate line, which is what Control 16 needs. Full terms are on our pricing page.
What you receive
- A penetration test report covering the entire live production environment supporting the app, written to be submitted as Partner Center evidence control by control.
- Every finding with a CVSS v3.1 and v4.0 score and full vector string, a CWE identifier, reproduction steps, evidence, business impact and specific remediation.
- The external attack surface documented in the report, as the control requires, not summarised.
- Segmentation validation where segmentation is used to isolate the in-scope environment.
- A v2.0 report after the retest, superseding v1.0, carrying updated status on every original finding plus fresh evidence of the fixed state.
- A Letter of Attestation signed by the lead tester after the retest, on the Growth plan.
Microsoft 365 Certification pentest questions
Does Microsoft 365 Certification require a penetration test?
Yes. Microsoft’s Application Security guidance states that penetration testing is a mandatory requirement for all applications undergoing Microsoft 365 Certification, covering both web application and infrastructure testing, at least annually. The stated exception is where you host or manage no supporting infrastructure, for example an app built solely from Microsoft 365 components or hosted entirely inside the customer’s own infrastructure with no backend you manage. Note that Publisher Attestation, the prerequisite step, is a self-assessment questionnaire and carries no pentest requirement at all.
Who is allowed to perform the test?
Microsoft’s wording is a reputable independent penetration testing company. It names no accreditation body, no approved-vendor list and no certification for the tester. That is worth reading against the neighbouring requirement on the same page, where Microsoft does impose gates: ISO 27001, SOC 2 and PCI DSS evidence must come from auditors who are members of international accreditation bodies, and a PCI DSS attestation must be signed off by a QSA. Microsoft wrote an accreditation requirement twice on that page and did not write one here.
What must be in scope?
The entire live production environment that supports the app, add-in or agent, including all systems, services and infrastructure that host, process, store or transmit data on its behalf. Web application testing covers authenticated and unauthenticated surfaces. The complete external attack surface must be in scope and documented in the report. Where the environment is not fully PaaS, the complete internal production network is in scope. Where segmentation isolates the in-scope environment, the report must validate it. Scope extends to any additional production environments, systems or services that interact with or support the application.
Can you guarantee we pass Controls 7 to 15?
No, and a vendor who says otherwise has promised something no tester can deliver. Controls 7 to 15 are Microsoft’s automatic failure criteria and each is phrased as an absence: no unsupported operating system or JavaScript library, no default or guessable administrative accounts, no SQL injection, no cross-site scripting, no directory traversal, no HTTP protocol issues, no source code disclosure, nothing rated Critical or High under the patch management requirements, and no significant vulnerability that could reasonably be exploited to compromise large volumes of customer data. Whether your report can evidence those absences depends on what is in your application and what your engineers fix. Our job is to test for every one of them, write down what is actually there, and retest once you have fixed it so the report can show the fixed state. Not being able to promise the outcome is not the same as not being able to help you reach it.
How does the retest satisfy Control 16?
Control 16 requires that all Critical and High severity vulnerabilities, and anything constituting an automatic failure, are retested by the penetration testing company following remediation and clearly identified as resolved within the final report. Two phrases decide what to ask a vendor for. By the penetration testing company means the firm that found it verifies the fix, so a retest quoted as a separate engagement is a certification risk rather than a line item. Within the final report means the evidence lives in the document the reviewer reads. Our retest produces a v2.0 report that supersedes v1.0 and is included in both plans: one month from v1.0 is the outer bound, not a wait, and we go sooner once your fixes land. Note the two clocks differ. Microsoft’s own remediation window runs one month from the completion of testing, which starts before v1.0 is issued, so on a certification engagement we sequence the retest to Microsoft’s date rather than ours.
What does a Microsoft 365 Certification pentest cost?
Our published price. The plan is the Growth Pentest at INR 1,79,999, which covers two scopes, and each additional scope is INR 74,999. A typical certification engagement is two or three scopes: the web application, the external attack surface, and the internal production network where you manage infrastructure. A fully PaaS environment often comes to two. Three scopes is INR 2,54,998. Prices exclude taxes.
Can you test a staging environment instead of production?
Sometimes, and Microsoft sets the terms. Where Infrastructure as Code provisions your environments, testing a staging environment may be accepted if you can demonstrate deterministic parity with production through the same IaC templates and CI/CD pipelines. Where production web application testing is not feasible, the report must at minimum confirm that the same application build was deployed to production at the time of testing. We will tell you which of those your estate actually supports before you commit.
Send us your architecture, not a plan choice
Tell us what you host and manage, what is PaaS, which other production systems touch the application, and the date the submission has to be in. That is what decides the scope count, and the scope count is what decides the price. Both co-founders are on the call. Certification itself is Microsoft's decision through its own assessor, and we will never tell you otherwise. What we can do is the part that falls to us: deliver the testing and the report its controls ask for, so the evidence side is covered and what is left is theirs to decide.
Where these requirements come from
Everything this page says about the platform's requirements is taken from the platform's own published documentation, linked below and last checked on 2026-10-03. We quote the requirement rather than our reading of it wherever the difference matters.
- Microsoft 365 Certification: Application Security sample evidence guide (Controls 1 to 16)
- Microsoft 365 Certification: certification overview
Our aim is to describe these requirements as accurately and as currently as we can, and to show you where to check us. We are reading someone else's documentation: a platform can revise it without an announcement, and our reading of it can be imprecise or go out of date. How we source, draft and review what we publish, including where software sits in the drafting, is set out in our editorial policy. A page like this is only as good as the date on it. We re-read the sources on a standing audit, date what we checked, and update the page when a source moves or when we can state something more precisely. If something here no longer matches the source, tell us at errors@cybersecify.com. We will review it against the source and tell you what we decide; where it needs changing we change it and date the change. This page is published for information. It is a best-effort account of someone else's published requirements, not a commitment about your engagement: what we deliver, and what it costs, is set out in the Statement of Work both parties sign, and our terms state that where website content and a signed agreement differ, the signed agreement governs.