Physical Penetration TestingOn-Site Security Assessment for Offices, Plants, and Server Rooms
Physical penetration testing is an authorized attempt to get past the doors, badges, guards, locks, and people that protect a building, and then to reach the things inside it that matter: server rooms, workstations, network closets, filing cabinets, and the Controlled Unclassified Information or patient records they hold. Petronella Technology Group has run authorized physical security assessments for regulated businesses and defense suppliers from Raleigh, North Carolina since 2002, and every engagement ends with a written report that ties each finding to a fix and to the compliance requirement it affects.
- A physical penetration test measures whether an outsider can reach your systems in person. The tester tries tailgating, badge cloning, lock bypass, pretexting, and after-hours entry under written rules of engagement, then documents exactly how far each path went.
- It is different from a physical security assessment or audit. An assessment reviews controls against a standard on a walkthrough; a penetration test proves which controls fail under a real attempt. Most clients need both, and the table below explains when.
- Physical access is a named requirement in the frameworks you already answer to. NIST SP 800-171 Family 3.10 (Physical Protection), the CMMC Physical Protection domain, the HIPAA Security Rule physical safeguards at 45 CFR 164.310, and PCI DSS Requirement 9 all require you to limit and monitor who can touch the equipment.
- Every test runs under an authorization letter and stop conditions. Nothing is broken, no production system is touched, and the tester carries signed proof of authorization at all times.
- The deliverable is a remediation plan, not a highlight reel. Findings are ranked by the access they produced, mapped to the affected requirement, and retested after you fix them.
What Is Physical Penetration Testing?
Physical penetration testing, sometimes called a physical pen test or physical security testing, is a controlled engagement in which a security professional attempts to gain unauthorized physical access to a facility and to the assets inside it, using the same techniques a real intruder would use. The tester works from a scope and a set of rules the client approves in advance, carries a signed authorization letter, and stops the moment a pre-agreed condition is met. The goal is not to embarrass anyone. It is to learn, before someone with bad intentions does, which door props open, which badge reader accepts a cloned card, which receptionist waves through a person in a contractor vest, and which server room has a drop ceiling that bypasses the lock entirely.
The test matters because most of the security spending a business makes assumes that the attacker is on the other side of a network. Firewalls, endpoint detection, multifactor authentication, and encryption in transit all lose their value once a person is standing at an unlocked workstation, plugging a device into a network jack in a conference room, or walking out with a backup drive. Physical access is the shortest path to almost every asset an organization protects, and it is the path that receives the least testing.
Petronella Technology Group treats physical testing as one leg of the same offensive program that includes external, internal, and social engineering testing. The findings feed each other: a cloned badge gets a tester to a network closet, the closet gives an internal foothold, and the internal test shows how far that foothold reaches. Reporting all of it together is what turns a list of observations into a picture of real risk.
- An authorized, scoped, and documented attempt to enter a facility and reach defined target assets
- A test of people, procedures, and hardware together: guards, receptionists, badge systems, locks, cameras, alarms, and visitor rules
- A measured exercise with stop conditions, safe words, and an authorization letter carried on the tester's person
- A source of evidence for NIST SP 800-171, CMMC, HIPAA, PCI DSS, and SOC 2 physical access requirements
- A repeatable engagement that ends in a ranked remediation plan and a retest
- Not a break-in: no forced entry, no property damage, and no interference with life-safety systems
- Not a test of individual employees; findings are written against controls and procedures, never against a named person
- Not a substitute for a written physical security assessment against a standard, which reviews the whole control set rather than the paths a tester happened to find
- Not a network test; touching production systems is out of scope unless the client explicitly adds an internal test
- Not an exercise a facilities vendor should run on its own installation
Physical Penetration Test vs Physical Security Assessment vs Audit
The three terms get used interchangeably, and the confusion costs money because a buyer who wants proof of a working control sometimes purchases a checklist, and a buyer who needs a full control review sometimes purchases a single covert entry attempt. This is how we separate them for clients.
What a Physical Penetration Test Actually Tries
Every facility is different, so the scope is built from a threat model rather than a fixed menu. These are the paths that appear in almost every engagement, because they are the paths intruders use.
Tailgating and Piggybacking
The tester follows an employee through a badge-controlled door, often carrying boxes, coffee, or a phone conversation that makes holding the door feel rude to refuse. This single technique defeats more access control systems than any lock-picking tool, and it is the first thing we test at every entrance.
Pretexting at Reception
The tester arrives as a copier technician, a fire inspector, a new hire from a satellite office, or a delivery driver with a package that needs a signature upstairs. The test measures whether reception verifies identity against a schedule or a callback, or simply issues a visitor badge and points to the elevator.
Badge and RFID Cloning
Many proximity badges still use low-frequency formats that can be read at short range and written to a blank card. The tester captures a badge in a coffee line or a parking deck, clones it, and tries the reader. The finding, if it succeeds, usually points to a credential technology upgrade rather than a procedure change.
Lock and Door Hardware Bypass
Request-to-exit sensors that trigger from outside, latch guards that are missing, drop ceilings that bridge a locked room, and interior doors that never got a strike plate are all tested without damage. We document the bypass with photos and recommend the specific hardware fix.
Server Rooms, Network Closets, and Workstations
Once inside, the tester heads for the defined targets: an unlocked IDF closet with a live switch port, a shared workstation left logged in, a badge printer on the network, or a stack of backup media. Photographs replace any actual interaction with the systems unless the client has added an internal test.
Documents, Dumpsters, and Dropped Devices
Printed CUI on a shared printer, unshredded patient schedules in a recycling bin, and a USB drive left in a break room are classic findings. The dropped-device test in particular shows whether staff plug in what they find, which is the bridge between a physical test and a social engineering test.
Why Physical Access Testing Shows Up in Your Framework
Physical protection is not an optional extra in the standards regulated businesses answer to. It is a named family or requirement in each of them, and an assessor will ask for evidence that the controls work, not just that a policy says they should.
NIST SP 800-171 and CMMC
Family 3.10, Physical Protection, in NIST SP 800-171 Revision 2 requires limiting physical access to authorized individuals, protecting and monitoring the facility, escorting visitors, keeping access audit logs, and controlling physical access devices such as keys and badges. The CMMC Physical Protection domain carries those same practices into Level 1 and Level 2 assessments. Our CMMC Physical Protection guide walks through the practices; a physical penetration test produces the evidence that they hold. Read our NIST 800-171 Rev 3 explainer for how the family is numbered in the newer revision.
HIPAA Security Rule
The physical safeguards at 45 CFR 164.310 cover facility access controls, workstation use, workstation security, and device and media controls. A tester who walks to an unlocked nursing station and photographs a logged-in EHR screen has just produced the exact finding an Office for Civil Rights investigator looks for after a breach. See our HIPAA compliance services for the wider program.
PCI DSS Requirement 9
Requirement 9 of PCI DSS is titled "Restrict physical access to cardholder data" and covers facility entry controls, visitor handling, media protection, and point-of-interaction device inspection. A physical test of a retail back office or a call center floor maps directly to it. Our PCI DSS compliance page explains the rest of the standard.
SOC 2 and Cyber Insurance
The SOC 2 Trust Services Criteria include physical access restrictions among the logical and physical access controls an auditor evaluates, and cyber insurance applications increasingly ask whether physical security has been tested. A dated report from an independent firm answers both. Learn more about SOC 2 compliance with Petronella Technology Group.
Not Sure Whether You Need a Test or an Assessment?
Bring us your floor plan, your badge system make and model, and the framework you are preparing for. A short scoping call is usually enough to say whether a covert entry attempt, an announced control review, or both is the right first step, and what the rules of engagement should look like for your building.
A Facility Before and After Physical Penetration Testing
The change a test produces is rarely a new camera system. It is usually a handful of procedure fixes, one or two hardware corrections, and a staff that has seen the technique once and does not fall for it again.
Access control on paper
A badge policy exists, but the side door to the loading dock is propped for smoke breaks, and nobody has reviewed the badge system's active credential list since the last round of departures.
Reception as a greeting, not a gate
Visitors are welcomed, handed a sticker, and directed upstairs. No callback, no schedule check, and no escort requirement for anyone who says they are a vendor.
Targets within reach
The network closet on the second floor has a push-button lock with a code written on the frame, and the conference room has live wall jacks on the production VLAN.
No evidence for the assessor
When the CMMC or HIPAA assessor asks how the organization knows its physical controls work, the answer is a policy document and a good-faith belief.
Doors that close, credentials that expire
Door position sensors alarm on the propped dock door, terminated employees' badges are disabled the same day, and the badge format is upgraded where cloning succeeded.
Verification at the front desk
Reception verifies vendors against a schedule and a callback number, issues time-limited visitor badges, and escorts anyone headed for a restricted area. The staff know why, because they saw the pretext work.
Targets behind real barriers
The closet gets a keyed or badged lock with an access log, the code comes off the frame, and unused conference room jacks are disabled at the switch.
Dated, independent evidence
A report from Petronella Technology Group, with the retest results attached, sits in the ComplianceArmor® evidence library under the Physical Protection family, ready for the assessor.
How Petronella Technology Group Runs a Physical Penetration Test
The process is designed so that the client always knows what is being tested, the tester is always protected by written authorization, and the outcome is always something a facilities manager and a compliance lead can act on together.
Scoping and rules of engagement: sites, targets, hours, off-limits areas, stop conditions, and the trusted contacts who know the test is running
Authorization letter signed by an executive with authority over the property, carried by the tester and verifiable by phone at any hour
Reconnaissance: open-source research on the building, vendors, staff routines, badge technology, and entrances, plus in-person observation of shift changes and deliveries
On-site attempts across the agreed paths, with photo and timestamp evidence collected at each milestone and no interaction with production systems
Same-day debrief with the trusted contacts, so any exposure found is closed before the report is written
Report, remediation plan mapped to your framework, and a scheduled retest of every finding you fix
Because our founder, Craig Petronella, is a North Carolina Licensed Digital Forensics Examiner (license 604180-DFE) and serves as a cybersecurity expert witness for law firms, the evidence in a Petronella Technology Group report is collected and documented the way evidence is collected for a case: dated, attributed, and reproducible. That matters if a finding ever has to be explained to an assessor, an insurer, or a court. It also means the report reads as a factual narrative rather than a set of opinions, which is what a board or a compliance committee needs in order to fund the fixes.
Rules of Engagement: How the Test Stays Safe and Lawful
A physical penetration test is only legal because it is authorized, and it is only useful because it is controlled. These are the rules Petronella Technology Group builds into every engagement before anyone approaches a door.
What the Authorization Covers
- The exact addresses, floors, and suites in scope, and any shared-tenant spaces that are explicitly excluded
- The dates and hours during which attempts may occur, including whether after-hours entry is permitted
- The named targets the tester may reach and photograph, and the assets the tester may never touch
- The techniques permitted: tailgating, pretexting, badge cloning, and non-destructive bypass, with lock picking and after-hours work listed individually
- The signatory's authority over the property, and landlord or property-management consent where a lease requires it
How the Test Stops
- The tester stops immediately when challenged by security or law enforcement, identifies the engagement, and presents the letter and a verification phone number
- A safe word agreed with the trusted contacts ends the test at any time, for any reason
- Life-safety systems, fire doors in alarm mode, and any situation involving a distressed employee end the attempt on that path
- Nothing is removed from the building; evidence is photographed in place and sensitive images are stored encrypted and deleted after the report is accepted
- Findings are written against controls and procedures, never against a named employee, and the debrief with staff is framed as training
DIY Walkthrough vs Physical Pen Test vs Combined Offensive Program
Some organizations start with an internal walkthrough, and that is better than nothing. The table shows what each option finds and what it misses.
Why Businesses Bring Physical Security Testing to Petronella Technology Group
Petronella Technology Group has provided cybersecurity, compliance, and managed security services from Raleigh, North Carolina since April 2002, has held a BBB A+ rating since 2003, and is a CyberAB Registered Provider Organization (RPO #1449) with an entirely CMMC-RP certified team. Physical testing sits inside that compliance practice rather than beside it, so a finding at a loading dock is written up against the NIST SP 800-171 requirement it affects, and the fix lands in the same System Security Plan the assessor will read.
Craig Petronella, our founder, is an MIT-certified cybersecurity professional, a cybersecurity expert witness, and a North Carolina Licensed Digital Forensics Examiner. He has written about how intruders combine physical, human, and technical weaknesses in his Amazon best-selling book How Hackers Can Crush Your Business, and he has been featured as a cybersecurity commentator on NBC, ABC, CBS, FOX, and WRAL. That background shapes how our reports are written: as evidence, with a chain of custody, and with the reader's next decision in mind.
What You Get
- Scoping and rules of engagement written with your facilities lead and your compliance lead in the same room
- A tester who is unknown to your staff, carrying a verifiable authorization letter for the entire engagement
- Photo and timestamp evidence at every milestone, stored encrypted and deleted on report acceptance
- Findings mapped to NIST SP 800-171 Family 3.10, the CMMC Physical Protection domain, HIPAA 164.310, PCI DSS Requirement 9, or SOC 2 as applicable
- A retest of every remediated finding, and evidence filed in ComplianceArmor® if you use it
Verified Reputation
- Rated 4.7 across 92 verified TrustIndex reviews and 5.0 across 15 Google reviews
- "Petronella Cybersecurity provides outstanding service! Their team is extremely knowledgeable, responsive, and truly cares about protecting their clients. They take the time to explain complex issues in simple terms and deliver real solutions, not just promises." (GB Entraînement, TrustIndex verified review)
- Founded 2002, BBB A+ since 2003, CyberAB RPO #1449
- Engagements scoped to clear deliverables; no long-term contract is required for a physical test
Find Out How Far Someone Can Get Before Someone Does
A physical penetration test from Petronella Technology Group answers one question with evidence: can an outsider reach your servers, your records, or your network from the parking lot? Tell us about your facility and the framework you answer to, and we will propose a scope, rules of engagement, and a timeline. Prefer to start with a wider view? Download the free 2026 SMB Cybersecurity Survival Guide or try our free phishing security test.
Physical Penetration Testing: Frequently Asked Questions
What is the difference between physical penetration testing and a physical security assessment?
A physical penetration test is a covert or semi-covert attempt to enter a facility and reach defined targets, and it proves which controls fail under a real attempt. A physical security assessment is an announced review of the full set of physical controls against a standard such as NIST SP 800-171 Family 3.10 or HIPAA 164.310, and it finds design gaps a tester might never encounter. Most regulated organizations benefit from an assessment first and a test to validate the fixes.
Is physical penetration testing legal?
Yes, when it is authorized in writing by someone with authority over the property and performed within the agreed scope, dates, and techniques. Petronella Technology Group requires a signed authorization letter before any on-site work, the tester carries it at all times, and the letter includes a phone number that security or law enforcement can call to verify the engagement. Where a lease requires it, landlord or property-management consent is obtained as well.
Will the tester damage doors or locks?
No. All bypass techniques are non-destructive. Forced entry, drilling, and any interference with fire or life-safety systems are outside the rules of engagement. If a lock can only be defeated destructively, the finding is documented as a strength of that control and the tester moves to another path.
Does a physical pen test satisfy NIST SP 800-171 or CMMC physical protection requirements?
It produces evidence that the Family 3.10 practices, such as limiting physical access, escorting visitors, keeping access logs, and controlling keys and badges, are working, and that evidence is what an assessor asks for. It does not by itself write the policy or the System Security Plan entries those practices require. We pair the test with our CMMC compliance services so both the control and its proof are in place.
How long does a physical penetration test take?
Scoping and reconnaissance are usually spread over one to two weeks so that the tester can observe shift changes and deliveries, on-site attempts typically take one to three days per facility depending on the number of entrances and targets, and the report follows within about a week. The retest is scheduled once you confirm the fixes are in place.
Who at my company should know about the test?
As few people as possible: the executive sponsor who signs the authorization, and one facilities or security lead who can verify the tester if challenged and end the test with the safe word. Reception, guards, and general staff should not know, because their response is part of what is being measured. After the test, the debrief with staff is framed as training, and no finding names an individual.
Can the physical test be combined with social engineering or internal network testing?
Yes, and that combination is what most defense suppliers and healthcare clients choose. The physical leg gets the tester to a network closet or a workstation, the social engineering leg tests whether staff hand over credentials or plug in a dropped device, and the internal penetration test shows how far that foothold reaches. One report covers the full chain.
What does the report contain?
An attack narrative for each path attempted, photo and timestamp evidence, a ranked list of findings by the access each produced, the framework requirement each finding affects, a remediation plan with hardware and procedure fixes, and the results of the retest. The report is written so that a facilities manager and a compliance lead can act on it together without translation.
Related Penetration Testing and Compliance Resources
Penetration Testing Services
→Social Engineering Testing
→Internal Penetration Testing
→External Penetration Testing
→Network Penetration Testing
→Penetration Testing in Raleigh, NC
→CMMC Physical Protection Domain
→Security Awareness Training
→Last Updated: September 6, 2026. This page references NIST SP 800-171 Revision 2 Family 3.10 (Physical Protection), the CMMC Physical Protection domain under 32 CFR Part 170, the HIPAA Security Rule physical safeguards at 45 CFR 164.310, and PCI DSS Requirement 9. We update it when any of those sources change. For the wider security picture, download the free 2026 SMB Cybersecurity Survival Guide, browse Craig Petronella's published books, or listen to the Encrypted Ambition podcast.
Test the Doors Before Someone Else Does
Petronella Technology Group has secured regulated businesses and defense suppliers since 2002, holds a BBB A+ rating dating to 2003, and operates as a CyberAB Registered Provider Organization (RPO #1449). Tell us about your facility and we will propose a physical penetration test with rules of engagement you approve, evidence you can hand to an assessor, and a retest that proves the fixes worked.