It's not something you frequently get asked to do by a supplier (just twice in my experience so far) but I suspect may become a more frequent request as people are now more likely to be doing e-learning out of the secure workplace/school network...
It would be good to know that some level of test has already been conducted on the 'core bundle' at least...
Interesting PDF on the subject: http://www.cis.syr.edu/~wedu/Research/paper/xds_attack.pdf