Timeline · 29 Sep 2026

How Long Does a Penetration Test Take?

Short answer: most tests run 3 to 10 business days of active testing, plus 2 to 4 days to write the report. A focused web app is usually a week; a network or Active Directory environment, one to two. The honest answer is "it depends on scope" - here is exactly what that means, and how to plan around a deadline.

The three phases every timeline is made of

When people ask how long a pentest takes, they usually mean one of two different things: how many days of testing, or how long from signing off to holding the final report. Both matter, and they're not the same. Every engagement breaks into three phases:

  • Scoping - a free 30-minute call, then a written proposal with a fixed price and exact dates within 24 hours. Once you approve it, testing is booked.
  • Active testing - the actual hands-on work against your systems. This is the number that scales with scope.
  • Reporting - writing up each finding with the evidence that proves it, a CVSS rating, and a remediation step. Usually 2 to 4 business days after testing ends.

A free retest to confirm your fixes is included after remediation, and that's typically short - a day or two.

Typical testing windows by type

Web application

A focused, single-role application is usually 3 to 5 business days of active testing. More user roles, a larger endpoint count, a REST or GraphQL API, or complex business logic (checkout flows, payment handling, file processing) each add days - a large multi-role SaaS platform can run 1 to 2 weeks.

Network and Active Directory

An internal network or Active Directory assessment is usually 5 to 10 business days. Host count, the number of domains, forests and trust relationships, and whether segmentation needs validating all move the number. A single-domain environment lands at the short end; multi-forest with trust chaining at the long end.

External network

An external perimeter test is often 2 to 5 business days, depending on how many live hosts and services are exposed. If you want a free, instant preview of what an attacker sees from outside before you scope anything, the free perimeter scan gives you that in seconds.

Compliance tests (SOC 2, PCI DSS)

A SOC 2 or PCI DSS test scoped like a standard web or network test takes about the same amount of testing time as one. The compliance framework changes how the report is formatted and how evidence maps to controls for your auditor or QSA - it doesn't add testing days on its own.

What makes a test take longer

  • Scope discovered mid-test - undocumented endpoints, extra subdomains, or hosts nobody mentioned. Accurate scoping up front avoids this.
  • Environment access delays - waiting on VPN credentials, test accounts, or allowlisting eats calendar days even when testing itself is quick.
  • Fragile production systems - if testing has to be careful and coordinated around a live environment, it moves slower than a staging copy.
  • Deep business logic - the more an application does that's unique to your business, the more manual testing it takes, because a scanner can't understand it.

Planning around a deadline

If you're testing for an audit or a customer's security review, work backwards from the deadline and give yourself room. A safe plan is to book 3 to 4 weeks before the date you need the report in hand - that covers the scoping call, the testing window, report delivery, and, crucially, time for your own team to fix findings and have them retested before the deadline. The most common scheduling mistake is booking so late that there's no room left to remediate what the test finds, which defeats the point.

How scheduling works here

Every engagement starts with a free 30-minute scoping call, followed by a written proposal with a fixed price and exact start and delivery dates within 24 hours - no hourly billing, no timeline that quietly slips once testing starts. See the full pricing breakdown, browse a specific service, or read how to prepare for your first penetration test so your testing window starts on day one instead of waiting on access.

Common questions about pentest timelines

Most engagements run 3 to 10 business days of active testing, plus 2 to 4 business days to write the report. A focused single-role web application is usually 3 to 5 days of testing; a network or Active Directory environment is usually 5 to 10. From booking to final report, a typical calendar timeline is 1 to 3 weeks depending on scheduling.

If you have a compliance deadline or an audit date, book 3 to 4 weeks out. That leaves room for a scoping call, the testing window itself, report delivery, and time for your team to fix findings and have them retested before the deadline.

No. The testing and reporting timeline ends when you receive the report. Remediation time is yours and depends on how many findings there are and their severity. A free retest to confirm your fixes is included, and that retest is usually short - a day or two.

Scheduling can often be moved up, but the active testing window itself should not be compressed below what the scope needs. Manual testing finds business-logic flaws and chained attack paths that automated scanning misses, and rushing that window is how those get missed. A tighter deadline is better handled by booking sooner or narrowing scope, not by shortening the test.

Need the report by a specific date?

Free scoping call, fixed-price proposal with exact dates within 24 hours.

See pricing