September 20, 2026
The Testing Takes a Week. The Calendar Around It Is What Breaks Your Audit Deadline
For teams planning a first or annual pentest โ how long each phase really takes, what stretches it, and how to work back from a due date

By Invadel
5 min read
When a prospect asks me how long a penetration test takes, I give two answers. The short one: about one week of hands-on testing for a standard scope, followed by the report. The honest one: that week sits in the middle of a five-phase engagement, and the phases around it decide when the evidence actually lands on an auditor's desk.
In my experience, deadlines are missed in the phases nobody put on the plan, almost never in the testing itself. Here is how the time splits up, what stretches it, and how to plan around a date you cannot move.
Five phases, one calendar
- Scoping: you describe the target, we agree the scope and a fixed price in writing. A call or an online questionnaire.
- Onboarding: kickoff, access, credentials, rules of engagement. Begins within 24 hours of a signed proposal.
- Testing: manual testing of the agreed scope. Typically starts within a week of scoping; about one week for a standard scope.
- Reporting: executive and technical reports plus a readout. Follows the testing window.
- Retest: verification of your fixes. On your schedule, once remediation is done.
Larger and multi-component scopes take longer than a week, and a red team engagement runs for weeks rather than days.
Scoping sets the dates as much as the price
A proper scoping conversation asks how many applications, user roles, API endpoints, hosts and environments are in play, which compliance framework the report has to satisfy, and when the test must be finished. What comes out is a written scope and a fixed price, agreed before any work starts.
Show up with an inventory and this phase is quick. A firm that quotes without asking these questions is guessing, and the guess gets corrected mid-engagement, in the calendar as well as the invoice.
Onboarding: access is the variable
Once the proposal is signed, onboarding starts within 24 hours: a named tester, a point of contact on your side, and rules of engagement covering testing windows, off-limits systems and how critical findings will be raised mid-test.
Access gets sorted in parallel: test accounts for every role, API documentation, VPN or appliance access for internal work, WAF allowlisting. Testing typically begins within a week of scoping, and access is what moves that date. I cannot start against an application whose credentials have not arrived.
What a week means for each type of test
For a standard scope, testing takes about a week regardless of type. What differs is what "standard" means and what expands it. The starting prices below apply to a standard scope; larger scopes are quoted after scoping and take longer.
- Web application: pages and features, user roles, workflow complexity. Authenticated testing across roles is where the hours go, because every access-control check is repeated per role per function. One app with a couple of roles fits the week; an admin console plus a customer portal plus a partner API does not. Starts at $5,200.
- API: endpoint count first, then authentication schemes and roles. A documented API tests faster: an OpenAPI spec or a Postman collection at kickoff saves days of discovery. Starts at $4,000.
- External network: live hosts and exposed services. Discovery comes first, because the real internet footprint is nearly always larger than the asset list. It needs the least from your team, so it is the easiest to schedule quickly. Starts at $4,200.
- Internal network: host count, Active Directory domains and network segments. Most internal tests run through a small appliance or virtual machine inside your network, so provisioning it is on the critical path. Starts at $6,000.
- Cloud: the number of accounts, subscriptions or projects matters more than the size of any one of them. Each extra account repeats the configuration-review-plus-exploitation cycle. Starts at $6,800.
- Mobile: both platforms when both exist, usually with the backend API in scope because the serious findings often live there. Jailbreak and root detection, certificate pinning and offline features add reverse-engineering time. Starts at $6,000 with both platforms included.
- Red team: a different shape entirely, running for weeks rather than days. It models a real adversary from reconnaissance and initial access through persistence and lateral movement, and part of the duration is deliberate pacing to see whether your detection notices. Starts at $12,500.
Scope grows in depth (more roles, endpoints, hosts or accounts on one target) and in breadth (several components, say a web app, its API and the cloud underneath). Both extend the testing window, and both are settled in scoping so the dates in the proposal are the dates you get.
Reporting is work, not an export
Each finding needs reproduction steps a developer can follow, evidence that it is real, a severity rating that survives an auditor's questions, and remediation guidance specific to your stack. You get an executive report for leadership and auditors and a technical report for the people fixing things, plus an included findings platform so your team can track remediation and request retests without emailing PDFs around.
Remediation and retest decide the total
This phase decides the total calendar, and it is mostly on your side. The test can take a week and the report can follow promptly, but if remediation takes two months, the retest happens two months later. Plan engineering time for fixes before the test starts, not after the report arrives.
The retest verifies each remediated finding and updates the report to show it closed. I include it free on every engagement, with phishing campaigns as the one exception, since they produce no findings to remediate. After the retest we issue an attestation letter summarizing scope, dates and outcome for anyone who does not need the full report.
Why tests run long
Nearly every delayed engagement I have seen comes down to one of five problems:
- Credentials that arrive late. Test accounts for every role should exist before kickoff, not on day two.
- Environments that are not ready. Staging that goes down, gets redeployed mid-test or differs from production costs testing days.
- Blocking without allowlisting. A WAF or IPS that bans tester addresses turns an hour of testing into a day of tickets.
- Missing documentation. An API with no specification means the first days go to mapping it instead of attacking it.
- Scope changes mid-engagement. Adding a second application on day three restarts scoping, pricing and scheduling.
A week of preparation removes most of that
- Finish the inventory before scoping: applications, roles, endpoints, hosts, cloud accounts and environments.
- Create test accounts for every role in scope and confirm they log in.
- Stand up and freeze the test environment, or agree production testing windows.
- Allowlist tester addresses on the WAF, IPS and rate limiters, and tell the SOC the dates.
- Share API specifications, architecture diagrams and prior reports at kickoff.
- Name one technical contact who can answer questions within the day.
- Reserve engineering time for remediation in the weeks after the report.
Working back from an audit date
A SOC 2 Type II report needs the test, the remediation and the retest inside the observation period. PCI DSS expects testing at least annually and after significant changes. NYDFS 23 NYCRR 500 expects annual penetration testing of covered systems.
Work backward from the day the evidence is due: set the retest date first, reserve the remediation time your engineers will need, place the report and the testing week before that, then add the week between scoping and the start of testing. That is your latest date to sign the proposal.
Tell the testing firm the deadline during scoping. A firm that knows the date can schedule around it; a firm that learns it after testing starts cannot.
And no, a penetration test cannot be done in a day. A vulnerability scan runs in hours; a manual test of a standard scope takes about a week, because finding business-logic flaws, broken access control and chained exploits is human work that does not compress well. Anything sold as a one-day penetration test deserves a close read.
What to remember
- Hands-on testing for a standard scope is about one week. The calendar is decided by the other four phases.
- Onboarding begins within 24 hours of signing; testing typically starts within a week of scoping, if access is ready.
- Depth and breadth of scope extend the week. Red team engagements run for weeks.
- The retest is only as early as your remediation is finished.
- Late credentials, unready environments, WAF blocking, missing documentation and mid-test scope changes cause nearly every delay.
- For SOC 2, PCI DSS or NYDFS deadlines, set the retest date first and work backward to the latest signing date.
This article is based on Invadel's guide "How Long Does a Penetration Test Take?": https://invadel.com/blog/how-long-does-a-penetration-test-take/ โ read it for the full detail. Mark Kiss is the founder of Invadel, a penetration-testing firm โ https://invadel.com/ has the services and fixed prices.