Blog · C.25 · Guide

How long does a penetration test take? Real timelines

The short answer is one to three weeks of testing plus reporting — but the honest answer depends on scope. Here are realistic timelines by test type, what actually drives the duration, and the full engagement timeline most buyers forget to plan for.

TimelinesScopingPlanningDuration2026
Timelines: Testing 1–3 Weeks · Web App 5–10 Days · Reporting +3–5 Days · Full Engagement 3–6 Weeks · Scope Drives Duration Timelines: Testing 1–3 Weeks · Web App 5–10 Days · Reporting +3–5 Days · Full Engagement 3–6 Weeks · Scope Drives Duration
// TL;DR

A typical penetration test takes one to three weeks of active testing, plus 3–5 days for reporting. A single small application or external network can finish in under a week; a large or complex multi-asset scope runs four weeks or more. Counting the whole engagement — scoping, testing, reporting and a remediation retest — plan for three to six weeks end to end. The biggest driver is scope: the number of applications, IPs, endpoints and user roles. You can compress the calendar with tight scoping, prepared access and prioritisation — but quality testing cannot be rushed below the effort the scope genuinely needs without missing findings.

// 01 How long does a penetration test take?

For most engagements, active testing takes one to three weeks, and reporting adds a few days on top. That range holds for the majority of single-target tests — a web application, an external network, an API. The reason it is a range and not a number is that "a penetration test" covers everything from a five-day test of one small app to a month-long assessment of a complex, multi-system environment. As with cost, the useful way to think about it is by scope tier.

Crucially, the testing window is not the whole timeline. Buyers who plan only for the testing days are often surprised by the scoping at the front and the reporting and retest at the back — which is why deals waiting on a report can slip. Plan the full engagement, not just the hands-on portion.

// 02 Timeline by test type

Different test types take different amounts of active testing time. These are typical ranges for a single, reasonably-scoped target; larger or more complex scopes extend proportionally.

Test typeActive testing (typical)Elapsed (incl. reporting)
External network2–5 days~1 week
Web application5–10 days1–2 weeks
API4–8 days1–2 weeks
Mobile application (per platform)5–10 days1–2 weeks
Internal network5–15 days2–3 weeks
Cloud5–15 days2–3 weeks
Red team engagement3–8+ weeks1–3 months

// 03 What determines the duration

Three factors move the timeline more than anything else, and understanding them lets you influence your own schedule.

01

Scope size

The count of applications, IPs, endpoints, user roles and dynamic pages. The single biggest driver — double the scope, roughly double the time.

02

Complexity

Intricate business logic, multiple tech stacks, heavy integrations and custom workflows all add testing time per asset.

03

Methodology depth

A grey-box test with credentials reaches authenticated areas fast; a black-box test starting from zero knowledge spends time getting in first.

A fourth, often-overlooked factor is environment readiness: delays in providing test accounts, credentials or access can stretch the calendar even when the testing effort itself is unchanged. Preparing these in advance is the cheapest way to keep an engagement on schedule.

// 04 The full engagement timeline

Here is the timeline most buyers should actually plan around — from first contact to evidenced closure.

Stage 01

Scoping (2–5 days)

Agree targets, rules of engagement, methodology and windows. Faster if you know your scope; slower if it needs discovery.

Stage 02

Scheduling (varies)

Booking into the tester's calendar and your change windows — often the least predictable part.

Stage 03

Testing (1–3 weeks)

The active engagement itself.

Stage 04

Reporting (3–5 days)

Writing up findings with severity, impact, proof and remediation.

Stage 05

Remediation (your pace)

You fix the findings — days to weeks depending on severity and your team.

Stage 06

Retest (2–5 days)

Verifying the fixes worked, so closure can be evidenced.

// 05 How to get it done faster

When a deadline is real — an audit, a customer requirement, a launch — you can genuinely compress the calendar without cutting corners on the testing itself. Scope tightly to the systems that matter rather than everything you own; prepare access, credentials and test accounts before day one; tell your provider the timeline so the engagement is prioritised and staffed; and ask for an interim attestation summary the moment testing and critical-issue remediation are complete, rather than waiting for the polished final report. What you cannot do is compress the active testing below the effort the scope genuinely requires — a real test of a large application takes the time it takes, and a provider who promises otherwise is planning to run a scan. See our cost guide for how scope drives both time and price, and our guide for deals waiting on a report.

// 06 Frequently asked questions

How long does a penetration test take?

One to three weeks of active testing plus a few days of reporting; three to six weeks for the full engagement including scoping and retest. Scope drives the number.

How long for a web app test?

Roughly 5–10 working days of testing for a single application, one to two weeks elapsed, plus reporting. More roles and logic mean more time.

What determines the duration?

Scope size, complexity, methodology depth, and environment readiness. Scope is the biggest factor.

Can it be done faster?

Yes, with tight scope, prepared access, prioritisation and an interim attestation — but not below the effort the scope genuinely requires.

UG

Usama Gul

Founder & Penetration Testing Lead, CyberFortify

Scopes and schedules dozens of engagements a year. Writes on how testing time is estimated so buyers can plan realistically around audits, deals and launches.

Need it done on a deadline?

Tell us your scope and your date. We'll give you an honest timeline, prioritise the engagement, and provide an interim attestation the moment testing and critical remediation are done.

Get a timeline → See the cost →