A typical penetration test takes one to three weeks of active testing, plus 3–5 days for reporting. A single small application or external network can finish in under a week; a large or complex multi-asset scope runs four weeks or more. Counting the whole engagement — scoping, testing, reporting and a remediation retest — plan for three to six weeks end to end. The biggest driver is scope: the number of applications, IPs, endpoints and user roles. You can compress the calendar with tight scoping, prepared access and prioritisation — but quality testing cannot be rushed below the effort the scope genuinely needs without missing findings.
// 01 How long does a penetration test take?
For most engagements, active testing takes one to three weeks, and reporting adds a few days on top. That range holds for the majority of single-target tests — a web application, an external network, an API. The reason it is a range and not a number is that "a penetration test" covers everything from a five-day test of one small app to a month-long assessment of a complex, multi-system environment. As with cost, the useful way to think about it is by scope tier.
Crucially, the testing window is not the whole timeline. Buyers who plan only for the testing days are often surprised by the scoping at the front and the reporting and retest at the back — which is why deals waiting on a report can slip. Plan the full engagement, not just the hands-on portion.
// 02 Timeline by test type
Different test types take different amounts of active testing time. These are typical ranges for a single, reasonably-scoped target; larger or more complex scopes extend proportionally.
| Test type | Active testing (typical) | Elapsed (incl. reporting) |
|---|---|---|
| External network | 2–5 days | ~1 week |
| Web application | 5–10 days | 1–2 weeks |
| API | 4–8 days | 1–2 weeks |
| Mobile application (per platform) | 5–10 days | 1–2 weeks |
| Internal network | 5–15 days | 2–3 weeks |
| Cloud | 5–15 days | 2–3 weeks |
| Red team engagement | 3–8+ weeks | 1–3 months |
// 03 What determines the duration
Three factors move the timeline more than anything else, and understanding them lets you influence your own schedule.
Scope size
The count of applications, IPs, endpoints, user roles and dynamic pages. The single biggest driver — double the scope, roughly double the time.
Complexity
Intricate business logic, multiple tech stacks, heavy integrations and custom workflows all add testing time per asset.
Methodology depth
A grey-box test with credentials reaches authenticated areas fast; a black-box test starting from zero knowledge spends time getting in first.
A fourth, often-overlooked factor is environment readiness: delays in providing test accounts, credentials or access can stretch the calendar even when the testing effort itself is unchanged. Preparing these in advance is the cheapest way to keep an engagement on schedule.
// 04 The full engagement timeline
Here is the timeline most buyers should actually plan around — from first contact to evidenced closure.
Scoping (2–5 days)
Agree targets, rules of engagement, methodology and windows. Faster if you know your scope; slower if it needs discovery.
Scheduling (varies)
Booking into the tester's calendar and your change windows — often the least predictable part.
Testing (1–3 weeks)
The active engagement itself.
Reporting (3–5 days)
Writing up findings with severity, impact, proof and remediation.
Remediation (your pace)
You fix the findings — days to weeks depending on severity and your team.
Retest (2–5 days)
Verifying the fixes worked, so closure can be evidenced.
// 05 How to get it done faster
When a deadline is real — an audit, a customer requirement, a launch — you can genuinely compress the calendar without cutting corners on the testing itself. Scope tightly to the systems that matter rather than everything you own; prepare access, credentials and test accounts before day one; tell your provider the timeline so the engagement is prioritised and staffed; and ask for an interim attestation summary the moment testing and critical-issue remediation are complete, rather than waiting for the polished final report. What you cannot do is compress the active testing below the effort the scope genuinely requires — a real test of a large application takes the time it takes, and a provider who promises otherwise is planning to run a scan. See our cost guide for how scope drives both time and price, and our guide for deals waiting on a report.
// 06 Frequently asked questions
How long does a penetration test take?
One to three weeks of active testing plus a few days of reporting; three to six weeks for the full engagement including scoping and retest. Scope drives the number.
How long for a web app test?
Roughly 5–10 working days of testing for a single application, one to two weeks elapsed, plus reporting. More roles and logic mean more time.
What determines the duration?
Scope size, complexity, methodology depth, and environment readiness. Scope is the biggest factor.
Can it be done faster?
Yes, with tight scope, prepared access, prioritisation and an interim attestation — but not below the effort the scope genuinely requires.