After you book, a penetration test runs through set stages: scoping & rules of engagement → kickoff → active testing (1–3 weeks, with live escalation of any critical finding) → reporting → readout call → remediation → retest → updated report or attestation. Total elapsed time is usually 4–6 weeks. The two things you provide that most affect quality are test credentials (for authenticated testing) and a responsive technical contact. Insist that a retest is included — it's what turns a list of findings into evidence you're now secure. Stage-by-stage walkthrough below; to get ready, pair this with how to prepare for a pentest.
// 01 Stage 1 — Scoping & rules of engagement
Nothing gets touched until this is done. You and the provider pin down exactly what's in scope — which applications, IP ranges, environments — the test type (external, internal, web, API, cloud), the testing window, key contacts, and the escalation path for anything critical. You sign the rules of engagement, and where your assets are hosted by a third party (a cloud provider, a SaaS platform), you may need an authorisation letter confirming you're permitted to have them tested. This stage feels like paperwork, but it's where a good engagement is won: precise scope means the testers spend their time on your real risk, not clarifying boundaries mid-test.
// 02 Stage 2 — Kickoff
A short call to switch the engagement on. Here you confirm the final scope, hand over access and credentials (for authenticated testing, test accounts at each relevant privilege level), sort any allow-listing of the testers' source addresses, and agree the communication channel — often a shared secure chat — plus who gets called if something critical turns up. Five minutes of clarity here saves days later. This is also your moment to flag anything fragile (a delicate production system, a maintenance window to avoid), so the testers plan around it.
// 03 Stage 3 — Active testing (with live alerts)
Now the actual work: one to three weeks of hands-on testing depending on scope, blending manual technique with tooling against your systems. You won't hear constant updates — testers are heads-down — but you will hear immediately if they find something severe. A responsible provider doesn't sit on a critical, actively-exploitable issue until the report; the rules of engagement define a live escalation path, and a genuine emergency (a route into sensitive data, a path to full compromise) triggers a prompt call to your named contact so remediation can start at once. Your job during this stage is simply to keep that contact responsive to access issues and escalations.
// 04 Stage 4 — Reporting & readout
The report
Every finding with reproducible evidence, a severity rating, business impact and concrete remediation guidance.
Executive summary
A non-technical overview for leadership and, in redacted form, for customers and auditors.
The readout
A walkthrough call explaining findings, priorities and root causes — and answering your team's questions.
Prioritisation
Clear guidance on what to fix first, so remediation targets real risk rather than the longest list.
Learn to get the most from the document with how to read a penetration test report and how to prioritise findings.
// 05 Stage 5 — Remediation & retest
The engagement isn't finished when the report lands — it's finished when the findings are fixed and verified. You remediate (with a remediation plan to sequence the work), then the tester retests: re-checking each fix to confirm it actually closed the issue and didn't introduce a new one, and issuing an updated report or attestation reflecting the closed status. This stage is the one buyers most often overlook and most need — a retest is what converts “here are your vulnerabilities” into “these vulnerabilities are now closed,” which is exactly the evidence auditors, insurers and customers want. Confirm at booking that a retest is included, and for how long after the initial test. End to end, budget four to six weeks — and if you're on a regulator's clock, start early.
// 06 Frequently asked questions
What happens first after you book?
Scoping and rules of engagement, not testing. You confirm which systems are in scope, the test type, the window, contacts, and the critical-finding escalation path, then sign the rules of engagement and (for third-party-hosted assets) any authorisation letter. Getting this right up front makes the rest of the engagement smooth.
What does the client need to provide?
An agreed scope and signed rules of engagement; access to in-scope systems, including test accounts at the right privilege levels for authenticated testing; any allow-listing of the testers' addresses; a responsive technical contact; and, for cloud/hosted assets, provider authorisation. Test credentials and a responsive contact most affect how deep the test can go.
Will I hear about critical findings during the test?
Yes. A responsible provider doesn't wait for the report to raise a critical or actively-exploitable issue. The rules of engagement define an escalation path, and severe findings are alerted to your named contact promptly so remediation can start immediately. Everything else is consolidated into the report.
Is retesting included?
It should be, and it's worth insisting on. After you remediate, the tester re-checks the findings to confirm the fixes work and issues an updated report or attestation showing closed status. A retest turns a list of findings into evidence you're now secure — what auditors, insurers and customers want. Clarify at booking whether it's included and for how long.
// 07 Related reading
- How to prepare for a penetration test — get ready before stage 1.
- How to read the report and prioritise the findings.
- Building a remediation plan and why retesting matters.