Fast CREST penetration test

What a removed day actually costs you in findings, the four dates to get in writing before you sign, and why the organisations that get tested quickly sorted it out months earlier.

When do you need the report by?

Tell us the date you need something in your hand, rather than the date you would like testing to start. We will work backwards from it and tell you what is realistic before you commit to anything.

Your details are handled by a real person, never fed into AI.

Fast and urgent are different purchases

Worth separating these before anything else, because they lead to different decisions. Urgent means a date already exists and you are behind it, so the question is what can still be salvaged. Fast means you are choosing a provider partly on turnaround, with time to choose well. If you are in the first situation, urgent CREST penetration test deals with reading the clause, verifying accreditation quickly and what a buyer will accept when the date cannot be met.

This page is the other one. It is about what speed actually costs, what it does not cost, and why the organisations that get tested quickly are usually the ones that did something about it months earlier.

What a removed day actually costs you

The unhelpful version of this conversation treats days as interchangeable, as though a five-day test is the same work as a three-day test with less padding. It is not. Days on a penetration test are not evenly productive, and the ones at the end are worth more than the ones at the start.

Roughly how the work distributes on a contained web application engagement:

  • The first day is mapping. Finding what exists, how the application hangs together, where the interesting functionality is. Little of it appears in the report and none of it can be skipped, because it is what makes the rest of the days useful.
  • The middle is the systematic pass. Every input, every role, the whole OWASP-shaped surface. This is the part people imagine when they picture a penetration test, and it produces most of the findings by count.
  • The last day or two is where the tester chains things together. A low-severity information leak plus a weak access control becomes a way into another customer's data. Business logic gets pushed on properly. This produces fewer findings by count and, in our experience, most of the ones that actually matter.

So when a scope that genuinely needs five days is bought as three, what gets dropped is not spread evenly across the report. It is the end of the engagement, which is the expensive part to lose. That is the honest trade, and it is worth making knowingly rather than discovering afterwards.

None of this argues against buying three days. A three-day test that everybody understands as a three-day test is a perfectly reasonable purchase, particularly for a first engagement or a narrow scope. What is not reasonable is buying three days and believing you bought five.

The four dates, and which one your provider means

Providers quoting turnaround are rarely quoting the same thing, which makes comparing them harder than it looks. Ask for four dates in writing and the comparison becomes straightforward.

The four dates worth having in writing before you sign
DateThe question it answersWhy people get caught out
Earliest startWhen can a tester actually begin"Two week lead time" often describes the average rather than the next free slot. Ask for a date, not a duration.
Testing windowHow many days, and which daysA window split across two weeks around other commitments finishes later than the day count suggests.
Report deliveredWhen you can hand something to whoever askedThis is the date your deadline actually runs against, and it is the one least often quoted up front.
Retest completedWhen you can evidence the issues are closedSome requirements want findings closed, not merely found. If that is yours, the retest is on your critical path.

For reference, ours are: two to three weeks to start as standard and frequently within a week at short notice, the report within five working days of testing completing, and a retest included once you have made the fixes. Critical findings go to you the moment they are confirmed rather than waiting for the document. There is no rush premium, so a short-notice booking is priced exactly like a planned one, and what a penetration test costs sets out the ranges.

How to be an organisation that can be tested next week

Most of the elapsed time on a fast engagement is not the provider working. It is waiting for the client, and almost all of it is avoidable by people who set a few things up before they needed a test at all.

  1. Know who signs the authorisation, and check they can. The rules of engagement document is what makes the testing lawful, and it needs somebody with authority to commit the organisation. Finding out who that is while a tester sits idle is the single most common delay on work that was meant to be quick.
  2. Get third-party permission agreed in principle now. If your systems sit with a hosting provider or a managed service provider, their written authorisation is usually needed. Asking them once, in calm conditions, and keeping the answer on file is a twenty minute job that has saved people a fortnight.
  3. Keep test accounts alive. Two working accounts per user role, created deliberately rather than borrowed from a real user, and logged into occasionally so they have not silently expired. Credential problems on day one are routine and they waste the most expensive hours of the engagement.
  4. Maintain a list of what you own. Confirmed IP ranges that are genuinely yours, and the applications that matter with their environments. Scoping against a real list takes an afternoon. Scoping against a vague recollection takes a fortnight and produces a worse scope.
  5. Decide in advance who fixes things. A report delivered the day before your deadline leaves no time to act on it. Knowing whose backlog the remediation lands in, and roughly what capacity they have, turns a report into closed findings rather than a document that ages.

None of that is difficult and none of it requires a provider. It is the difference between a test that can start on Monday and one that starts in three weeks because of a signature.

If you need speed repeatedly, buy the slot rather than the rush

Some organisations need testing quickly once. Others need it quickly several times a year, because they ship continuously, because customers keep asking, or because the security requirement sits on a rolling contract rather than an annual one. Those are different problems and only one of them is solved by finding a fast supplier.

The arrangement that works for the second group is a block of testing days agreed up front and drawn down as needed, across whatever comes up. It changes the shape of the problem rather than the speed of the provider. The commercial conversation has already happened, so a new piece of work is a scheduling question rather than a procurement cycle, and it prices better than quoting each engagement separately. We run this with clients who sit close to a release cycle, and it is the reason they can say yes to a three-week deadline without going near a purchase order.

If that sounds like you, say so on the first call. It is not something we advertise heavily and it is usually the right answer for anybody who has searched for fast penetration testing more than once.

Where we stand on speed

Solusec is accredited by CREST at company level and is a CREST member company, and testing is delivered by a CREST-registered tester. Accreditation governs method and quality assurance rather than speed, so it does not make a test faster, and any provider claiming otherwise is describing a shortcut you would not want. What it does mean is that the report which arrives at the end satisfies a clause that names CREST, which is usually why the deadline exists in the first place.

We will tell you on the first call whether your date is achievable, and if a smaller scope would meet the actual requirement we will say that too. If what you need turns out not to be a penetration test at all, because the requirement is really Cyber Essentials, we would rather point you there than sell you the wrong thing quickly.

Common questions

How fast is a fast CREST penetration test, realistically?
For a contained scope such as one web application or an external range, a week from agreed scope to testing is often achievable and two to three days occasionally is. Standard is two to three weeks. The number that matters more is the date you can hold the report, which is usually the testing window plus five working days, so work backwards from your real deadline rather than from the start date.
If I buy fewer days, do I get the same test faster?
No. You get a smaller test. The testing days are the one part of an engagement that does not compress, because they are the work itself rather than an overhead around it. Fewer days means less of the scope is reached, and the parts usually dropped first are the deeper authenticated work where the more serious findings tend to sit.
Which parts of a fast engagement cost nothing to speed up?
Scoping, mobilisation and report issue. A scoping conversation can happen the same day, a critical finding reaches you the moment it is confirmed rather than waiting for the document, and a draft or an attestation letter can be issued ahead of the full report. None of that reduces what gets tested, so there is no trade-off to weigh.
What is the single biggest cause of delay on a test that was meant to be fast?
Authorisation, and it is not close. The rules of engagement need signing by somebody who can commit the organisation, and where the systems are hosted or managed by a third party their written permission is needed too. That depends on people who are not in the security conversation yet, and it regularly takes longer than the testing.
We need testing at short notice several times a year. Is there a better way than asking each time?
Yes. Buy a block of testing days up front and draw them down as you need them. The commercial conversation has already happened, so mobilising is a scheduling question rather than a procurement one, and it prices better than quoting each engagement separately.
Does a faster provider mean a worse one?
Not necessarily, but ask what is being made faster. Faster scoping, faster scheduling and faster reporting are real efficiencies. A five-day scope delivered in two days is not a faster test, it is a smaller one, and a provider who will not say which of those they are offering is telling you something.

Related

Ready to talk?

Scoping conversations are free and there is no sales team to get past. Tell us what you're dealing with and we'll tell you honestly what you need.