Fast CREST penetration test
What a removed day actually costs you in findings, the four dates to get in writing before you sign, and why the organisations that get tested quickly sorted it out months earlier.
When do you need the report by?
Tell us the date you need something in your hand, rather than the date you would like testing to start. We will work backwards from it and tell you what is realistic before you commit to anything.
Fast and urgent are different purchases
Worth separating these before anything else, because they lead to different decisions. Urgent means a date already exists and you are behind it, so the question is what can still be salvaged. Fast means you are choosing a provider partly on turnaround, with time to choose well. If you are in the first situation, urgent CREST penetration test deals with reading the clause, verifying accreditation quickly and what a buyer will accept when the date cannot be met.
This page is the other one. It is about what speed actually costs, what it does not cost, and why the organisations that get tested quickly are usually the ones that did something about it months earlier.
What a removed day actually costs you
The unhelpful version of this conversation treats days as interchangeable, as though a five-day test is the same work as a three-day test with less padding. It is not. Days on a penetration test are not evenly productive, and the ones at the end are worth more than the ones at the start.
Roughly how the work distributes on a contained web application engagement:
- The first day is mapping. Finding what exists, how the application hangs together, where the interesting functionality is. Little of it appears in the report and none of it can be skipped, because it is what makes the rest of the days useful.
- The middle is the systematic pass. Every input, every role, the whole OWASP-shaped surface. This is the part people imagine when they picture a penetration test, and it produces most of the findings by count.
- The last day or two is where the tester chains things together. A low-severity information leak plus a weak access control becomes a way into another customer's data. Business logic gets pushed on properly. This produces fewer findings by count and, in our experience, most of the ones that actually matter.
So when a scope that genuinely needs five days is bought as three, what gets dropped is not spread evenly across the report. It is the end of the engagement, which is the expensive part to lose. That is the honest trade, and it is worth making knowingly rather than discovering afterwards.
None of this argues against buying three days. A three-day test that everybody understands as a three-day test is a perfectly reasonable purchase, particularly for a first engagement or a narrow scope. What is not reasonable is buying three days and believing you bought five.
The four dates, and which one your provider means
Providers quoting turnaround are rarely quoting the same thing, which makes comparing them harder than it looks. Ask for four dates in writing and the comparison becomes straightforward.
| Date | The question it answers | Why people get caught out |
|---|---|---|
| Earliest start | When can a tester actually begin | "Two week lead time" often describes the average rather than the next free slot. Ask for a date, not a duration. |
| Testing window | How many days, and which days | A window split across two weeks around other commitments finishes later than the day count suggests. |
| Report delivered | When you can hand something to whoever asked | This is the date your deadline actually runs against, and it is the one least often quoted up front. |
| Retest completed | When you can evidence the issues are closed | Some requirements want findings closed, not merely found. If that is yours, the retest is on your critical path. |
For reference, ours are: two to three weeks to start as standard and frequently within a week at short notice, the report within five working days of testing completing, and a retest included once you have made the fixes. Critical findings go to you the moment they are confirmed rather than waiting for the document. There is no rush premium, so a short-notice booking is priced exactly like a planned one, and what a penetration test costs sets out the ranges.
How to be an organisation that can be tested next week
Most of the elapsed time on a fast engagement is not the provider working. It is waiting for the client, and almost all of it is avoidable by people who set a few things up before they needed a test at all.
- Know who signs the authorisation, and check they can. The rules of engagement document is what makes the testing lawful, and it needs somebody with authority to commit the organisation. Finding out who that is while a tester sits idle is the single most common delay on work that was meant to be quick.
- Get third-party permission agreed in principle now. If your systems sit with a hosting provider or a managed service provider, their written authorisation is usually needed. Asking them once, in calm conditions, and keeping the answer on file is a twenty minute job that has saved people a fortnight.
- Keep test accounts alive. Two working accounts per user role, created deliberately rather than borrowed from a real user, and logged into occasionally so they have not silently expired. Credential problems on day one are routine and they waste the most expensive hours of the engagement.
- Maintain a list of what you own. Confirmed IP ranges that are genuinely yours, and the applications that matter with their environments. Scoping against a real list takes an afternoon. Scoping against a vague recollection takes a fortnight and produces a worse scope.
- Decide in advance who fixes things. A report delivered the day before your deadline leaves no time to act on it. Knowing whose backlog the remediation lands in, and roughly what capacity they have, turns a report into closed findings rather than a document that ages.
None of that is difficult and none of it requires a provider. It is the difference between a test that can start on Monday and one that starts in three weeks because of a signature.
If you need speed repeatedly, buy the slot rather than the rush
Some organisations need testing quickly once. Others need it quickly several times a year, because they ship continuously, because customers keep asking, or because the security requirement sits on a rolling contract rather than an annual one. Those are different problems and only one of them is solved by finding a fast supplier.
The arrangement that works for the second group is a block of testing days agreed up front and drawn down as needed, across whatever comes up. It changes the shape of the problem rather than the speed of the provider. The commercial conversation has already happened, so a new piece of work is a scheduling question rather than a procurement cycle, and it prices better than quoting each engagement separately. We run this with clients who sit close to a release cycle, and it is the reason they can say yes to a three-week deadline without going near a purchase order.
If that sounds like you, say so on the first call. It is not something we advertise heavily and it is usually the right answer for anybody who has searched for fast penetration testing more than once.
Where we stand on speed
Solusec is accredited by CREST at company level and is a CREST member company, and testing is delivered by a CREST-registered tester. Accreditation governs method and quality assurance rather than speed, so it does not make a test faster, and any provider claiming otherwise is describing a shortcut you would not want. What it does mean is that the report which arrives at the end satisfies a clause that names CREST, which is usually why the deadline exists in the first place.
We will tell you on the first call whether your date is achievable, and if a smaller scope would meet the actual requirement we will say that too. If what you need turns out not to be a penetration test at all, because the requirement is really Cyber Essentials, we would rather point you there than sell you the wrong thing quickly.
Common questions
How fast is a fast CREST penetration test, realistically?
If I buy fewer days, do I get the same test faster?
Which parts of a fast engagement cost nothing to speed up?
What is the single biggest cause of delay on a test that was meant to be fast?
We need testing at short notice several times a year. Is there a better way than asking each time?
Does a faster provider mean a worse one?
Related
Solusec
Typically replies within one business day
Had an incident, or need a penetration test or Cyber Essentials at short notice?
Tell us what you're dealing with and we'll come back to you.
+44 (0)1902 288763 ✉️ Email us
info@solusec.co.uk 📝 Leave a message
We'll reply within one business day
Ready to talk?
Scoping conversations are free and there is no sales team to get past. Tell us what you're dealing with and we'll tell you honestly what you need.