- Baseline
- At least annually
- Also test
- After significant change
- High-change apps
- More often / continuous
- Always
- Retest after fixes
The baseline: annually, and after change
For most organisations, a penetration test at least once a year is the sensible baseline — it catches drift, new exposures and issues introduced since the last test, and it’s the cadence buyers and insurers expect to see. On top of the annual test, test again after any significant change: a new application or major feature, a migration, a network redesign, or a merger that bolts on someone else’s estate.
What moves the cadence
- Rate of change. A fast-moving product shipping weekly needs testing far more often than a stable internal system — often a continuous or per-release approach for the application.
- Risk and data. The more sensitive the data and the more exposed the system, the more often it’s worth testing.
- Who’s asking. Some requirements set the cadence for you (below).
When the rules decide for you
Several frameworks already mandate a cadence. NHS DTAC expects an external test at least annually with a re-test of Critical and High findings. PCI DSS requires annual testing and after significant change. Many cyber-insurers and tenders want a test dated within the last 12 months. If any of these apply to you, they set your floor.
Don't forget the retest
A test you never re-test is half a job. After you’ve fixed the findings, a re-test confirms the serious issues are actually closed — which is exactly the evidence buyers and insurers want. We include re-testing of Critical and High findings as standard.
Common questions
Is one penetration test a year enough?
For a stable environment, often yes — plus a test after any significant change. For fast-moving applications or high-risk systems, more frequent or continuous testing is wiser. The annual test is a floor, not a ceiling.
Do we need to test after every change?
After every significant change — a new app or major feature, a migration, a network redesign. Minor tweaks don’t each need a full test, but they should feed your ongoing vulnerability scanning.
How soon should we retest after fixing issues?
Once remediation is done. A prompt re-test confirms the Critical and High findings are genuinely closed and gives you clean evidence for buyers and insurers. We include it as standard.
Related
Solusec
Typically replies within one business day
Had an incident, or need a pen test at short notice?
Tell us what you're dealing with and we'll come back to you.
+44 (0)1902 288763 ✉️ Email us
info@solusec.co.uk 📝 Leave a message
We'll reply within one business day