How Often Should You Get a Penetration Test?

‘At least annually, and after significant change’ is the honest short answer — but the right cadence depends on how fast you change and who’s asking. Here’s how to decide.

Baseline
At least annually
Also test
After significant change
High-change apps
More often / continuous
Always
Retest after fixes

The baseline: annually, and after change

For most organisations, a penetration test at least once a year is the sensible baseline — it catches drift, new exposures and issues introduced since the last test, and it’s the cadence buyers and insurers expect to see. On top of the annual test, test again after any significant change: a new application or major feature, a migration, a network redesign, or a merger that bolts on someone else’s estate.

What moves the cadence

  • Rate of change. A fast-moving product shipping weekly needs testing far more often than a stable internal system — often a continuous or per-release approach for the application.
  • Risk and data. The more sensitive the data and the more exposed the system, the more often it’s worth testing.
  • Who’s asking. Some requirements set the cadence for you (below).

When the rules decide for you

Several frameworks already mandate a cadence. NHS DTAC expects an external test at least annually with a re-test of Critical and High findings. PCI DSS requires annual testing and after significant change. Many cyber-insurers and tenders want a test dated within the last 12 months. If any of these apply to you, they set your floor.

Don't forget the retest

A test you never re-test is half a job. After you’ve fixed the findings, a re-test confirms the serious issues are actually closed — which is exactly the evidence buyers and insurers want. We include re-testing of Critical and High findings as standard.

Common questions

Is one penetration test a year enough?

For a stable environment, often yes — plus a test after any significant change. For fast-moving applications or high-risk systems, more frequent or continuous testing is wiser. The annual test is a floor, not a ceiling.

Do we need to test after every change?

After every significant change — a new app or major feature, a migration, a network redesign. Minor tweaks don’t each need a full test, but they should feed your ongoing vulnerability scanning.

How soon should we retest after fixing issues?

Once remediation is done. A prompt re-test confirms the Critical and High findings are genuinely closed and gives you clean evidence for buyers and insurers. We include it as standard.

Related

Work out the right testing cadence

Tell us what you run and who’s asking. We’ll recommend a sensible testing schedule — no more, no less than you need.