Urgent penetration testing

Real lead times from a CREST-accredited provider, an honest account of what can be compressed, and what to do when your date is not achievable.

Tell us your date. We can help at short notice.

Give us the deadline and roughly what needs testing. We will tell you on the first call whether it is achievable and quote a fixed price. No sales team to get past, and you are dealing with the senior people who will do the testing, overseen by our founder throughout.

Your details are handled by a real person, never fed into AI.

How fast can a penetration test actually happen?

Our standard lead time from agreed scope to testing is two to three weeks. At short notice we can frequently start within a week, and occasionally within a couple of days for a contained scope such as a single web application or an external infrastructure range.

Penetration testing lead times, Solusec
ScopeStandard lead timeAt short notice
Single web application, defined scope2 to 3 weeksOften within a week, occasionally 2 to 3 days
External infrastructure range2 to 3 weeksOften within a week, occasionally 2 to 3 days
Verifying a single disclosed vulnerability1 to 2 weeksFrequently within days
Internal network, single site3 to 4 weeksWithin 2 weeks, subject to site access
Large multi-application estate4 to 6 weeksRarely compressible below 3 weeks

If you are planning rather than rescuing, fast CREST penetration test sets out what a removed day costs in findings and the four dates worth having in writing. Urgency does not change our day rate. A short-notice engagement is priced the same as a planned one: see what a penetration test costs for ranges by test type. What urgency costs you is choice of dates, not money.

What we will not do is agree to a date we cannot meet. If your deadline is not achievable we will say so on the first call, because discovering that two days before your submission is worse than knowing immediately.

Mobilising at a day’s notice

The lead times above are measured from agreed scope, and they assume the usual back and forth about authorisation and access. Where that is already settled, mobilisation is a good deal quicker. On a contained scope we can normally have a tester working within about a day of everything being in place, which is what the two to three day figure in the table collapses to once the waiting is taken out of it.

Everything being in place means all of the following, not most of it:

  • Scope confirmed in writing. The URLs, IP ranges or applications that are in, and the ones that are out.
  • Signed authorisation from somebody who can commit the organisation. This is what makes the testing lawful, and there is no version of this we will start without.
  • Third-party permission in writing where a hosting or managed service provider’s terms require it.
  • Working credentials, ideally two accounts per user role, where the test is authenticated.
  • A named technical contact reachable during testing, and an agreed testing window.

Miss one and the day becomes a week, which is the argument for sorting the list out before you need it rather than after. If it is all genuinely ready, say so on the first call, because it changes what we are able to offer you.

What drives urgency, and what each case needs

A client or tender requires a recent test report

The most common reason people call at short notice. Usually a contract cannot complete without evidence of independent testing by an accredited provider. If the requirement names CREST, verify that your provider holds accreditation at company level rather than an individual certification (see urgent CREST penetration test for how to check and what the clause wording changes): the wording in proposals is sometimes deliberately blurred, and a report from the wrong kind of provider may not satisfy the requirement.

These are often the easiest to expedite, because the scope is defined by the requirement itself.

An insurer or renewal deadline

Cyber insurance renewals increasingly ask for evidence of testing. Check the policy wording before scoping: some insurers specify particular coverage or accreditation, and a test scoped to the wrong thing satisfies nobody.

An audit or certification deadline

Cyber Essentials, IASME Cyber Assurance, ISO 27001 surveillance. These usually have some flexibility on date, and it is worth checking whether the auditor will accept a scheduled test rather than a completed one.

You have had an incident

Different problem, different answer. If you are dealing with an active compromise, you need incident response first: containment, investigation and establishing whether the attacker still has access. A penetration test tells you what could happen; it does not tell you what did. Test afterwards, once the environment is stable.

A vulnerability has been disclosed to you

Someone has reported a flaw and you need it verified and the surrounding area checked. This is usually a fast, contained engagement and one of the easiest to turn around quickly.

What can be compressed, and what cannot

Being clear about this saves everyone time:

  • Scoping: compressible to a same-day call. We do not require you to complete a 40-field form first.
  • Scheduling: compressible depending on our current commitments. Ask, and we will tell you honestly what is free.
  • Reporting: compressible. Critical findings are reported the moment we confirm them rather than held for the final document, and we can issue a draft or a letter of attestation ahead of the full report where a deadline demands it.
  • Testing itself: not compressible. A five-day test does not become a two-day test because the deadline moved. It becomes a two-day test, with two days of coverage. Anyone who tells you otherwise is selling you a scan.
  • Your remediation time, not compressible either, and worth planning for. A report delivered the day before your deadline leaves no time to fix anything, which may defeat the purpose.

How to make an urgent engagement go faster

Most delay in short-notice work is not the provider. It is waiting on things from the client:

  • Send the actual requirement. The tender clause, the insurer's question, the client questionnaire. Scoping against the real wording is faster and more accurate than scoping against a summary.
  • Have credentials ready for every user role, ideally two accounts per role, tested and working before day one.
  • Confirm authorisation. If the systems are hosted or managed by a third party, written authorisation may be needed and that can take longer than the test.
  • Name one technical contact who can answer questions during testing without going through a change board.
  • Provide documentation: API specs, architecture diagrams, anything you already have. Grey-box testing finds substantially more per day than black-box, which matters when there are fewer days.

What we will tell you honestly

If the deadline cannot be met properly, we will say so rather than take the work and deliver something thin. If a smaller scope would meet the actual requirement, we will tell you that too. And if what you need is not a penetration test at all, because the requirement is really for Cyber Essentials, or because you have foundational gaps that a test would simply confirm: we will point you at that instead.

Scoping conversations are free and we do not charge a premium for urgency.

Common questions

How quickly can you start a penetration test?

Standard lead time is two to three weeks from agreed scope. At short notice we can often start within a week, and occasionally within a couple of days for a contained scope such as a single web application or an external range. Call and ask: we will tell you what is genuinely free rather than what we would like to sell.

Do you charge more for urgent work?

No. We do not apply a rush premium. The day rate is the same whether you book six weeks out or ask us to start on Monday.

Can I get a report the same week as the test?

Usually yes. Standard turnaround is five working days after testing completes, and we can compress that where a deadline requires it. Critical findings are communicated as soon as they are confirmed, not held back for the report.

Our contract needs proof of testing by a date we cannot meet. What are the options?

Send us the wording. Some requirements are satisfied by a scheduled and contracted test rather than a completed one, some accept a letter of attestation, and some genuinely need the full report. Reading the actual clause usually opens options that were not obvious.

Is a rushed test worth doing?

It depends what is being rushed. Compressing scoping and reporting costs you nothing. Compressing the testing itself means less coverage, and you should know that is the trade rather than assume the same test happened faster. We will tell you exactly what a given number of days can cover.

We think we have been breached. Should we book a penetration test?

No, not first. You need incident response: containment, investigation, and establishing whether the attacker still has access. A penetration test tells you what an attacker could do, not what one already did. Test once the environment is stable.

Related

Ready to talk?

Scoping conversations are free and there is no sales team to get past. Tell us what you're dealing with and we'll tell you honestly what you need.