Urgent Penetration Testing

A contract, an audit or an incident has put a date on your penetration test. Here is what is actually achievable at short notice, and how to tell quickly whether your deadline is realistic.

Standard lead time
2–3 weeks
Expedited
Often under 1 week
Report
5 working days, faster if needed
Scoping call
Same day, free

How fast can a penetration test actually happen?

Our standard lead time from agreed scope to testing is two to three weeks. At short notice we can frequently start within a week, and occasionally within a couple of days for a contained scope such as a single web application or an external infrastructure range.

What we will not do is agree to a date we cannot meet. If your deadline is not achievable we will say so on the first call, because discovering that two days before your submission is worse than knowing immediately.

What drives urgency, and what each case needs

A client or tender requires a recent test report

The most common reason people call at short notice. Usually a contract cannot complete without evidence of independent testing by an accredited provider. If the requirement names CREST, verify that your provider holds accreditation at company level rather than an individual certification — the wording in proposals is sometimes deliberately blurred, and a report from the wrong kind of provider may not satisfy the requirement.

These are often the easiest to expedite, because the scope is defined by the requirement itself.

An insurer or renewal deadline

Cyber insurance renewals increasingly ask for evidence of testing. Check the policy wording before scoping: some insurers specify particular coverage or accreditation, and a test scoped to the wrong thing satisfies nobody.

An audit or certification deadline

Cyber Essentials, IASME Cyber Assurance, ISO 27001 surveillance. These usually have some flexibility on date, and it is worth checking whether the auditor will accept a scheduled test rather than a completed one.

You have had an incident

Different problem, different answer. If you are dealing with an active compromise, you need incident response first — containment, investigation and establishing whether the attacker still has access. A penetration test tells you what could happen; it does not tell you what did. Test afterwards, once the environment is stable.

A vulnerability has been disclosed to you

Someone has reported a flaw and you need it verified and the surrounding area checked. This is usually a fast, contained engagement and one of the easiest to turn around quickly.

What can be compressed, and what cannot

Being clear about this saves everyone time:

  • Scoping — compressible to a same-day call. We do not require you to complete a 40-field form first.
  • Scheduling — compressible depending on our current commitments. Ask, and we will tell you honestly what is free.
  • Reporting — compressible. Critical findings are reported the moment we confirm them rather than held for the final document, and we can issue a draft or a letter of attestation ahead of the full report where a deadline demands it.
  • Testing itselfnot compressible. A five-day test does not become a two-day test because the deadline moved. It becomes a two-day test, with two days of coverage. Anyone who tells you otherwise is selling you a scan.
  • Your remediation time — not compressible either, and worth planning for. A report delivered the day before your deadline leaves no time to fix anything, which may defeat the purpose.

How to make an urgent engagement go faster

Most delay in short-notice work is not the provider. It is waiting on things from the client:

  • Send the actual requirement. The tender clause, the insurer's question, the client questionnaire. Scoping against the real wording is faster and more accurate than scoping against a summary.
  • Have credentials ready for every user role, ideally two accounts per role, tested and working before day one.
  • Confirm authorisation. If the systems are hosted or managed by a third party, written authorisation may be needed and that can take longer than the test.
  • Name one technical contact who can answer questions during testing without going through a change board.
  • Provide documentation — API specs, architecture diagrams, anything you already have. Grey-box testing finds substantially more per day than black-box, which matters when there are fewer days.

What we will tell you honestly

If the deadline cannot be met properly, we will say so rather than take the work and deliver something thin. If a smaller scope would meet the actual requirement, we will tell you that too. And if what you need is not a penetration test at all — because the requirement is really for Cyber Essentials, or because you have foundational gaps that a test would simply confirm — we will point you at that instead.

Scoping conversations are free and we do not charge a premium for urgency.

Common questions

How quickly can you start a penetration test?

Standard lead time is two to three weeks from agreed scope. At short notice we can often start within a week, and occasionally within a couple of days for a contained scope such as a single web application or an external range. Call and ask — we will tell you what is genuinely free rather than what we would like to sell.

Do you charge more for urgent work?

No. We do not apply a rush premium. The day rate is the same whether you book six weeks out or ask us to start on Monday.

Can I get a report the same week as the test?

Usually yes. Standard turnaround is five working days after testing completes, and we can compress that where a deadline requires it. Critical findings are communicated as soon as they are confirmed, not held back for the report.

Our contract needs proof of testing by a date we cannot meet. What are the options?

Send us the wording. Some requirements are satisfied by a scheduled and contracted test rather than a completed one, some accept a letter of attestation, and some genuinely need the full report. Reading the actual clause usually opens options that were not obvious.

Is a rushed test worth doing?

It depends what is being rushed. Compressing scoping and reporting costs you nothing. Compressing the testing itself means less coverage, and you should know that is the trade rather than assume the same test happened faster. We will tell you exactly what a given number of days can cover.

We think we have been breached. Should we book a penetration test?

No, not first. You need incident response — containment, investigation, and establishing whether the attacker still has access. A penetration test tells you what an attacker could do, not what one already did. Test once the environment is stable.

Related

Ready to talk?

Scoping conversations are free and there is no sales team to get past. Tell us what you're dealing with and we'll tell you honestly what you need.