Penetration Testing
Penetration Testing: Process, Duration and What It Costs
Anyone buying a penetration test for the first time wants to know three things: how it runs, how long it takes, and what it costs. The honest answer to the third question is that it depends on the scope. This article explains why that is not an evasion but the only responsible answer, and what really matters about the process and the duration.
- A penetration test runs in clear phases: scope, reconnaissance, testing, verification, report, retest.
- The duration follows the size of the application, the number of roles and the depth of the review.
- The cost hangs on the scope. Anyone naming a fixed figure without looking at the system is guessing.
- What makes a test dependable: a proof per finding instead of a list full of hunches.
How a penetration test runs
A good test follows a traceable process. The phases build on one another, and each has a clear purpose.
Scope and authorization
First, we define which systems, roles and impacts are tested and which are explicitly not. These boundaries and the authorization belong in writing before anything is tested.
Reconnaissance and mapping
The attack surface is mapped: entry points, trust boundaries, permissions. This is where it becomes clear where an attacker would start.
Testing and chaining
Every relevant vulnerability class is examined. Individual weaknesses are connected into chains, because the real impact usually emerges only when several small gaps combine.
Verification per finding
Every candidate is cross-checked. Only what can be backed by an executed proof of concept is carried as a finding. The rest is discarded honestly, rather than padding the list.
Report and handover
The result is a review-ready report with an executive summary, a risk register, a proof and a suggested fix per finding, plus a call to help you prioritize.
Retest
After the fixes, the resolved findings are re-examined, so that the remediation is evidenced and not merely asserted.
How long a penetration test takes
The duration is not a fixed quantity but a function of the scope. Three factors drive it most strongly:
- Size and complexity of the application. A single interface is examined faster than a grown platform with many modules.
- Number of roles and permission levels. Every additional role means new trust boundaries that have to be checked individually.
- Depth of the review. A broad overview needs less time than a review that backs each finding with an executed proof of concept.
The duration can only be gauged responsibly after a look at the system. That is why the start is always a conversation about scope, not a figure from a price list.
What a penetration test costs
Here is the honest answer, and it matters more than a figure: the price depends on the scope. A provider who names a fixed sum without having seen your system is doing one of two things. Either they have a fixed, narrow frame in mind that may not fit your product. Or they are guessing, and a guessed price leads either to a shallow review or to a later top-up.
The factors that determine the effort are the same as for the duration: size, roles and depth. Add to that whether a retest of the resolved findings is included, because an evidenced remediation is worth more than a reported gap. Rather than a flat rate, the sensible path is therefore to discuss the scope first, then give an individual quote. That way you pay for the review your system needs, not for a standard package.
For good reason, we name no figures here. A number without a scope would be misleading, and a price always hangs on the specific project.
How to recognize a dependable test
Not every test is worth the same. The most important quality difference lies in whether findings are verified or merely suspected. A pure scanner report lists what matches known patterns, false alarms included. A dependable test backs each individual finding with an executed proof of concept and discards what cannot be confirmed, rather than upgrading it to boost the count.
Watch for three things. Does every reported finding come with a reproducible proof? Are false alarms sorted out honestly instead of filling the list? And is the report built so that an enterprise procurement team or an external reviewer can work with it? If so, you are holding a result that carries weight.
Let us talk about your scope
In a free 30-minute conversation we outline what a sensible penetration test covers for your system and how it runs. Afterwards you know what matters before effort is even discussed.
Request a conversationCyberSec42 provides independent technical security testing. It is not an accredited certification body and does not provide legal advice.
Frequently asked questions
How does a penetration test run?
In clear phases: define scope and authorization, map the attack surface, test and chain the vulnerability classes, verify each finding, hand over a review-ready report, and re-examine the resolved findings in a retest.
How long does a penetration test take?
It depends on the scope: the size of the application, the number of roles and the depth of the review. A dependable estimate is only possible after a look at the system.
What does a penetration test cost?
The price follows the scope. A fixed figure without knowledge of the system would be a guess. The sensible path is to discuss the extent first and then give an individual quote.
Why are no concrete prices named here?
Because a price without a scope would be misleading. Size, number of roles, depth of review and a possible retest determine the effort, and those can only be judged on the specific project.
What separates a good test from a shallow one?
Whether findings are verified or merely suspected. A dependable test backs each individual finding with an executed proof of concept, sorts out false alarms, and delivers a report that holds up to review.