Penetration Testing: Scope, Frequency, and What Actually

A penetration test is a time-boxed engagement in which security professionals attempt to compromise your systems using the same techniques real attackers.

Penetration Testing: The Adversarial Review That Enterprise Buyers Ask About First

A penetration test is a scoped, time-limited engagement where security professionals attempt to find and exploit vulnerabilities in your product, infrastructure, or corporate environment — using the same techniques a real attacker would. Unlike automated scanners, pentesters bring adversarial creativity and chained-attack reasoning. Pentests are required or expected for SOC 2 Type II, HIPAA, PCI DSS, and any enterprise sales conversation past a certain deal size.

Types of pentests

(1) Web application pentest — testers exercise your app as authenticated and unauthenticated users, looking for injection flaws, auth bypasses, IDOR, business logic issues. Most common for SaaS. (2) Network/infrastructure pentest — external and internal network testing, cloud misconfigurations, exposed services. (3) API pentest — dedicated focus on your public/private APIs, often with a spec (OpenAPI) provided. (4) Social engineering — phishing simulations, physical tests. (5) Red team — an unscoped, goal-oriented engagement ('exfiltrate customer data') across every attack surface. Most startups run #1 and #3 annually; add #2 when infrastructure grows; add #4/#5 at enterprise maturity.

Black box, gray box, white box

Black box — testers know only what a public attacker would (usually the URL). Realistic but wastes tester time on reconnaissance. Gray box — testers get authenticated accounts across role types and light documentation. The standard for most engagements; best ROI. White box — testers get source code, architecture diagrams, and internal access. Highest finding depth, most tester time. Gray-box is the correct default for annual SOC 2-driving pentests; white-box makes sense for high-stakes greenfield systems or when you specifically want architecture review.

Choosing a pentest firm

Firms vary widely. Boutique firms (NCC Group, Trail of Bits, Doyensec, IncludeSec, Latacora) — deep expertise, thoughtful reports, $30-100K per engagement, competitive schedules. Mid-market firms (Bishop Fox, Praetorian, GoSecure) — solid quality, faster availability, $20-60K. Pentest-as-a-service (HackerOne Pentest, Cobalt, Bugcrowd) — crowdsourced testers, faster kickoff, $10-30K, quality varies. Avoid the cheapest option — a report of low-severity findings from a tester who ran an automated scanner is worth less than nothing because it produces false confidence. Ask for sample reports before hiring.

Scope, timeline, and rules of engagement

A well-defined statement of work includes: exact URLs, IP ranges, and APIs in scope; testing dates and testing hours (avoid business-critical windows); allowed techniques and prohibited ones (no DoS, no social engineering unless separately scoped); testing accounts and how to obtain them; escalation contact if the tester finds something critical mid-engagement; deliverable format and timeline. Typical annual pentest: 1-2 weeks of testing, 1 week of report writing, kickoff to final report in 4-6 weeks. Budget 2-4 weeks of engineering time for remediation after.

What the report should contain and what to do with it

A good report includes: executive summary for non-technical stakeholders, methodology, findings with severity (Critical/High/Medium/Low/Info), reproduction steps, business impact, and remediation guidance. Findings tracked in your normal issue tracker with a security label. Critical/High get fixed before the report is used in customer-facing conversations; Medium/Low get scheduled based on effort/impact. Publish an attestation letter (summary the firm signs stating scope and that testing was completed) — this is what enterprise procurement actually asks for. Retest after remediation for High/Critical findings; most firms include one retest round.

Frequently asked questions

How often do we need to pentest?
SOC 2 Type II requires annual. Best practice: annual full-scope pentest plus focused pentests on major new features (new billing system, new API surface) before they go GA. Continuous pentest-as-a-service supplements but doesn't replace the annual engagement.
Can our own engineers do this?
Internal security testing is valuable and should happen continuously, but doesn't replace external pentests for compliance or credibility. Enterprise buyers explicitly want an outside firm's signature. Internal + external is the mature answer, not either/or.
What if the pentest finds critical vulnerabilities right before an important sale?
Fix them immediately and be honest with the customer. 'We recently pentested, found and fixed X, here's the remediation attestation' lands much better than 'we're clean' followed by the customer's own security team finding it. Security-mature enterprise buyers respect the pattern.

Related fundraising guides (40)

Investor directory · Fundraising library · Articles A–Z · Company funding database