How long does a penetration test take?

By The PenTest Index · Provider timing checked October 10, 2026

How long does a penetration test take? In the provider terms we checked, timeframes for tests led by people run from 3 working days (Pentest-Tools.com's anonymous web app test) to 20 working days (Astra's longer estimate). Report delivery is a separate milestone, and fixes and retesting can overlap with testing. So first decide what you need by your date.

Here is the short version, based on our reading of those terms:

  • Six weeks or more until you need the report: if the provider confirms your scope and report delivery fit, choose on scope and price.
  • Three to six weeks: start this week and get the report date in writing.
  • Under three weeks: go to What if I need it fast?

A penetration test (pentest) is an authorized, hands-on attempt to break into your systems and show what an attacker could do. The rest of this page shows what each provider's number measures, then works back from a real date.

The five clocks inside "how long"

A pentest has five separate waits, and a provider's number usually covers only one of them. That is why you can hear "three days" and "six weeks" about the same job and both be honest.

  1. Wait to start. From saying yes to the first day of testing. Contracts, test accounts and the provider's queue live here.
  2. Testing. The days testers work on your systems.
  3. Report. From the end of testing to the finished report in your inbox.
  4. Fixing. Your own team's time. No provider quotes it.
  5. Retest. The provider checks your fixes. This has its own request or completion deadline.

It is like asking how long a home inspection takes. The inspection is a few hours. Getting on the calendar and getting the written report are separate waits.

How long does a penetration test take at each provider?

Published timeframes range from 3 working days to 20 working days for tests done by people, and as little as a day for some tests led by AI. But the providers count in different units, so check the last two columns before you compare.

Every figure below is the provider's own published statement, read on October 10, 2026. Providers are listed A to Z. This is not a ranking, and we have not bought or timed any of these tests.

Tests led by people

Published timing terms for penetration tests led by people.
Provider and offerWait to startTestingReportWhat the number countsStill to confirm
Astra, manual pentestClock starts when Astra has "all required information"; its queue can add time10–15 working days in one help article and the pricing FAQ; 10–20 working days in another articleNot stated separatelyWorking days for "the entire exercise"Which range applies to you
Cobalt, Agile pentest3, 2 or 1 business days after you submit the test for review, by plan tier (pricing, docs); start times may vary by engagement, and submission after 11 AM PST adds a business day7 days (3 or 4 credits) or 14 days (5 or more) (docs)Automated reportDays; weekday or calendar not definedReport is described as for internal use
Cobalt, Comprehensive pentestSame14 days standard; "may vary" (docs)2–3 business days after the test endsDays; weekday or calendar not definedNeeds a credit contract first; Cobalt confirms the end date after review
HackerOne, Essential and PremiumScoping: 48 hours to 7 business days; setup, kickoff and staffing follow (docs)14 calendar days3–5 business days after testingCalendar daysYour actual slot
Pentest-Tools.com, black-box web appNot stated3 working days, best effort (service page)"On the 4th day"Working daysBooking wait. Tests as an anonymous attacker only
Pentest-Tools.com, grey-box web appNot stated4+ working days, best effort"When ready"Working days, a minimumReport date; booking wait
Synack, SynackSTNot stated5-day assessment window (pricing)Not statedCalendar window, one human testerStart and report dates
Synack, Synack14Not stated14-day assessment windowNot statedCalendar window, a teamStart and report dates

Tests led by AI

Published timing terms for penetration tests led by AI.
Provider and offerStated speedLimit that matters
Astra, Pentest Auto"First report on the same day" (pricing)A first report, not a contracted final date
Cobalt, AutonomousStandard timeline 1 business day (docs)Web only, up to 25 pages and 2 user roles; report audience listed as internal
Intruder, AI web app pentest"Same day pentest reports" (pricing)Built around connecting your code repository
Synack, Sara Pentest4–5 day assessment window (pricing)One low-complexity web app or 100 host IPs

An AI-led test and a test done by people are different purchases. Whoever needs your report decides whether an AI-led one counts. Ask them before you buy on speed.

What the table tells you

Three units are hiding behind the word "days." Pentest-Tools.com and Astra count working days. HackerOne counts calendar days. Synack sells a window. Cobalt's docs say "days" without saying which kind. Three working days and a 14-day window are not comparable until you ask how many tester-days sit inside each.

Astra's own pages disagree. One article and the pricing FAQ say 10–15 working days. Another article says 10–20. That is a one-week gap. Ask which applies to your agreement.

Only two providers here publish the gap between testing and the report: Cobalt (2–3 business days) and HackerOne (3–5 business days). Pentest-Tools.com gives a report day for its black-box test only. Everyone else leaves it open.

The wait to start varies most. Cobalt publishes 1 to 3 business days on an existing plan. HackerOne publishes 48 hours to 7 business days for scoping, with setup, kickoff and staffing afterward. Three testing firms describe weeks: Secure Ideas says tests are "generally" scheduled 2–4 weeks out once both parties have signed and all agreements are in place, Triaxiom says to plan 2–3 weeks for contracts and planning, and Schellman says an average project runs 4 to 5 weeks for the assessment and report delivery. Those are three firms describing their own process, some on pages a few years old. They are not a market average.

Which offer fits a three-week deadline?

Say you run a 30-person SaaS company. A customer wants a pentest report within 21 calendar days. The test must cover your web app with two logged-in user roles. Your accounts and paperwork are ready on a Monday. This buyer is made up; the terms are the real ones above.

Table columns: Offer; Finding; Why; What would change it.
OfferFindingWhyWhat would change it
Pentest-Tools.com black boxMismatch on scopeIt tests as an anonymous attacker. Your customer asked for logged-in roles.Nothing. Speed cannot fix a scope gap.
Pentest-Tools.com grey boxRoles supported; date unresolvedLogged-in testing is included, priced from $3,400 plus $900 per user role. Testing is "4+ working days" and the report comes "when ready."A written report date.
Astra manual pentestUnresolvedThe 10–15-working-day engagement lands between day 14 and day 21. The 20-working-day exercise lands on day 28. Final report delivery is not stated separately.Which estimate applies, and a written date.
Cobalt ComprehensiveUnresolvedStart in 1–3 business days, 14 days of testing, report 2–3 business days later: about day 17 to day 22 if the 14 days are calendar days. That also assumes you already hold a Cobalt contract and the published start time applies to your engagement.The end date Cobalt confirms after review.
HackerOneUnresolvedScoping takes 48 hours to 7 business days; setup, kickoff and staffing follow, then 14 calendar days of testing and 3–5 business days for the report. The complete wait to start is not published.A committed testing start and final-report date within the deadline.

What to do with that. No offer here is cleared by its public terms alone. Three are worth an email today: Pentest-Tools.com grey box, Astra and Cobalt. Send each the same question: "If we give you access on [date], what date will the final report be delivered?" If you already have a testing provider, send them the same question first. A current provider who can commit to the date is a perfectly good answer.

"Supported" here means one condition is backed by the published terms. It does not mean the provider is good, has a free slot, or that your customer will accept the report.

See the grey-box web app test

See Astra's plans

See Cobalt's packages

For each provider's prices, commitment and retest terms, see our profiles of Astra, Cobalt, HackerOne, Pentest-Tools.com and Synack.

When do I need to start to hit my date?

Take the date you need the report, then subtract the report gap, the testing time and the wait to start. The answer changes by weeks if you also need proof that the fixes worked.

Here is that math for a report needed by Friday, December 11, 2026, using each provider's published terms. For this illustration, Cobalt's unspecified testing and retest "days" are assumed to be calendar days. We counted weekdays and did not remove public holidays, because no provider here says how it treats them.

Table columns: Offer; Terms used; Latest start.
OfferTerms usedLatest start
Cobalt ComprehensiveReport 3 business days after testing; 14 days of testing; start 3, 2 or 1 business days after submission, subject to engagement typeTesting must end Tuesday, December 8 and start Tuesday, November 24. Submit for review by Thursday, November 19 (Standard), Friday, November 20 (Premium) or Monday, November 23 (Enterprise), before 11 AM Pacific.
HackerOneReport 5 business days after testing; 14 calendar days; scoping takes up to 7 business days, with setup, kickoff and staffing afterwardTesting must end Friday, December 4 and start Friday, November 20. The scoping/setup deadline needs confirmation from HackerOne.
Astra manual pentest15 working days from Astra having everything; 20 on the longer readingGet Astra everything by Friday, November 20, or Friday, November 13 on the longer reading. These are engagement dates; final report delivery needs confirmation.
Pentest-Tools.com black box3 working days; report on day 4Testing starts Tuesday, December 8. The wait to get that slot is not published.

These are conditional latest possible dates before any unpublished wait. They are our calculations from published terms and the assumptions above. They are not booking dates, and no provider has confirmed them.

Do you need the report, or proof the fixes worked?

This one question moves your start date more than the choice of provider. Some customers and auditors only want the report. Others want to see that the serious findings were fixed and checked again.

Run the Cobalt example both ways. Assume your team needs 10 working days to fix what the test finds. That number is ours, picked for the example. Yours will depend on the findings.

Table columns: What you need by December 11; Submit to Cobalt by (Standard tier).
What you need by December 11Submit to Cobalt by (Standard tier)
The reportThursday, November 19
Retest results showing the fixes workedTuesday, November 3

The second date is 16 days earlier. The steps: Cobalt says a retest is done within 7 days of you submitting the finding. Assuming calendar days and an active contract with an eligible retest window, you submit by Friday, December 4. Ten working days of fixing puts the end of testing at Friday, November 20, and the start at Friday, November 6. You can shorten this if your team begins fixing while testing is still running, since Cobalt shares findings as they are found.

Planning tool · no sign-up

Deadline Work-Back

Work backward from the date you need evidence. Published timing is not a booking or delivery promise.

What must exist by that date?

Only dates, a fix-time number and your selected tier are used; processing stays in this browser. Nothing is sent or stored.

Two messages worth sending before you book

Send the first to whoever asked for the test. Their answer picks your finish line.

By [date], do you need the full technical report, a summary letter, or evidence that specific findings were fixed and retested? Please confirm what the test must cover before we book.

Send the second to every provider you are considering, word for word, so the answers line up.

We need [the report / retest evidence] for [who] by [date and time zone]. The scope is [apps, APIs, environments, user roles, anything excluded].

Please confirm: what you need from us and by when; your earliest test start; the date testing ends; the date the final report is delivered; and whether those dates are committed or estimates. Tell us whether your days are working days or calendar days.

If we need fixes checked, please also confirm the last day we can ask for a retest, how long a retest takes once we ask, and when we would get updated evidence.

Please tell us anything in this scope your offer cannot cover.

A provider's reply to this is a schedule. It is not permission to test. Written authorization has to name the actual systems and activities.

If you cannot fill in the scope line yet, that is the thing to fix first. Our free scope checklist walks through what needs testing, the user roles and what your report recipient needs, so you can copy or print it and send every provider the same brief. No contact details required.

Find My PenTest Match

How long does a web application or network penetration test take?

For a web app, the published figures we read run from 3 working days for an anonymous-attacker test to 2–3 weeks of testing for a large app. Logged-in user roles can add days.

Two sources show the role effect. Pentest-Tools.com's logged-in test is "4+ working days" against 3 for its anonymous one, and it charges per user role. Triaxiom says a small app takes about a week of testing, larger ones 2–3 weeks, and that each role "can move testing from 1 week to multiple weeks." Limits on when testers may work, such as nights only, spread the same work over more of the calendar.

For networks, we read one usable figure. Schellman says 20 hosts on an external network take about a week to test and another week to report. Synack's 5-day window covers up to 100 host IPs.

We did not find enough provider-published figures to give honest ranges for internal network, mobile, cloud or API tests, so we are not going to make them up. If one of those is your job, start with which type of penetration testing service fits and ask each provider how many tester-days your scope needs.

How long after testing do I get the report?

Where providers say, it is one working day to about a week. Most do not say.

  • Pentest-Tools.com: the day after its 3-day black-box test.
  • Cobalt: 2–3 business days after a Comprehensive test.
  • HackerOne: 3–5 business days.
  • Triaxiom: about a week for writing and quality checks.
  • Schellman: a week for a small scope.

Findings showing up in a provider's dashboard during testing is not the same as a finished report. If someone outside your company needs a document, ask for the final report date by name. Our guide to what a penetration testing report should contain covers what to check when it arrives.

How far ahead should I book a penetration test?

Secure Ideas generally schedules tests two to four weeks out once both parties have signed and all agreements are in place. Triaxiom publishes 2–3 weeks for contracts and planning. On an existing plan it can be days: Cobalt publishes 1–3 business days, subject to engagement type and the submission cutoff. HackerOne publishes 48 hours to 7 business days for scoping; setup, kickoff and staffing follow.

Much of that wait is yours to shorten. Have these ready before the first call:

  • The list of apps, APIs and environments to test, and what is off limits.
  • A working test account for every user role.
  • API documentation, if APIs are in scope.
  • Signed paperwork and written authorization.
  • Any hours when testing is not allowed.
  • One named person who can answer questions the same day.

Do not put passwords or keys in an email or a brief. Agree with the provider how access will be shared. Our scope guide has a filled-in example.

What if I need it fast?

You have three real options, and each comes with a catch.

A fixed short test. Pentest-Tools.com's black-box web app test is 3 working days with the report on day 4, at a published fixed price of $3,400 (checked October 10, 2026). The catch: it tests as an anonymous attacker. If your customer asked for logged-in testing, this is the wrong test at any speed.

A provider you already have a contract with. Cobalt's 1–3 business day start applies once a test is submitted on an existing plan, subject to engagement type and the submission cutoff. If you are not a customer yet, the time to sign is not published. Your current provider, whoever it is, is the first call to make.

An AI-led test. Several publish same-day or next-day results. The catch: the person who needs the report decides whether it counts, and some of these offers describe their reports as for internal use. Ask first.

Astra's help page also mentions an express option through its sales team. Its timing and price are not published.

Two things do not solve a deadline. A vulnerability scan finishes in minutes to hours, but it is a different purchase from a pentest; see penetration testing vs vulnerability scanning. And a fast start is not a fast report. If the full report will miss your date, ask the recipient whether a later date or a summary letter is acceptable before you cut the scope.

If you know your scope and your date, compare the published offers and send the message above.

How long do I have to fix things and get a retest?

It depends on the retest window in your agreement, and that window has its own deadline. A retest is the provider checking whether a reported problem is really fixed. It is not a whole new test.

Keep two numbers apart: how long you have to ask or finish, and how long the check takes once you ask.

Table columns: Provider; How long you have to ask or finish; How long the check takes.
ProviderHow long you have to ask or finishHow long the check takes
Astra, Pentest Expert/Pentest AutoWithin 30 days from the date the vulnerabilities were reported; 2 manual re-scans on Pentest Expert, 1 on Pentest Auto; extensions case by case (policy)Not published
Cobalt, Agile/Comprehensive6 months (Standard) or 12 months (Premium, Enterprise), but requests close 10 days before your contract ends, and the contract must be active (policy)Within 7 days of submitting
HackerOneDuring a remediation period that is "typically" 30 or 90 calendar days, depending on the pentest (policy)"Usually within 72 hours" once a tester picks up the request; the wait before that is not published
TriaxiomRetesting usually needs to be completed within 90 days of report delivery (post)Not published

Put the applicable request or completion deadline on your calendar when its clock starts. If findings were reported on December 11, 2026, Astra's 30 days on Pentest Expert/Pentest Auto end on January 10, 2027. Triaxiom's usual 90-day completion window from a December 11 report ends on March 11, 2027. If a fix fails the retest, you need more engineering time and another check, so ask up front what a second request or an extension costs. Our remediation guide covers planning the fix work.

Why do two quotes give different lengths for the same test?

Usually because they are counting different things. One counts working days and the other a calendar window. One includes the report and the other stops when testing stops. One tests as an outsider and the other with logged-in roles.

Ask both providers the same three questions:

  1. How many tester-days are in this quote, and over how many calendar days?
  2. Does your timeline end when testing ends, or when the final report is delivered?
  3. Which user roles and which APIs does that time cover?

Once both answer, the gap usually explains itself. To line up the rest of the terms, run both through a Quote Check.

A few more questions

Can a penetration test be done in a day?

An AI-led one, by its own published terms, yes. Among tests done by people, the shortest figure we read is Pentest-Tools.com's 3 working days for a single web app tested from the outside.

Do the days include weekends?

It depends on the provider. Astra and Pentest-Tools.com count working days. HackerOne counts calendar days. Cobalt's docs do not say. Ask, because 14 calendar days and 14 working days are almost a week apart.

Is a faster test a worse test?

Not on its own. A time figure is not a measure of effort: a 14-day window and 3 working days can hold similar hours of work. What matters is whether the test covers what your report recipient asked for. Ask how many tester-days are inside the window and which roles they cover.

If you came here asking how long it takes to learn penetration testing or pass a certification, this page is for buyers; our step-by-step guide to how a penetration test is done is a better start.

Sources

All read on October 10, 2026. Provider figures are the providers' own published statements. We did not book, buy or time any test, and we did not check any provider's open slots. See how we check offers.