How Long Does a Penetration Test Take? Durations by Target
Testing days by target, from 3 for an API to 30 for an ECU, plus the calendar time for scoping, report and retest, and what makes a pentest longer or shorter.
Zyberum Security Team · Published · 6 min read
Most penetration tests take one to four weeks of testing time, and about twice that in calendar time once scoping, reporting and the retest are included. A small API is done in three days; a full automotive ECU takes up to 30. The number that matters for your planning is not the testing days but the date on which you hold a final report you can hand to a customer or an auditor.
Here is how the time breaks down, and what moves it.
Testing time by target
The ranges below are typical for a manual penetration test by experienced engineers, with scope and depth as most customers order them. They match the typical market prices on our pentest cost page; the price follows the days.
| Target | Typical scope | Testing days | Typical price |
|---|---|---|---|
| Web application | One application, 2 to 4 roles, including its API | 5 to 10 | 6,000 to 15,000 euros |
| API | One REST or GraphQL API, 20 to 60 endpoints | 3 to 6 | 4,000 to 9,000 euros |
| Mobile app | One app per platform, including backend | 4 to 8 | 5,000 to 12,000 euros |
| External infrastructure | Internet-facing systems of one company | 2 to 5 | 3,000 to 7,500 euros |
| Internal network and Active Directory | One site or domain, assumed breach | 5 to 12 | 7,500 to 18,000 euros |
| Cloud | One AWS, Azure or Microsoft 365 tenant | 4 to 8 | 6,000 to 12,000 euros |
| Hardware and embedded | One device: interfaces, firmware, secure boot | 8 to 15 | 12,000 to 25,000 euros |
| IoT product | Device, firmware, radio, app and cloud | 10 to 20 | 15,000 to 30,000 euros |
| Automotive ECU | One ECU: hardware, diagnostics, networks | 15 to 30 | 20,000 to 45,000 euros |
| OT and industrial | One plant segment or control system | 8 to 15 | 12,000 to 25,000 euros |
These are typical market ranges for Germany and the EU, not an offer. A testing day is one engineer for one day; a 10-day test can be two engineers for a week.
From first call to final report
Testing days are the middle of a longer sequence. A realistic timeline for a web application test:
| Phase | Duration | Who is busy |
|---|---|---|
| Scoping call and offer | 1 to 2 weeks until signature | You and the sales engineer |
| Preparation | 1 week, in parallel | You: accounts, test environment, authorisation letter |
| Testing | 5 to 10 days | The testers; one contact on your side |
| Reporting | 2 to 3 days | The testers |
| Results presentation | 1 hour | Everyone |
| Fixing | 2 to 8 weeks | Your engineers |
| Retest | 1 to 2 days | The testers |
From the first call to a final report with retest results, plan six to twelve weeks. If you need the report for a fixed date, a customer audit or a product launch, start the scoping at least eight weeks before.
What makes a test longer
Five things add days, and all of them are visible at scoping:
- Size of the attack surface. Every user role, every integration, every interface is a set of tests to run. An application with 2 roles and 30 pages is 5 days; the same with 6 roles, an admin backend and three partner APIs is 12.
- Hardware. Opening a device, finding debug ports, dumping firmware and understanding it comes before the first vulnerability is even looked for. That is why an IoT product starts at 10 days and an ECU at 15.
- Reverse engineering. Proprietary protocols, obfuscated firmware or a custom radio layer add days of analysis before testing. On a TriCore-based power-electronics ECU, understanding the diagnostics and the bootloader alone can take a week.
- Access problems. Accounts that arrive on day three, a test environment that differs from production, a VPN that drops. Each lost day is a day not spent testing.
- Depth. A grey-box test with source code or architecture documents finds more per day than a black-box test, but the reading takes time. A compliance-driven test against a checklist is shorter than a “find everything” test.
What makes a test shorter
- A clear scope with a written list of hosts, URLs, roles and exclusions. Half a day of your time saves a day of ours.
- Working accounts and a stable environment on the first morning. Two accounts per role, so the tester can check whether user A can see user B’s data.
- Documentation: an architecture diagram, API specification, data-flow description. For hardware: schematics, a firmware image, a second unit that may be destroyed.
- Results from your scanner. Known missing patches do not need to be found a second time.
- One contact who answers within hours, not days.
Why not faster
A test offered as “two days, all inclusive” for a complete web application with API is a scan with a human glance at it. Scanners run in hours. What takes days is the part only a person does: logging in with every role, understanding the business logic, forming hypotheses, confirming each finding, and chaining three medium findings into one critical path. The BSI’s practical guide for penetration tests describes exactly this manual, hypothesis-driven approach, and NIST SP 800-115 distinguishes it from automated vulnerability scanning for the same reason.
If your budget allows for two days, order an external infrastructure test or a vulnerability scan with a review, and say so. You will get an honest result for the money. See penetration test vs vulnerability scan for the difference.
How we plan it
We fix the testing days and the price in the offer after a free scoping call, and we name the dates for testing, report and presentation. Retests of fixed findings are part of the offer. If a target turns out to be larger than scoped, we tell you on day one, not in the report. Book a free 15-minute call with your target in mind and we will give you the days for your case.
FAQ
Frequently asked questions
How long does a web application pentest take?
Typically 5 to 10 testing days for one application with two to four user roles and its API. Add two to three days for the report and one to two days for the retest. From the scoping call to the final report, plan four to six weeks of calendar time.
Can a pentest be done in one day?
A one-day engagement is a vulnerability scan with a human looking at the output, not a penetration test. Even a small external infrastructure test needs two to five days, because confirming findings, chaining them and writing them up takes time.
Why does the report take so long after testing ends?
Every finding is reproduced, rated in context and given a fix recommendation that your engineers can act on without asking back. For a typical web test that is two to three days; for an ECU or IoT product with hardware findings it is often a full week.