Skip to content
Zyberum Cyber Security Firm
Menu
Penetration testing

How Long Does a Penetration Test Take? Durations by Target

Testing days by target, from 3 for an API to 30 for an ECU, plus the calendar time for scoping, report and retest, and what makes a pentest longer or shorter.

Zyberum Security Team · Published · 6 min read

Most penetration tests take one to four weeks of testing time, and about twice that in calendar time once scoping, reporting and the retest are included. A small API is done in three days; a full automotive ECU takes up to 30. The number that matters for your planning is not the testing days but the date on which you hold a final report you can hand to a customer or an auditor.

Here is how the time breaks down, and what moves it.

Testing time by target

The ranges below are typical for a manual penetration test by experienced engineers, with scope and depth as most customers order them. They match the typical market prices on our pentest cost page; the price follows the days.

TargetTypical scopeTesting daysTypical price
Web applicationOne application, 2 to 4 roles, including its API5 to 106,000 to 15,000 euros
APIOne REST or GraphQL API, 20 to 60 endpoints3 to 64,000 to 9,000 euros
Mobile appOne app per platform, including backend4 to 85,000 to 12,000 euros
External infrastructureInternet-facing systems of one company2 to 53,000 to 7,500 euros
Internal network and Active DirectoryOne site or domain, assumed breach5 to 127,500 to 18,000 euros
CloudOne AWS, Azure or Microsoft 365 tenant4 to 86,000 to 12,000 euros
Hardware and embeddedOne device: interfaces, firmware, secure boot8 to 1512,000 to 25,000 euros
IoT productDevice, firmware, radio, app and cloud10 to 2015,000 to 30,000 euros
Automotive ECUOne ECU: hardware, diagnostics, networks15 to 3020,000 to 45,000 euros
OT and industrialOne plant segment or control system8 to 1512,000 to 25,000 euros

These are typical market ranges for Germany and the EU, not an offer. A testing day is one engineer for one day; a 10-day test can be two engineers for a week.

From first call to final report

Testing days are the middle of a longer sequence. A realistic timeline for a web application test:

PhaseDurationWho is busy
Scoping call and offer1 to 2 weeks until signatureYou and the sales engineer
Preparation1 week, in parallelYou: accounts, test environment, authorisation letter
Testing5 to 10 daysThe testers; one contact on your side
Reporting2 to 3 daysThe testers
Results presentation1 hourEveryone
Fixing2 to 8 weeksYour engineers
Retest1 to 2 daysThe testers

From the first call to a final report with retest results, plan six to twelve weeks. If you need the report for a fixed date, a customer audit or a product launch, start the scoping at least eight weeks before.

What makes a test longer

Five things add days, and all of them are visible at scoping:

  1. Size of the attack surface. Every user role, every integration, every interface is a set of tests to run. An application with 2 roles and 30 pages is 5 days; the same with 6 roles, an admin backend and three partner APIs is 12.
  2. Hardware. Opening a device, finding debug ports, dumping firmware and understanding it comes before the first vulnerability is even looked for. That is why an IoT product starts at 10 days and an ECU at 15.
  3. Reverse engineering. Proprietary protocols, obfuscated firmware or a custom radio layer add days of analysis before testing. On a TriCore-based power-electronics ECU, understanding the diagnostics and the bootloader alone can take a week.
  4. Access problems. Accounts that arrive on day three, a test environment that differs from production, a VPN that drops. Each lost day is a day not spent testing.
  5. Depth. A grey-box test with source code or architecture documents finds more per day than a black-box test, but the reading takes time. A compliance-driven test against a checklist is shorter than a “find everything” test.

What makes a test shorter

  • A clear scope with a written list of hosts, URLs, roles and exclusions. Half a day of your time saves a day of ours.
  • Working accounts and a stable environment on the first morning. Two accounts per role, so the tester can check whether user A can see user B’s data.
  • Documentation: an architecture diagram, API specification, data-flow description. For hardware: schematics, a firmware image, a second unit that may be destroyed.
  • Results from your scanner. Known missing patches do not need to be found a second time.
  • One contact who answers within hours, not days.

Why not faster

A test offered as “two days, all inclusive” for a complete web application with API is a scan with a human glance at it. Scanners run in hours. What takes days is the part only a person does: logging in with every role, understanding the business logic, forming hypotheses, confirming each finding, and chaining three medium findings into one critical path. The BSI’s practical guide for penetration tests describes exactly this manual, hypothesis-driven approach, and NIST SP 800-115 distinguishes it from automated vulnerability scanning for the same reason.

If your budget allows for two days, order an external infrastructure test or a vulnerability scan with a review, and say so. You will get an honest result for the money. See penetration test vs vulnerability scan for the difference.

How we plan it

We fix the testing days and the price in the offer after a free scoping call, and we name the dates for testing, report and presentation. Retests of fixed findings are part of the offer. If a target turns out to be larger than scoped, we tell you on day one, not in the report. Book a free 15-minute call with your target in mind and we will give you the days for your case.

FAQ

Frequently asked questions

How long does a web application pentest take?

Typically 5 to 10 testing days for one application with two to four user roles and its API. Add two to three days for the report and one to two days for the retest. From the scoping call to the final report, plan four to six weeks of calendar time.

Can a pentest be done in one day?

A one-day engagement is a vulnerability scan with a human looking at the output, not a penetration test. Even a small external infrastructure test needs two to five days, because confirming findings, chaining them and writing them up takes time.

Why does the report take so long after testing ends?

Every finding is reproduced, rated in context and given a fix recommendation that your engineers can act on without asking back. For a typical web test that is two to three days; for an ECU or IoT product with hardware findings it is often a full week.

Call usBook a call

Pick a time that suits you

Open in a new tab