Most penetration tests take 2 to 4 weeks from kickoff to final report, broken into scoping, discovery, active exploitation, and reporting/retest phases. Timelines stretch mainly due to environment size, access delays, and scope creep, not the testing itself. Compliance-driven tests (PCI DSS, SOC 2) follow the same core process with added documentation steps. The fastest way to shrink your timeline is a precise, complete scoping form submitted upfront.
Your CFO wants a number. Your auditor wants a date. Your dev team wants to know when the servers get poked.
And you’re stuck saying “it depends,” because nobody gave you a straight timeline.
That vague answer is exactly why so many security projects stall. Teams delay booking a test because they assume it’ll eat a whole quarter, blow up sprint planning, and disappear into a black box.
So let’s fix that. If you’ve been asking how long does a penetration test take, the honest answer is: usually two to four weeks, start to finish, depending on scope. Not months. Not a mystery.