Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.
How often should you do a penetration test?
Last verifiedThe common bar is at least annually and after significant change — that is PCI DSS 11.4 when PCI applies, and common auditor practice elsewhere. It is not a universal law. Continuous SAST/DAST and scanning cover the gaps between tests. This page is not legal advice.
Pen-test cadence, last verified 10 September 2026 against PCI DSS v4.0.1 Requirement 11.4, AICPA Trust Services Criteria, ISO/IEC 27001:2022 A.8.8 and A.8.29, and NIST SP 800-115. “Annual plus on major change” is the common bar, not a statute that binds every company. Not legal advice.
Cadence is instrument-specific
Audience: a CISO or founder setting a testing calendar. This page is not legal advice. Kind of text: PCI DSS 11.4 is a program requirement only if PCI applies. TSC criteria do not name an interval. ISO Annex A does not say “annual pen test.” NIST SP 800-115 discusses planning and retesting as methodology guidance. Industry best practice is annual plus significant change. ShipReady Metrics recommendation: keep continuous testing running between point-in-time engagements.
Cadence table by framework
Last verified 10 September 2026. Not YOUR dates. Not legal advice.
| Instrument | What the text says about frequency | Kind of text | Last verified |
|---|---|---|---|
| PCI DSS v4.0.1 Req. 11.4 | At least annually and after any significant upgrade or modification; re-test to confirm remediation. | Program requirement if PCI applies. | 10 September 2026 |
| AICPA TSC (SOC 2) | No named annual pen-test interval. Examiners often look for testing evidence inside the review period that supports CC4.1 and CC7.1. | Attestation criteria plus auditor practice. | 10 September 2026 |
| ISO/IEC 27001:2022 A.8.8 / A.8.29 | No verbatim “annual pen test.” Vulnerability identification and security testing must operate; interval is a risk decision documented in the ISMS. | Normative if in the SoA; interval is not prescribed as “pen test yearly.” | 10 September 2026 |
| NIST SP 800-115 | Plan tests from risk, change, and prior results. Discusses retesting after remediation. | Methodology guidance, not a statute. | 10 September 2026 |
| Customer exhibit | Whatever recency the exhibit states (often 12 months). | Contract — only if it binds YOU. | 10 September 2026 |
Significant-change trigger checklist
PCI DSS discusses significant infrastructure or application change. NIST SP 800-115 treats new attack surface as a planning input. This list is operational hygiene, not a determination that PCI applies. Not legal advice.
- New internet-facing application, API, or tenant-isolation boundary.
- Material cloud-account, identity-provider, or network-segmentation change.
- Major dependency or authentication redesign.
- M&A integration that adds production systems you now operate.
- Remediation of a prior critical finding that needs independent confirmation (retest, not necessarily a full re-engagement).
What to do now
Operational steps. Last verified 10 September 2026. Not legal advice.
- Write the driver (PCI, exhibit, auditor practice, or optional maturity) next to the next test date. Do not invent a universal law.
- Define “significant change” in your change policy so the trigger is not argued after the fact.
- Keep SAST, DAST, SCA, and vuln ingest running between tests. Open the continuous-testing guide on this site.
- If SOC 2 or ISO 27001 is the driver, read those expectation pages before you lock a statement of work.
Checklist
Question list, not YOUR file. Not legal advice.
- What instrument, if any, sets YOUR interval?
- Is “annual” measured from last fieldwork start, last report date, or last retest?
- Who decides that a change is significant enough to pull the trigger early?
- Is continuous testing covering the months between engagements?
Where this shows up in ShipReady Metrics
Continuous SAST/DAST and vulnerability ingest (KEV, EPSS, CVSS, dedup, blast radius) cover gaps between point-in-time tests. The product does not replace an independent pen test, does not start a clock, and does not determine that a framework applies to YOU.
Primary sources (last verified 10 September 2026)
PCI DSS v4.0.1 Req. 11.4 (if PCI applies). AICPA TSC CC4.1 / CC7.1 (no named interval). ISO/IEC 27001:2022 A.8.8 / A.8.29 (no verbatim annual pen test). NIST SP 800-115 (guidance). Not legal advice.