Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.

How often should you do a penetration test?

Last verified

The common bar is at least annually and after significant change — that is PCI DSS 11.4 when PCI applies, and common auditor practice elsewhere. It is not a universal law. Continuous SAST/DAST and scanning cover the gaps between tests. This page is not legal advice.

Pen-test cadence, last verified 10 September 2026 against PCI DSS v4.0.1 Requirement 11.4, AICPA Trust Services Criteria, ISO/IEC 27001:2022 A.8.8 and A.8.29, and NIST SP 800-115. “Annual plus on major change” is the common bar, not a statute that binds every company. Not legal advice.

Cadence is instrument-specific

Audience: a CISO or founder setting a testing calendar. This page is not legal advice. Kind of text: PCI DSS 11.4 is a program requirement only if PCI applies. TSC criteria do not name an interval. ISO Annex A does not say “annual pen test.” NIST SP 800-115 discusses planning and retesting as methodology guidance. Industry best practice is annual plus significant change. ShipReady Metrics recommendation: keep continuous testing running between point-in-time engagements.

Cadence table by framework

Last verified 10 September 2026. Not YOUR dates. Not legal advice.

Indicative cadence by instrument (not YOUR calendar; not a universal law; not legal advice)
InstrumentWhat the text says about frequencyKind of textLast verified
PCI DSS v4.0.1 Req. 11.4At least annually and after any significant upgrade or modification; re-test to confirm remediation.Program requirement if PCI applies.10 September 2026
AICPA TSC (SOC 2)No named annual pen-test interval. Examiners often look for testing evidence inside the review period that supports CC4.1 and CC7.1.Attestation criteria plus auditor practice.10 September 2026
ISO/IEC 27001:2022 A.8.8 / A.8.29No verbatim “annual pen test.” Vulnerability identification and security testing must operate; interval is a risk decision documented in the ISMS.Normative if in the SoA; interval is not prescribed as “pen test yearly.”10 September 2026
NIST SP 800-115Plan tests from risk, change, and prior results. Discusses retesting after remediation.Methodology guidance, not a statute.10 September 2026
Customer exhibitWhatever recency the exhibit states (often 12 months).Contract — only if it binds YOU.10 September 2026

Significant-change trigger checklist

PCI DSS discusses significant infrastructure or application change. NIST SP 800-115 treats new attack surface as a planning input. This list is operational hygiene, not a determination that PCI applies. Not legal advice.

  • New internet-facing application, API, or tenant-isolation boundary.
  • Material cloud-account, identity-provider, or network-segmentation change.
  • Major dependency or authentication redesign.
  • M&A integration that adds production systems you now operate.
  • Remediation of a prior critical finding that needs independent confirmation (retest, not necessarily a full re-engagement).

What to do now

Operational steps. Last verified 10 September 2026. Not legal advice.

  • Write the driver (PCI, exhibit, auditor practice, or optional maturity) next to the next test date. Do not invent a universal law.
  • Define “significant change” in your change policy so the trigger is not argued after the fact.
  • Keep SAST, DAST, SCA, and vuln ingest running between tests. Open the continuous-testing guide on this site.
  • If SOC 2 or ISO 27001 is the driver, read those expectation pages before you lock a statement of work.

Checklist

Question list, not YOUR file. Not legal advice.

  • What instrument, if any, sets YOUR interval?
  • Is “annual” measured from last fieldwork start, last report date, or last retest?
  • Who decides that a change is significant enough to pull the trigger early?
  • Is continuous testing covering the months between engagements?

Where this shows up in ShipReady Metrics

Continuous SAST/DAST and vulnerability ingest (KEV, EPSS, CVSS, dedup, blast radius) cover gaps between point-in-time tests. The product does not replace an independent pen test, does not start a clock, and does not determine that a framework applies to YOU.

Primary sources (last verified 10 September 2026)

PCI DSS v4.0.1 Req. 11.4 (if PCI applies). AICPA TSC CC4.1 / CC7.1 (no named interval). ISO/IEC 27001:2022 A.8.8 / A.8.29 (no verbatim annual pen test). NIST SP 800-115 (guidance). Not legal advice.

Frequently asked questions