For most organisations, the answer is: a full penetration test at least once a year, plus targeted testing whenever something significant changes. The right cadence for you depends on how fast your environment changes, where your risk actually sits, and what your compliance frameworks and enterprise customers expect.
Why annual is the baseline
A penetration test is a snapshot. The day the report lands, it starts going stale — code ships, infrastructure drifts, new vulnerabilities are published, and attacker techniques keep evolving. Twelve months is roughly the point at which a report stops being useful evidence of your current posture.
Annual testing is also the de facto standard everyone else works to. Auditors, enterprise procurement teams and cyber insurers almost universally ask for a penetration test performed 'within the last 12 months'. If your most recent report is older than that, expect it to be politely declined.
That makes annual the floor, not the target. High-change environments — a SaaS product shipping weekly, for instance — often justify testing more often, or scoping each test around what changed since the last one.
Events that should trigger a test sooner
Do not wait for the anniversary if any of these happen:
- You launch a new product or major feature. New authentication flows, payment handling, file uploads, integrations or AI features all introduce brand-new attack surface that last year's test never saw.
- You re-architect or migrate. Moving from a monolith to microservices, from a data centre to the cloud, or between cloud providers changes your security properties wholesale. Test the new architecture, not the memory of the old one.
- You acquire a company. An acquisition means inheriting an estate you did not build, with unknown exposures and often unknown assets. Testing (and mapping the attack surface) early in integration is far cheaper than discovering problems after the networks are joined.
- A compliance deadline is coming. ISO 27001 certification and surveillance audits, SOC 2 audit windows, and PCI DSS obligations all run on their own clocks. Book testing well ahead — good testing teams schedule two to six weeks out.
- You have had a security incident. After remediation, testing verifies the holes are genuinely closed and looks for adjacent weaknesses the attacker could have used.
- A big deal depends on it. Enterprise security questionnaires routinely require a recent report. A pentest commissioned in a hurry to unblock procurement is common; a pentest already on the shelf is better.
What compliance frameworks actually expect
Framework language varies, but the practical expectations are consistent:
- ISO 27001:2022 — Annex A 8.8 requires managing technical vulnerabilities, and certification auditors overwhelmingly expect penetration testing as evidence. We cover the specifics in our ISO 27001 penetration testing service.
- SOC 2 — penetration testing is not literally mandated, but auditors and the customers who read your report treat an annual pentest as table stakes.
- PCI DSS — requirement 11.4 is explicit: penetration testing at least annually and after any significant change, on top of quarterly vulnerability scans.
- ACSC Essential Eight — focused on preventive controls rather than testing, but Australian organisations aligning to it generally pair the controls with regular testing to validate them.
- APRA CPS 234 — regulated financial entities must systematically test their information security controls, with frequency commensurate with the rate of change and criticality.
Matching cadence to risk
Not everything deserves the same schedule. A sensible pattern:
- Internet-facing, fast-changing, or crown-jewel systems — your customer-facing product, its APIs, your external perimeter — test annually at minimum, and after each major release.
- Stable internal systems — test less frequently, and rotate them through scope so everything is covered over a two-to-three-year cycle rather than pretending you will test it all every year.
- New builds — test before launch, when fixing findings is cheapest and no customer data is at stake yet.
Rotating scope keeps annual budgets realistic while avoiding the trap of testing the same application forever and ignoring everything else.
What to do between penetration tests
An annual test is not a twelve-month holiday. Between engagements:
- Run vulnerability scanning continuously. It catches newly published issues in software you already run — see penetration test vs vulnerability scan for where each fits.
- Monitor your external attack surface. New subdomains, forgotten hosts and exposed services appear between tests; external attack surface management is how you notice.
- Actually fix the findings. The fastest way to waste a pentest is to file the report. Remediate, then retest — we retest fixed issues free within 90 days precisely so the loop gets closed.
FAQ
Is an annual penetration test legally required in Australia?
For most private companies, no law mandates it directly. The obligations arrive indirectly: PCI DSS if you handle card payments, APRA CPS 234 if you are a regulated financial entity, ISO 27001 or SOC 2 if your customers demand certification, and contractual clauses in enterprise agreements. In practice, most growing companies end up on an annual cycle because customers require it.
Do we need to test every application every year?
No. Test your highest-risk, most-changed and internet-facing systems annually, and rotate lower-risk systems through scope over a longer cycle. A focused test of what matters beats a shallow pass over everything.
How long is a penetration test report considered current?
Twelve months is the near-universal convention among auditors, enterprise customers and insurers. Some sectors and contracts specify six months for critical systems. After a major change, a report predating the change is effectively stale regardless of its date.
If you are working out the right testing cadence for your organisation, get in touch. A free scoping call is enough for us to recommend a schedule and give you a fixed quote within one business day.
Need cybersecurity expertise?
Drop your email and we'll be in touch within one business day.