How often do I need a penetration test?
There is no single universal rule, but the widely accepted practice is at least once a year and after any significant change to your systems or applications. Some frameworks are explicit: PCI DSS requires penetration testing at least annually and after significant changes. SOC 2 and ISO 27001 do not mandate a fixed frequency, but auditors expect regular testing, and annual is the norm.
The common baseline: annually and after major change
Most security programs run an external penetration test at least once a year, plus an additional test after significant changes such as a major architecture change, a new product, or a move to a new environment.
What the frameworks say
PCI DSS v4.0.1 requires penetration testing at least annually and after significant changes. SOC 2 and ISO/IEC 27001 do not set a fixed interval, but both expect vulnerability management and regular testing as part of a mature program, and annual testing is the practical expectation.
Match frequency to risk
Higher-risk or fast-changing systems warrant more frequent testing. Pair periodic penetration tests with continuous or regular vulnerability scanning, which is a different, more frequent activity.
FAQ
Is a vulnerability scan the same as a penetration test?
No. A vulnerability scan is an automated check for known issues and is typically run frequently (monthly or more). A penetration test is a deeper, often manual assessment where a tester actively tries to exploit weaknesses, usually run at least annually.
Does SOC 2 require a penetration test?
SOC 2 does not mandate one by name, but auditors generally expect evidence of regular testing as part of your vulnerability management, and an annual penetration test is the common way to satisfy that expectation.
Get audit-ready with Keel
The AI-native GRC platform for SMBs: one control-and-evidence graph across SOC 2, ISO 27001, HIPAA, PCI DSS, NIST CSF, and more. Start free, no credit card.
Start free