Live Webinar | Building AI Governance That's Audit-Ready on September 23 @ 1:00PM ET

Contact Us
Services
Services
Crypto and Digital Trust
Crypto and Digital Trust
Schellman Training
Schellman Training
Sustainability Services
Sustainability Services
AI Governance
AI Governance
About Us
About Us
Leadership Team
Leadership Team
Corporate Social Responsibility
Corporate Social Responsibility
Careers
Careers
Strategic Partnerships
Strategic Partnerships

Stop Waiting to Schedule Your Pen Test

Cybersecurity Assessments | Penetration Testing

Published: Jun 17, 2021

Last Updated: Sep 18, 2026

A compliance manager called me a few weeks ago. She was three weeks into a new job and had just learned a pen test report was due by the end of the quarter. She didn't know when the last test ran, what had changed since, or who had to sign off before testing could start. 

She is not alone. I see this all the time. 

More and more, the person responsible for scheduling a pen test is not in security or IT. It may be someone in product, procurement, or compliance who inherited the task alongside a long list of other work to accomplish. They know a deadline exists, but they don't have visibility into every step that has to happen before it. 

Still, timing is the single biggest aspect that can cause challenges during a pen test, and most of it is avoidable if you get in front of it early. 

Best Practices for an Effective Penetration Test 

Start Your Pen Test with The Basic Facts 

If you're new to the role, find out when the last pen test happened and what the scope covered. Ask whether the requirement is annual or quarterly, because it's not the same across every organization, and it can change over time. Requirements, scope, and frequency changes. What worked for your audit two years ago might not be enough now. 

Know Your Pen Test Deadline and Every Date That Matters In Between

Your ATO date, ROC date, and SOC review window are fixed dates and there's not much flexibility with them. But they are rarely the only dates that matter most. A big client may be waiting for a clean report before they'll sign a contract. Your dev team's release schedule might determine when the environment is even testable. Some teams also have blackout periods where testing isn't allowed at all. 

Treat The Pen Test Itself as One piece of The Job 

The actual testing window gets most of the attention, but it's only one link in a longer chain: 

  • Contracting
  • Planning
  • Environment Preparation
  • Reporting
  • Remediation
  • Retesting

Legal alone can eat weeks redlining a contract back and forth. And if you need sign-off from procurement, security, and the dev team before you can even kick things off, that's real time on the calendar, not paperwork you can skip. 

How Long Does a Penetration Test Take? 

Say the requirement is a clean report by September 30th. Here's roughly what the path can look like, working backwards: 

Date

Stage

Details

May 15

Scope / business need determined

Business driver or compliance requirement identified

June 1 to June 14

Sourcing options (2 weeks)

Potential testing vendors identified

June 15

Vendor selection

Third-party tester chosen

June 30

Contract execution

Paperwork, POs, and approvals complete

July 7

Kickoff / planning meeting

All parties aligned, walkthrough done, three weeks before testing

July 15

Rules of engagement / scope

Scope documented and understood, two weeks before testing

July 22

Environment prep

Non-production environment fully ready

Aug 1 to Aug 15

Pen test execution (2 weeks)

Technical assessment delivered

Aug 16 to Aug 20

Reporting / cleanup (1 week)

Report delivered, environment cleaned up

Aug 21 to Sept 23

Remediation (~1 month)

~30 days for dev and IT to fix findings

Sept 24

Retest (1 week before finish)

Retest performed, final report received

Sept 30

Final day

Clean report required

That's a six-week testing and remediation cycle sitting on top of about four months of planning, contracting, and prep work. And that's a fairly clean scenario. Bigger tests take longer. Some organizations need 60 or 90 days just for remediation. Factor in holidays, PTO, or a busy pen test provider that needs more lead time to staff the right people, and the timeline stretches even further. 

Why Early Planning Results in a Smoother Pen Test 

A pen test crammed into the last two weeks of a quarter is like trying to renovate a kitchen the week before hosting Thanksgiving. Everything gets rushed and corners get cut. No one is happy with the results. 

Early planning helps in other ways too. You can bundle the test with other projects instead of running everything separately. You can make sure your environment is actually ready before the tester shows up, instead of burning testing days on access issues and broken accounts. You give remediation the real time it requires instead of a last-minute scramble. 

Sometimes last-minute planning and testing are inevitable. A new requirement might drop suddenly. A client may move up a deadline. Unavoidable things happen. But most of the time, the pressure is self-inflicted, and it doesn't have to be. Either way, the goal is to reduce the damage by getting the facts, lining up the dates, and making the next move as early as you can. 

When was your last pen test? If you don't know the answer off the top of your head, that's the first thing to go find out. Bonus tip: if you don’t want to scramble to do this next year, Schellman offers multi-year agreements, and we’ll be there to make sure your next assessment (or consolidated audit with PCI, SOC, FedRAMP, HIPAA, etc.) runs smoothly and on time. Contact us today or fill in our Penetration Testing Scoping Questionnaire to learn more about how to better plan for your next penetration test. 

Penetration Test Timing Q&A

Q: Why is it so important to schedule a pen test early?

A: The pen test is only one piece of the work. Contracting, legal review, procurement approvals, scope, prep, reporting, remediation, and retesting all take time. If you wait too long, you may not have room to finish before the due date.

Q: What should someone do first if they inherit the task of getting a pen test?

A: The first step is to find out when the last test took place, what it covered, and what rule drives the next one. The need may be annual, quarterly, tied to an audit, or tied to a client request. That gives you the right scope and a better idea of the timeline.

Q: Which dates matter in the pen test process besides the final due date?

A: ATO dates, ROC dates, SOC review windows, client contract dates, release dates, and blackout periods can all affect your pen test plan. A clean report may be needed before the final deadline if another team depends on it.

Q: Why should remediation and retesting be part of the pen test plan?

A: A pen test may find issues that dev, IT, or security must fix. After that, the tester may need to retest and issue a final report. If you skip those steps in the plan, you can still miss the planned date. 

Q: What are the benefits of planning a pen test ahead? 

A: Beyond experiencing less stress, you can bundle work, avoid wasted test time, give teams time to fix findings, and work better with the vendor. That lowers the chance of scrambling, missing steps, and facing deadline pain. 

About Josh Tomkiel

Josh Tomkiel is a Managing Director on Schellman’s Penetration Testing Team based in the Greater Philadelphia area with over a decade of experience within the Information Security field. He has a deep background in all facets of penetration testing and works closely with all of Schellman's service lines to ensure that any penetration testing requirements are met. Having been a penetration tester himself, he knows what it takes to have a successful assessment. Additionally, Josh understands the importance of a positive client experience and takes great care to ensure that expectations are not only met but exceeded.