The best timing for a pentest depends on your operational reality and compliance obligations. This page describes concrete moments when a pentest adds value, when you should postpone, and how to schedule the test outside peak hours. For the question of how often you should conduct a pentest, see the FAQ on the recommended pentest cadence.
When to schedule a pentest
These concrete triggers are good moments to plan a pentest:
- Before a production rollout. Pentest findings can still be remediated without impact on end users.
- After a major release. New features and changed code introduce new vulnerabilities that only testing reveals.
- Upon architectural changes. Cloud migration, SSO implementation, integration with new partners or large-scale refactoring call for verification.
- For compliance audits. Mandatory annually under DigiD (Logius framework v4.0), common under ISO 27001, NIS2 and NEN 7510. Financial entities under DORA test at least annually.
- Before a certification or external audit. Auditors expect a recent pentest report (usually within 12 months).
- After a security incident. To verify that the root cause has been resolved and no other vulnerabilities remain.
- During M&A or due diligence. Mergers, acquisitions and investment reviews often require a pentest as part of technical due diligence.
When to postpone
In these situations we recommend postponing the pentest to a later moment:
During critical business processes
Peak seasons, product launches, major events or closing periods demand full attention from your team. A pentest can load systems, and your team has no capacity to respond quickly to critical findings. End users are also not served by potential disruptions.
When the system is still unstable
During major system changes, migrations or persistent bugs, pentest findings may not be representative of normal operations. Wait until the system is stable, otherwise you are testing a temporary state.
Without available capacity for remediation
A pentest produces findings that require action. If your team has no capacity in the coming weeks to remediate critical findings, the report has limited value at that moment. Schedule the pentest so remediation capacity is available immediately after delivery.
Industry-specific considerations
- E-commerce and retail. Avoid October to early January (Black Friday, holidays). Best period: February-April or August-September.
- Financial services. Avoid quarterly and year-end closings. Under DORA, specific test windows align with regulatory reporting cycles.
- Healthcare. Outside peak season (flu peak January-March, summer holiday peak in acute care). NEN 7510 audit cycles are a good anchor.
- Government and public sector. Align with budget cycles and internal audit planning. DigiD audits have fixed calendar windows.
- Education. Best period is the summer holiday (July-August) when students and faculty are less active.
Best day and time within the test period
For production tests we recommend scheduling intensive test activities outside peak hours. For most organizations, mornings from Tuesday to Thursday are quiet moments. Avoid:
- Monday mornings (systems starting up, high login load)
- Friday afternoons (reduced staffing for possible incident response)
- Immediately after deployment moments (system still stabilizing)
For acceptance and test environments these restrictions are less relevant, as there is no production impact.
Want to discuss when a pentest fits your operational planning? Contact us for a complimentary scoping conversation, or view our pentest packages.
Nederlands