How often should I perform a pentest?

The right frequency depends on your risk profile, changes to your systems and any audit or contractual requirements. Annual testing can be a useful starting point, but it is not a universal legal requirement for every organization.

When should you test more often?

Critical applications, sensitive data or frequent changes may justify more frequent assessments. A major release, new integration or authentication change can warrant a targeted pentest. Align the coverage with what has changed and the resulting risks.

Which requirements may apply?

DigiD requires an annual ICT security assessment under the Logius requirements. Align the pentest and any retest with your auditor and submission deadline.

Under DORA, financial entities other than microenterprises must conduct appropriate tests at least annually on ICT systems and applications supporting critical or important functions. This is not equivalent to a mandatory annual external pentest for every institution. Designated entities face additional TLPT requirements. See DORA Articles 24–26.

For NIS2, GDPR, ISO 27001 and NEN 7510, testing must reflect the applicable requirements and risks; do not assume a fixed pentest frequency from the framework alone. Customer contracts, procurement requirements or PCI DSS obligations may also specify testing requirements. Check which apply to your scope.

Allow time for follow-up

Reserve time to assess findings, remediate vulnerabilities and arrange a retest where needed. Review the frequency when your risk profile, architecture or services change.

Discuss your testing schedule with us or view our pentest plans.