How often should I perform a pentest?

The recommended pentest frequency depends on your compliance obligations, risk profile and release cadence. This page describes concrete cadence recommendations. For the question of when to schedule a pentest (in relation to events), see the FAQ on the best timing for a pentest.

Standard cadence per organization type

  • Annually. Standard for most organizations. Recommended for SMB webshops, portals, internal applications and organizations meeting ISO 27001, NIS2 or DigiD obligations.
  • Semi-annually. For critical applications in financial services (DORA), healthcare (NEN 7510), essential entities under NIS2 and organizations with elevated threat profiles.
  • Quarterly. For systems with continuous critical changes, SaaS platforms with large customer bases and organizations in supply chains of essential entities.
  • Per release. For agile development teams practicing Continuous Deployment. Every major release triggered via pentest gate before production rollout.

Legally mandated cadence

Regulations often prescribe specific frequencies. The most important ones:

  • DigiD. Annually mandatory per Logius framework v4.0 for all organizations that allow citizens to log in via DigiD.
  • DORA. At least annually for financial entities (banks, insurers, payment institutions, crypto-asset service providers). Major financial institutions additionally undergo Threat-Led Penetration Testing (TIBER-NL) every three years.
  • NIS2. Risk-based cadence for essential and important entities under the Dutch Cybersecurity Act. Typically at least annually, semi-annually for critical infrastructure.
  • ISO 27001. Test frequency depends on your risk assessment (Annex A.8.8). Typically at least annually, with additional tests upon significant changes.
  • NEN 7510. Annual audit for healthcare institutions, supported by at least annual pentests.
  • MIAUW. Cadence depends on the contract within the Dutch government-wide framework agreement for government pentests.
  • PCI DSS. At least annually for organizations handling card payments, plus after significant changes to the cardholder data environment.

Additional event-driven pentests

Beyond standard cadence, certain events justify an additional pentest:

  • With a major release. New features and changed code introduce new vulnerabilities.
  • Upon architectural changes. Cloud migration, SSO implementation, new integrations or large-scale refactoring.
  • After a security incident. Verification that the root cause has been resolved and no other vulnerabilities remain.
  • Upon new compliance requirements. For example when coming under NIS2 or DORA after expansion of services.
  • Before an external audit. To ensure the auditor encounters no open findings.

Ongoing pentest engagement

For organizations that prefer structural testing, DongIT offers ongoing pentest engagements in which we execute a structured testing programme annually or per release under a single framework agreement. This is attractive for SaaS platforms in continuous development, critical infrastructure and organizations with complex compliance requirements. Benefits: consistency in approach, predictable planning, deepened knowledge of your application and efficiency in scoping.

Not sure which cadence fits your situation? Contact us for a complimentary scoping conversation, or view our pentest packages.