The lead time for a pentest at DongIT varies per package and scope. Our standard lead times are summarized below, including what happens during this period.
Lead times per DongIT package
- Basic Scan. 1 week lead time. Quick security check for smaller web applications.
- Quick Pentest. 1-2 weeks lead time. Manual pentest for straightforward web applications.
- Expert Pentest. 2-3 weeks lead time. Thorough pentest for more complex applications.
- Extensive Pentest. 2-4 weeks lead time. Comprehensive pentest including compliance mapping.
For enterprise scope, multi-target assessments, DORA programmes or TIBER-NL-aligned assessments, we prepare a tailored quote with corresponding lead time. View the packages page for complete details.
What the lead time includes
The stated lead time runs from pentest start to final report delivery. It covers:
- Kick-off and reconnaissance. Introduction, scope verification, access testing, initial analysis.
- Active testing phase. Manual testing by pentester, automated scans as support, exploitation verification.
- Peer review. Four-eyes principle where a second senior ethical hacker verifies all findings.
- Reporting. Publication on the Security Reporter platform with management summary, risk classifications and remediation guidance.
- Final discussion. For Expert and Extensive pentests: report discussion with your team.
In addition to the lead time, there is a preparation period in which your team prepares the test environment, creates backups, whitelists IP addresses and adjusts SMTP settings. This phase is planned in parallel and does not count towards the pentest lead time.
Factors that influence lead time
- Scope size. Number of URLs, endpoints, user roles and integrations.
- Application complexity. Business logic, multi-tenant architecture, number of user roles.
- Type of pentest. Black-box typically takes longer because the pentester must first perform reconnaissance. See the FAQ on black-box, grey-box and white-box pentests.
- Number of critical findings. If critical vulnerabilities are discovered during the pentest, we discuss these directly and sometimes additional verification is needed.
- Team availability. Quick response to questions during the pentest speeds up the process.
Accelerating when possible
Do you have a tight deadline (for example before an audit or go-live)? We plan flexibly with you. Ensure:
- A well-prepared test environment with all needed accounts and documentation
- A directly available contact person with decision-making authority
- Pre-arranged backups and whitelisting agreements
- Clearly defined scope without open questions
With optimal preparation we can often keep the lead time at the shorter end of the stated ranges.
Want to discuss the lead time for your specific scope? Contact us for a complimentary scoping conversation, or view our pentest packages.
Nederlands