How often to pentest based on compliance requirements, release frequency and risk, with practical schedules for startups, SaaS and regulated companies.
The baseline: at least once a year
Most frameworks and customers expect a penetration test at least every twelve months. PCI DSS requires annual internal and external testing. SOC 2 and ISO 27001 auditors usually expect annual testing. Many Indian regulators expect annual or more frequent VAPT for critical systems.
Test after significant change
An annual test is not enough if your system changes a lot. Plan a test after a major new feature, a new authentication or payment flow, a cloud migration, a new API for partners, or an acquisition. PCI DSS explicitly requires testing after significant changes.
Example schedules
Early-stage startup: one focused pentest a year, timed before the enterprise deals or audits that need it. Growing SaaS: an annual full test plus targeted tests for major releases, with quarterly vulnerability scans. Bank or NBFC: VAPT of critical and internet-facing systems at the frequency your RBI framework requires, often half-yearly, plus testing after change.
When continuous testing makes sense
Teams that ship weekly may prefer PTaaS, where testing is spread through the year and aligned to releases. It gives fresher results and predictable budgets.
