Penetration testing
How long a penetration test takes and whether it disrupts your operations
In short
Realistic penetration test timelines by scope, from a single web app to a full network or OT plant, what stretches them, and how to plan around an audit date.
Two questions come up before almost every penetration test: how long will it take, and will it knock something over? Both answers come down to the same thing, scope and planning, rather than luck. The short version for planning purposes: a focused test is measured in days, a broad one in weeks, and the full cycle from scoping to final report in one to two months. The rest of this page puts numbers against each scope and shows where those numbers stretch.
Typical timelines by scope
Scope is the biggest lever: how many targets, how deep the testing goes, and what kind of test it is. The test style matters too. A black-box test, where the tester starts with no inside knowledge, takes longer to find a foothold than a grey-box or white-box test where you share some access up front. These are the planning ranges we scope against.
| Scope | Hands-on testing | Elapsed, scoping to report |
|---|---|---|
| Single web application | 5 to 10 working days, driven by the number of features, user roles, and APIs behind the front end | 3 to 4 weeks |
| Mobile app (iOS and Android) | 5 to 10 working days covering both platforms and the backend API they share | 3 to 4 weeks |
| External network or perimeter | 3 to 8 working days for a typical estate, longer as live hosts and services grow | 2 to 3 weeks |
| Internal network or red team | 2 to 4 weeks, because the tester chains across many systems toward a goal | 5 to 8 weeks |
| Standalone API | 4 to 8 working days for a documented API, longer without documentation | 2 to 4 weeks |
| OT/ICS environment | 2 to 5 weeks, much of it passive analysis, with active testing confined to maintenance windows | 6 to 10 weeks |
These are planning guides from engagements we scope, not quotes. The real number falls out of a scoping call where you agree the targets, the depth, and the rules. OT environments sit at the long end for a reason: testing live industrial systems safely requires a different method entirely, which is covered in OT VAPT vs IT VAPT.
The phases, start to finish
A penetration test is more than the hands-on week, and planning the timeline around only that part is where schedules slip.
Scoping sets the targets and the rules of engagement. Testing is the hands-on part. The report turns raw findings into something your team can act on, and typically lands about a week after testing ends. You remediate, and a retest confirms the fixes actually held. Budget time for the bookends, not just the testing.
What stretches a timeline
In practice, four things stretch pentest schedules far more often than the testing itself does.
Scoping drag comes first. An incomplete asset list, an approval that needs a signature from someone on leave, or an undecided question about whether the mobile app is in scope can add weeks before a tester touches anything. Environment access is the second: test accounts not created, VPN access not granted, source IPs not whitelisted, or a staging copy that is still being built. Every day a tester waits for access is a day on the schedule.
The business calendar is the third. Change freezes around month-end closing, year-end, and the Lebaran period are common across Indonesian companies, and a test that cannot run during a freeze has to be booked around it. The fourth is the retest cycle: the gap between receiving the report and completing remediation is entirely in your hands, and it is the phase teams underestimate most. If the goal is a clean report for an auditor, remediation time belongs in the plan from day one.
Will it disrupt our systems
This is the fear that holds many teams back, and for a well-run test it is largely unfounded. A reputable tester plans around your operations: destructive or load-heavy checks are flagged in advance, run in a maintenance window, or pointed at a staging copy rather than production. The tester keeps a live contact open during the engagement and stops if something looks fragile. The aim is to find weaknesses the way an attacker would, without behaving like one who wants to cause damage.
Most of that protection is built in the scoping call, not during the testing. Agree the targets and the rules of engagement, set the timing windows, flag any fragile systems, decide what runs against production versus staging, and name an emergency contact on both sides.
Planning around a compliance or certification deadline
Most penetration tests in Indonesia are anchored to a date. For commercial banks, SEOJK 29/2022 under POJK 11/2022 requires cyber security testing at least once a year, with the results of scenario-based exercises reported to OJK within ten business days of completion. Operators of vital information infrastructure carry their own assessment expectations under Perpres 82/2022, and ISO 27001 certification audits routinely ask for a recent test report plus evidence that the findings were fixed.
Working backwards from a fixed date, a safe plan looks like this: one to two weeks for scoping and contracting, one to two weeks of provider lead time before testing starts, the testing window itself, a week for the report, two to four weeks for your team to remediate, and a short retest so the auditor sees closed findings. That is roughly ten to twelve weeks end to end. Teams that book a test one month before an audit usually end up presenting a report full of open findings. Teams that book a quarter ahead present a closed one, and the difference is visible to a regulator.
If the annual test is part of a wider program, it pairs with a recurring scan cadence; the split between the two is covered in vulnerability assessment vs penetration testing.
If you tell us what you want tested, what you are worried about breaking, and the date the result has to land on, we can scope an engagement around all three. See the full scope of our penetration testing services in Indonesia for methodology, targets, and reporting.
Reviewed by Karina Kosasih, Offensive Security Lead
Frequently asked questions
It depends on scope. A single web or mobile application is usually one to two weeks of hands-on testing, an external perimeter about a week, and a full internal network or OT engagement several weeks. Add scoping beforehand and a written report afterward, and the elapsed time from first call to final report is typically three to eight weeks.
Related
Solutions
Our services
Ready to strengthen your security posture?
Talk to our Jakarta-based team about your requirements.
Jakarta-based team. We reply within one business day.