Pentest or continuous project?
A pentest answers a point-in-time question. A continuous project keeps scanning on a cadence. Most clients need both.
- A penetration test is depth at a point in time: testers chain weaknesses and show the real impact.
- A continuous project is breadth over time: scheduled scanning in cycles, with every finding followed from scan to scan.
- Compliance often asks for both, such as an annual pentest and quarterly PCI ASV scans.
- The best programmes keep both in one record.
Security testing budgets are usually spent on one of two things: a penetration test of something important, or recurring vulnerability scanning of everything. Both are useful, and they answer different questions. Choosing well starts with knowing which question you are asking.
Two different questions
A penetration test answers a point-in-time question: how secure is this system today, and what could an attacker actually do with it? Testers work through a methodology, chain weaknesses together and show the impact. It is the right tool before a launch, after a major change, for an audit, or when a customer asks for evidence.
A continuous project answers a different question: what has changed since the last scan? Vulnerability assessments and PCI ASV scans run in cycles on a set cadence, so new exposure is found between pentests rather than at the next annual test.
What a pentest gives you
- Depth: business logic flaws, access control between roles and chained attacks that scanners cannot find
- Judgement: a tester assesses real impact, not just a scanner's severity label
- Evidence: a report with steps to reproduce and recommendations, and retests that prove the fixes
Its limitation is time. The day after the test ends, new code, new hosts and new vulnerabilities start to appear.
What a continuous project gives you
- Coverage of the wider estate, cycle after cycle
- Tracking: the same issue on the same host is followed across scans, so each cycle shows what is new, what keeps coming back and what looks fixed
- A clear status for every cycle and, for PCI ASV, a passing quarter that can be attested
Its limitation is depth. Scanning finds known weaknesses and misconfigurations; it does not chain them together or understand the business.
| Aspect | Penetration test | Continuous project |
|---|---|---|
| Shape | One project with a start and an end | Cycles that repeat on a cadence |
| Finds | Exploitable weaknesses, logic flaws and attack chains | Known vulnerabilities and misconfigurations across many hosts |
| Cadence | Annually, or after significant change | Monthly to annually; PCI ASV is quarterly |
| Proof of a fix | A retest of the original finding | A verification scan, confirmed by an analyst |
| Typical driver | Launches, audits and customer assurance | Hygiene, compliance scanning and a large estate |
Choosing a cadence
For continuous projects, the cadence should follow how quickly the estate changes:
- Monthly for internet-facing estates that change often, or where new vulnerabilities in common software need catching quickly
- Quarterly for PCI ASV scanning, where it is required, and for stable internal estates
- Twice a year or annually for small, slow-changing environments, usually alongside a pentest
Within each cycle, verification scans confirm fixes without waiting for the next primary scan.
When you need both
Many compliance programmes ask for both. PCI DSS requires external vulnerability scans by an Approved Scanning Vendor every quarter, and penetration testing at least once every 12 months and after significant change. ISO 27001 and SOC 2 audits typically look for ongoing vulnerability management alongside periodic independent testing.
A practical pattern is a scoped pentest of the most important applications each year and after major releases, plus continuous scanning of the wider estate in between. The pentest finds what scanning cannot; the scanning keeps the estate from drifting between tests.
If the budget only allows one, ask which failure would hurt more: an exploitable flaw in your most important application, or an unpatched host somewhere in a large estate. The answer usually points to the right starting place.
Signs the mix is wrong
- Every pentest report opens with missing patches and default credentials. The estate needs continuous scanning, so testers can spend their time on what scanners miss.
- Scans come back clean, but each pentest still finds serious logic or access control flaws. Scanning alone is not enough for those applications.
- Nobody can say what is open across both. The results live in too many places.
Run both from one record
Whichever mix you choose, keep the results in one place. When pentest findings and scan findings live in different spreadsheets and PDFs, nobody can answer the simple questions: what is open right now, and what is overdue? In Cerberos Nexus, pentests and continuous projects run side by side, and the client follows both in the same Client Portal.