🛡️ Pentest from €539 · Compliance from €89. See All Services →
Optimum Web
Resource · Vendor Questionnaires

How to Answer "When Was Your Last Penetration Test?"

Reviewed: 2 August 2026 — reviewed quarterly

Quick Answer

Answer with a specific date, the scope actually tested, and the status of any findings — vague answers ('recently', 'periodically') invite follow-up questions. If no test has happened yet, state that plainly alongside a scheduled date for one; a concrete near-term commitment is generally accepted better than an open-ended promise.

Why Does This Question Trip People Up?

It's usually not the test itself that's the problem — it's translating what actually happened into an answer that satisfies a reviewer who's comparing your response against dozens of other vendors. Vague answers ("we test regularly," "our systems are secure") read as evasive even when real testing has happened, because they don't give the reviewer anything to verify. A specific date, a named or described tester, and an accurate scope statement is what actually moves the questionnaire forward.

Template Answers for Common Situations

You've tested recently and have a clean report

"Our most recent penetration test was completed on [date] by [tester/firm name], covering [scope]. No Critical findings were identified; all High findings were remediated and retested. A summary report is available under NDA on request."

You've tested recently but had findings still being remediated

"Our most recent penetration test was completed on [date], covering [scope]. All Critical and High findings identified have an active remediation plan with target closure dates; [N] of [N] have been closed to date. A summary and remediation status are available on request."

Your last test is over 12 months old

"Our last formal penetration test was completed on [date]. Since then, [describe interim controls — e.g. continuous vulnerability scanning, patch management cadence]. A new test is scheduled for [date/quarter] as part of our recurring testing programme."

You've never had a formal test

"We have not yet completed a third-party penetration test. We are addressing this with a scheduled Vulnerability Assessment on [date], and will share the resulting report once available. In the interim, our security controls include [describe what's in place]."

Before You Submit Your Answer

State the actual date, not an approximate one — reviewers commonly follow up on vague answers
State scope precisely — don't imply broader coverage than was actually tested
Don't attach the full technical report unless asked and covered by an NDA
If findings are still open, say so and give a remediation timeline rather than omitting it
If no test has happened, give a concrete scheduled date rather than an open-ended commitment

Need a scheduled date to point to right now? Our €539 Vulnerability Assessment includes a signed attestation letter you can attach directly to a questionnaire. Not sure what a term in the questionnaire means? Check our security testing glossary.

Start with Vulnerability Assessment

Frequently Asked Questions

What if we've never had a penetration test and the question is a dealbreaker?+
Say so plainly and pair it with a concrete next step — a scheduled date for a Vulnerability Assessment carries far more weight with a reviewer than a vague commitment to "look into it." Many procurement teams will accept a near-term scheduled test as sufficient to proceed, especially if paired with a description of existing interim controls.
Should we share the full penetration test report with a vendor questionnaire?+
Generally no — full reports typically contain enough technical detail to be useful to an attacker and are usually shared only under NDA and only with parties who have a legitimate need. A summary, an attestation letter, or a scoped excerpt is the more common way to answer a questionnaire without over-sharing sensitive findings detail.
Does the answer need to name the testing firm?+
It's common practice and often expected, since it lets the reviewer assess the tester's independence and credibility. If there's a confidentiality reason not to name the firm, describing it generically (e.g. "an independent third-party security firm") while still providing the date and scope is a reasonable fallback.
What if the test only covered part of our infrastructure, not everything being asked about?+
State the actual scope precisely rather than letting the reviewer assume full coverage — for example, "covering our customer-facing web application; internal infrastructure was not in scope." An accurate, scoped answer holds up much better under follow-up questions than an answer that implies broader coverage than was actually tested.
How do we avoid this question coming up as a blocker in every deal?+
The underlying fix is a recurring testing cadence, not a better one-off answer — once testing happens on a defined schedule (e.g. annually), the answer becomes a template you update with a new date each cycle, rather than a scramble triggered by each new deal's security questionnaire.