How to Answer "When Was Your Last Penetration Test?"
Reviewed: 2 August 2026 — reviewed quarterly
Quick Answer
Answer with a specific date, the scope actually tested, and the status of any findings — vague answers ('recently', 'periodically') invite follow-up questions. If no test has happened yet, state that plainly alongside a scheduled date for one; a concrete near-term commitment is generally accepted better than an open-ended promise.
Why Does This Question Trip People Up?
It's usually not the test itself that's the problem — it's translating what actually happened into an answer that satisfies a reviewer who's comparing your response against dozens of other vendors. Vague answers ("we test regularly," "our systems are secure") read as evasive even when real testing has happened, because they don't give the reviewer anything to verify. A specific date, a named or described tester, and an accurate scope statement is what actually moves the questionnaire forward.
Template Answers for Common Situations
You've tested recently and have a clean report
"Our most recent penetration test was completed on [date] by [tester/firm name], covering [scope]. No Critical findings were identified; all High findings were remediated and retested. A summary report is available under NDA on request."
You've tested recently but had findings still being remediated
"Our most recent penetration test was completed on [date], covering [scope]. All Critical and High findings identified have an active remediation plan with target closure dates; [N] of [N] have been closed to date. A summary and remediation status are available on request."
Your last test is over 12 months old
"Our last formal penetration test was completed on [date]. Since then, [describe interim controls — e.g. continuous vulnerability scanning, patch management cadence]. A new test is scheduled for [date/quarter] as part of our recurring testing programme."
You've never had a formal test
"We have not yet completed a third-party penetration test. We are addressing this with a scheduled Vulnerability Assessment on [date], and will share the resulting report once available. In the interim, our security controls include [describe what's in place]."
Before You Submit Your Answer
Need a scheduled date to point to right now? Our €539 Vulnerability Assessment includes a signed attestation letter you can attach directly to a questionnaire. Not sure what a term in the questionnaire means? Check our security testing glossary.
Start with Vulnerability Assessment