Active testing is only part of the calendar. Access provisioning is the single most common cause of delay — test accounts for every role, a staging environment that mirrors production, and a signed authorisation letter. Teams that prepare these in advance routinely save three or four days.
Reporting takes longer than people expect because it should. Writing a finding properly means reproducing it cleanly, confirming impact, scoring it, and describing a fix that works in your framework. A report delivered the same afternoon testing ends is a template with findings pasted in.
You should not wait for the report to start fixing. On a well-run engagement, critical findings reach you within hours of confirmation, so remediation and testing overlap and the retest becomes a formality rather than a second project.
Where the time goes in a typical engagement
| Phase | Duration | What you need to provide |
|---|---|---|
| Scoping and authorisation | 2–3 days | Environment details, signed authorisation |
| Access setup | 1–2 days | Test accounts per role, builds, VPN if needed |
| Active testing | 5–10 days | A contact reachable during the window |
| Reporting | 3–5 days | Nothing — but expect critical findings early |
| Remediation | Your schedule | Engineering time |
| Retest and final report | 2–3 days | Confirmation that fixes are deployed |
In short
- Book three to four weeks ahead of any hard compliance deadline.
- Provisioning delays, not testing, cause most missed dates.
- Critical findings should reach you during the test, not after it.
- Retests are short — usually two days — if the fixes are actually deployed.