What Is Penetration Testing (Pentest)? Types and Phases
Penetration testing probes a system's weaknesses with real attack techniques and written permission. Types, phases, reading the report and test frequency.

Short answer: A penetration test (pentest) is a controlled test of a system, network or application that uses real attack techniques against its weaknesses. A vulnerability scan lists possible weaknesses; a penetration test shows whether they can actually be exploited. Testing happens only with the system owner's written approval and within a scope agreed in advance. PCI DSS requires internal and external testing at least once every 12 months, and Türkiye's banking regulator, the BDDK, requires banks to test at least once a year.
What is penetration testing?
NIST's technical guide to security testing, SP 800-115, defines penetration testing as security testing in which evaluators mimic real-world attacks to identify ways to circumvent the security features of an application, system or network. It often involves real attacks on real systems and data, using the same tools and techniques that actual attackers use. Most penetration tests look for combinations of vulnerabilities that give more access than any single vulnerability could.
The short form "pentest" is common in the industry; you will find a brief definition in our glossary.
Penetration testing vs vulnerability scanning
The two answer different questions:
- Vulnerability scanning: According to NIST, it identifies hosts and their attributes, such as open ports and applications, and then attempts to identify vulnerabilities. It relies on automated tools and, per the PCI SSC guidance, takes several seconds to several minutes per scanned host.
- Penetration testing: Essentially a manual effort. In NIST's words, scanners check only for the possible existence of a vulnerability, while a penetration test exploits the vulnerability to confirm it exists. According to the same guidance, an engagement may last days or weeks depending on scope and the size of the environment.
PCI DSS requires scans at least once every three months and after any significant change; penetration testing is a separate requirement. We describe how scanning is set up on our vulnerability scan page.
Types of penetration test
The PCI SSC classifies tests by how much the testers are told:
- Black box: No information is provided before testing starts.
- Grey box: Partial details of the target systems are shared.
- White box: The testers receive full details of the systems.
NIST looks at where the test is run from:
- External test: Conducted from outside the organization's security perimeter.
- Internal test: Conducted from the internal network, taking the position of a trusted insider or an attacker who has already penetrated the perimeter.
By target, three types stand out:
- Network test: Servers, services, open ports and network devices.
- Web application test: Application-layer controls such as authentication, session management and input validation. OWASP's Web Security Testing Guide is a testing resource built for this area; its current stable version is 4.2.
- Social engineering: In NIST's definition, an attempt to trick someone into revealing information (such as a password) that can be used to attack systems or networks. It can be done in person, by phone or by email; the variant that uses authentic-looking emails is called phishing.
Phases of a penetration test
NIST SP 800-115 describes four phases:
- Planning: Rules are identified, management approval is finalized and documented, and testing goals are set.
- Discovery: First comes information gathering and scanning: target hosts, IP addresses, open ports and services are identified. Then the services, applications and operating systems found are compared against vulnerability databases.
- Attack: Potential vulnerabilities are verified by attempting to exploit them. A successful exploit can lead to privilege escalation, more tools installed on the target, or new knowledge about the network, in which case the test loops back to discovery.
- Reporting: Runs alongside the other three phases. At the end, a report describes the vulnerabilities, their risk ratings and how to mitigate them.
Why written permission and scope are mandatory
NIST states plainly that systems may be damaged or rendered inoperable during penetration testing. According to the PCI SSC, all testing should follow rules of engagement agreed by both parties. The testing conditions and the degree of exploitation permitted are documented and agreed before testing begins, and that step is what authorizes the tester to test the systems. Even a covert test, per NIST, runs without the IT staff's knowledge but with the full knowledge and permission of upper management.
The scope document should state at least the following:
- The systems, IP addresses and applications in scope, and those out of scope
- The testing time window and any prohibited or restricted techniques
- Communication channels and who to call when something goes wrong
- What happens if the testers find signs of a previous or active compromise
- Whether testing stops at the point where the next step would cause damage
How often should you run a penetration test?
The current version of PCI DSS is v4.0.1, published in June 2024 with no new requirements. Its requirements 11.4.2 and 11.4.3 call for internal and external penetration testing at least once every 12 months and after any significant infrastructure or application upgrade or change. The testing can be done by a qualified internal resource or an external third party, but the tester must be organizationally independent. Organizations that use segmentation to isolate the cardholder data environment must also test those controls at least once every 12 months; for service providers, every six months. We cover the wider compliance process on our PCI DSS page.
For banks in Türkiye, the rule is written into regulation. The BDDK's Regulation on Banks' Information Systems and Electronic Banking Services requires a bank to have penetration tests carried out at least once a year by independent teams with no role in designing, developing, implementing or running the services it provides through its information systems (Article 18(7)). We cover the cloud and outsourcing rules for banks in our BDDK article, and the obligations of critical infrastructure sectors in our Cybersecurity Law article.
How to read a penetration test report
The report structure recommended by the PCI SSC includes an executive summary, statement of scope, methodology, limitations, testing narrative, segmentation test results, findings, tools used and cleanup after the test. Start with the scope and limitations: a system missing from the report has not been found secure, it has simply not been tested.
Finding severity is usually expressed with CVSS. On the scale in FIRST's CVSS v4.0 specification, 0.1–3.9 is low, 4.0–6.9 medium, 7.0–8.9 high and 9.0–10.0 critical. The Base score reflects a vulnerability's intrinsic characteristics, constant over time and across environments; its impact on your own systems is captured by the Environmental metrics. The PCI SSC also expects the report to state clearly how severity rankings were derived.
How findings get closed
PCI DSS requirement 11.4.4 requires exploitable vulnerabilities to be corrected according to the organization's assessment of the risk, and penetration testing to be repeated to verify the corrections. In practice, every finding gets an owner and a target close date, and closure is confirmed when the testers try again. For web application findings, the lasting fix is in the code; until it ships, a WAF rule can reduce the risk. Closure records also serve as evidence of vulnerability management in audits; we explain what auditors look for in our ISO 27001 article.
Frequently asked questions
What does pentest mean? It is short for penetration test: a controlled, authorized test of a system's weaknesses using real attack techniques.
How long does a penetration test take? It depends on the scope and the size of the environment. According to the PCI SSC guidance, an engagement can last days or weeks, and longer if additional scope turns up along the way.
Can a penetration test damage systems? It can, and NIST says so explicitly. That is why the time window, prohibited techniques and stopping point are agreed in writing before testing starts.
Who can perform a penetration test? PCI DSS allows a qualified internal resource or an external third party, provided the tester is organizationally independent. In Turkish banks, testing is done by independent teams with no role in the services being tested.
Can a vulnerability scan replace a penetration test? No. A scan lists possible weaknesses automatically; a penetration test manually verifies whether they can be exploited.
Sources
- NIST, CSRC Glossary: penetration testing: definition of penetration testing
- NIST, SP 800-115 Technical Guide to Information Security Testing and Assessment: test types, phases and risks (September 2008)
- PCI SSC, Information Supplement: Penetration Testing Guidance: scanning vs testing, test types and report structure (September 2017)
- PCI SSC, Just Published: PCI DSS v4.0.1: current version (June 11, 2024)
- Microsoft, Microsoft Entra ID and PCI-DSS Requirement 11: text of the PCI DSS 11.4 requirements
- PCI SSC, FAQ 1447: segmentation testing frequency (June 2025)
- PCI SSC, FAQ 1087: vulnerability scan frequency (July 2023)
- OWASP, Web Security Testing Guide: web application testing guide
- FIRST, CVSS v4.0 Specification Document: severity scale and metric groups
- BDDK, Bankaların Bilgi Sistemleri ve Elektronik Bankacılık Hizmetleri Hakkında Yönetmelik: annual independent penetration testing, Article 18(7) (Official Gazette, March 15, 2020, No. 31069; in Turkish)
- How we run this layer: security assessment