A penetration test follows a predictable lifecycle: scoping, reconnaissance, testing, reporting and retesting. The scoping phase defines what is in and out of bounds, establishes rules of engagement, identifies emergency contacts and sets the testing window. This is the most important phase. A poorly scoped test either misses critical assets or wastes budget testing systems that do not matter.
Reconnaissance comes next. The tester maps your external attack surface and gathers open source intelligence before probing anything directly. Our OSINT reconnaissance guide walks through this first active phase.
During active testing, the penetration tester works through your environment methodically. They enumerate services, identify potential entry points, attempt exploitation and document every step with screenshots and technical evidence. Communication during this phase is critical. A good tester will notify you immediately if they discover a critical vulnerability that poses an active risk to your organization rather than waiting for the final report.
The engagement concludes with a written report and a walkthrough call where the testing team explains each finding, answers questions and discusses remediation priorities. After your team addresses the findings, a retest validates that fixes were implemented correctly. The retest is not optional. Without it, you have no verification that your remediation actually closed the gaps.
Read the full guide to your first pentest