"Test every six months" is the most common vulnerability assessment cadence we're asked to quote against. It's a reasonable default — and, per our own guidance on the Vulnerability Assessment page, a sensible minimum. But treated as a ceiling rather than a floor, it quietly assumes something that isn't true for most applications: that your attack surface stays still between assessments.

What actually changes between tests

In a six-month window, a typical business application will usually see several dependency updates, at least one new third-party integration, and a handful of feature releases that touch authentication, file handling, or user input in some way. Each of those is a plausible new entry point. A calendar-based assessment schedule doesn't know that any of this happened — it just knows six months have passed.

A better way to think about cadence

Instead of anchoring purely to a date, anchor to events. The assessments that catch the most is the ones triggered by:

  • A major release that changes authentication, payments, or access control
  • A new third-party API or integration going live
  • A significant framework or platform upgrade
  • A merger, acquisition, or new business unit joining the same infrastructure
  • A security incident anywhere in your environment, even one that didn't touch this specific application

Layer that on top of a baseline cadence — six months for stable applications, more frequently for anything business-critical or changing quickly — and you get coverage that actually tracks how your risk profile moves, not just how much time has passed.

What this looks like in practice

For clients on our Advanced Assessment plan, this usually means a scheduled baseline check plus ad hoc re-assessment triggers tied to release milestones, agreed upfront so there's no scope surprise later. It costs more than a single annual scan, but it costs a great deal less than finding out about a new vulnerability from an incident report instead of a report you asked for.

If you're not sure whether your current release cadence has outpaced your testing schedule, that's usually a quick conversation to have before it's a costly one. See our Vulnerability Assessment service for current scope and pricing, or get in touch to talk through your specific setup.