How to Manage a Penetration Testing Project with a Gantt Chart
Why Pen Tests Need Project Management
A penetration test is not a commodity service you order and receive. It's a multi-phase project involving scoping decisions, access provisioning, active testing windows, findings review, and remediation tracking — with stakeholders from security, engineering, legal, and leadership all needing visibility at different points.
Teams that treat pen tests as a black box — "we paid the firm, they'll deliver something in 4 weeks" — end up with reports that sit unreviewed, findings that don't get remediated, and the same critical vulnerabilities surfacing in next year's test.
A Gantt chart for a penetration testing engagement creates shared visibility across the engagement timeline, ensures remediation is tracked as a first-class deliverable, and gives leadership a clear view of when the engagement is complete versus when it's just tested.
Penetration Testing Engagement Phases
| Phase | Work | Duration | Dependency |
|---|---|---|---|
| Scoping | Define target systems, test type, rules of engagement | 1–2 weeks | None |
| Contract and legal | NDA, statement of work, authorization letters | 1 week | Scoping complete |
| Access provisioning | Provide credentials, VPN access, network diagrams | 1 week | Contract signed |
| Reconnaissance | OSINT, passive recon, attack surface mapping | 1 week | Access provisioned |
| Active testing | Exploitation attempts, vulnerability validation | 1–3 weeks | Recon complete |
| Internal debrief | Preliminary findings review with security team | 1 day | Active testing complete |
| Report drafting | Pen test firm writes findings report | 1–2 weeks | Debrief complete |
| Report review | Client reviews, requests clarifications | 1 week | Draft delivered |
| Final report | Signed-off final report with CVSS scores | 3–5 days | Review complete |
| Remediation tracking | Engineering fixes, re-test scheduling | 4–8 weeks | Final report received |
| Re-test | Pen test firm validates critical/high fixes | 1 week | Remediation complete |
| Remediation letter | Attestation that findings were addressed | 1 week | Re-test complete |
Prerequisites
- Scope defined: target systems, test type (black-box, gray-box, white-box), in-scope vs. out-of-scope
- Authorization letters signed by system owners (required for cloud environments)
- Engineering team aware of test window (to avoid responding to pen test traffic as an incident)
- Remediation budget and engineering capacity allocated post-engagement
- Legal review of statement of work complete
Building the Penetration Testing Gantt Chart
Step 1: Separate the Engagement from Remediation
Many pen test Gantt charts end at "final report delivered." That's wrong. The pen test engagement produces findings; remediation is the work that actually reduces risk.
Add remediation as a required phase in the chart, with engineering tasks, a re-test engagement, and a remediation letter milestone. If your compliance program requires the remediation letter (SOC 2, ISO 27001), those dates cascade from the remediation completion date.
Open gantt-chart.io and create two sections:
- Engagement (scoping through final report)
- Remediation (engineering fixes, re-test, letter)
Step 2: Block the Active Testing Window
Active testing has a defined window — pen testers are actively attempting to exploit your systems during this period. Your security operations team needs to know this window to avoid responding to test traffic as a real incident.
Add the active testing window as a distinct bar with clear start and end dates. Share the chart with your SOC or on-call rotation before testing begins.
Step 3: Add Parallel Tracks for Multiple Test Types
Many engagements combine multiple test types:
- External network penetration test
- Web application penetration test
- Internal network penetration test
- Social engineering / phishing simulation
- API security assessment
These can often run in parallel during the active testing phase. Create swim lanes for each test type so teams can track which areas have been tested and which findings belong to which test track.
Step 4: Track Remediation by Severity
After the final report is received, create remediation tasks organized by finding severity:
| Severity | Expected Remediation Window | Re-Test Required |
|---|---|---|
| Critical | 15 days | Yes |
| High | 30 days | Yes |
| Medium | 60–90 days | Optional |
| Low | Next quarterly patch cycle | Optional |
| Informational | No required action | No |
Add individual remediation tasks for each critical and high finding, with due dates and engineering owners. If you have 12 high findings, you need 12 tasks — not one "remediate highs" bar.
Step 5: Schedule the Re-Test
Pen test firms are often booked 4–6 weeks out. Schedule the re-test engagement immediately after receiving the final report, targeting 30 days after delivery. This gives engineering time to remediate critical and high findings while the re-test window is firm.
Add re-test scheduling as a task in week 1 of remediation, not week 4.
Common Mistakes
Not planning remediation capacity. Engineering teams are often surprised by pen test findings and have no capacity budgeted for remediation. The pen test ends, the report sits for 6 weeks, the same findings appear next year. Budget engineering time for remediation before the engagement starts.
No active testing window communication. If your security team isn't aware of the test window, they'll respond to pen test traffic as a real incident — escalating to an all-hands fire drill. Communicate the window to every on-call team before testing begins.
Treating "findings delivered" as "engagement complete." The engagement isn't complete until remediation is tracked, re-tested, and a remediation letter is issued. Keep the chart open until that milestone is hit.
Scoping after contracting. Scope creep mid-engagement is expensive. Finalize scope — what systems are in-scope, what's out of scope, what test types — before the statement of work is signed.
No rules of engagement documentation. Rules of engagement define what testers can and cannot do: specific systems excluded, prohibited attack types (DoS), testing hours, escalation contact during active testing. These must be written and signed before testing starts. Add "rules of engagement signed" as a milestone gating active testing.
Template: 10-Week Pen Test Engagement + Remediation
Engagement
Scoping |████░░░░░░░░░░░░░░░░░░| Week 1
Contract + Legal |░░░░████░░░░░░░░░░░░░░| Week 2 → scoping
Access Provisioning |░░░░░░████░░░░░░░░░░░░| Week 3 → contract
Reconnaissance |░░░░░░░░████░░░░░░░░░░| Week 4
Active Testing |░░░░░░░░░░██████░░░░░░| Weeks 5-6 → recon
Internal Debrief |░░░░░░░░░░░░░░░░█░░░░░| Week 6 end
Report Drafting |░░░░░░░░░░░░░░░░░░████| Weeks 7-8
Report Review |░░░░░░░░░░░░░░░░░░░░░░| (overlaps)
Final Report Week 9 ◆
Remediation
Critical Findings (15d) |░░░░░░░░░░░░░░░░░░░░░░████| ~2 weeks after report
High Findings (30d) |░░░░░░░░░░░░░░░░░░░░░░████████| ~4 weeks after report
Re-Test Scheduling |░░░░░░░░░░░░░░░░░░░░░░██░░░░| Book immediately
Re-Test Engagement |░░░░░░░░░░░░░░░░░░░░░░░░░░████| ~5 weeks after report
Remediation Letter Week 16+ ◆
Milestones
Rules of Engagement Signed Week 2 ◆
Active Testing Window Open Week 5 ◆
Active Testing Window Close Week 6 ◆
Final Report Received Week 9 ◆
Remediation Complete Week 14 ◆
Re-Test Complete Week 15 ◆
Next Steps
Build your penetration testing project plan in gantt-chart.io. Start by placing the active testing window, then work backward to scoping and forward to remediation. Share the chart with your security team, engineering leads, and SOC before the engagement kicks off.