Request a penetration test when a security decision requires current evidence — a major launch, an enterprise customer review, or a significant application, API or infrastructure change — scoped around the trigger, not a fixed calendar.
A periodic penetration test provides a planned point of assessment. An on-demand engagement is useful when a new business, technology or security requirement creates a need for fresh assessment evidence.
NuageSEC's current PTaaS guidance describes its service as supporting continuous or on-demand testing, while its broader VAPT services are scoped around the customer's actual applications, APIs, infrastructure, technology stack, compliance requirements and testing needs.
NuageSEC's current SaaS guidance specifically describes customer-requested penetration testing as a common requirement before enterprise onboarding or during a major sales cycle.
On-demand penetration testing means that testing can be requested when an organization has a specific security objective or trigger, rather than relying only on a predefined recurring schedule.
NuageSEC states that security-assessment scoping is performed upfront and that proposals define scope boundaries, deliverables and retesting options before the engagement begins.
Choose the delivery model that matches the requirement.
| Dimension | Recurring Penetration Testing | On-Demand Penetration Testing |
|---|---|---|
| Trigger | Predefined schedule | Specific business or security requirement |
| Timing | Monthly, quarterly, semi-annual or other agreed cadence | Requested when needed |
| Best suited to | Ongoing security validation | New or urgent security requirement |
| Scope | Defined for each scheduled engagement | Defined around the current requirement |
| Example | Quarterly application assessment | New enterprise customer requests a recent pentest |
| Change-driven testing | May be included | Core reason for engagement |
| Retesting | Can be included | Can be included |
| Reporting | Assessment report | Assessment report |
| Planning | Scheduled ahead | Scoped around the immediate requirement |
NuageSEC currently states that recurring models include monthly, quarterly and semi-annual testing, while its PTaaS guidance also describes on-demand testing.
Many organizations can use both:
Use the trigger, not the calendar. An on-demand assessment is most useful when the security question is tied to a specific event.
The organization needs security evidence for the new environment.
The security model itself has changed.
New endpoints and authorization flows may create new testing requirements.
The organization needs a current report aligned with the customer's requested scope.
The previously tested infrastructure may no longer represent the production architecture.
The application's trust boundaries and data flows have changed.
A focused assessment may be needed to evaluate a particular security question.
NuageSEC's current guidance identifies major application, API, authentication, infrastructure, cloud and integration changes as reasons to reconsider penetration testing.
Enterprise buyers frequently evaluate the security of SaaS and technology providers before onboarding. A customer security review may request:
NuageSEC's published SaaS guidance specifically addresses customer-requested penetration testing and recommends defining the scope around the actual customer-facing application, APIs, user roles, authentication, authorization, tenant isolation, business logic and relevant cloud environment.
The key principle: don't test unrelated assets simply because a customer requested "a pentest." Build the assessment around what the customer actually needs evidence about. That can make the engagement more focused and easier to explain.
A major release can change more than the user interface. It can introduce:
NuageSEC's current SaaS guidance identifies major platform changes, new APIs, authentication architecture changes, cloud migrations and major integrations as situations where testing should be reconsidered. An on-demand engagement can therefore be scoped around the new or changed security boundaries, rather than automatically repeating every previous test.
An API assessment can be requested independently when an API becomes a new security requirement.
NuageSEC's current API testing materials cover authentication, authorization, BOLA/IDOR, business logic, rate limiting and sensitive-data exposure.
A full application assessment may be appropriate for a major product change. For a more targeted requirement, the scope can be built around specific application areas:
NuageSEC's Web Application Security Testing methodology covers enumeration, exploitation simulation, reporting and retesting, with a manual-first approach focused on application behavior and business logic.
Infrastructure changes can alter external exposure, trust relationships and attack paths. Relevant triggers can include:
NuageSEC's current Network Penetration Testing service describes internal and external testing, controlled exploitation, reporting, remediation support and re-testing.
A useful on-demand engagement starts with the security question, then defines the technical scope. NuageSEC's current VAPT pricing and scoping guidance identifies scope, complexity, user roles, authentication, business logic, APIs, infrastructure, compliance requirements and timeline as factors affecting the work required. NuageSEC states that its proposals define scope, deliverables and retesting options upfront.
NuageSEC's published web-application methodology describes phases including enumeration, exploitation simulation, reporting/collaboration and retesting. Its broader security services describe a lifecycle from scoping through vulnerability assessment, manual penetration testing, risk validation, reporting, remediation support and retesting.
"On-demand" does not automatically mean "same-day." This distinction is important. The time required for a penetration test depends on:
NuageSEC's current pricing guidance identifies these factors as drivers of testing effort and cost.
On-demand describes when the service is requested, not a guaranteed testing duration. The timeline should be agreed after understanding the actual assessment scope.
Yes — when the security question is clearly defined. An on-demand pentest does not necessarily need to reproduce the entire scope of an earlier assessment.
Focus on the customer-facing SaaS application and relevant APIs.
Focus on the payment workflow, related APIs and authorization controls.
Focus on the newly exposed external attack surface.
Focus on login, session management, authentication flows and authorization boundaries.
The scope should remain broad enough to answer the security question reliably, while avoiding unrelated testing that does not contribute to the objective.
The deliverables should reflect the agreed objective.
NuageSEC's current services describe executive and technical reporting, remediation guidance and re-testing, while its Web and Network service pages provide detailed examples of these deliverables.
The engagement does not necessarily end when the report is delivered. NuageSEC currently states that standard re-testing support is included to validate that identified vulnerabilities have been successfully remediated before issuing the final clean report. This is particularly useful when a penetration test was performed for an external customer requirement, because the organization may need evidence that reported issues were addressed.
When an enterprise prospect requests a penetration-testing report, start with the customer's actual requirements. Ask: What application needs to be assessed? Are APIs included? Which user roles need testing? Does the customer require authentication testing? Does multi-tenant isolation need to be tested? Are specific cloud assets included? How recent must the assessment be? Does the customer require retesting evidence?
NuageSEC's published SaaS guidance recommends reviewing the customer-facing application, APIs, roles, authentication, authorization, tenant isolation, business logic, cloud environment and customer requirements when preparing for a customer-requested assessment.
Choose the assessment based on the security question.
| Dimension | Vulnerability Scan | On-Demand Penetration Test |
|---|---|---|
| Primary purpose | Identify potential technical weaknesses | Assess and validate security weaknesses |
| Timing | Can be run frequently | Requested for a defined security requirement |
| Human assessment | Usually limited | Expert-led |
| Business logic | Limited | Can be assessed |
| Authorization | Limited contextual analysis | Can be deeply assessed |
| Exploit validation | Varies | Core assessment capability |
| Reporting | Scanner output | Structured security report |
| Remediation guidance | Depends on tool | Included according to engagement |
| Retesting | Varies | Can be included |
The distinction matters because an on-demand penetration test is not simply a scanner run on a different date. It is a defined professional security assessment.
There is no universal price for an on-demand penetration test. NuageSEC's current pricing guidance identifies cost drivers including:
NuageSEC states that it provides customized proposals after understanding the actual environment and requirements.
This makes comparing proposals more meaningful than comparing headline prices alone.
Better preparation can make the engagement more efficient. Have the following ready where applicable:
NuageSEC's current SaaS testing guidance recommends clearly reviewing application scope, APIs, user roles, authentication, authorization, tenant isolation, business logic, cloud environment and customer requirements before an assessment.
An on-demand penetration test can answer a specific security question within an agreed scope and testing period. It does not mean "the environment is now secure indefinitely." If the environment changes significantly afterward, the assessment may no longer represent the current state.
For organizations with frequent releases or continuously changing attack surfaces, a recurring testing model may be more appropriate. NuageSEC currently offers both on-demand and recurring testing models, making the engagement approach dependent on the organization's requirements.
| Your situation | Recommended starting point |
|---|---|
| One specific requirement | On-demand testing |
| Repeated requirement | Recurring testing |
| Dynamic environment | Recurring + event-driven testing |
On-demand penetration testing is a security assessment requested when an organization has a specific testing requirement rather than relying only on a fixed recurring schedule.
Common triggers include major application changes, new APIs, customer security requirements, product launches, authentication changes, cloud migrations, new public-facing infrastructure and other significant security events.
Not necessarily. On-demand describes when the service is requested. It does not guarantee a specific turnaround time. Testing duration depends on scope, complexity, testing depth, resources and reporting requirements.
Yes. NuageSEC's current PTaaS guidance explicitly describes its model as offering continuous or on-demand testing through a dashboard.
The engagement can be scoped around the actual assets and security objective. NuageSEC's current pricing guidance specifically states that scope and complexity determine the effort required and that proposals are customized around the customer's requirements.
Yes. Customer-requested penetration testing is a documented use case in NuageSEC's current SaaS security guidance, particularly during enterprise onboarding, major sales cycles and customer security assessments.
NuageSEC currently states that standard retesting support is included to validate whether identified vulnerabilities were successfully remediated.
Yes. API testing can be scoped around the relevant API environment and requirements. NuageSEC's current API testing material covers authentication, authorization, BOLA/IDOR, business logic, rate limiting and related API security risks.
Yes. A product launch or significant platform change can create a reason to request a fresh assessment. The appropriate scope should focus on the components and security changes relevant to the launch.
There is no universal price. NuageSEC states that cost depends on scope, applications, APIs, infrastructure, user roles, complexity, testing depth, compliance requirements, timeline and retesting.
Define the reason for testing, authorized assets, applications/APIs, user roles, testing objectives, timeline, customer or compliance requirements and required deliverables before scoping the engagement.
Have a security requirement that cannot wait for the next testing cycle? Whether you are preparing for an enterprise customer, launching a major application change, introducing a new API or reassessing infrastructure, NuageSEC can scope an on-demand penetration test around the security question that matters.
Tell us about your organization. Our PTaaS team will get back within one business day to define the right scope and next steps.