The mean time-to-exploit a vulnerability is now negative seven days. Attackers move before patches exist. They hand off access in 22 seconds. They dwell undetected for 14 days. And the compliance frameworks most organizations cite to justify annual pentesting already require more and have for over a year.
The Numbers Your Testing Program Was Not Built For
Mandiant’s M-Trends 2026 draws on 500,000+ hours of frontline IR engagements. The mean time-to-exploit in 2025 was negative seven days, exploitation now routinely occurs before a patch is publicly available. In 2018, defenders had 63 days. In 2024, the metric crossed zero. Now it sits at negative seven. The window did not just shrink. It inverted.
The volume problem compounds the speed problem. In 2025, 48,185 new CVEs were published, a 20.6% jump on top of 2024’s record 38% surge. NIST has announced it will not categorize all of them. Twenty-eight percent of CISA’s Known Exploited Vulnerabilities were exploited on or before the day of CVE publication. There was nothing to patch yet.
“The patch is now the exploit roadmap. When vendors ship fixes, sophisticated threat actors diff the patch, derive the flaw, and weaponize it before most organizations have read the advisory.”
Mandiant M-Trends 2026 / Google Threat Intelligence Group
An annual pentest evaluates a point-in-time snapshot of an environment that no longer exists by the time the report lands. When mean time-to-exploit is -7 days and 48,000 new CVEs drop every year, the question is not whether annual testing is sufficient, it’s whether a scheduled test still maps to the threat model at all.
AI Has Eliminated the Skill Floor for Exploitation
University of Illinois researchers demonstrated in 2024 that GPT-4 could autonomously exploit 87% of one-day vulnerabilities when given only the CVE description at $8.80 per exploit. CrowdStrike’s 2026 Global Threat Report documents a 42% increase in zero-days exploited before public disclosure. CISA is considering cutting the KEV remediation window from 14 days to 3 days in direct response to AI-accelerated exploitation timelines.
The implication is direct: the attacker’s bottleneck is no longer capability, it’s inventory. The organization that hasn’t mapped its exposed attack surface continuously is handing attackers a target list they can work through faster than any annual cadence can track.
Why “Annual” Was Never Actually the Rule
PCI DSS v4.0.1 Requirement 11.4 mandates testing at least annually and after any significant infrastructure or application change. The “and” does all the work. Annual is the floor, not the ceiling. All v4.0.1 requirements became mandatory March 31, 2025. If your program still references v3.2.1 numbers, a QSA will catch it.
Req 11.4.2: documented industry-accepted methodology. Req 11.4.3: authenticated internal testing with expanded scope. Req 11.4.5/6: segmentation testing annually (every 6 months for service providers). Retesting after every remediation is mandatory — no retest, no compliance. The days of running a scanner and calling it a pentest are over.
NYDFS 23 NYCRR 500.05 (2023 amendments) pairs annual pentesting with continuous monitoring obligations. FFIEC frames pentesting as ongoing vulnerability management, not a discrete event. The frameworks already adjusted. Most programs didn’t.
What Continuous Testing Actually Means
It is not automated scanning
PCI DSS maintains separate requirements for ASV vulnerability scans (Req 11.3.2) and penetration tests (Req 11.4). They are not interchangeable. QSAs are trained to catch programs that treat them as such.
It is an operational model with four components
Attack surface management that maps exposed assets in near-real time. Change detection that fires when a new asset, port, or subdomain appears. Automated initial validation. Human-led testing for exploit chains and logic flaws automation cannot reach. The fourth component is what separates real continuous pentesting from a scanner checkbox.
Continuous penetration testing combines ASM, change detection, automated validation, and human-led testing into a single ongoing program. Unlike annual pentesting, a point-in-time snapshot, it runs in parallel with the environment, detecting exposures as they appear rather than as they accumulate.
What to Do This Quarter
- Audit your last pentest against actual change. Pull the asset list from your most recent report. Cross-reference against today’s inventory. Every gap is a system tested once and modified before retest.
- Map testing cadence to deploy cadence. If your environment changes weekly and tests run annually, you have 51 untested weeks per year. Some contain the change that mattered.
- Establish event-driven triggers. Infrastructure change, app release, acquisition, segmentation modification, each should fire a scoped test. PCI DSS 4.0.1 Req 11.4 names most of these already.
- Add an always-on ASM layer. Most organizations can’t enumerate their internet-exposed assets accurately. Until ASM is running, every testing decision is made against a partial map.
- Pre-audit your own program. Read PCI DSS 4.0.1 Req 11.4 with your last pentest report beside it. What you find is what your next QSA conversation should cover, not what you hope they miss.
The Bigger Picture
The frameworks adjusted. PCI DSS 4.0.1 is more prescriptive than 3.2.1. NYDFS strengthened continuous monitoring in 2023. FFIEC has framed pentesting as continuous in spirit for years. Gartner’s CTEM model is no longer niche — it’s how every major regulator describes the same idea.
“The pentest report lands. Findings get remediated. Then for 365 days the environment that was tested ceases to exist, replaced piece by piece through deployments, configuration changes, acquisitions, and contractor pushes.”
Propelex Security Intelligence
Propelex Pentest 360 combines on-demand testing for compliance milestones with continuous testing for the rest of the year, the part where attackers actually operate. Red Team-led, ITSM-integrated, live dashboard. Fortune 50-experienced consultants across healthcare, financial services, and government.


