How long does a penetration test take?

The honest answer is that active testing and total elapsed time are two very different numbers, and conflating them is how schedules slip. For a typical web application, the hands-on testing is often a handful of days, but the calendar from kickoff to a final report you can hand an auditor usually runs a week or two. Here is where the time goes.
The phases that consume the clock
- Scoping and scheduling: agreeing what is tested, provisioning accounts and access, and finding a window. This can take longer than the test if access is slow to arrange.
- Active testing: commonly a few days for a standard web app, longer for complex, multi-role, API-heavy, or multi-tenant systems.
- Reporting: writing up proven findings with evidence and remediation, typically a couple of days.
- Review and delivery: internal quality review before the report reaches you, often another few days.
What makes it longer
Complexity is the main driver, the same thing that drives cost: more roles, more endpoints, APIs, integrations, payments, and tenancy all add testing days. The other big variable is access. A black-box engagement spends real time just mapping and getting in, while granting accounts and an allowlist compresses that, which is one more reason to lean toward more access, covered in how much access should you give a pentester.
What you can compress, and what you cannot
You can compress scheduling and access by preparing accounts and a production-like environment before kickoff. You can compress reporting turnaround by choosing a vendor who does not let reports sit in a queue. What you should not compress is the active testing itself; a test rushed to fit a deadline is a test that skipped the chaining and judgment where the serious findings live.
The fastest way to slow down a pentest is to start it before the access is ready. The fastest way to ruin one is to cut the testing short to hit a date.
Where continuous changes the question
The week-or-two cadence assumes a one-off engagement scheduled like a project. When testing runs continuously, on every release, the question shifts from "how many weeks until the report" to "is what we shipped this week already tested," which is the cadence software is actually built at. We make that case in your annual pentest is already out of date.
That is the model Uvy runs: proof-backed testing fast enough to keep pace with how you ship, instead of a project you schedule once a year. See how it works.