// GLOSSARY
Continuous Penetration Testing
An offensive assurance program of at least three months, managed with planned monthly validation sprints and a fix-verify cycle. It is not a one-off test; nor is it unlimited testing - a planned rhythm within package limits. Measurable closure and monthly management visibility form the backbone.
Often confused
The Application Security Penetration Test (PT-1) is one-off deep validation; Continuous Penetration Testing is not its “continuous version”.