Key Takeaways
- A 2026 industry report analyzing 142 pentest engagements found an average of about 6.7 findings per engagement, with roughly a third rated critical or high severity.
- Separate research focused specifically on startup-scale engagements found 29 percent of targets had at least one critical vulnerability, and 62 percent had at least one medium or higher.
- Critical severity findings have become more common industry wide, rising from roughly 1 in 40 findings in 2024 to closer to 1 in 10 in 2025 across large scale testing datasets.
- A number near zero on a first pentest is statistically unusual, not reassuring, and is worth double checking the scope and methodology behind it.
How many vulnerabilities is normal in a SaaS startup pentest is a question founders ask right before their first engagement, usually out of quiet dread that the number will be alarmingly high. Real engagement data across multiple independent sources gives a more specific and less scary answer than most founders expect going in.
What the Actual Data Shows
Approach Cyber’s 2026 Pentest Annual Report, drawn from 142 real security engagements over the past year, found 952 total findings across those engagements, an average of roughly 6.7 per engagement. Separately, research focused specifically on startup-scale companies found 29 percent of targets carried at least one critical vulnerability, and 62 percent had at least one medium or higher severity finding. Industry wide, the severity mix has also shifted noticeably, large scale continuous testing data shows critical severity findings rose from about 1 in 40 findings in 2024 to closer to 1 in 10 in 2025.
Put together, these numbers describe a fairly consistent picture for a typical SaaS startup’s first engagement, somewhere in the range of a handful of findings total, with a real chance, not a rare one, that at least one lands at critical or high severity. That range is what average pentest findings actually look like at this scale, not the near-zero result many founders quietly hope for.
Why a Near-Zero Result Is the Actual Red Flag
This is the part that surprises most founders. A report with very few or zero findings on a first pentest is not the reassuring outcome it feels like, it is statistically unusual given how consistently real engagement data shows at least some findings, often including something critical or high severity. A suspiciously clean report is more often a sign of a shallow, automated-leaning engagement than a sign of an unusually secure product. Our earlier post on whether you can fail a pentest covers this same idea from a different angle, there is no pass or fail score, and a high finding count is generally a sign of thorough testing, not a bad outcome.
Curious what a real benchmark of your own environment would likely surface? Book a scoping call and we will talk through what to realistically expect.
How to Actually Read Your SaaS Startup Pentest Results
SaaS startup pentest results should be read by severity distribution, not raw count. A report with 15 low and informational findings and zero critical or high findings is a very different result than a report with 4 total findings where 2 are critical. The count on its own tells you very little, the severity breakdown tells you almost everything. This is exactly why a scoped SaaS penetration test should always include severity ratings on every finding, not just a raw list. Critical findings pentest reports flag should get remediated first regardless of how many other, lower severity items are sitting in the same report, chasing down every informational finding before addressing a single critical one is a common, avoidable mistake.
Frequently Asked Questions
Is it normal for a first pentest to find critical vulnerabilities? Yes. Startup-specific data shows roughly 29 percent of first engagements surface at least one critical finding, and industry wide, critical severity findings have become proportionally more common in recent testing data.
What does an average number of pentest findings actually look like? A 2026 report analyzing 142 real engagements found an average of about 6.7 findings per engagement. The exact number varies by scope and application complexity, but this gives a realistic benchmark rather than a guess.
Should I worry if my report has more findings than I expected? Generally no. A higher finding count, especially across lower severities, is often a sign of thorough manual testing rather than a poorly built product. What matters most is the severity distribution and how quickly critical and high findings get remediated.
If you want a realistic sense of what your own SaaS startup pentest would likely surface before you commit to one, book a scoping call and we will walk through it.
Packet33 is a penetration testing and compliance advisory firm serving SaaS and HealthTech startups in the US, Canada, and UK.
Mohamed is the founder of Packet33. He worked as a cybersecurity analyst before launching the firm and now leads an OSCP-certified team serving SaaS and HealthTech startups in the US, Canada, and UK.
