Annual or quarterly pentesting has a structural problem: it tests a snapshot of your application, not the one you’re shipping today.
Most security testing is billed regardless of outcome. Tying payment to verified results changes the incentive structure entirely.