Pentesting should be conducted during the development lifecycle of the application, ideally before its release to identify and mitigate security vulnerabilities early. Additionally, regular pentesting is recommended, especially after significant updates or changes to the application.