Testing stops based on risk criteria and completion criteria, not arbitrary constraints like time or executing all planned tests. The decision depends on the acceptable level of residual risk for the system under test. Even after planned tests complete, you may continue testing if residual risk is unacceptable, or stop early if risk is sufficiently mitigated.