How much does penetration testing cost in the UK?

Penetration testing cost in the UK cover

SHARE

For a credible, manually led penetration test services in the UK, most buyers should budget around £4,000–£6,000 at the low end£6,000–£18,000 for many commercial web application, API, mobile, or cloud pentest assessments, and £25,000+ for complex, regulated, or multi-surface environments.

As a planning benchmark, serious manual testing often works out at around £1,000–£1,800 per consultant day, although narrow scopes may be lower and specialist, urgent, regulated or out-of-hours work can exceed £2,000/day. Very narrow starter packages below £3,000 exist, but they are usually limited-scope validation exercises rather than a realistic benchmark for serious commercial testing.

The final price depends less on the vendor’s logo and more on the scope, testing depth, reporting requirements, accreditation needs and timeline. A simple external test for a small company is not priced like a multi-role SaaS platform, an internal network assessment, or a regulated financial services engagement.

This article is based on our review of publicly available UK Digital Marketplace, G-Cloud and Contracts Finder data. The typical published day rate for penetration testing services in the UK public sector sits at around £1,031 per day. We analysed 49 pricing records across 44 suppliers, then focused the daily-rate calculation on 32 usable day-rate observations from 29 suppliers, excluding non-daily pricing, transaction-based fees and zero-lower-bound ranges that were unlikely to represent real billable rates. Where suppliers published a price range, we used the midpoint to calculate the market median. The data suggest that standard penetration testing clusters around the £1,000/day mark, while more specialized work, such as red teaming, tends to command a higher rate.

This guide breaks down realistic UK pricing benchmarks, what different day rates usually mean, how CREST and CHECK affect cost, and how to compare quotes without buying the wrong scope. For a broader international view, see our separate guide to penetration testing cost and pricing.

UK penetration testing pricing benchmarks

The table below gives broad UK pentest market ranges. These are not fixed prices, and they are not a substitute for proper scoping and commissioning. They are a useful starting point if you are budgeting, comparing vendors, or trying to understand whether a quote looks unusually low or unusually high.

Always confirm whether VAT, retesting, debrief calls, project management, reporting time, attestation letters and out-of-hours testing are included before comparing two proposals.

Assessment type Typical UK price range Typical duration What usually affects the price
Narrow web application validation £3,000–£5,000 2–4 days Limited scope, few roles, basic assurance need
Commercial web application pentest £6,000–£18,000 5–10 days Multiple roles, authentication, authorisation, business logic, customer data
API penetration test £4,000–£12,000 4–8 days Number of endpoints, documentation quality, auth model, business logic
Mobile application pentest £5,000–£18,000 5–12 days iOS/Android coverage, API interaction, storage, authentication, build access
External network pentest £3,000–£10,000 3–8 days Number of IPs, exposed services, segmentation, previous hardening
Internal network pentest £6,000–£20,000 6–15 days Active Directory, lateral movement, privilege escalation, segmentation
Cloud security assessment £5,000–£18,000 5–12 days AWS/Azure/GCP scope, IAM, storage, secrets, exposed services, attack paths
Red team assessment £30,000–£80,000+ 4–12 weeks Threat modelling, phishing, physical/social elements, detection and response
Regulated TLPT / CBEST-style work £80,000+ 8–16+ weeks Threat intelligence, regulator expectations, governance, reporting depth

The lower end of this table is best understood as narrow validation work, not as the right benchmark for every buyer. It may be suitable when the application is small, the risk is limited, and the company needs basic third-party assurance. It is less suitable for SaaS platforms, financial applications, healthcare products, customer-facing portals or systems where the report needs to stand up to audit, procurement or enterprise customer review.

The higher end usually involves more systems, more stakeholder requirements, deeper manual testing, stricter reporting, or a formal regulatory driver.

A good quote should explain what is included, what is excluded, how many days are allocated, who will perform the work, and what evidence you will receive at the end.

UK penetration testing cost benchmarks

What the price should include

A useful penetration test does not end when the tester finds vulnerabilities. The value comes from the full engagement: scoping, preparation, manual testing, reporting, explanation and remediation support.

At a minimum, a serious commercial assessment should include a scoping call, a written statement of work, rules of engagement, manual tester-led validation, a technical report with evidence and reproduction steps, severity ratings, remediation guidance and a secure way to share results.

For most mid-market buyers, the quote should also explain whether the final price includes a debrief call, an executive summary, a customer-facing attestation letter and one round of retesting. These items are often where cheap quotes become less useful. A £4,000 test with no retest, no debrief and a thin report may end up being worse value than a £7,000 test that produces evidence your auditor, customer and engineering team can actually use.

It is also worth asking who will perform the work. A quote from a named senior pentester is different from a quote in which the provider cannot say whether the work is done in-house, subcontracted or assigned to a junior resource.

Why prices vary so much

Two quotes for the same “web app pentest” can differ by a factor of 3x because they often don’t quote the same work.

The main driver is scope. A small app with one user role is not the same as a multi-tenant SaaS platform with admin, support, billing and customer roles. An API with clear documentation is easier to test than one where the tester has to reconstruct behaviour from browser traffic.

The second driver is depth. A light black-box test may be cheaper, but a grey-box assessment usually offers better value because the tester has access to accounts, context and documentation. That means more time can be spent on real attack paths, authorisation issues and business logic rather than basic discovery.

The third driver is reporting. A short technical report is not the same as an audit-ready report with an executive summary, reproduction steps, remediation guidance, severity rationale, retesting evidence and a customer-facing attestation letter.

This is where manual testing matters. Scanners can find missing headers, exposed services and outdated software. They are much weaker at finding broken access control, tenant isolation issues, workflow abuse or logic flaws. Those findings often separate a basic validation exercise from a serious penetration test.

Why penetration testing quotes vary?

What do day rates usually mean

Day rates are useful because they let you look beyond the headline price. For example, a £9,000 quote for three consultant days is very different from a £9,000 quote for six consultant days.

Effective day rate What it usually indicates What buyers should check
Under £600/day Very low-cost delivery, narrow scope, junior resource, automation-heavy work, or offshore delivery Is the work performed by a human expert? Who performs it? What is excluded?
£800–£1,200/day Budget-to-standard commercial testing Is reporting, retesting and business logic testing included?
£1,200–£1,800/day Senior manual testing, CREST/CHECK-style delivery, complex app/API/cloud work Is the scope detailed enough to justify the cost?
£2,000+/day Specialist work, urgent delivery, red team, niche expertise, complex governance or premium consultancy Is the premium linked to named expertise and scope, or mostly to brand and overhead?

A low day rate is not automatically a red flag. It may be reasonable for a narrow external test, a small app, or a provider with a lower cost base. The risk is when a low rate is combined with a vague scope, no sample report, no methodology, no named tester experience, and no retesting policy.

On the other hand, a high day rate is not necessarily better. It may be justified for a specialist assessment, a difficult timeline, regulated work, out-of-hours testing, or senior consultants with rare expertise. But the provider should be able to explain what the extra cost buys.

Out-of-hours testing

Out-of-hours testing is often priced above the standard day rate because it requires evening, overnight or weekend work and can be harder to staff. As a planning assumption, buyers should expect an uplift of around 1.5x the standard day rate for out-of-hours work, although the exact multiplier depends on the provider, timing and scope.

OOH testing can be justified when production systems are sensitive, testing could disrupt users, or the organisation has a strict change window. It should not be treated as automatically necessary. If a provider recommends out-of-hours testing, ask which parts of the scope need it, why normal business hours are unsuitable, and whether only the higher-risk activities can be scheduled outside normal hours.

Penetration testing cost in the UK: Fixed price or day rate?

Many pentest providers now prefer fixed-price engagements because buyers want budget certainty. A fixed price can work well when the scope is clear: one web application, one API, a defined IP range, or a known cloud environment.

Day rates are still useful because they reveal how the provider has estimated the work. Even if the proposal is fixed price, it is reasonable to ask how many testing and reporting days are included. Without that detail, two proposals with the same total price may represent very different levels of effort.

A fixed-price quote is not automatically better than a day-rate quote. The important thing is whether the provider has properly scoped the work. A fixed price based on weak scoping can still lead to exclusions, shallow testing or uncomfortable change requests later.

The best model is usually a fixed-price proposal with transparent assumptions: what is being tested, how many days are allocated, what is excluded, what deliverables are included and what happens if the scope changes.

A simple way to sanity-check any quote is:

Total quote ÷ number of testing and reporting days = effective day rate

For example, a £12,000 quote with eight delivery days works out at £1,500/day. A £12,000 quote with four delivery days works out at £3,000/day. Same total, very different model.

The first quote may be reasonable if it includes senior manual testing, reporting, a debrief call and one round of retesting. The second may still be justified for specialist work, urgent delivery or a narrow but difficult scope, but the provider should be able to explain why the effective rate is higher.

This is why buyers should avoid comparing proposals only by total price. A quote is not just a number; it is a delivery model. You are buying time, expertise, methodology, reporting quality and evidence that your team can actually use.

What changes the final cost

The factors below usually explain why one quote is cheaper, broader, deeper or more expensive than another.

Pricing factor Lower-cost scenario Higher-cost scenario
Scope size One app, few roles, limited endpoints Multiple apps, APIs, tenants, environments or cloud accounts
Testing depth Black-box or limited grey-box testing Full grey-box or white-box testing with source/config access
Application complexity Simple login, few workflows Multi-role SaaS, payments, permissions, admin panels, sensitive data
Methodology Standard vulnerability validation OWASP, business logic, abuse cases, chained exploit paths
Reporting requirements Basic technical report Executive summary, control mapping, attestation, board/auditor-ready evidence
Accreditation needs No formal accreditation required CREST, CHECK, Cyber Scheme or regulator/customer-mandated requirements
Timeline Standard scheduling Rush delivery, audit deadline, fixed release window, out-of-hours testing
Retesting No retest or paid retest One or more included fix-validation rounds

If a quote is much cheaper than the others, look for what has been excluded. If a quote is much more expensive, ask what has been added. The answer is often in the assumptions, not the price.

Cheap, fair or expensive?

A cheaper quote is not automatically bad. It may be fine for a small scope or basic assurance need. The risk is treating a narrow starter package as if it were equivalent to a full manual assessment.

A quote in the £6,000–£18,000 range is more typical for serious web application, API, mobile or cloud testing where the pentesters and the provider need time for manual work, business logic testing, reporting and retesting.

Higher-cost quotes can be justified when the environment is complex, regulated, multi-surface, urgent or requires specialist expertise. They are harder to justify when the scope is vague, and the provider cannot explain what the extra cost buys.

This also applies to large, well-known consultancies. A familiar logo can help with board, procurement or regulator confidence, but it does not automatically mean the best tester is assigned to your project or that the work will be deeper.

CREST, CHECK and individual certifications

In the UK, CREST and CHECK often come up during procurement. They matter, but they do not matter equally in every situation.

CREST is commonly used as a quality signal for penetration testing companies and individual testers. CHECK is especially relevant for the UK public sector and government-related work. Some buyers, auditors, regulators or customer questionnaires may explicitly ask for CREST, CHECK or equivalent evidence.

When accreditation may be required

You should pay close attention to accreditation requirements if:

  • You are selling into UK government or public sector organisations.
  • Your customer contract explicitly asks for CREST, CHECK or an equivalent provider.
  • You are in a heavily regulated sector, and the assessment forms part of a formal assurance process.
  • Your procurement team or auditor has already defined the accreditation requirement.
  • You need testing under a specific framework rather than a general commercial pentest.

In these cases, the accreditation requirement can affect the price because it narrows the pool of acceptable providers and may add governance, methodology or reporting expectations.

When it is useful but not mandatory

For many commercial SaaS, fintech, healthcare and technology companies, CREST is a useful signal but not always a hard requirement. For SOC 2, ISO 27001, customer security reviews or general product assurance, buyers often have more flexibility.

A non-CREST provider may still be a good fit if the team has strong individual certifications, relevant experience, a clear methodology, a strong sample report and credible references. Certifications such as OSCP, OSWE, OSCE, CREST CRT and GIAC qualifications can help validate individual tester capability.

The practical question is not “does the logo exist?” It is: will this provider produce evidence your customer, auditor or internal team will accept?

Public sector frameworks and marketplaces

If you are buying penetration testing for a UK public sector body, charity, education provider, NHS organisation or supplier to government, procurement may involve a recognised marketplace or framework rather than a standard direct purchase.

Two routes commonly worth knowing are G-Cloud 14 and Cyber Security Services 3 DPS. G-Cloud 14 is an online catalogue used by public sector organisations and charities to buy cloud-based services, including cloud support services. Cyber Security Services 3 DPS is a flexible agreement for cyber security services and includes penetration testing, CHECK and IT health check services.

These frameworks can help public sector buyers shortlist suppliers, compare service descriptions and run procurement more structured. They can also provide useful market context because some suppliers publish day rates, service definitions and pricing documents.

However, a marketplace listing should not be treated as a complete quality assessment. It can tell you that a supplier is available through a procurement route, but you still need to check whether the proposed team, methodology, sample report, retesting process and sector experience fit your actual scope.

Public-sector pricing can also differ from commercial pricing. Some suppliers offer lower rates on public-sector frameworks because they expect a higher volume of repeatable assessments, clearer procurement routes, or longer-term relationship value. That does not necessarily mean the work is lower quality, nor does it mean the same rate will apply to every commercial buyer. It simply means framework pricing should be interpreted in context.

For commercial buyers, public marketplace pricing can still be useful as a reference point. It shows that day rates in this market vary widely, and that public-sector rates may sometimes be lower because of volume, procurement structure or standardised service descriptions. Use it as one input, not the whole decision.

Useful official references:

Compliance and audit impact

Compliance rarely changes the laws of testing. It changes the evidence, scope, reporting and assurance expectations around the test.

Driver Does it always require a manual pentest? How can it affect the quote
Cyber Essentials Plus No May add vulnerability testing expectations or customer assurance pressure
ISO 27001 No universal explicit requirement Often increases evidence, reporting and control-mapping needs
SOC 2 No strict pentest mandate May require stronger evidence for customer/auditor review
PCI DSS Yes, where relevant cardholder-data environments are in scope Adds formal scope definition, methodology, segmentation and retesting expectations
UK GDPR / ICO expectations Not as a blanket named requirement Security testing can support evidence of appropriate technical measures
FCA / PRA / CBEST Depends on firm and system importance Can significantly increase governance, assurance and reporting expectations
DORA exposure Relevant to in-scope EU financial entities and suppliers May increase resilience, third-party assurance and TLPT-related expectations
UK NIS / Cyber Security and Resilience Bill Sector-dependent May increase assurance needs for regulated or critical services

This is where many buyers overpay or underbuy. They either purchase a generic report that does not satisfy the audit need, or they pay for a heavy compliance wrapper when a focused technical assessment would have been enough.

The best approach is to explain to the provider why you need the test before asking about the price. A test for internal engineering improvement may need a different report from one being used for PCI DSS evidence, an ISO 27001 audit, a customer security review or a regulated financial services requirement.

PCI DSS

PCI DSS is one of the clearest cases in which penetration testing can be an explicit requirement for relevant cardholder data environments. The PCI Security Standards Council publishes the official PCI DSS materials in its document library. If PCI DSS is the driver, the quote should be clear about scope, segmentation, methodology, retesting and evidence. For a practical walkthrough, see our PCI penetration testing guide.

A cheap generic application test may not be enough if the assessor needs to see specific coverage and documentation.

ISO 27001 and SOC 2

ISO 27001 and SOC 2 do not usually mandate one exact penetration testing format for every organisation. In practice, auditors and customers often expect evidence that security testing is performed regularly and that findings are tracked and remediated.

This means the report matters. A useful report should explain business impact, severity, reproduction steps, remediation guidance and the status of retesting where applicable.

UK GDPR and ICO expectations

UK GDPR security guidance from the ICO focuses on appropriate technical and organisational measures. Penetration testing can help demonstrate that an organisation regularly tests and evaluates the effectiveness of security controls, especially where personal data is involved.

That does not mean every organisation has the same testing obligation. It does mean that for systems processing sensitive or high-volume personal data, a recent, well-scoped penetration test can be valuable evidence of due diligence.

Financial services and resilience requirements

For FCA- or PRA-regulated firms, the cost impact depends on the firm, the systems in scope and the assurance requirement. A standard application pentest is very different from a threat-led penetration test or CBEST-style engagement.

If the assessment is tied to operational resilience, systemic importance or formal regulatory expectations, expect more governance, planning, reporting and stakeholder involvement. UK organisations with EU financial-sector exposure should also understand DORA, while sector-dependent UK buyers should monitor the Cyber Security and Resilience Bill.

How to compare quotes properly

A good penetration testing quote should make the assumptions visible. If you cannot tell what is included, you cannot compare it fairly.

Start with the effective day rate:

Total quote ÷ number of delivery days = effective day rate

Then check what those days include. Some providers include testing, reporting, retesting and a debrief call in the total. Others separate those items or exclude them entirely.

Before choosing a provider, compare more than the final number. For a deeper breakdown, see our guide to comparing penetration testing quotes. Look at how many days are allocated to testing and reporting, whether all user roles are included, whether APIs and business logic are in scope, and whether retesting is part of the package.

You should also check whether the quote includes an attestation letter, a debrief call, cloud assets, named tester qualifications and any subcontracting arrangements. If the provider is charging a premium rate, ask what makes the engagement premium: named senior testers, specialist methodology, stronger reporting, regulated-sector experience, faster turnaround or simply a larger consultancy structure.

Finally, ask for a sample report. It is one of the fastest ways to understand what you are actually buying. A polished sales deck is useful, but the report is what your engineering team, auditor, customer or board will actually consume.

It should also show whether the provider understands business logic. For example, a strong report will not simply say “access control weakness identified”. It should explain which role could access which data, how the issue was reproduced, why it matters to the business, and what the engineering team should change.

If the report is vague, scanner-heavy or hard to act on, the test may create more work for your team rather than less.

Red flags in a quote

Most bad purchasing decisions happen before testing starts. The warning signs are usually visible in the quote.

A fixed price with no scoping questions is one of the clearest warning signs. The provider should want to understand the application, user roles, APIs, environment, compliance driver and reporting expectations before giving you a final number.

Very low day rates also need context. They may reflect a narrow scope or a lower-cost delivery model, but they should not come with vague methodology, unnamed testers, no sample report and no retesting policy.

Be careful with quotes that do not explain whether APIs, business logic, cloud assets, admin roles or retesting are included. These exclusions can make a quote look cheaper than it really is.

You should also question broad compliance promises, unrealistic turnaround dates, or “AI-powered pentest” claims that do not explain how experienced human testers validate the results.

The cheapest quote is often only cheaper because something important has been excluded. The problem is that the exclusion may not become visible until the test is finished and the report does not satisfy your auditor, customer or engineering team. Our guide to questions to ask penetration testing providers can help buyers challenge vague proposals before signing.

What to prepare before requesting a quote

You do not need a perfect scope before speaking to a provider. But the more information you can provide, the more accurate the quote will be. If you are running a formal procurement process, our guide to writing a penetration testing RFP can help you structure the request.

Prepare this Why it matters
Asset list Helps the provider size apps, APIs, IP ranges, cloud accounts and mobile apps
User roles Determines how much authorisation and business logic testing is needed
Compliance driver Changes reporting, evidence and retesting requirements
Deadline Affects scheduling, staffing and possible rush fees
Access model VPN, MFA, test accounts, source code and staging access affect effort
Reporting needs Executive, technical, auditor-facing or customer-facing reports vary in depth
Retesting expectations Confirms whether fix validation is included or separately charged
Internal stakeholders Engineering, security, compliance, procurement and legal may all affect scope

For a web application or API test, include the number of user roles, whether the app is single-tenant or multi-tenant, whether there are admin functions, and whether payment, healthcare, financial or personal data is involved.

For network testing, include IP ranges, environment type, whether testing is external or internal, and any restrictions around production systems.

For cloud assessments, include the cloud provider, the number of accounts or subscriptions, the major services in use and whether the goal is a configuration review, an attack path analysis or both.

This information does not just help the provider price the work. It helps you avoid buying a scope that is too small for the risk you actually need to understand.

UK, US and EU pentest pricing differences

UK pricing is often lower than US enterprise pricing, especially for comparable manual testing. EU pricing can be similar to the UK or slightly lower, depending on the region, provider and scope.

That does not mean buyers should choose a provider based only on geography. Timezone, regulatory familiarity, reporting expectations, data handling, language, procurement requirements and sector experience can matter as much as price.

For US or EU companies buying from a UK provider, the UK can offer a useful balance: strong technical capability, mature security talent and pricing that is often lower than large US consultancies.

For UK companies buying from outside the UK, the main questions are whether the provider understands the buyer’s audit or customer requirements, whether data handling is acceptable, and whether the final report will be credible for the intended audience.

For broader international pricing benchmarks, see our global guide: How much does penetration testing cost?

Conclusion

For serious commercial work, buyers should usually think in terms of scope, tester seniority, methodology, reporting quality and retesting, not just the final number on the quote. A £6,000 assessment with clear assumptions, manual testing, useful reporting and one round of fix validation can be better value than a cheaper test that produces a thin report. Equally, a premium quote from a large provider should still be challenged if the delivery team, methodology and level of effort are unclear.

The best approach is to give the provider enough context before asking for a final price: what needs testing, why the assessment is being done, who will use the report, what deadline matters, and what evidence your auditor, customer or board expects to see.

A good penetration testing quote should make the trade-offs visible. It should explain what is included, what is excluded, who will do the work, how much time is allocated, and what evidence you will receive at the end. That is what allows you to compare providers fairly and avoid buying either too little testing or an inflated scope you do not actually need.

If you are comparing UK penetration testing quotes and want a second opinion on scope, Blaze can help you determine which level of assessment fits your scope and timeline.

FAQs

How much does a penetration test cost in the UK?

The wider UK market includes narrow starter packages below £3,000, but serious commercial assessments usually start closer to £4,000–£6,000 and often sit between £6,000 and £18,000 for web application, API, mobile or cloud work. Larger, regulated or multi-surface assessments can exceed £25,000.

What is a typical day rate?

A common planning range is £800–£1,800 per consultant day. Lower rates can be appropriate for narrow or less complex work. Higher rates may be justified for s

About the author

Picture of Julio Fort

Julio Fort

Julio has been professionally in the field of cybersecurity for over 15 years. With extensive international experience, he worked as a security consultant for London Olympics 2012, and served as a senior application security advisor at a global investment bank. Julio holds a master’s degree from Royal Holloway, University of London, in application security and fuzzing.

RELATED POSTS

Ready to take your security
to the next level?

We are! Let’s discuss how we can work together to create strong defenses against real-life cyber threats.

Stay informed, stay secure

Subscribe to our monthly newsletter

Get notified about new articles, industry insights and cybersecurity news