
Penetration Testing Cost Guide
Penetration testing cost is the fee for an authorised, human-led ethical hacking engagement, not an automated vulnerability scan, and UK organisations typically pay between £2,000 and £15,000+ depending on scope, complexity, and tester seniority.
The figures in this guide are typical market ranges used for budgeting and quote comparison. They are not guaranteed quotes. A scoped proposal is the only way to pin down a firm price for your attack surface.
What Does Penetration Testing Cost in the UK?
Penetration testing in the UK typically costs between £2,000 and £15,000+, depending on scope, complexity, and provider seniority.
Use the ranges below as a budget anchor before you approach providers. Match the test type to the asset you need to protect, then treat the price band as a planning figure, not a catalogue price.
Most organisations should price the internet-facing web application and the network perimeter first. Add mobile, social engineering, or physical testing only when those assets are material, and treat red teaming as a later step once a regular testing programme already exists.
| Test Type | Typical UK Price Range | Typical Duration | When You Need This |
|---|---|---|---|
| Network penetration testing | £4,000-£10,000 | 3-7 days | You need to test internal or external infrastructure, VPNs, firewalls, servers, or office networks. |
| Web application testing | £3,000-£12,000 | 5-10 days | You expose customer portals, SaaS products, APIs behind a web UI, or ecommerce applications to the internet. |
| Mobile app testing | £3,000-£8,000 | 4-8 days | You ship iOS or Android apps that store credentials, session tokens, or personal data on the device. |
| Social engineering testing | £2,000-£6,000 | 3-5 days | You need evidence of phishing, pretexting, or helpdesk impersonation risk, not just technical flaws. |
| Physical security testing | £3,000-£8,000 | 2-5 days | You need to test buildings, data centres, badges, tailgating, or on-site access to critical systems. |
| Red teaming | £15,000-£50,000+ | 2-6 weeks | You already run a mature security programme and need an adversary simulation against people, process, and technology together. |
London pricing: London rates typically run 10-20% above the UK average due to higher overheads and demand. Remote testing can reduce this premium.
A £500 Automated Scan
A £500 automated scan is not a penetration test. Scanning, and most vulnerability assessments, produce unvalidated findings that still need a human to prove exploitability, discard false positives, and show business impact.
A Human-Led Penetration Test
A penetration test uses skilled testers to exploit, chain, and evidence real risk, then explain how to fix it. Do not use a scan price as your pentest benchmark.
Do not buy every test type in the table unless each attack surface is in play this cycle. Duration in the table is tester effort, not elapsed calendar time.
A standard 5-10 man-day web application test often spans 1-3 weeks once access, environment stability, and reporting are included. Strong providers are commonly booked 4-6 weeks ahead, so a compliance deadline next month is already a rush job.
The 7 Factors That Drive Penetration Testing Cost
Seven quantified factors drive penetration testing cost in the UK, and five of them account for most quote variation: scope, complexity, provider seniority, timeline, and compliance requirements.
On-site presence and reporting depth make up the remaining two. Use the impact ranges to pressure-test a quote and to decide which extras you actually need.
| Cost Factor | Typical Impact on Price | How to Control It |
|---|---|---|
| Scope (number of assets) | Adding a second web application typically increases cost by 30-50%. | List in-scope IP ranges, domains, and applications. Exclude systems you do not need tested this cycle. |
| Complexity (authentication, custom code, APIs) | Custom application logic can add 20-40% over standard testing. | State login flows, roles, SSO, and API count up front so testers do not pad for unknowns. |
| Provider seniority | Senior testers command 25-40% more than standard testers. | Pay the premium where the stack is custom. Do not pay senior rates for a junior assigned at kick-off. |
| Timeline | Rush delivery (under 2 weeks) typically adds 20-30%. | Book 4-6 weeks ahead where you can. Avoid compressing testing and reporting into the same week. |
| Compliance requirements (ISO 27001, PCI DSS, Cyber Essentials) | Compliance-driven testing may add 10-25% for specific methodologies or accreditations. | Name the standard and evidence you need. Do not buy CHECK-grade delivery if you only need commercial CREST assurance. |
| On-site presence | Adds 20-30% compared with fully remote testing. | Use remote testing unless physical access, segmented networks, or air-gapped systems require attendance. |
| Reporting depth | Executive summaries, board-ready reports, and remediation workshops add 10-20%. | Specify who reads the report. Skip board packaging if the audience is engineering only. |
Scope is the largest lever because every extra host, app, or user role adds attack surface the tester must cover in man-days. Cutting one unused staging app from scope is often worth more than haggling the day rate.
Combining a network test and a web application test into one engagement is usually cheaper than two fully separate projects because kick-off and reporting overlap, but it is not double one price, and each extra authenticated role still adds days.
Complexity then multiplies those days. Multi-factor login, role-based access, payment flows, and undocumented APIs force manual testing that scanners cannot replace, which is why two similar web application tests can differ by thousands of pounds.
If you cannot describe the login model and API count, the provider will price in contingency. That padding is avoidable with a clearer brief.
Seniority is the third lever. A senior tester costs more per day but usually needs fewer days on a difficult stack and produces findings a junior scan-and-report engagement will miss.
Ask who will actually test, not who sold the work. A quote that uses senior day rates and then assigns a graduate at kick-off is not a cheaper deal. It is a different product.
How to Scope Your Penetration Test to Control Cost
The single biggest way to control penetration testing cost is to scope the engagement precisely before you approach providers.
A well-defined scope can reduce cost by 10-20% because providers can price accurately without adding contingency for ambiguity.
Over-scoping wastes budget on assets that do not matter this quarter. Under-scoping produces a cheap test that fails the audit or misses the system an attacker would actually use.
- List all assets to be tested (IP ranges, domains, applications). Write the inventory yourself. Calling the job the corporate network is not a scope. Include live, staging, and admin interfaces only if they are in play.
- Specify the number of web applications and their authentication requirements. Count distinct apps, environments, and roles (anonymous, user, admin, SSO). Each extra role is extra attack surface.
- Identify any APIs, microservices, or integrations in scope. Hidden APIs are a common source of mid-test change requests and extra days. Name the ones that handle authentication, payments, or personal data.
- Define the testing window and any blackout periods. Production restrictions, release freezes, and out-of-hours-only testing all affect effort and price. Out-of-hours work is not the same day rate as standard hours.
- State compliance deadlines and required standards (ISO 27001, PCI DSS, Cyber Essentials). The evidence pack the auditor expects should drive methodology, not the other way round. Name the deadline so reporting is scheduled before it, not after.
- Confirm whether on-site presence is required or remote testing is acceptable. Remote delivery removes travel loading for most web and external tests.
- Specify retest expectations (included, discounted, or separate). Agree the window in writing before kick-off, including whether it covers critical findings only or the full issue list.
- Define report format requirements (executive summary, technical annex, board-ready). Extra audiences mean extra writing time.
- Identify who will receive the report and who needs remediation support. Engineering-only delivery is cheaper than a board workshop plus developer walkthroughs. Name a remediation owner before testing starts.
- Confirm whether social engineering or physical testing is in scope or excluded. These are separate workstreams. Leaving them vague invites either an inflated quote or a gap in coverage.
Send the same written brief to every provider. Identical scope is the only way later quotes can be compared on substance.
Before kick-off, also prepare role-based test accounts, VPN or IP allowlisting, a technical contact for the window, and a remediation window after the report. Late access is one of the most common reasons a fixed price turns into a change request.
Boutique Firm vs. Large Consultancy: What You're Paying For
The provider you choose matters as much as the price you pay, because boutique firms and large consultancies deliver different value at different price points.
Choose the tier that matches your primary driver: technical depth on a specific stack, balanced delivery, or brand weight for an auditor or enterprise customer. Day rates below are typical UK market ranges, not a single firm’s tariff.
| Provider Type | Typical Day Rate | Typical Engagement Cost | Best For | Limitations |
|---|---|---|---|---|
| Boutique specialist firms | £800-£1,200 | £3,000-£8,000 | Deep technical expertise on specific stacks | Less brand weight for some compliance audits |
| Mid-sized agencies | £900-£1,300 | £5,000-£12,000 | Balanced technical depth and compliance credibility | May still ration senior time across several jobs |
| Large consultancies | £1,200-£1,800 | £10,000-£30,000+ | Compliance sign-off and enterprise clients | Junior testers may be assigned despite senior rates |
| Freelancers | £400-£800 | £1,500-£5,000 | Budget-constrained projects with a tightly defined scope | Limited accountability, typically no CREST accreditation, variable quality |
Price versus quality: A £500 test is not the same as a £5,000 test. Low-cost tests typically rely on automated scanning, limited manual verification, and template reports. They miss complex business logic flaws, chained exploits, and deep remediation guidance. The expensive outcome is not the extra day rate. It is the critical issue the cheap test never proved.
CREST accreditation is the usual commercial quality signal in the UK. NCSC CHECK is a separate gate for public sector and Critical National Infrastructure work. Those accreditations justify higher rates because they evidence methodology, tester competence, and report standards.
If a quote sits far below market and cannot show CREST or CHECK where your sector needs it, you are buying a scan with a pentest label.
- Choose a boutique specialist when the stack is custom and you need senior hands on the keyboard.
- Choose a large consultancy when a customer, regulator, or board needs a recognised brand on the report.
- Choose a mid-sized agency when you need CREST-grade delivery without enterprise packaging.
- Avoid a freelancer for PCI DSS, CHECK, or supplier-assurance work unless they operate under an accredited company that will stand behind the report.
Day Rates vs. Fixed Pricing: What to Expect in Your Quote
Penetration testing providers typically price engagements in one of two ways: day rates or fixed pricing.
Senior testers in the UK typically charge £800-£1,500 per day, with London rates at the higher end. Day rates offer flexibility when scope may grow, but they give you less budget certainty.
Fixed pricing quotes a single fee for a defined scope. That clarity often includes a 10-20% premium to cover the provider’s risk if the application is harder than the brief suggested.
Man-days are the unit of effort behind both models: a typical web application test is 5-10 man-days, and a typical network test is 3-7 man-days.
| Pricing Model | Budget Certainty | Best When | Main Trade-off |
|---|---|---|---|
| Day rate | Low to medium | Exploratory or ongoing testing where scope is not fully known | The invoice can grow if complexity appears mid-test |
| Fixed price | High | Compliance-driven testing with a written asset list | You may pay a 10-20% risk premium, and out-of-scope work is extra |
Choose fixed pricing when a regulator, auditor, or board needs a number that will not move. Choose day rates when you are mapping an unfamiliar estate or running a retainer with changing targets.
Always ask whether the quote is fixed or estimated. An estimate can increase if the tester finds unexpected complexity.
Reverse-check the arithmetic. Engagement fee divided by stated man-days should land near the day-rate band for that provider type. A £3,000 fee described as a 10-day senior test is not a senior test. It is either a scan, a junior resource, or a scope too thin to cover the assets listed.
Retesting and the Full Engagement Lifecycle: What It Really Costs
The initial penetration test is only part of the cost. Retesting, remediation support, and ongoing testing can add 30-50% to your total budget.
Budget the lifecycle, not the kick-off invoice. A complete engagement usually runs through scoping, testing, reporting, remediation support, retesting, then the next scheduled test.
- Scoping call: Confirms assets, access, windows, and out-of-scope systems. Ambiguity here becomes cost later. This step is often bundled, but it is still the cheapest place to cut unused systems.
- Testing: The man-days in the quote. This is the headline fee most organisations remember.
- Reporting: Technical findings plus, where specified, an executive summary or board-ready pack. Extra formats may be included or charged separately. Ask for a sample report before you buy. Report quality is the best preview of the work.
- Remediation support: Some providers put guidance in the report. Others charge dedicated support time at £150-£300 per hour.
- Retesting: Typically 30-50% of the original test cost. Many providers include one retest within 30-60 days. A retest usually verifies previously reported issues. It is not a second full test of new features shipped after the original window.
- Ongoing testing: Annual, quarterly, or continuous cycles. Most compliance frameworks expect at least an annual repeat, so treat year one as the start of a recurring line, not a one-off project.
What to ask your provider: Ask about retest policies before signing. If a provider does not offer a discounted retest within 30-60 days, ask why. Confirm whether critical findings are retested as a block or billed per item, and whether the retest expires if remediation slips past the window.
Skipping the retest leaves you with an unproven fix list.
Auditors and customers increasingly ask whether high-risk issues were verified closed, so the cheaper path on paper is often the more expensive path at the next assessment.
Cheap scan-led reports also create extra remediation waste because engineers spend time on false positives that a proper test would have discarded.
Budgeting for Ongoing Testing: Annual, Quarterly, and Continuous Models
Most compliance frameworks require annual penetration testing, but many organisations benefit from quarterly or continuous testing, and the cost model changes accordingly.
Annual testing is the most common model. Costs align with the one-off ranges in the opening table, plus retest loading. It is the minimum you should budget if ISO 27001, PCI DSS, Cyber Essentials, or customer contracts demand evidence of regular testing.
Quarterly testing typically costs 3-4 times an annual engagement, but a retainer can discount that by 10-20%.
Continuous testing is a retainer where the provider works the attack surface throughout the year. Costs typically range from £2,000-£5,000 per month depending on scope.
| Model | Typical Cost Shape | 3-Year Planning Note |
|---|---|---|
| Annual | One engagement per year at the relevant test-type range | A company paying £6,000 for an annual web application test should budget £18,000-£24,000 over three years, including retests and scope growth. |
| Quarterly (retainer) | 3-4x annual, often 10-20% less than four standalone tests | Use this when releases are frequent or the attack surface changes every quarter. |
| Continuous | £2,000-£5,000 per month | Use this for large or sensitive estates where a once-a-year snapshot is too slow. |
Retainer models often include priority scheduling, discounted day rates, and faster retest turnaround. That operational value matters when a production finding needs a retest before a go-live date.
Retainers work when you can forecast a minimum number of days per quarter. If you cannot, you will pay for unused time or fall back to one-off quotes.
Keep annual testing as the floor for compliance. Move to quarterly or continuous testing if you handle sensitive data, ship frequently, or present a large external attack surface.
Bring testing forward after a major release, a cloud migration, or an acquisition rather than waiting for the anniversary. Do not budget only for the first invoice and then discover year two has no line against it.
How to Compare Penetration Testing Quotes Fairly
The cheapest quote is rarely the best value, and the most expensive is not always the best quality, so compare quotes on identical scope, tester seniority, methodology, reporting, and retest terms.
Ask every provider to price the same written brief and to itemise the quote. Headline totals cannot be compared if one proposal includes two apps, a retest, and a board report, and the other includes a scan of a single URL.
- Are the same assets and scope included in every quote? If the asset lists differ, the prices are not comparable.
- What is the seniority of the testers who will actually do the work? Named seniority beats a generic team description. Ask whether the named tester is CREST registered, or a CHECK team member, rather than relying on the company badge alone.
- Is the price fixed or estimated? Estimates can rise when complexity appears.
- What methodology will be used (OWASP, PTES, and similar)? Named methods show the work is structured, not improvised.
- Is the provider CREST or CHECK accredited? Match the badge to your sector: CREST for commercial assurance, CHECK where public sector or CNI procurement requires it.
- What does the report include (executive summary, technical annex, remediation guidance)? Template PDFs are not the same as evidence an engineer can fix from.
- Is a retest included or discounted within 30-60 days? Price the close-out, not just day one.
- What is the expected timeline for testing and reporting? A cheap slot that reports after your audit date is not cheap.
- Are there any additional costs (travel, on-site presence, remediation support)? On-site loading of 20-30% should be visible before you sign.
- Can the provider share a sample report? Report quality is the clearest preview of the engagement you will actually receive.
Red flags:
- Quotes significantly below typical market range.
- Providers who cannot name the testers.
- Vague scope.
- No retest policy.
- Pressure to sign immediately.
Treat those as reasons to walk away, not as a bargaining win.
Do not pick the lowest number and hope the gaps are theoretical. The three common buying mistakes are choosing purely on headline price, under-scoping to hit a budget line, and ignoring retest cost until the report arrives.
The Cost of Getting It Wrong: Why Penetration Testing Is a High-ROI Investment
The cost of a penetration test is a fraction of the cost of a data breach, making it one of the highest-ROI security investments you can make.
Industry estimates put the average cost of a data breach in the millions. Against that, a typical UK penetration test of £2,000-£15,000 is a controlled, planned spend.
For a small business, a serious incident commonly lands at £100,000+ once you count investigation, interruption, notification, legal support, and lost trade. Enterprises measure the same event in millions.
| Spend or event | Typical cost context | What you buy |
|---|---|---|
| Penetration test | £2,000-£15,000 (typical UK range by scope) | Authorised exploitation, evidenced risk, and a fix list before an attacker uses the same path |
| Serious incident (smaller organisation) | Typically £100,000+ | Unplanned response, downtime, and reputation damage you do not control |
| Serious incident (enterprise) | Industry estimates in the millions | Regulatory, legal, and customer impact on a much larger base |
Failing a compliance audit can result in fines, loss of certification, and lost clients. The cost of testing is negligible compared with the cost of non-compliance.
Many enterprise clients now require evidence of regular penetration testing from their suppliers. Without it, you may lose contracts even if no breach has occurred.
Present the test as risk reduction with a compliance by-product, not as a discretionary IT extra. A CFO does not need a tooling lecture. They need the comparison above: a planned five-figure test versus an unplanned six- or seven-figure incident, plus the contracts you cannot bid for without a current report.
Get a custom quote for your scope from our penetration testing team at Pentesting Company when you have the asset list, standards, and retest window defined. TEST. FIND. FIX. PROTECT.
Frequently Asked Questions
Typical UK penetration testing costs sit between £2,000 and £15,000+, with day rates, retest fees, and testing frequency explaining most remaining price questions.
How much does penetration testing cost in the UK?
Penetration testing in the UK typically costs between £2,000 and £15,000+, depending on scope, complexity, and provider seniority.
Network tests often sit around £4,000-£10,000, web application tests around £3,000-£12,000, and red teaming from £15,000-£50,000+.
Treat these as typical market ranges and obtain a scoped quote for a firm figure.
Why is penetration testing so expensive?
Penetration testing is expensive because it requires skilled testers to manually exploit systems, chain findings, and write remediation guidance.
A £500 automated scan is not a penetration test. You are paying for authorised human attack time, evidence quality, and a report that engineers and auditors can act on.
How much does a penetration tester charge per day?
Senior penetration testers in the UK typically charge £800-£1,500 per day, with London rates at the higher end.
Boutique and mid-sized firms often land in the £800-£1,300 band, while large consultancies commonly charge £1,200-£1,800. Freelancers may quote £400-£800 per day with weaker accountability.
Is a cheaper penetration test as good as an expensive one?
No. A cheaper penetration test is not as good as an expensive one when the low price comes from scanning, junior time, or a narrower scope.
Low-cost tests typically miss business logic flaws, chained exploits, and usable remediation detail.
Do I need to pay extra for a retest?
You often pay extra for a retest, typically 30-50% of the original test cost, unless the provider includes one within 30-60 days.
Ask for the retest policy in the quote before you sign, and confirm it verifies reported issues rather than repeating a full test.
How often do I need penetration testing?
You need penetration testing at least annually for most compliance frameworks, and more often if you handle sensitive data or change systems frequently.
Quarterly retainers and continuous models at £2,000-£5,000 per month exist for large or fast-moving attack surfaces.
Ready to get a scoped penetration testing quote?
Bring your asset list, standards, and retest window. We will price the attack surface you actually need tested this cycle, not a catalogue bundle. TEST. FIND. FIX. PROTECT.