Cyber Securix Global Blog

Cheap Penetration Testing: What You Actually Get for the Money

Written by Macx | Sep 10, 2026, 5:52:05 PM

Searching for cheap penetration testing is not a red flag. Most organisations looking for affordable testing are not trying to cut corners — they are small, they have a genuine reason to test, and the quotes they have received so far assumed a company ten times their size.

The problem is that "cheap" in this market covers two very different things. One is a properly scoped small engagement. The other is an automated scan with a report cover on it. They can be priced similarly, and the difference does not become obvious until you need the report to withstand scrutiny.

Here is how to tell them apart.

What affordable testing legitimately looks like

Testing gets cheaper honestly by being smaller, not by being worse. A genuinely affordable engagement is one where the scope has been narrowed to what matters most.

Our external infrastructure test starts at £500. That figure is not a loss leader — it reflects a real, bounded piece of work: up to 10 external IPs, external attack surface discovery, leaked credential detection, password spraying risk, and a report with executive and technical summaries. For a small organisation whose internet-facing footprint is a website, a mail server and a VPN endpoint, that is not a cut-down test. It is the right size of test.

The same logic applies elsewhere. A web application test from £1,000 covers a single application properly. A cloud configuration review at £1,500 covers one environment against benchmarks.

Cheap is fine. Vague is not.

The thing that is usually being sold instead

The most common cheap "penetration test" is an automated vulnerability scan, run by a tool, exported to PDF, and sold as a manual assessment.

You can usually spot it before you buy:

  • No scoping conversation. A real test cannot be priced without knowing how many IPs, applications or user roles exist. If nobody asks, nobody is planning to do bespoke work.
  • Instant turnaround. Manual testing takes days. A report the same afternoon is a tool's output.
  • Findings with no exploitation. "Port 445 open, SMB signing not required" is a scanner observation. A tester tells you they used it to reach a file share containing credentials.
  • No named tester. If nobody can tell you who performed the work, it may be that nobody did.
  • Flat per-IP pricing with no ceiling. Real scoping accounts for what those hosts actually are.

None of this makes scanning worthless. We sell managed vulnerability scanning from £1,000 a year precisely because running one regularly catches newly disclosed issues between tests. It is a good product. It is simply not a penetration test, and it will not satisfy a customer who has asked for one.

Why the price gap between providers is so wide

Four things account for most of the variation.

Manual effort

Tester days are the main cost in any honest quote. A test that involves more human hours costs more, and finds more.

Accreditation

CREST and NCSC CHECK accreditation are expensive to obtain and maintain, and that cost is in the price. If your procurement process or insurer requires one, this is not optional and the requirement decides your shortlist. If nobody has asked for it, you are paying for a credential that buys you nothing on this particular engagement.

Whether retesting is included

A cheaper headline price with retesting charged separately can end up costing more than a higher price with it included — and you will want the retest, because a report showing issues resolved is usually what the customer who triggered this actually asked for.

Overheads

Some of what you pay at a large consultancy is the consultancy. That is not a criticism; scale buys things. But if you are a twelve-person company testing one web application, you are unlikely to need them.

What should never be cut, at any price

Whatever you spend, insist on these. If a quote omits them, the saving is not real.

  • A written scope in countable units. Numbers of IPs, applications, roles or environments.
  • A named methodology — OWASP Top 10, OWASP Mobile Top 10, CIS benchmarks or equivalent.
  • Manual testing, explicitly stated. Ask directly what proportion is manual. The answer, and how readily it comes, tells you what you are buying.
  • A report with reproduction steps. Your developers need to reproduce an issue to fix it with confidence.
  • Immediate disclosure of critical findings. If something serious is found on day one, you hear on day one.
  • A retest path — included or priced. Both are acceptable. "We don't do that" is not.

Spending less without buying less

Three legitimate ways to reduce cost:

Narrow the scope deliberately. Test the application holding customer data rather than all six internal tools. A well-tested critical system beats a shallow sweep of everything.

Fix the obvious things first. If you have unsupported operating systems and missing patches, a test will spend its first day documenting what a vulnerability scan would have told you for a fraction of the price. Clear those, then test. This is one reason we suggest Cyber Essentials before testing for organisations doing both.

Get your scoping information ready. Uncertainty gets priced in. A provider who knows exactly what exists can quote tightly; one guessing at your environment will build in contingency, and you pay for it.

When cheap is genuinely the wrong answer

If you handle payment card data, health records or anything under a regulatory regime, or if a contract specifies an accreditation, the cheapest option is not a saving. Read the actual requirement before you shop — it will tell you whether price is a variable at all.

For everyone else, the honest position is that a small, well-scoped test from a provider who explains what they are doing beats an expensive one you bought because the brand felt safer.

Tell us what you are running and we will tell you what we would test and what it costs. Our full pricing is in the UK penetration testing cost guide. If a scan is what you actually need, we will tell you that and charge you scan prices.