Searching for cheap penetration testing is not a red flag. Most organisations looking for affordable testing are not trying to cut corners — they are small, they have a genuine reason to test, and the quotes they have received so far assumed a company ten times their size.
The problem is that "cheap" in this market covers two very different things. One is a properly scoped small engagement. The other is an automated scan with a report cover on it. They can be priced similarly, and the difference does not become obvious until you need the report to withstand scrutiny.
Here is how to tell them apart.
Testing gets cheaper honestly by being smaller, not by being worse. A genuinely affordable engagement is one where the scope has been narrowed to what matters most.
Our external infrastructure test starts at £500. That figure is not a loss leader — it reflects a real, bounded piece of work: up to 10 external IPs, external attack surface discovery, leaked credential detection, password spraying risk, and a report with executive and technical summaries. For a small organisation whose internet-facing footprint is a website, a mail server and a VPN endpoint, that is not a cut-down test. It is the right size of test.
The same logic applies elsewhere. A web application test from £1,000 covers a single application properly. A cloud configuration review at £1,500 covers one environment against benchmarks.
Cheap is fine. Vague is not.
The most common cheap "penetration test" is an automated vulnerability scan, run by a tool, exported to PDF, and sold as a manual assessment.
You can usually spot it before you buy:
None of this makes scanning worthless. We sell managed vulnerability scanning from £1,000 a year precisely because running one regularly catches newly disclosed issues between tests. It is a good product. It is simply not a penetration test, and it will not satisfy a customer who has asked for one.
Four things account for most of the variation.
Tester days are the main cost in any honest quote. A test that involves more human hours costs more, and finds more.
CREST and NCSC CHECK accreditation are expensive to obtain and maintain, and that cost is in the price. If your procurement process or insurer requires one, this is not optional and the requirement decides your shortlist. If nobody has asked for it, you are paying for a credential that buys you nothing on this particular engagement.
A cheaper headline price with retesting charged separately can end up costing more than a higher price with it included — and you will want the retest, because a report showing issues resolved is usually what the customer who triggered this actually asked for.
Some of what you pay at a large consultancy is the consultancy. That is not a criticism; scale buys things. But if you are a twelve-person company testing one web application, you are unlikely to need them.
Whatever you spend, insist on these. If a quote omits them, the saving is not real.
Three legitimate ways to reduce cost:
Narrow the scope deliberately. Test the application holding customer data rather than all six internal tools. A well-tested critical system beats a shallow sweep of everything.
Fix the obvious things first. If you have unsupported operating systems and missing patches, a test will spend its first day documenting what a vulnerability scan would have told you for a fraction of the price. Clear those, then test. This is one reason we suggest Cyber Essentials before testing for organisations doing both.
Get your scoping information ready. Uncertainty gets priced in. A provider who knows exactly what exists can quote tightly; one guessing at your environment will build in contingency, and you pay for it.
If you handle payment card data, health records or anything under a regulatory regime, or if a contract specifies an accreditation, the cheapest option is not a saving. Read the actual requirement before you shop — it will tell you whether price is a variable at all.
For everyone else, the honest position is that a small, well-scoped test from a provider who explains what they are doing beats an expensive one you bought because the brand felt safer.
Tell us what you are running and we will tell you what we would test and what it costs. Our full pricing is in the UK penetration testing cost guide. If a scan is what you actually need, we will tell you that and charge you scan prices.