Ask most UK penetration testing companies what a test costs and you will be asked to book a scoping call. There are reasons for that — scope genuinely drives price — but it makes life difficult if you are simply trying to work out whether security testing fits in this year's budget.
So here are our actual prices, what sits behind them, and what to check before you sign anything.
Our penetration testing prices
These are the starting prices we publish on our service pages. They are honest starting points for a well-defined scope, not teaser rates.
Infrastructure testing
- External penetration test — from £500. Covers up to 10 external IPs, external attack surface discovery, detection of leaked credentials and password spraying risks.
- Internal penetration test — from £1,500. Internal attack surface discovery, Active Directory misconfiguration, lateral movement and privilege escalation.
Application testing
- Web application penetration test — from £1,000. Methodology aligned to the OWASP Top 10, with vulnerability chaining to demonstrate real impact rather than a list of isolated issues.
- Mobile application penetration test — from £2,000. Aligned to the OWASP Mobile Top 10.
Cloud and ongoing scanning
- Cloud configuration review — £1,500 for a one-time baseline of a single environment (Microsoft 365, Azure, AWS), or from £2,000 for managed ongoing reviews.
- Managed vulnerability scanning — from £1,000/year quarterly, or from £2,000/year monthly.
What actually drives the price
Penetration testing is priced in tester days. Almost everything that moves the number moves it by changing how many days the work takes.
Scope size
For infrastructure, this is the count of live IP addresses, not the size of your subnet. A /24 with eleven live hosts is an eleven-host job. For applications, it is the number of distinct user roles, the number of unique functional areas, and whether there is an API behind the interface. A five-role application takes considerably longer than a single-role one, because privilege boundaries have to be tested in both directions between every pair.
Internal versus external
Internal testing costs more than external testing, and the gap in our own pricing — £500 against £1,500 — is typical. An external test looks at a comparatively small, well-defined perimeter. An internal test starts inside the network and has far more ground to cover: Active Directory, file shares, service accounts, segmentation, lateral movement paths. There is simply more to look at.
Retesting
Finding vulnerabilities is only half the job. You fix them, and then someone should confirm the fixes actually worked. Some providers price retesting as a separate engagement. We include a retest of findings and reissue the report with updated status, which matters when you need to show a customer or auditor a clean report rather than a list of issues you promise you have fixed.
Whether remediation support is included
A report that says "SMB signing is not enforced" is not much use to a team that has not met that problem before. Support during remediation costs the provider time, so it either sits in the price or it does not exist. Ours is included.
What a quote should include
Whoever you buy from, a quote worth accepting should be explicit about all of the following. If any are missing, ask.
- Scope in countable units — number of IPs, applications, user roles, cloud environments. Not "your infrastructure".
- Methodology — OWASP Top 10, OWASP Mobile Top 10, CIS benchmarks, or a named equivalent.
- Deliverables — an executive summary for people who make decisions, a technical summary for people who fix things, and detailed findings with reproduction steps.
- Retest policy — included, extra, or unavailable. All three are legitimate answers. Not knowing is not.
- Timeline — when testing starts, how long it runs, and when the report lands.
- Who is doing the work — and whether it is the same people you spoke to during scoping.
A note on accreditation
You will see CREST and NCSC CHECK mentioned a great deal when researching UK providers. Both are real accreditation schemes, and if your procurement process or your insurer requires one, that requirement decides your shortlist before price enters the conversation. It is worth checking early whether you have such a requirement, because it will save you time.
If you do not have that requirement — and many organisations buying their first test do not — then judge providers the way you would judge any other technical supplier. Ask to see a redacted sample report. It tells you more about the quality of the work than any badge, because it shows you exactly what you will receive.
Why cheap tests are usually cheap
If a quote comes in far below everything else you have seen, the usual explanation is that you are being sold an automated vulnerability scan described as a penetration test. A scan is a useful thing — we sell managed vulnerability scanning precisely because running one regularly is worthwhile — but it is not the same product.
A scanner reports that a service is running an outdated version. A tester determines whether that outdated version can actually be exploited in your environment, chains it with the misconfiguration two hosts away, and shows you what an attacker reaches at the end of it. The difference is the difference between a list of possible problems and an accurate picture of your risk.
If you want a scan, buy a scan and pay scan prices. Just make sure you know which one you are buying.
Working out what you need
Most organisations testing for the first time start with an external infrastructure test, because it covers what an attacker can reach without any access at all, and it is the least expensive place to begin. If you run a customer-facing application, a web application test usually matters more, because that is where your data lives.
If your environment is mostly Microsoft 365 or Azure rather than servers you own, a cloud configuration review will find more than an infrastructure test will.
Not sure which applies? Tell us what you are running and we will tell you what we would test and what it would cost. If the answer is that you do not need a penetration test yet, we will say that too.
Prices correct as of publication and quoted excluding VAT. Final pricing depends on confirmed scope.