How Much Does a Penetration Test Cost in the UK?

  • September 10, 2026

Ask most UK penetration testing companies what a test costs and you will be asked to book a scoping call. There are reasons for that — scope genuinely drives price — but it makes life difficult if you are simply trying to work out whether security testing fits in this year's budget.

So here are our actual prices, what sits behind them, and what to check before you sign anything.

Our penetration testing prices

These are the starting prices we publish on our service pages. They are honest starting points for a well-defined scope, not teaser rates.

Infrastructure testing

  • External penetration test — from £500. Covers up to 10 external IPs, external attack surface discovery, detection of leaked credentials and password spraying risks.
  • Internal penetration test — from £1,500. Internal attack surface discovery, Active Directory misconfiguration, lateral movement and privilege escalation.

Application testing

  • Web application penetration test — from £1,000. Methodology aligned to the OWASP Top 10, with vulnerability chaining to demonstrate real impact rather than a list of isolated issues.
  • Mobile application penetration test — from £2,000. Aligned to the OWASP Mobile Top 10.

Cloud and ongoing scanning

  • Cloud configuration review — £1,500 for a one-time baseline of a single environment (Microsoft 365, Azure, AWS), or from £2,000 for managed ongoing reviews.
  • Managed vulnerability scanning — from £1,000/year quarterly, or from £2,000/year monthly.

What actually drives the price

Penetration testing is priced in tester days. Almost everything that moves the number moves it by changing how many days the work takes.

Scope size

For infrastructure, this is the count of live IP addresses, not the size of your subnet. A /24 with eleven live hosts is an eleven-host job. For applications, it is the number of distinct user roles, the number of unique functional areas, and whether there is an API behind the interface. A five-role application takes considerably longer than a single-role one, because privilege boundaries have to be tested in both directions between every pair.

Internal versus external

Internal testing costs more than external testing, and the gap in our own pricing — £500 against £1,500 — is typical. An external test looks at a comparatively small, well-defined perimeter. An internal test starts inside the network and has far more ground to cover: Active Directory, file shares, service accounts, segmentation, lateral movement paths. There is simply more to look at.

Retesting

Finding vulnerabilities is only half the job. You fix them, and then someone should confirm the fixes actually worked. Some providers price retesting as a separate engagement. We include a retest of findings and reissue the report with updated status, which matters when you need to show a customer or auditor a clean report rather than a list of issues you promise you have fixed.

Whether remediation support is included

A report that says "SMB signing is not enforced" is not much use to a team that has not met that problem before. Support during remediation costs the provider time, so it either sits in the price or it does not exist. Ours is included.

What a quote should include

Whoever you buy from, a quote worth accepting should be explicit about all of the following. If any are missing, ask.

  • Scope in countable units — number of IPs, applications, user roles, cloud environments. Not "your infrastructure".
  • Methodology — OWASP Top 10, OWASP Mobile Top 10, CIS benchmarks, or a named equivalent.
  • Deliverables — an executive summary for people who make decisions, a technical summary for people who fix things, and detailed findings with reproduction steps.
  • Retest policy — included, extra, or unavailable. All three are legitimate answers. Not knowing is not.
  • Timeline — when testing starts, how long it runs, and when the report lands.
  • Who is doing the work — and whether it is the same people you spoke to during scoping.

A note on accreditation

You will see CREST and NCSC CHECK mentioned a great deal when researching UK providers. Both are real accreditation schemes, and if your procurement process or your insurer requires one, that requirement decides your shortlist before price enters the conversation. It is worth checking early whether you have such a requirement, because it will save you time.

If you do not have that requirement — and many organisations buying their first test do not — then judge providers the way you would judge any other technical supplier. Ask to see a redacted sample report. It tells you more about the quality of the work than any badge, because it shows you exactly what you will receive.

Why cheap tests are usually cheap

If a quote comes in far below everything else you have seen, the usual explanation is that you are being sold an automated vulnerability scan described as a penetration test. A scan is a useful thing — we sell managed vulnerability scanning precisely because running one regularly is worthwhile — but it is not the same product.

A scanner reports that a service is running an outdated version. A tester determines whether that outdated version can actually be exploited in your environment, chains it with the misconfiguration two hosts away, and shows you what an attacker reaches at the end of it. The difference is the difference between a list of possible problems and an accurate picture of your risk.

If you want a scan, buy a scan and pay scan prices. Just make sure you know which one you are buying.

Working out what you need

Most organisations testing for the first time start with an external infrastructure test, because it covers what an attacker can reach without any access at all, and it is the least expensive place to begin. If you run a customer-facing application, a web application test usually matters more, because that is where your data lives.

If your environment is mostly Microsoft 365 or Azure rather than servers you own, a cloud configuration review will find more than an infrastructure test will.

Not sure which applies? Tell us what you are running and we will tell you what we would test and what it would cost. If the answer is that you do not need a penetration test yet, we will say that too.

Prices correct as of publication and quoted excluding VAT. Final pricing depends on confirmed scope.

Blog Post

Related Articles

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique.

Penetration Testing for Small Businesses: A Practical UK Guide

September 10, 2026
Most penetration testing marketing is written for organisations with a security team, a compliance function and a...

Your First Penetration Test: What to Expect and How to Prepare

September 10, 2026
Most organisations do not buy a penetration test because they woke up wanting one. They buy because a customer sent a...

Cheap Penetration Testing: What You Actually Get for the Money

September 10, 2026
Searching for cheap penetration testing is not a red flag. Most organisations looking for affordable testing are not...
Blog Post CTA

H2 Heading Module

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique.