Back to Articles

Penetration Testing Cost in the UK: 2026 Pricing Guide

Penetration Testing Cost in the UK: 2026 Pricing Guide

Penetration testing cost UK is the number almost every buyer wants pinned down before they will pick up the phone, and it is the number providers are most reluctant to publish. The honest answer is that a credible pen test in 2026 starts at around £1,800 for a tightly scoped external infrastructure assessment and runs past £40,000 for a full red team engagement — and the gap between those two figures is almost entirely explained by scope, not by provider greed.

This guide breaks down real 2026 UK pen test pricing by test type, by scope size and by provider tier. It explains why two quotes for what looks like the same job can differ by a factor of three, what a fixed price penetration test actually covers and what it quietly excludes, and how a small business in the UK can budget sensibly without either overpaying a tier-one consultancy or under-scoping the work so badly that the report is worthless. Every figure below is expressed as a day-rate-derived band, because that is how the industry genuinely prices, and once you can read a quote in days rather than pounds you stop being at the mercy of the number on the front page.

What you are actually paying for in a penetration test

A penetration test is a time-boxed, authorised simulation of an attack against a defined set of systems, carried out by a qualified tester who documents what they found, how they found it, what it would let an attacker do and how to fix it. That definition matters commercially because every clause in it is a cost lever. “Time-boxed” means you are buying consultant days. “Defined set of systems” means the scope you agree drives the day count. “Qualified tester” means the accreditation you insist on sets the day rate. “Documents” means roughly a quarter of what you pay is report writing, not hacking.

What a pen test is not is a vulnerability scan. An automated scan against your external estate can be bought as a subscription for £50 to £300 a month and will tell you which of your services are running software with known published flaws. That is useful, and it is not the same product. A tester chains findings together, tests business logic that no scanner understands, escalates privileges, and tells you that the low-severity information disclosure on one host combined with the default credential on another gives an attacker domain administrator in forty minutes. If a quote looks suspiciously cheap, the first question to ask is whether you are being sold a scan with a covering letter. We covered the mechanics of the discipline in depth in The Complete Guide to Penetration Testing for UK Businesses; this article is purely about what it costs.

The second thing you are paying for is independence. Under UK GDPR Article 32 an organisation must have a process for “regularly testing, assessing and evaluating the effectiveness” of its technical measures, and the ICO has been consistent that self-assessment by the team that built the system carries less weight than independent testing. For regulated buyers the requirement hardens considerably: PCI DSS 4.0.1 requirement 11.4 mandates annual internal and external penetration testing plus retesting after significant change, ISO 27001:2022 control A.8.8 expects technical vulnerability management with evidence, and financial services firms in scope of the Bank of England’s CBEST or the STAR-FS scheme are looking at intelligence-led testing in a different price bracket entirely. The compliance driver behind your test is frequently the single biggest determinant of what it will cost.

Pro Tip

Before you request a single quote, write down the answer to one question: what decision will this report let me make? “Satisfy our insurer”, “pass a client security questionnaire”, “prove the new customer portal is safe to launch” and “find out how bad things really are” are four different tests at four different price points. Buyers who cannot answer that question end up paying for the most expensive interpretation of it.

Penetration testing cost UK — the 2026 headline numbers

Four figures frame the whole market. The consultant day rate is the atom of pen test pricing; the typical SME engagement length tells you how many atoms you need; the entry point tells you what the floor looks like for a genuinely scoped piece of work; and the report-writing share explains why a two-day test never costs two days of labour.

£950–£1,200
Typical UK CREST-accredited consultant day rate, 2026
£1,800
Realistic entry point for a scoped external infrastructure test
4–6 days
Median engagement length for a UK SME annual test
25%
Share of a typical engagement spent on reporting and QA

Read those together and the arithmetic of the market falls out. A four-day web application test at £1,050 a day is £4,200 before VAT, of which roughly one day is the tester writing up, quality-assuring and presenting the findings rather than testing. That is not padding — an unreviewed report from a single tester with no peer QA is where the industry’s worst deliverables come from — but it does mean that shaving a day off the scope removes a quarter of the testing time and only a fraction of the cost. Very short engagements are disproportionately expensive per hour of actual testing, which is why almost nobody sells a one-day pen test worth having.

Two further numbers are worth carrying in your head. Retesting, where the tester re-checks that your fixes actually worked, typically runs half a day to a day and a half, so £500 to £1,500 — and whether it is included in the headline price is the single most common source of quote-to-quote variance. And urgency carries a real premium: booking inside two weeks against a normal four-to-six-week lead time attracts a 15% to 30% uplift from most UK providers, because they are displacing other scheduled work to fit you in.

Day-rate consultancy versus a fixed price penetration test

UK providers sell the same underlying work in two commercial wrappers, and choosing the wrong one for your situation is where budgets go wrong. A day-rate engagement is priced on consultant days at a published rate, with the scoping call establishing an estimated day count that can flex. A fixed price penetration test is quoted as a single number against a hard scope definition — so many IP addresses, so many application roles, so many API endpoints — with anything outside that definition triggering a change request.

Neither is inherently better value. Fixed price is the right instrument when your estate is small, stable and easy to describe, which covers most SME external infrastructure and single-application tests. Day rate is the right instrument when nobody yet knows how big the problem is, which covers internal network tests in organisations that have never had one, and anything involving a bespoke platform. The failure mode of fixed price is a scope so tightly drawn that the interesting findings sit just outside it. The failure mode of day rate is an engagement that quietly doubles.

Day-rate engagement

Priced per consultant day, scope estimated

Typical rate £850–£1,500 per day
Scope Flexible, refined during testing
Budget certainty Low until the scoping call lands
Overrun risk Carried by you
Best for Unknown estates, internal tests, bespoke platforms
Retest Usually charged separately
Watch for Estimates quoted as “from” a day count

Fixed price package

One number against a hard scope definition

Typical price £1,800–£8,000 per test
Scope Locked at contract, counted in assets
Budget certainty High, subject to the scope holding
Overrun risk Carried by the provider
Best for Stable estates, annual compliance testing, single apps
Retest Often included within 30–90 days
Watch for Asset counts that exclude what matters

The practical move is to ask any fixed-price provider what day count sits behind their number. A reputable one will tell you without hesitation, because the scoping questionnaire they sent you is precisely how they calculated it. If a provider will not decompose a £4,500 quote into “four days of testing at £950 plus half a day of reporting plus a retest”, you cannot compare it with anyone else’s number, and comparison is the entire point of collecting three quotes.

One structural warning about fixed price. Providers protect their margin on fixed-price work by defining scope in units they can count from the outside: IP addresses, subdomains, application roles, API endpoints. Those units correlate imperfectly with effort. Twelve near-identical marketing subdomains are far less work than one authenticated application with three privilege levels and a payments flow, yet a naive per-asset price list charges more for the twelve. Read the unit definitions before you read the total.

Where the money goes: 2026 UK cost by test type

“Penetration test” is a category, not a product. The seven engagement types below are the ones UK SMEs actually buy, and the spread between them is wide enough that quoting an average is meaningless. The bars show the median 2026 UK price for a typical SME-sized scope of each type, indexed against a £12,000 ceiling so the relative weight is visible at a glance.

Wireless
£2,400
External infrastructure
£2,600
Phishing simulation
£3,100
Cloud / M365 review
£4,000
Web application
£5,200
Internal network
£5,800
Mobile application
£7,000

External infrastructure sits at the cheap end because the scope is genuinely countable. You hand over a list of public IP addresses and domains, the tester enumerates services, probes them and reports. Sixteen live IPs is two to three days of work. The price only climbs when the estate sprawls — and it sprawls more often than people expect, because a decade of marketing campaigns, abandoned staging environments and forgotten VPN appliances leaves most organisations with a public footprint larger than their asset register says.

Web application testing is where budgets most frequently overshoot, because the natural scoping unit is not the page count but the number of distinct privilege levels multiplied by the number of state-changing functions. An unauthenticated brochure site with a contact form is two days. The same visual design with customer login, an admin console, a document upload, a Stripe integration and a partner API is eight to ten. Providers who quote from a URL without asking about roles are guessing, and the guess will be revised upwards once testing starts.

Internal network testing carries a cost most buyers do not anticipate: the logistics. Historically this meant a consultant on site for the duration, with travel and accommodation on top. In 2026 the large majority of UK internal tests run remotely from a small hardware implant or a virtual machine dropped onto the LAN, which removes travel but adds a shipping, provisioning and connectivity step. If a provider still quotes on-site days by default, ask what a remote-implant delivery would cost — on a five-day test outside the M25 the difference is often £800 to £1,500 in expenses alone.

Mobile application testing is the priciest per-scope line for most SMEs because iOS and Android are effectively two engagements. Each platform needs its own tooling, its own binary analysis, its own runtime instrumentation, and both share an API backend that also has to be tested authenticated. Quoting one platform and assuming the other “comes free” is a reliable way to be surprised by a change request in week two.

Scope-risk scoring: which lines in your quote will move

Every quote contains lines that are effectively fixed and lines that are estimates wearing a fixed price’s clothing. Knowing which is which before you sign is the difference between a budget you can defend to your finance director and one you have to revisit in six weeks. The grids below score the common scope elements by how likely they are to move the final invoice.

Most likely to move the number
Undiscovered public-facing assets High risk
Additional application roles found mid-test High risk
API endpoints not listed at scoping High risk
Retesting after remediation High risk
Out-of-hours or weekend testing windows Medium risk
Third-party authorisation delays Medium risk
Usually stable once agreed
Counted external IP ranges Low risk
Standard written report and executive summary Low risk
Remote delivery via implant or VM Low risk
Agreed consultant day rate Low risk
Findings debrief call Low risk
Wireless SSID count at a single site Low risk
Frequently missing from the quote entirely
Attestation letter for clients or insurers Medium risk
Remediation advice beyond the written report High risk
Cloud tenancy configuration review High risk
Segregation testing between VLANs Medium risk
Report in the client’s own template Low risk

The pattern is consistent: anything the provider can count from outside your organisation is stable, and anything that depends on what they find once they are inside is not. That is not a criticism of the model, it is arithmetic. The mitigation is to run your own asset discovery before you go to market. Enumerate your public DNS records, your certificate transparency logs and your cloud tenancies, and hand the provider a complete list. A scoping call built on a complete asset inventory produces a quote that holds; one built on “we think it is about fifteen servers” produces a change request.

The same discipline applies internally. Organisations that have already done the segmentation work described in Network Segmentation for UK SMEs can scope an internal test to a defined zone rather than a flat estate, and a defined zone is both cheaper to test and more meaningful to report on. Flat networks are expensive to test precisely because everything is reachable from everywhere, so the tester has to look at all of it.

2026 UK pen test price bands by scope

The table below converts the day-rate arithmetic into the bands UK providers actually quote in. Figures exclude VAT and assume a CREST-accredited or equivalent provider at a mid-market day rate of £950 to £1,200. Add roughly 40% to 120% at the top end of the market and subtract 20% to 30% for an independent consultant without accreditation overheads.

Scope band What it typically covers Consultant days 2026 price range
Entry External infrastructure, up to 16 live IPs, unauthenticated 2–3 £1,800–£3,500
Standard SME External plus one web application with two roles, or a single-site internal test 4–6 £3,800–£7,500
Extended Internal and external, authenticated application, cloud tenancy review, wireless 8–12 £8,000–£15,000
Regulated PCI DSS or ISO 27001 driven, segmentation testing, formal attestation, retest included 12–18 £14,000–£25,000
Adversarial Objective-led red team or assumed-breach with social engineering and physical elements 15–30 £18,000–£45,000

Most UK businesses under 100 staff belong in the Entry or Standard SME bands and should be suspicious of anything that pushes them higher without a specific reason. The two legitimate reasons to jump a band are a contractual obligation — a client, an insurer or a framework demanding a defined scope — and a genuine change in the estate, such as launching a customer-facing portal that handles payment or personal data for the first time.

The Adversarial band deserves a note, because it is frequently mis-sold. A red team is not a better pen test; it is a different exercise measuring a different thing. A pen test asks “what vulnerabilities exist in this system?” A red team asks “can our detection and response function notice and stop a determined attacker pursuing a specific objective?” If you do not yet have a detection and response function, a red team has nothing to measure and you will have spent £25,000 to be told what a £5,000 test would have told you. Organisations without a security operations capability should stay in the Standard or Extended bands until they have one.

Are you ready to buy? The budget readiness gauge

Providers price uncertainty. The less confident they are about what they will find, the more contingency they build into the day count, and the more likely a change request becomes. The gauge below reflects a composite benchmark drawn from the scoping documentation UK SMEs typically arrive with: asset inventory completeness, clarity of the compliance driver, named internal owner, agreed testing window and a remediation budget set aside before the report lands.

57/100
Cloudswitched pen test budget readiness benchmark, UK SMEs 2026

A score in the fifties is the norm, and it is expensive. The most common gaps are the last two: no agreed testing window, which pushes the engagement into a rush slot with its 15% to 30% premium, and no remediation budget, which is the one that genuinely wastes money. A test that finds twenty-two issues and is followed by no remediation programme has bought you a document, not a security improvement, and next year’s test will find the same twenty-two issues plus whatever has accumulated since.

As a planning heuristic, budget for remediation at roughly the same order of magnitude as the test itself for a first engagement, and considerably less for subsequent annual tests once the structural problems are fixed. A £5,000 first test that surfaces missing multi-factor authentication, an unpatched edge appliance and a flat internal network implies real remediation work behind it. Organisations that have already completed a Cyber Essentials gap analysis and remediation exercise typically score fifteen to twenty points higher on this benchmark and see materially fewer high-severity findings, because the basic hygiene controls are already in place.

The engagement timeline and where each cost lands

Pen test invoices arrive as one number, but the work is a sequence of distinct stages with very different cost profiles. Understanding where in the timeline your money is being spent tells you which stages you can compress and which you cannot. The eight stages below describe a typical five-day UK SME engagement from first contact to signed-off remediation.

Stage 1 — Scoping call and questionnaire (no charge)
Thirty to sixty minutes with a technical scoper, plus a written questionnaire covering asset counts, application roles, hosting arrangements and compliance drivers. Reputable UK providers do not charge for this. The quality of your answers here sets the day count for everything downstream, so treat it as the most valuable free hour in the process.
Stage 2 — Proposal, authorisation and third-party consent (no charge)
The rules of engagement document, the scope schedule and the authority-to-test letter. If any part of your estate is hosted by a third party, their written authorisation is needed. AWS, Azure and Google Cloud all permit customer-initiated testing of their own resources under published policies without prior approval, but a managed hosting provider or a SaaS vendor may not. Chasing this consent is the most common source of slipped start dates.
Stage 3 — Scheduling and lead time (no charge, but a cost driver)
Standard UK lead time in 2026 runs four to six weeks for a mid-market provider and eight or more for the largest consultancies in Q4, when annual compliance testing peaks. Booking inside two weeks attracts a rush premium of 15% to 30%. This is the single cheapest cost saving available to any buyer: book three months out.
Stage 4 — Setup and reconnaissance (roughly 0.5 day)
Implant shipping and provisioning for internal tests, VPN or jump-host access for cloud environments, credential provisioning for authenticated application testing. Where credentials are late or wrong, this half day becomes a full one and it is billable. Have the test accounts created, verified and documented a week before the start date.
Stage 5 — Active testing (3–4 days of a 5-day engagement)
The part everyone imagines they are buying. Enumeration, exploitation, privilege escalation, lateral movement and business-logic testing against the agreed scope. Critical findings are normally communicated the same day rather than held for the report, and your team should have someone reachable throughout to receive them.
Stage 6 — Reporting and peer QA (roughly 1 day)
Write-up, CVSS scoring, evidence capture, remediation guidance and an executive summary that a non-technical board can act on. A second consultant reviews the findings. This is the stage cut-price providers skip, and it is the stage that determines whether the document is usable by your engineers or is a scanner export with a logo on it.
Stage 7 — Debrief and remediation planning (0.5 day, sometimes included)
A walkthrough call with the tester where your engineers can ask what a finding actually means in your context. Genuinely valuable and frequently omitted from cheap quotes. Ask explicitly whether a technical debrief is included, and insist that the tester who did the work attends rather than an account manager.
Stage 8 — Remediation and retest (0.5–1.5 days, often charged separately)
Your team fixes; the tester verifies. Typical retest windows run 30 to 90 days from report delivery. Where retesting is included, the window is usually the constraint rather than the price — if your remediation programme runs past 90 days you will pay again. Where it is excluded, budget £500 to £1,500.

Notice that four of the eight stages carry no direct charge and yet three of them are decisive cost levers. The scoping call sets the day count. The authorisation chase sets the start date. The lead time sets whether you pay a rush premium. A buyer who runs those three stages well and a buyer who runs them badly can pay 40% different prices for identical testing work.

What proportion of the fee each activity actually consumes

Break a five-day, £5,200 web application engagement down into its constituent activities and the distribution surprises most first-time buyers. The rows below show the share of total billable effort each activity consumes on a representative UK SME engagement, drawn from the way mid-market providers structure their delivery.

Share of billable effort, typical 5-day UK web application test

Manual exploitation and business logic
26%
Report writing and executive summary
18%
Enumeration and mapping
14%
Authenticated role-by-role testing
12%
Evidence capture and screenshots
8%
Peer review and quality assurance
7%
Automated scanning and triage
6%
Setup, access and credential wrangling
5%
Debrief call and client questions
4%

Automated scanning accounts for 6% of the effort. That single figure is the answer to the most common objection UK finance directors raise, which is some version of “can we not just run the tool ourselves?” You can, and it will cover 6% of the engagement. The 26% spent on manual exploitation and business logic is the part that finds the authorisation flaw letting one customer read another customer’s invoices, and no scanner on the market finds that, because a scanner does not know what an invoice is or who should be allowed to see one.

The 18% on reporting is the other figure worth defending internally. It looks like overhead and it is the deliverable. A finding that your engineers cannot reproduce, cannot prioritise and cannot fix has cost you the testing time for no return. When comparing quotes, ask every provider for a redacted sample report. The difference between a good and a bad one is immediately obvious, and it is a far better discriminator than the price on the front page.

Retesting: the cost most buyers forget to budget

Retesting is where the real total cost of a penetration test is decided, and it is the line most commonly absent from a comparison spreadsheet. In a review of how UK mid-market providers structure their standard commercial terms, a substantial minority treat retesting as a chargeable extra rather than an included deliverable — and the buyers who discover this do so after the report has landed and the remediation work is already done.

38%
Of UK SME pen test quotes where remediation retesting is charged separately

There are three commercial patterns in the market and they are not equally good value. The first is retest included within a fixed window, typically 30 to 90 days, at no extra charge. This is the strongest position for a buyer with an organised remediation capability and a weak one for a buyer whose engineering team is booked solid for the next quarter, because an unused window has no residual value. The second is retest charged at a reduced day rate, often half rate, with no window constraint. This suits organisations with slower remediation cycles. The third is retest charged as a fresh engagement, which is the pattern to negotiate away before signing, because it can add 25% to 40% to the true cost of the exercise.

The pragmatic move at quotation stage is to ask for the retest to be priced as a separate, explicitly stated line rather than bundled or omitted. That does two things: it makes competing quotes genuinely comparable, and it forces a conversation about your remediation timeline before the test rather than after it. If you know your team cannot deploy infrastructure changes inside 90 days, an included-window retest is worth less to you than a half-rate open-ended one, regardless of which quote looks cheaper.

One further point on retest scope. A retest verifies that the specific findings from the original report have been remediated. It is not a fresh test, and it will not find issues introduced by the remediation itself — which is a real risk, since rushed fixes to authorisation logic are a well-known source of new authorisation flaws. Where remediation involved substantial code or architecture change rather than patching and configuration, the honest answer is that you need a partial re-test of the changed component, not a findings verification, and that is a different day count.

A real budget: what a 42-person Manchester fintech actually spent

An anonymised example makes the arithmetic concrete. A 42-person financial technology firm in Manchester, running a customer-facing web platform on Azure with a Microsoft 365 tenancy and a single office, needed testing to satisfy a new enterprise client’s security questionnaire and to support an ISO 27001 certification already in progress. They had never commissioned a penetration test before and their initial budget line was £3,000, based on a figure someone had seen quoted online.

The three quotes they received came in at £4,100, £7,900 and £19,500. The spread was not provider margin; it was three different readings of the same request. The cheapest covered external infrastructure only and would not have answered the client questionnaire, which asked specifically about application-layer testing. The most expensive was a tier-one consultancy quoting a red team engagement against a business with no security operations function to test. The middle quote — eight days covering external infrastructure, the authenticated web platform across its three user roles, an Azure and M365 configuration review and a 90-day retest — was the one that matched the actual requirement.

The final spend told the more useful story. The test itself came to £7,900. Remediation ran to a further £6,400, dominated by two structural items: enforcing multi-factor authentication and conditional access across the tenancy, and rebuilding an authorisation check in the customer portal that allowed an authenticated user to retrieve another organisation’s statements by changing an identifier in a URL. The retest was included and consumed one day inside the window. Total first-year cost was £14,300 against an initial budget of £3,000 — and the following year’s test, against a hardened estate with the structural issues resolved, was quoted at £6,800 with materially fewer findings.

We budgeted for the test and not for the fixing, which in hindsight was the wrong way round. The report was not the expensive part. The report was the cheap part that told us what the expensive part was going to be.

Three lessons generalise. First, the questionnaire or framework driving the test dictates the scope, so read it before you scope rather than after. Second, the first test in an organisation that has never been tested is a discovery exercise and its remediation bill will be larger than its testing bill; plan the two together. Third, prices fall in year two if — and only if — the year-one findings were actually fixed. The firms that pay the same or more every year are the ones treating the report as a compliance artefact rather than a work list. Much of what that fintech remediated overlaps with the controls covered in Email Security in Microsoft 365, which is worth reading before rather than after a first engagement.

The 12-point pen test budgeting checklist

Work through this list before you request a single quote. Every item on it either removes uncertainty from the provider’s day-count estimate or prevents a change request later, and both of those translate directly into pounds.

  1. Write down the driver. Client questionnaire, insurer requirement, ISO 27001 or PCI DSS obligation, pre-launch assurance, or genuine curiosity about your exposure. Each one implies a different scope and a different report format.
  2. Enumerate your public footprint properly. Pull your DNS zone, check certificate transparency logs for subdomains you have forgotten, list every cloud tenancy and every third-party-hosted service. Hand the provider a complete inventory, not an estimate.
  3. Count application roles, not pages. For each web or mobile application in scope, list the distinct privilege levels and the state-changing functions each can reach. This is the single largest driver of application testing cost.
  4. Document your APIs. An OpenAPI or Swagger specification handed over at scoping saves the tester enumeration time and saves you money. An undocumented API discovered mid-test is a change request.
  5. Decide black box, grey box or white box. Grey box — tester has credentials and basic architecture knowledge — delivers the most findings per pound for most SMEs. Black box spends billable days rediscovering things you could have simply told them.
  6. Agree the testing window early. Business hours are cheapest. Out-of-hours and weekend windows carry a premium. If your platform cannot tolerate testing during trading, say so at scoping rather than negotiating it later.
  7. Secure third-party authorisation before you book. Managed hosting providers, SaaS vendors and payment processors may all need to consent. Start this the day you decide to test.
  8. Provision test credentials a week ahead. One account per role, verified working, documented, with any MFA arrangements resolved. Late credentials burn billable setup time.
  9. Ask for the day count behind the price. Any provider who will not decompose their quote into testing days, reporting days and retest days has given you a number you cannot compare with anyone else’s.
  10. Get the retest terms in writing. Included or extra, what window, at what rate, and whether it covers findings verification only or a partial re-test of changed components.
  11. Request a redacted sample report. Judge the deliverable, not the brochure. Look for reproduction steps your engineers could actually follow and remediation advice specific to your technology stack.
  12. Set the remediation budget now. For a first engagement, plan for remediation costs of a similar order to the test itself. A report with no funded fix programme is an expensive document.
Note

Items 2, 3 and 12 account for most of the variance between a quote that holds and a quote that moves. If you only have time for three, do those. And be aware that a provider who accepts a vague scope without pushing back on it is not doing you a favour — they are deferring the conversation to a point where you have less negotiating leverage.

Costly mistakes when buying a penetration test

The mistakes below are not exotic. They are the ordinary ones that turn a £4,000 exercise into a £9,000 one, or worse, into a £4,000 exercise that achieves nothing.

  • Buying on price alone. The cheapest quote is frequently the narrowest scope, and a narrow scope that misses the system your client asked about has cost you the full amount for zero value. Compare scopes first, then compare prices within the scopes that actually meet your requirement.
  • Confusing a vulnerability scan with a penetration test. If a quote comes in dramatically below the bands in this article, establish whether a human being is doing manual testing or whether you are buying an automated scan with a formatted export. Both have their place; only one satisfies a client questionnaire asking for penetration testing.
  • Scoping to the budget rather than to the risk. Deciding you have £3,000 and asking what fits is how organisations end up testing their brochure site while the customer portal handling personal data goes untested. Scope to the risk, then stage the work across quarters if the budget cannot absorb it at once.
  • Ignoring accreditation when it is contractually required, or paying for it when it is not. CREST or CHECK accreditation carries a real cost premium. It is non-negotiable for public sector CHECK work and many financial services contracts, and it is optional for a private business testing its own estate for its own assurance. Know which you are.
  • Leaving no time between the test and the deadline. If a client needs your report by the end of the quarter, a test finishing in the final week leaves no room to remediate and retest. Work backwards: retest window, remediation time, report turnaround, testing days, lead time. That is usually three months, not three weeks.
  • Treating the report as the deliverable. The deliverable is a remediated estate. Organisations that file the report and repeat the exercise annually pay full price every year and see the same findings every year.
  • Excluding the things you are most worried about. Legacy systems get excluded from scope precisely because everyone knows they are fragile, which is exactly why an attacker will target them. If a system genuinely cannot tolerate testing, test a staging replica rather than pretending the risk does not exist.
  • Forgetting VAT and expenses in the budget line. Quotes are conventionally ex-VAT, and on-site engagements outside your provider’s home region carry travel and accommodation. On a £6,000 test that is a £1,200 VAT line plus potentially £800 of expenses that nobody put in the forecast.
Watch out

Be particularly careful with quotes that price per IP address or per application without a scoping call. Per-asset price lists are built for automated scanning economics and they systematically underprice complex authenticated applications and overprice simple infrastructure. A provider who quotes you a firm number from a web form has not looked at your estate.

Penetration testing cost UK at a glance

The reference table below consolidates the figures from this guide. All prices exclude VAT and assume a UK mid-market provider at a £950 to £1,200 day rate in 2026.

Item 2026 UK figure Notes
Independent consultant day rate £600–£900 No accreditation overhead; verify certifications individually
Mid-market accredited day rate £950–£1,200 CREST or equivalent; the reference rate for this guide
Tier-one consultancy day rate £1,400–£2,500 Brand, indemnity cover and regulatory recognition
External infrastructure, up to 16 IPs £1,800–£3,500 2–3 days; the usual entry point
Wireless, single site £1,800–£3,500 2–3 days; scales with SSID and site count
Web application, single role £3,000–£6,000 3–5 days; unauthenticated or one privilege level
Web application, multi-role plus API £5,000–£12,000 5–10 days; the most common overrun
Internal network, single site £4,000–£7,500 4–6 days; assumes remote implant delivery
Cloud and M365 configuration review £2,500–£6,000 3–5 days; configuration review, not infrastructure testing
Mobile application, iOS and Android £5,000–£10,000 5–8 days; two platforms plus the shared backend
Phishing and social engineering £1,800–£4,500 2–4 days; scales with pretext sophistication
Red team engagement £18,000–£45,000 15–30 days; requires a detection capability to be meaningful
Remediation retest £500–£1,500 0.5–1.5 days; included by roughly six providers in ten
Rush booking premium +15% to +30% Applies inside a two-week lead time
Standard UK lead time 4–6 weeks 8+ weeks at tier-one providers during Q4

How Cloudswitched approaches penetration testing for UK businesses

Cloudswitched scopes penetration testing against the decision the report has to support rather than against a price list. That means a scoping conversation that starts with the client questionnaire, the insurer’s wording or the certification requirement driving the work, an asset discovery exercise so the scope reflects the estate you actually have, and a quote decomposed into testing days, reporting days and retest days so it can be compared honestly with anyone else’s. Where the sensible answer is a smaller test than you expected, that is what we will say.

Get a scoped, decomposed pen test quote

Talk through your estate, your compliance driver and your remediation capacity with someone who will price the work in days before pounds.

Talk to a Penetration Testing Specialist

Frequently Asked Questions

How much does a penetration test cost in the UK in 2026?

A scoped external infrastructure test covering up to 16 live IP addresses runs £1,800 to £3,500 for two to three consultant days. A typical UK SME annual engagement covering external infrastructure plus one authenticated web application sits at £3,800 to £7,500 across four to six days. Extended engagements adding internal network testing, a cloud tenancy review and wireless run £8,000 to £15,000. Red team engagements start around £18,000. The underlying variable in every case is the consultant day rate, which sits at £950 to £1,200 for a mid-market accredited UK provider, so the fastest way to sanity-check any quote is to divide it by that rate and ask whether the resulting day count is plausible for your scope.

Why do penetration testing quotes vary so much for the same job?

Because the quotes are almost never for the same job. Three quotes against one enquiry commonly reflect three different readings of the scope: one provider tests only what was explicitly listed, another includes the cloud tenancy and the API, and a third proposes an adversarial engagement. Day rates vary by roughly a factor of three between independent consultants and tier-one consultancies, and retest terms differ enough to change the true total by 25% to 40%. Normalise the comparison by asking each provider for the day count, the asset list they priced and the retest terms in writing, then compare those three things before you compare the totals.

What is a fixed price penetration test and is it better value?

A fixed price penetration test is quoted as a single number against a hard scope definition — a stated count of IP addresses, application roles or API endpoints — with anything beyond that triggering a change request. It transfers overrun risk to the provider, which is genuinely valuable when your estate is small, stable and easy to describe. It is a poor fit when nobody yet knows how large the environment is, because the provider will price defensively or draw the scope so tightly that the interesting findings sit outside it. For most SME external and single-application testing, fixed price is the right instrument; for a first internal network test, day rate usually is.

How much should a small business in the UK budget for pen testing?

A UK business under 50 staff with a straightforward estate — a public website, Microsoft 365 and a single office network — should budget £3,500 to £6,000 for a meaningful annual test, plus a remediation budget of a similar order in the first year. If a customer-facing application handles payments or personal data, add £3,000 to £6,000 for application-layer testing. Booking three months ahead avoids the rush premium. The most common budgeting error is funding the test and not the fixes, which leaves you with a document rather than an improvement and the same findings again next year.

Does Cyber Essentials require a penetration test?

No. Cyber Essentials is a self-assessment against five technical controls, and Cyber Essentials Plus adds a hands-on technical audit carried out by a certification body — typically £1,500 to £3,000 — which verifies those same five controls. Neither is a penetration test and neither substitutes for one. They answer different questions: certification asks whether specific baseline controls are correctly implemented, while a pen test asks what an attacker could actually achieve against your particular estate. Many UK organisations sensibly do both, and doing certification first usually reduces the number of high-severity findings the subsequent test produces.

How often should a UK business commission a penetration test?

Annually is the baseline expectation across UK compliance frameworks, and PCI DSS 4.0.1 requirement 11.4 makes annual internal and external testing explicit for organisations handling card data. Beyond the calendar, test after any significant change: a new customer-facing application, a material architecture change, a cloud migration, a merger that joins two networks, or a move to a new hosting provider. Organisations running continuous deployment against a customer-facing platform increasingly supplement the annual engagement with lighter quarterly application testing rather than relying on a single yearly snapshot that is out of date within weeks.

Is retesting included in the price of a penetration test?

Roughly six UK providers in ten include a retest, usually within a 30 to 90 day window from report delivery. The remainder charge separately, typically £500 to £1,500 for half a day to a day and a half of verification work. Ask for the retest to be quoted as an explicit separate line even where it is included, because that makes competing quotes comparable and forces an honest conversation about whether your engineering team can actually remediate inside the window. An unused retest window has no residual value, so an open-ended half-rate retest can be worth more than an included one.

What is the difference between a vulnerability scan and a penetration test?

A vulnerability scan is an automated tool that compares your exposed services against a database of published flaws, available on subscription for £50 to £300 a month. A penetration test is a qualified human chaining findings together, escalating privileges and testing business logic that no scanner understands. On a typical five-day engagement, automated scanning accounts for about 6% of the billable effort while manual exploitation and business-logic testing accounts for around 26%. Both are worth having; scanning gives you continuous coverage of known issues, testing gives you an assessment of what an attacker could achieve. Only the latter satisfies a client questionnaire asking for penetration testing.

Do I need a CREST-accredited provider?

It depends entirely on what is driving the test. CHECK accreditation is mandatory for UK public sector work under NCSC arrangements, and CREST accreditation is contractually required by many financial services clients and increasingly requested in enterprise supplier questionnaires. If neither applies to you, accreditation is a quality signal rather than a requirement, and it carries a real cost premium. A private business testing its own estate for its own assurance can reasonably work with a well-referenced independent consultant holding recognised individual certifications, provided you check those certifications and see a sample report first.

Can we reduce the cost by doing some of the work ourselves?

Yes, and the savings come from preparation rather than from testing. Completing an accurate asset inventory, documenting application roles and API endpoints, provisioning verified test credentials in advance and securing third-party authorisation before booking can remove a full day of billable effort from a five-day engagement. Running your own automated scanning beforehand and fixing the obvious findings means the tester spends their time on the issues that require a human. What does not save money is narrowing scope to fit a budget, because an untested system is not a cheaper system, it is an unmeasured one.

How far in advance should we book a penetration test?

Four to six weeks is the standard UK lead time for a mid-market provider, extending to eight weeks or more at the largest consultancies during the Q4 compliance peak. Booking inside two weeks attracts a rush premium of 15% to 30%. If the test supports a deadline — a client questionnaire, a certification audit, a product launch — work backwards from the deadline through the retest window, the remediation time, the report turnaround and the testing days. That calculation almost always lands three months before the date, not three weeks.

What should a good penetration test report contain?

An executive summary a non-technical board can act on, a prioritised findings list with CVSS scores and a plain-English statement of business impact, reproduction steps detailed enough for your engineers to confirm each issue independently, evidence in the form of screenshots or request captures, and remediation guidance specific to your technology stack rather than generic advice. It should also state clearly what was tested, what was excluded and why. Ask every provider for a redacted sample before you buy — the difference between a good report and a scanner export with a logo on it is immediately visible, and it discriminates between providers far better than price does.

Pin down your number before you go to market

Most of the variance in penetration testing cost UK buyers experience comes from scope definition rather than from provider pricing, which means the work that reduces the bill happens before the first quote arrives. Cloudswitched will run that groundwork with you — asset discovery, scope definition against your actual compliance driver, and a quote broken down into days — so the number you take to your board is one you can defend.

Scope your penetration test properly

Bring us your client questionnaire, your asset list or just your budget line, and we will tell you what a credible test of your estate involves.

Talk to a Penetration Testing Specialist
Tags:Penetration Testing
CloudSwitched

London-based managed IT services provider offering support, cloud solutions and cybersecurity for SMEs.

CloudSwitched Service

Penetration Testing

CREST-accredited and standard pen tests — infrastructure, web app, cloud and Microsoft 365

Learn More
CloudSwitchedPenetration Testing
Explore Service

Technology Stack

Powered by industry-leading technologies including SolarWinds, Cloudflare, BitDefender, AWS, Microsoft Azure, and Cisco Meraki to deliver secure, scalable, and reliable IT solutions.

SolarWinds
Cloudflare
BitDefender
AWS
Hono
Opus
Office 365
Microsoft
Cisco Meraki
Microsoft Azure

Latest Articles

28
  • Azure Cloud

Azure Disaster Recovery: A UK Business Guide to Building a Tested Failover Plan for Cloud Servers in 2026

28 Aug, 2026

Azure disaster recovery is the discipline that decides whether a ransomware detonation, a failed storage migration or a regional service degradation costs your...

Read more
27
  • Cloud Email

Email Security in Microsoft 365: A UK Business Guide to Stopping Phishing, Spoofing and Business Email Compromise in 2026

27 Aug, 2026

Microsoft 365 email security is the set of tenant configuration decisions, domain authentication records and human controls that determine whether a fraudulent...

Read more
26
  • Penetration Testing

CREST vs Standard Penetration Testing: Which Does Your Business Need?

26 Aug, 2026

CREST penetration testing is not a different kind of hacking. It is the same technical work wrapped in an independently audited assurance layer a layer that...

Read more

Enquiry Received!

Thank you for getting in touch. A member of our team will review your enquiry and get back to you within 24 hours.