Penetration testing cost in the UK

What a penetration test actually costs, what drives the price up or down, and how to compare quotes without getting caught out. Use the free estimator below for a ballpark, then compare real firms in our directory.

Estimate your cost

The calculator below gives an indicative range based on typical UK day rates and engagement lengths. It is a starting point for budgeting, not a quote — real prices depend on the specifics of your scope.

Describe the engagement

Pick what best matches your test. The estimate updates as you go — nothing is sent anywhere.

Type of test
Scopewhat counts as small / medium / large depends on the test
Organisation size
Compliance driveradds reporting overhead

What drives the price

Four things move a penetration testing quote more than anything else:

  • Scope — the number of applications, external IPs, internal hosts, or user roles in the test. This is the dominant factor.
  • Test type — a focused web-app test is quicker than a full internal network assessment or a red-team engagement.
  • Depth — a light, largely automated scan costs far less than a manual, exploitation-led test, and buys far less assurance.
  • Compliance — PCI DSS, ISO 27001, SOC 2, or Cyber Essentials Plus reporting adds documentation time.

How to compare quotes fairly

The most common mistake is comparing prices before comparing scopes. Ask every firm to state, in writing, exactly what is in and out of scope, how many days they have allocated, whether testing is manual or automated, who will do the work and what they are accredited to, and what the deliverable looks like. Two quotes are only comparable once those are equal.

For a test that an auditor or a customer will scrutinise, the firm's accreditation (for example CREST) and the clarity of the final report often matter more than the day rate. A cheap report that fails an audit is the most expensive option of all.

Frequently asked

How much does a penetration test cost in the UK?

Most UK penetration tests are priced on a day rate — commonly around £600 to £1,200 per day depending on the firm, the seniority of the tester, and accreditations such as CREST. A small, focused test might run 2 to 4 days; a large network or red-team engagement can run two to four weeks or more, so real-world costs range from a few thousand pounds to well over £25,000.

Why do quotes vary so much?

The biggest driver is scope — the number of applications, IP ranges, user roles, or endpoints in play — followed by the depth of testing and any compliance reporting required. Two quotes can differ widely simply because they assume different scopes, which is why a clear scope is the single most important thing to agree before comparing prices.

Is the cheapest quote the best value?

Not usually. A very low quote often reflects a lighter, more automated test or a smaller assumed scope. For a test that has to satisfy an auditor or a customer, the accreditation of the firm and the quality of the report matter more than the headline price.

Does compliance make it more expensive?

A little. Frameworks such as PCI DSS, ISO 27001, and SOC 2 add reporting and evidence-mapping work, which typically adds a small amount of time to an engagement. The testing itself is much the same; the overhead is in documenting it to the standard.

Compare UK penetration testing companies

Our independent directory lets you filter firms by service, accreditation, and size — sourced from public records, never pay-to-play.

Browse the directory