Penetration testing services

A complete, independent guide to penetration testing in the UK — the main test types and what each covers, what to expect, what it costs, and how to find an accredited firm. Start with a guide, or jump straight to the directory.

Frequently asked

What are the main types of penetration testing?

The common types are network (external and internal), web application, API, mobile application, cloud, and wireless testing, plus red teaming and social engineering. Which you need depends on what you build and run and what you must protect.

Which penetration test do I need?

Start from what you are protecting and why. A public web app points to web-application testing; internet-facing infrastructure points to external network testing; a compliance obligation (PCI, ISO 27001, SOC 2) often dictates the scope. Many organisations combine several.

How do I choose a firm?

Compare firms on relevant accreditation (such as CREST), demonstrable methodology, report quality, and experience with your type of environment and any compliance driver. Our directory lets you filter UK firms by service, accreditation, and size from public records.

Compare UK penetration testing companies

Our independent directory lets you filter firms by service, accreditation, and size — sourced from public records, never pay-to-play.

Browse the directory