Penetration testing cost calculator

Get a realistic ballpark for what a penetration test should cost in the UK before you talk to a firm. Choose the type of test, its scope, your organisation size and any compliance driver, and you will get an honest £ range with the assumptions behind it. Everything runs in your browser — nothing you enter leaves this page.

Describe the engagement

Pick what best matches your test. The estimate updates as you go — nothing is sent anywhere.

Type of test
Scopewhat counts as small / medium / large depends on the test
Organisation size
Compliance driveradds reporting overhead

What drives the cost of a penetration test

Pentest pricing looks opaque from the outside, but it comes down to a small number of factors. Understanding them helps you read a quote and spot when one firm has scoped the work differently from another.

Type of test

A short external network scan and a full red team engagement are worlds apart in effort. Web apps, APIs, mobile apps, internal networks, cloud reviews and adversary simulations each have their own typical length.

Scope and complexity

The number of hosts, applications, user roles, endpoints and integrations drives the day count more than anything else. A single brochure site is a couple of days; a multi-role platform with third-party integrations is a week or more.

Day rate and seniority

UK testers are typically charged out at around £600–£1,200 a day. CREST-accredited consultancies and senior specialists sit at the higher end; smaller or newer firms can be lower.

Compliance and reporting

A test tied to PCI DSS, ISO 27001, SOC 2 or Cyber Essentials Plus usually needs a more formal report and evidence pack, which adds time on top of the hands-on testing.

Retesting and remediation checks

Many firms include a retest to confirm fixes, and some charge for it separately. It is worth asking what is included when you compare quotes.

Typical UK day rates and engagement lengths

The calculator uses a UK day rate of roughly £600–£1,200 and the engagement lengths below. These are market ballparks reported across UK buyer guides and CREST-accredited consultancies, not fixed prices — treat every figure as indicative.

Test typeTypical length
Web application2–12 days
External network2–10 days
Internal network3–15 days
Mobile application3–12 days
API2–11 days
Cloud configuration review2–10 days
Wireless2–8 days
Red team8–30 days
Social engineering2–12 days

Ranges span small to large scope. Compliance-driven engagements add roughly 0.5–2 days of reporting and evidence work.

Penetration testing cost questions, answered

How much does a penetration test cost in the UK?

Most UK penetration tests fall somewhere between roughly £2,000 and £15,000, but the range is wide because it depends entirely on the type of test and the scope. A small web application test might be £2,000–£4,000, while a large internal network test or a red team engagement can run well into five figures. The calculator above gives a ballpark based on the choices you make; a real quote always depends on the specifics.

How is the estimate calculated?

It multiplies a typical UK day rate (around £600–£1,200 per day) by an estimated number of testing days for the type and scope you choose, then adds a little for organisation size and any compliance-driven reporting. The result is shown as a deliberately wide range because real engagements vary. It is an indicative ballpark, not a quote.

Why is the range so wide?

Because honest cost estimates for testing are wide. Two engagements described the same way can differ by several days once a firm sees the real scope. Rather than give you false precision, the calculator shows the plausible low and high ends so you know what to expect before you talk to a firm.

What makes a penetration test more expensive?

Effort is the main driver: more hosts, more applications, more user roles and more integrations all mean more days. Beyond that, higher-seniority or CREST-accredited testers charge more, and compliance-driven tests (PCI DSS, ISO 27001, SOC 2) add reporting overhead. Red team and social engineering engagements are typically the most expensive because they run over weeks.

Is a cheaper penetration test worse?

Not necessarily, but be careful what you are comparing. A low price can mean a smaller scope, fewer testing days, a more junior tester, or an automated scan dressed up as a manual test. When you compare quotes, look at the number of days, the seniority and accreditation of the testers, and whether a retest is included — not just the headline figure.

Ready to get real quotes?

A ballpark tells you what to expect. A quote tells you what it will actually cost. Compare independent, accreditation-verified UK penetration testing companies in our directory and request quotes directly — sourced from public records, never pay-to-play.

Compare firms & request quotes