Penetration testing cost calculator
Get a realistic ballpark for what a penetration test should cost in the UK before you talk to a firm. Choose the type of test, its scope, your organisation size and any compliance driver, and you will get an honest £ range with the assumptions behind it. Everything runs in your browser — nothing you enter leaves this page.
Describe the engagement
Pick what best matches your test. The estimate updates as you go — nothing is sent anywhere.
What drives the cost of a penetration test
Pentest pricing looks opaque from the outside, but it comes down to a small number of factors. Understanding them helps you read a quote and spot when one firm has scoped the work differently from another.
Type of test
A short external network scan and a full red team engagement are worlds apart in effort. Web apps, APIs, mobile apps, internal networks, cloud reviews and adversary simulations each have their own typical length.
Scope and complexity
The number of hosts, applications, user roles, endpoints and integrations drives the day count more than anything else. A single brochure site is a couple of days; a multi-role platform with third-party integrations is a week or more.
Day rate and seniority
UK testers are typically charged out at around £600–£1,200 a day. CREST-accredited consultancies and senior specialists sit at the higher end; smaller or newer firms can be lower.
Compliance and reporting
A test tied to PCI DSS, ISO 27001, SOC 2 or Cyber Essentials Plus usually needs a more formal report and evidence pack, which adds time on top of the hands-on testing.
Retesting and remediation checks
Many firms include a retest to confirm fixes, and some charge for it separately. It is worth asking what is included when you compare quotes.
Typical UK day rates and engagement lengths
The calculator uses a UK day rate of roughly £600–£1,200 and the engagement lengths below. These are market ballparks reported across UK buyer guides and CREST-accredited consultancies, not fixed prices — treat every figure as indicative.
| Test type | Typical length |
|---|---|
| Web application | 2–12 days |
| External network | 2–10 days |
| Internal network | 3–15 days |
| Mobile application | 3–12 days |
| API | 2–11 days |
| Cloud configuration review | 2–10 days |
| Wireless | 2–8 days |
| Red team | 8–30 days |
| Social engineering | 2–12 days |
Ranges span small to large scope. Compliance-driven engagements add roughly 0.5–2 days of reporting and evidence work.
Penetration testing cost questions, answered
How much does a penetration test cost in the UK?
Most UK penetration tests fall somewhere between roughly £2,000 and £15,000, but the range is wide because it depends entirely on the type of test and the scope. A small web application test might be £2,000–£4,000, while a large internal network test or a red team engagement can run well into five figures. The calculator above gives a ballpark based on the choices you make; a real quote always depends on the specifics.
How is the estimate calculated?
It multiplies a typical UK day rate (around £600–£1,200 per day) by an estimated number of testing days for the type and scope you choose, then adds a little for organisation size and any compliance-driven reporting. The result is shown as a deliberately wide range because real engagements vary. It is an indicative ballpark, not a quote.
Why is the range so wide?
Because honest cost estimates for testing are wide. Two engagements described the same way can differ by several days once a firm sees the real scope. Rather than give you false precision, the calculator shows the plausible low and high ends so you know what to expect before you talk to a firm.
What makes a penetration test more expensive?
Effort is the main driver: more hosts, more applications, more user roles and more integrations all mean more days. Beyond that, higher-seniority or CREST-accredited testers charge more, and compliance-driven tests (PCI DSS, ISO 27001, SOC 2) add reporting overhead. Red team and social engineering engagements are typically the most expensive because they run over weeks.
Is a cheaper penetration test worse?
Not necessarily, but be careful what you are comparing. A low price can mean a smaller scope, fewer testing days, a more junior tester, or an automated scan dressed up as a manual test. When you compare quotes, look at the number of days, the seniority and accreditation of the testers, and whether a retest is included — not just the headline figure.
Ready to get real quotes?
A ballpark tells you what to expect. A quote tells you what it will actually cost. Compare independent, accreditation-verified UK penetration testing companies in our directory and request quotes directly — sourced from public records, never pay-to-play.
Compare firms & request quotes