Skip to main content
Daniel J Glover
Back to Blog

Penetration testing cost UK guide 2026

9 min read
Article overview
Written by Daniel J Glover

Practical perspective from an IT leader working across operations, security, automation, and change.

Published 23 July 2026

9 minute read with practical, decision-oriented guidance.

Best suited for

Leaders and operators looking for concise, actionable takeaways.

Penetration testing cost UK estimates vary because a test is not a standard product. A small external infrastructure scope may take a few days, while a complex customer application can require several specialists and weeks of work. This guide gives indicative 2026 UK price ranges, explains the main cost drivers and helps SMEs buy enough assurance without paying for unnecessary scope.

The figures below are indicative market observations rather than tariffs or quotes. They are based on published UK provider rate cards and quotes observed in consulting engagements during 2025 and 2026. Providers price differently, and final cost should follow a documented scoping exercise. For test types and the overall process, read my penetration testing guide for UK small businesses.

Indicative penetration testing cost UK ranges

An SME commissioning a professional test in 2026 might encounter these broad ranges. VAT, remediation work and travel may be additional.

Test typeIndicative 2026 UK rangeTypical scope variables
External infrastructure£2,000-£6,000Public IPs, services, cloud assets and complexity
Internal infrastructure£2,500-£7,500Sites, segments, Active Directory and assumed access
Web application£3,000-£15,000+Roles, functions, APIs and integrations
Mobile application£4,000-£15,000+Platforms, APIs, storage and authentication
Cloud attack paths£3,000-£12,000+Accounts, services, identities and permissions
Phishing or social engineering£1,500-£7,500+Staff sample, scenarios, channels and safeguards
RetestIncluded to £2,500+Findings, retest window and reporting

These bands overlap because asset count is a poor proxy for effort. Five similar brochure sites may take less time than one bespoke application with several user roles, payment flows and administrative functions.

Very small quotes are not automatically wrong. A narrow external scope with few services can be assessed efficiently. The warning sign is extensive manual coverage across multiple systems for a price that only supports a short automated scan.

What drives penetration testing prices

Most credible providers estimate tester days after scoping. Understanding what creates those days helps you compare proposals.

Scope and attack surface

For infrastructure testing, providers need IP addresses, domains, sites, network segments, cloud environments and exclusions. For an application, they need functions, APIs, user roles, authentication methods, integrations and technology details.

The quote should state assets and testing perspectives. An unauthenticated test of a public application differs from an assessment using customer, staff and administrator accounts. An internal test starting with ordinary network access differs from one assuming a compromised laptop and valid credentials.

Avoid asking for "everything". Identify systems that process sensitive data, support critical services or face the internet. A risk-led boundary produces a more useful test and defensible budget.

Methodology and depth

Automated tools help discover services and common weaknesses, but manual investigation takes time. It can include validating access controls, testing business logic, chaining findings, escalating privileges and demonstrating realistic impact without harming production.

Ask whether the provider follows a recognised approach such as the OWASP Web Security Testing Guide for applications or an established infrastructure methodology. A named method does not guarantee quality, but makes coverage easier to challenge.

Black-box testing starts with limited knowledge. Grey-box testing supplies accounts or architecture information, allowing deeper investigation. White-box work provides extensive documentation or source access. Grey-box testing often gives SMEs a strong balance between realism and efficient coverage.

CREST, CHECK and tester expertise

Accredited providers and highly qualified testers may charge more because examinations, quality assurance and secure delivery add cost. CREST accreditation can provide confidence in supplier processes and capability. Ask which individual testers will perform the work and which relevant qualifications they hold, rather than relying on a company logo alone.

CHECK is the UK government's scheme for appropriately assessed companies and personnel conducting authorised penetration tests of government and other qualifying public sector systems. It may be required for particular public sector scopes. Most ordinary SMEs do not need a CHECK engagement unless a contract, authority or system classification requires it.

Choose assurance that matches the buyer of the result. A regulated client may require an accredited company and named qualifications. Other SMEs may have more flexibility if the provider demonstrates competence, insurance, references and a sound method.

Environment and operational constraints

Production testing can require cautious techniques, restricted hours, monitoring coordination and stop conditions. Legacy equipment, operational technology and safety-critical systems need careful scoping. These constraints reduce testing speed and can increase price.

Remote testing usually avoids travel, but internal work may require an on-site consultant or securely shipped device. Multiple sites also add coordination.

Reporting and remediation support

A useful report is more than a scanner export. It should explain executive risk, affected assets, evidence, realistic impact, reproduction steps and proportionate remediation. Some engagements include a leadership presentation, developer workshop or technical debrief.

Confirm whether the quote includes:

  • A draft report and factual accuracy review
  • Executive and technical sections
  • Risk ratings with an explained method
  • A debrief for technical owners
  • Advice during remediation
  • A retest and updated closure status

More support costs more, but can reduce internal time spent interpreting findings.

Retesting

Retesting demonstrates whether findings were fixed. Some providers include one retest if remediation is completed within 30, 60 or 90 days. Others charge for time used.

Ask whether it covers all findings or only high-risk items, whether new attack paths are considered and what evidence follows. A closure letter may satisfy a customer, while an updated report may be needed internally. Align the window with realistic remediation capacity.

Reduce cost without reducing value

Cost control should remove wasted tester time, not meaningful coverage.

Define the decision

State whether the result supports customer assurance, a launch, annual risk management, acquisition due diligence or validation after change. This determines the assets, depth, credentials and report format.

If a customer contract names a standard or accreditation, obtain that wording before requesting quotes. Paying for the wrong test and repeating it later is costly.

Improve scope information

Give providers an accurate asset list, simple architecture diagram, application walkthrough and count of roles and endpoints. Disclose hosting, controls, restrictions and known fragile systems. Good information reduces contingency and makes proposals comparable.

Fix known basics first

Apply supported patches, remove abandoned services, enforce multi-factor authentication and resolve obvious scanner findings before specialist testers arrive. Expensive manual time should investigate weaknesses routine administration cannot find.

Do not hide known issues. Share them so the tester can avoid rediscovery or assess whether they combine into a larger attack path.

Test the highest-risk slice

An SME may gain more from testing its customer portal and identity environment thoroughly than spreading budget thinly across every asset. Rotate lower-risk scopes and retest after material changes.

Exposure, data sensitivity, business criticality, recent change and contractual obligations should determine priority.

Prepare access and ownership

Have accounts, approvals, contacts and monitoring arrangements ready. Delays from missing credentials or blocked tester IPs waste booked days. Nominate one technical contact who can resolve access issues.

The testing provider can explain findings, but your team or managed provider should normally own remediation. Independent testing is most valuable when it verifies rather than marks its own corrective work.

Questions to ask providers

Use the same questions for each bidder:

  1. What assets, roles, interfaces and perspectives are included?
  2. How many tester days have you allowed?
  3. How much manual testing goes beyond scanning?
  4. Which methodology will you use and exclude?
  5. Who will test, and what relevant experience and qualifications do they have?
  6. Is the company CREST accredited, and is CHECK required here?
  7. How will you protect credentials, evidence and reports?
  8. What are the stop conditions and incident contacts?
  9. What reporting and remediation support is included?
  10. Is a retest included, for how long, and what evidence follows?
  11. Can you provide a redacted example report?
  12. What professional indemnity and cyber insurance do you hold?

Ask providers to price optional items separately. A leadership presentation or additional role may be valuable, but separating it prevents an unclear bundle distorting comparisons.

When a lower-cost alternative is enough

Penetration testing answers a specific question: can a skilled tester find and demonstrate exploitable weaknesses within an agreed scope and time? It is not always the next best control.

Cyber Essentials

For an SME without a consistent baseline, Cyber Essentials certification may deliver more value first. The NCSC Cyber Essentials scheme covers firewalls, secure configuration, access control, malware protection and security updates. Cyber Essentials Plus adds independent verification.

Choose it for baseline improvement, procurement or recognised certification. It is not a substitute when a customer explicitly requires penetration testing or a bespoke application carries material risk.

Vulnerability scanning

A vulnerability scan is suitable for regular identification of known technical weaknesses. It is cheaper and repeatable, but does not normally test business logic, chained attacks or practical impact with the same depth.

Scanning may suffice when exposure is simple, risk is low and the goal is routine hygiene. Ensure somebody triages results, tracks remediation and confirms high-risk assets are covered.

Configuration or focused review

If concern centres on Microsoft 365, a firewall or cloud permissions, a configuration review may be more direct. Code review, architecture threat modelling or a focused authentication assessment can also answer a specific risk question better than a broad test.

Budget for the outcome

The cheapest quote is poor value if it misses the important system or produces an unusable report. The most expensive proposal is unnecessary if its assurance and presentation exceed your needs.

Compare tester time, method, competence, coverage, reporting and retest terms side by side. Reserve internal time for access, remediation and governance, because the test fee is only part of total cost.

My security consulting services help UK SMEs define proportionate assurance, scope independent testing and turn findings into prioritised action. I work from the East Riding of Yorkshire with organisations that need a commercial view of security investment, not simply another technical report.

Frequently Asked Questions

How much does penetration testing cost in the UK?

For 2026, an SME might see indicative prices from £2,000 to £7,500 for a straightforward infrastructure test and £3,000 to £15,000 or more for a web application test. Scope, complexity, methodology, tester expertise, reporting and retesting all affect the quote. These are market observations, not fixed tariffs, so compare like-for-like scopes.

Is a cheap penetration test worth buying?

A low price can be reasonable for a small, well-defined scope, but ask how much manual testing is included and who will perform it. A vulnerability scan presented as a penetration test offers less assurance because it may not validate exploitability or chained weaknesses. Judge value through methodology, coverage, evidence, reporting and retest terms, not price alone.

Does Cyber Essentials include penetration testing?

No. Cyber Essentials is a baseline certification covering five technical control areas, while Cyber Essentials Plus adds independent verification. Neither is the same as a scoped penetration test in which testers investigate exploitable attack paths. For many SMEs, Cyber Essentials is the right first investment, with penetration testing added when risk, customer requirements or system exposure justify it.

Should retesting be included in a penetration test quote?

Retesting should at least be clearly priced and defined. Some providers include one retest within a fixed period, while others charge by the hour or day. Confirm which findings are eligible, how evidence must be supplied, whether the provider issues an updated report or closure letter, and what happens if remediation misses the agreed window.

Share this post

About the author

DG

Daniel J Glover

IT Leader with experience spanning IT management, compliance, development, automation, AI, and project management. I write about technology, leadership, and building better systems.

Continue exploring

Keep building context around this topic

Jump to closely related posts and topic hubs to deepen understanding and discover connected ideas faster.

Browse all articles

Ready to Improve Your IT Operations?

Book a free 30-minute consultation to discuss your IT challenges. No commitment required — just a focused conversation about where you want to be.

Book a consultation

Get Occasional IT Leadership Insights

IT leadership insights, occasionally. No fluff. Unsubscribe any time.

No spam. Unsubscribe any time.