By EJN Labs · 20 Aug 2026 · 8 min read
National Highways does not publish a single universal penetration testing clause. Security requirements are set contract by contract, and tenders for digital, roadside and data-handling work commonly ask for recent independent testing evidence. A pen test report from a CREST-accredited firm, typically £4,400 to £8,400 for a 4 to 6 day engagement, is the strongest answer you can attach to a bid.
Why National Highways security assurance matters when you bid
National Highways security assurance matters at bid stage because supplier systems sit close to critical national infrastructure, and that proximity shapes how procurement teams evaluate bids. For suppliers of software, connected components or data services, it is now part of winning the work, not an afterthought.
National Highways runs England’s motorways and major A roads, and the systems its suppliers build and operate for the strategic road network range from traffic management platforms to roadside telemetry and asset data services.
In practice this shows up as security questionnaires, contractual security schedules and requests for testing evidence during tender evaluation. The suppliers who lose marks are rarely the ones with weak security. They are the ones who cannot prove their security in the format the evaluator wants: a recent, independent, scoped penetration test report with remediation evidence. This post explains what to have ready, how the testing is scoped, and what it costs.
The contractual driver: what National Highways actually asks for
Honesty first: there is no single published National Highways clause that says every supplier must commission a penetration test. Supplier security requirements are contractual and contract-specific. What a bidder faces depends on what the contract touches: a firm supplying roadside technology or a hosted data platform will see far more demanding security schedules than one supplying physical materials with no digital footprint.
Across transport-sector procurement, the pattern of what gets asked for is consistent:
- Evidence of an information security management approach, with ISO 27001 or Cyber Essentials Plus frequently named as a baseline.
- Contract-specific security testing evidence for the systems and services being supplied, which is where an independent penetration test report fits.
- Vulnerability management and patching commitments, with proof that findings from testing were actually remediated.
- Assurance over subcontractors and hosting providers in your own supply chain.
Because the requirement is contractual rather than a fixed national standard, the safest position for a bidder is a report that is recent (inside 12 months), scoped to the systems named in your bid, and produced by an independent UK firm the evaluator will recognise. That is the document this post helps you prepare.
What to test before you tender
Scope the test around what the contract will actually rely on. For most suppliers bidding into National Highways work, that means three layers.
The platform or product you are supplying
For a mobility SaaS provider or a vendor of connected roadside or vehicle components, this is the web application, the device management interface and, critically, the APIs. Machine-to-machine interfaces carry most of the operational data in transport systems and are routinely the weakest link. A dedicated API penetration test covering authentication, authorisation between tenants, and input handling is usually the highest-value single component of the engagement.
Your external perimeter and remote access
Evaluators want to know that the company holding their data cannot be trivially breached from the internet. An external infrastructure penetration test across your public IP ranges, VPN endpoints and exposed services answers that question directly and is the cheapest layer to evidence.
The cloud environment behind the service
Supplier platforms commonly run in AWS or Azure. A cloud penetration test reviews identity and access configuration, storage exposure, network segmentation and secrets handling. Contract security schedules increasingly name cloud configuration review explicitly, so including it pre-empts a follow-up question.
If you are unsure what belongs in scope, our penetration testing checklist walks through the questions to answer before you approach any testing firm.
How an engagement runs, and what the report must contain
A supplier-assurance engagement follows a predictable arc: a short scoping call and form, testing over an agreed window against staging or production with change-freeze safeguards, and findings delivered as they are confirmed rather than only at the end, so critical issues can be fixed while testing continues.
The scoping form gathers URLs, IP ranges, API specifications, cloud account structure and user roles.
For bid purposes, the report itself matters as much as the testing. It needs to work for two audiences at once. The procurement evaluator needs an executive summary stating what was tested, when, by whom, under what methodology, and the overall risk posture in plain English. Your engineers need the technical detail: each finding with evidence, severity, and a specific remediation step. The strongest bids attach a third element: a retest or remediation statement showing that the issues found were closed. A report full of open criticals is worse than no report at all, so leave time between testing and tender submission to remediate and retest.
What it costs and how scope drives the price
UK penetration testing is priced by effort in days. Typical UK day rates run £1,100 to £1,400, and the day count is driven by the size of your estate: number of API endpoints, application roles, external IPs and cloud accounts. Typical ranges for supplier-assurance scopes:
| Scope | Typical effort | Typical UK cost |
|---|---|---|
| External infrastructure only | 3 to 5 days | £3,300 to £7,000 |
| Web application and APIs | 4 to 6 days | £4,400 to £8,400 |
| Cloud configuration review | 4 to 7 days | £4,400 to £9,800 |
| Combined platform, perimeter and cloud | 8 to 12 days | £8,800 to £16,800 |
These are typical UK ranges rather than a price list; the exact figure depends on your estate and comes from a scoping call. For a fuller breakdown of what moves the number, see our guide to penetration testing costs in the UK. If you are comparing firms, our guide to choosing the best UK penetration testing provider covers the accreditation and reporting questions to ask.
How EJN Labs approaches supplier security assurance testing
EJN Labs is a UK firm delivering CREST-accredited penetration testing with UK-based testers, and we hold Cyber Essentials Plus and ISO 27001 ourselves, so we sit on the same side of supplier questionnaires that you do. When we scope a supplier-assurance engagement, we start from the contract, not the network diagram: we ask what systems the bid names, what data the customer will entrust to you, and which interfaces cross the boundary between your platform and theirs. Those boundary-crossing interfaces, typically APIs and data feeds, get the deepest manual testing, because they are what a transport-sector evaluator cares about most.
Every engagement produces a dual-audience report of the kind described above, and we include a free retest of remediated findings so the version you attach to your tender shows issues closed, not just found. Where a bid deadline is fixed, we schedule backwards from it so testing, remediation and retest all land before submission.
Frequently Asked Questions
Does National Highways require suppliers to have a penetration test?
Not universally. Supplier security requirements are set contract by contract, and no single published clause mandates testing for every supplier. Tenders involving digital systems, roadside technology or operational data do commonly request independent security testing evidence as part of the bid.
A recent penetration test report is the clearest way to satisfy that request without delay during evaluation.
What does a penetration test for a National Highways bid cost?
UK day rates typically run £1,100 to £1,400. An external infrastructure test at 3 to 5 days costs £3,300 to £7,000; a web application and API test at 4 to 6 days costs £4,400 to £8,400; a combined platform, perimeter and cloud scope at 8 to 12 days costs £8,800 to £16,800. Exact pricing comes from a scoping call.
How recent does the pen test report need to be?
Within the last 12 months is the general expectation, and sooner if the platform has changed materially since the last test. A report older than a year, or one predating a major release of the system you are bidding with, invites follow-up questions from evaluators.
Annual testing aligned to your release cycle keeps a current report available for every tender.
Should the report cover our whole company or just the supplied system?
Scope the report to what the contract relies on: the platform or product being supplied, the APIs and data feeds that connect to the customer, your external perimeter and the cloud environment hosting the service, rather than your entire company estate.
A tightly scoped report on the relevant systems is more persuasive to an evaluator than a shallow test spread across everything you run.
Do we need a CREST-accredited firm for supplier assurance work?
A CREST-accredited firm is the safest choice. CREST accreditation is the recognised independent benchmark for penetration testing firms in the UK, and naming a CREST-accredited firm in your bid removes a whole category of evaluator doubt about the quality and independence of the testing.
Uncredentialed testing, or self-assessment, is far more likely to trigger clarification questions.
Get your bid-ready pen test report scheduled
If a National Highways tender, or any transport-sector bid, is on your horizon, the time to test is before the security schedule lands on your desk. Tell us what you are bidding to supply and we will scope the engagement backwards from your deadline, with remediation and a free retest built in. Get a CREST penetration testing quote and have the report ready before the evaluator asks for it.




Leave a Reply