Guide: Do I Need a Pen Test?

Do I Need a Penetration Test?

Someone has asked you for a penetration test: an auditor, a customer, a tender, an insurer or a regulator. Here is what each of them actually requires, in plain English, and what to do next. Written by a CREST-accredited UK testing team.

  • Unlimited retesting
  • Unlimited pre-retesting
  • No hidden fees
Accredited & recognised
Cyber Essentials certified Cyber Essentials Plus certified IASME certifying body ISO 27001 certified ISO 9001 certified Crown Commercial Service supplier UK Cyber Security Council member
CREST
Approved Provider
Fixed
Price Before Work Starts
Free
Retest of Every Fix
24h
Fixed Quote
CLIENT REFERENCE
“I would highly recommend EJN Labs to any organisation seeking reliable, detailed, and well-managed penetration testing services, particularly for government or enterprise-level projects.”
SquareOneImran SaghirProject Lead, SquareOneRead the SquareOne case study →
CLIENT REFERENCE
“There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.”
CelloriDan WilcocksonFounder, CelloriRead the Cellori case study →
See all case studies →
START HERE
8

common reasons UK organisations are asked for a penetration test. Only some of them make it a formal requirement; the rest ask for evidence that a test is the usual way to give.

What a Penetration Test Is, and Why You Were Asked for One

What it is. A penetration test is a controlled, authorised attempt to break into your application, network or cloud the way a real attacker would. A CREST-certified tester works by hand, then gives you a report of what they found, how serious it is and how to fix it. See our simple guide to penetration testing.

What it is not. A vulnerability scan is automated and finds known weaknesses; a penetration test proves which of them an attacker can actually use, and finds the logic flaws a scanner cannot see. Cyber Essentials Plus is an assessor-led audit of your devices and settings, not a penetration test of your application.

Required or expected? Very few rules name a penetration test outright; PCI DSS is the clearest example. Most, including ISO 27001, SOC 2 and UK GDPR, ask you to show that your security controls work, and an independent test is the most common way to show it. The table below says which is which.

What to test. Start from what the person asking needs to see, then test the system they care about: a web application, an API, a mobile app, your network or your cloud. If you know what you built, our application pages show how we test each kind of system.

WHO IS ASKING

Who Asked for the Test, and What They Actually Require

PCI

Card Payments: PCI DSS

Required. PCI DSS Requirement 11.4.3 requires external penetration testing at least every 12 months and after significant change, and 11.4.2 the same internally, for systems in your cardholder data environment.

ISO

An ISO 27001 Audit

Not required by the standard. Annex A 8.8 asks you to manage technical vulnerabilities once you declare that control applicable, and ISO 27002 guidance for 8.8 lists periodic penetration tests. Auditors commonly look for one.

SOC2

A SOC 2 Audit

Not required by the criteria. SOC 2 lists penetration testing as one example of an evaluation under CC4.1; in practice auditors commonly expect a recent third-party test.

NHS

An NHS Buyer: DTAC or DSPT

Expected. NHS buyers applying DTAC look for an annual external test and a report from the last 12 months; the DSPT’s Guide 9 keeps an annual test. A buyer requirement rather than law.

TENDER

A Tender or Customer Questionnaire

Whatever the buyer asks for. Read the wording: some ask for Cyber Essentials or Cyber Essentials Plus, some for a recent independent penetration test report, some for both.

INSURE

A Cyber Insurance Proposal Form

Depends on the policy. Some proposal forms ask whether you test regularly and fix critical findings. Requirements vary by insurer and policy.

GDPR

UK GDPR and Personal Data

Testing is required, the method is not. Article 32(1)(d) requires a process for regularly testing the effectiveness of your security measures; a penetration test is the most direct evidence.

FCA

The FCA or PRA

Not prescribed. The FCA does not require penetration testing, but operational resilience rules ask in-scope firms to test that important business services stay within impact tolerances, and a test informs that work.

WHAT HAPPENS NEXT

From “We Need a Pen Test” to a Report You Can Hand Over

01

Tell Us Who Asked

Share the requirement, questionnaire or email. We tell you honestly what it needs, and whether it needs a penetration test at all.

02

Fixed Quote in 24h

A 30-minute scoping call covers the system in question. You get a fixed price, not a day-rate meter, within 24 hours.

03

Testing

CREST-certified UK testers test by hand, with live findings in your client portal as they go.

04

Report & Retest

An executive summary and a technical report, a walkthrough call, a free retest of every fix and a letter of attestation for whoever asked.

CREDENTIALS

Verified Accreditations Auditors Accept

Every credential below is independently verifiable. UK procurement teams, FCA supervisors, ISO 27001 / SOC 2 auditors, and cyber insurance underwriters all recognise these standards.

GET YOUR QUOTE

Get a CREST pen test quote in 24 hours

A fixed-price quote back in one business day, from a named CREST assessor. No sales pipeline, no chasing.

  • CREST and IASME accredited. Testing your auditors and clients already recognise.
  • Fast-track testing within 24 hours where required. Free retest of every fix included.
  • Live findings via your client portal, not a four-week PDF.
  • Fixed price from £3,500 for a single-role, single-app scope, agreed up front. Most engagements run £5,000 and up. No day-rate surprises.
What clients say
There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.
CelloriDan WilcocksonFounder, Cellori

Under NDA Further named references available on a scoping call.

What happens next
  1. We reply within one business day with a fixed-price quote from a named CREST assessor.
  2. You approve the scope and we book a start date, usually within 24 hours.
  3. Live findings land in your client portal as we test, with a free retest of every fix.
Accredited & recognised
CREST member Cyber Essentials certified Cyber Essentials Plus certified IASME certifying body ISO 27001 certified ISO 9001 certified UK Cyber Security Council Crown Commercial Service supplier

Get your fixed pen test quote in 24 hours

24h reply CREST tester Free retests

or book a 20-min scoping call first

We reply within one business day. Your data stays with us. No newsletter signup.

COMPLIANCE READY

What Each Rule Actually Says

Every statement below matches the primary text of the rule. Where a rule does not require a penetration test, we say so.

PCI DSS

Required: Requirement 11.4 internal and external testing at least every 12 months, where card data is in scope.

ISO 27001

Not required. Annex A 8.8 applies once you declare that control applicable.

SOC 2

Not required. Penetration testing is one example of an evaluation under CC4.1.

NHS DTAC

A buyer requirement: an independent test, a report from the last 12 months and an action plan.

UK GDPR

Article 32(1)(d) requires regular testing of your security measures; the method is not named.

Cyber Essentials Plus

An assessor-led audit, not a penetration test. Certified directly by us as an IASME certification body.

PRICING

What a Penetration Test Costs

Pricing depends on what you need tested: the number of applications, roles and integrations, or the size of your network. Every quote is a fixed price, and every figure matches our published pricing page.

✦ ALWAYS · ON EVERY TIER · NO EXCEPTIONS ✦
Free retests, no time limit
Free rescheduling
No cancellation fees
24-hour scope to active testing
Live findings to client portal
Executive + technical report
60-min walkthrough call
Letter of attestation
STANDARD
£8,000–£18,000
Depends on app complexity

Multi-role SaaS, business application with payment integration. Around 8 to 12 working days from kickoff to report.

Get a fixed quote
ENTERPRISE
£18,000–£35,000
Depends on app complexity

Multi-tenant platform, complex authorisation matrix, integration-heavy applications. Around 15 to 20 working days from kickoff to report.

Get a fixed quote

Full UK pen test cost guide

WHY EJN LABS

What You Get From an EJN Labs Penetration Test

Six concrete differentiators competitors don’t all match.

CREST-Certified Testers, Verifiable

Every test by a CREST-certified pen tester (CRT, CCT APP, CCT INF where applicable). Verify our company status at crest-approved.org.

24-Hour Startup, Where Required

From signed scope to active testing in a single business day for incident response, audit deadlines, or regulator-driven timelines.

Live Findings, Not 4-Week PDFs

Critical issues reported during testing through your client portal. Your team remediates while testing continues.

Audit-Ready Reports

Executive summary plus full technical report with CVSS scores and explicit framework mappings (ISO 27001, SOC 2, PCI DSS, FCA SYSC).

Free Retests, Standard

Verify remediation of every finding before close-out. Letter of attestation for audit submission included. Most competitors charge £1,500-£3,000 per retest.

UK-Based CREST Testers

Every engagement performed by vetted, UK-based CREST-certified testers, matched to your needs, security clearance, and compliance scope.

FAQ

Frequently Asked

Is a vulnerability scan the same as a penetration test?

No. A scan is automated and lists known weaknesses. A penetration test is done by hand, proves which weaknesses an attacker can actually use, and finds logic flaws a scanner cannot see. Some requirements, such as PCI DSS, ask for both.

Is Cyber Essentials Plus a penetration test?

No. Cyber Essentials Plus is an assessor-led technical audit of your devices and settings. It does not test your web application or API. If a buyer asks for a penetration test, Cyber Essentials Plus does not replace it. See our Cyber Essentials Plus page.

How often do I need one?

It depends on who asked. PCI DSS says at least every 12 months and after significant change; NHS buyers applying DTAC look for a report from the last 12 months. Most others expect a test each year and after major changes to your system.

What should I test first?

The system the person asking cares about. For a customer or tender that is usually your web application and its API; for PCI DSS it is your cardholder data environment; for an ISO 27001 audit it is the systems in your scope. We help you decide on the scoping call.

How do I choose a penetration testing provider?

Look for CREST accreditation, testers based in the UK, a fixed price agreed before work starts, a free retest, and a sample report you can read before you buy. See our sample report.

What do I need to prepare?

The URLs or systems in scope, test accounts for each user role, any API documentation, and a contact who can answer questions during testing. For production systems we agree limits on anything disruptive.

How much does a penetration test cost?

It depends on scope. Every figure is published on our pricing page, and the quote you receive within 24 hours is a fixed price.

What’s in the report?

Executive summary (board-ready), technical report with CVSS 3.1 scores, reproduction steps, screenshots, specific remediation guidance, and a 60-minute walkthrough call. Letter of attestation issued after free retest.

Do you sign NDAs?

Yes. We sign client-supplied NDAs as standard. Engagement data is protected under our ISO 27001 (BSI-audited) information security management system.

How quickly can you start?

From signed scope to active testing in 24 hours where required. Standard pipeline is 3-5 business days from initial scoping call to test start.

Are your testers UK-based and what certifications do they hold?

Every engagement is performed by vetted UK-based CREST-certified testers matched to your engagement based on security clearance, compliance scope, and sector specialism. Testers hold CREST certifications relevant to their discipline (CRT, CCT APP, CCT INF, CCSAM).

EXPLORE EVERY SERVICE

20+ CREST-accredited testing services in one place

Web, mobile, API, cloud, AI, infrastructure, red team. Pick the test that fits your environment.

Penetration testing services
READY TO START

Not sure what you need? Ask us

Send us the requirement or questionnaire. A CREST-certified pen tester will tell you within one business day what it needs, and give you a fixed price if it needs a test.