Do I Need a Penetration Test?
Someone has asked you for a penetration test: an auditor, a customer, a tender, an insurer or a regulator. Here is what each of them actually requires, in plain English, and what to do next. Written by a CREST-accredited UK testing team.
- Unlimited retesting
- Unlimited pre-retesting
- No hidden fees
“I would highly recommend EJN Labs to any organisation seeking reliable, detailed, and well-managed penetration testing services, particularly for government or enterprise-level projects.”
“There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.”
common reasons UK organisations are asked for a penetration test. Only some of them make it a formal requirement; the rest ask for evidence that a test is the usual way to give.
What a Penetration Test Is, and Why You Were Asked for One
What it is. A penetration test is a controlled, authorised attempt to break into your application, network or cloud the way a real attacker would. A CREST-certified tester works by hand, then gives you a report of what they found, how serious it is and how to fix it. See our simple guide to penetration testing.
What it is not. A vulnerability scan is automated and finds known weaknesses; a penetration test proves which of them an attacker can actually use, and finds the logic flaws a scanner cannot see. Cyber Essentials Plus is an assessor-led audit of your devices and settings, not a penetration test of your application.
Required or expected? Very few rules name a penetration test outright; PCI DSS is the clearest example. Most, including ISO 27001, SOC 2 and UK GDPR, ask you to show that your security controls work, and an independent test is the most common way to show it. The table below says which is which.
What to test. Start from what the person asking needs to see, then test the system they care about: a web application, an API, a mobile app, your network or your cloud. If you know what you built, our application pages show how we test each kind of system.
WHO IS ASKING
Who Asked for the Test, and What They Actually Require
Card Payments: PCI DSS
Required. PCI DSS Requirement 11.4.3 requires external penetration testing at least every 12 months and after significant change, and 11.4.2 the same internally, for systems in your cardholder data environment.
An ISO 27001 Audit
Not required by the standard. Annex A 8.8 asks you to manage technical vulnerabilities once you declare that control applicable, and ISO 27002 guidance for 8.8 lists periodic penetration tests. Auditors commonly look for one.
A SOC 2 Audit
Not required by the criteria. SOC 2 lists penetration testing as one example of an evaluation under CC4.1; in practice auditors commonly expect a recent third-party test.
An NHS Buyer: DTAC or DSPT
Expected. NHS buyers applying DTAC look for an annual external test and a report from the last 12 months; the DSPT’s Guide 9 keeps an annual test. A buyer requirement rather than law.
A Tender or Customer Questionnaire
Whatever the buyer asks for. Read the wording: some ask for Cyber Essentials or Cyber Essentials Plus, some for a recent independent penetration test report, some for both.
A Cyber Insurance Proposal Form
Depends on the policy. Some proposal forms ask whether you test regularly and fix critical findings. Requirements vary by insurer and policy.
UK GDPR and Personal Data
Testing is required, the method is not. Article 32(1)(d) requires a process for regularly testing the effectiveness of your security measures; a penetration test is the most direct evidence.
The FCA or PRA
Not prescribed. The FCA does not require penetration testing, but operational resilience rules ask in-scope firms to test that important business services stay within impact tolerances, and a test informs that work.
WHAT HAPPENS NEXT
From “We Need a Pen Test” to a Report You Can Hand Over
Tell Us Who Asked
Share the requirement, questionnaire or email. We tell you honestly what it needs, and whether it needs a penetration test at all.
Fixed Quote in 24h
A 30-minute scoping call covers the system in question. You get a fixed price, not a day-rate meter, within 24 hours.
Testing
CREST-certified UK testers test by hand, with live findings in your client portal as they go.
Report & Retest
An executive summary and a technical report, a walkthrough call, a free retest of every fix and a letter of attestation for whoever asked.
CREDENTIALS
Verified Accreditations Auditors Accept
Every credential below is independently verifiable. UK procurement teams, FCA supervisors, ISO 27001 / SOC 2 auditors, and cyber insurance underwriters all recognise these standards.
GET YOUR QUOTE
Get a CREST pen test quote in 24 hours
A fixed-price quote back in one business day, from a named CREST assessor. No sales pipeline, no chasing.
- CREST and IASME accredited. Testing your auditors and clients already recognise.
- Fast-track testing within 24 hours where required. Free retest of every fix included.
- Live findings via your client portal, not a four-week PDF.
- Fixed price from £3,500 for a single-role, single-app scope, agreed up front. Most engagements run £5,000 and up. No day-rate surprises.
Under NDA Further named references available on a scoping call.
- We reply within one business day with a fixed-price quote from a named CREST assessor.
- You approve the scope and we book a start date, usually within 24 hours.
- Live findings land in your client portal as we test, with a free retest of every fix.
Get your fixed pen test quote in 24 hours
Quote request received
We will reply within one business day with your fixed-price quote from a named CREST assessor.
Your data stays with us. No newsletter signup.
or book a 20-min scoping call first
We reply within one business day. Your data stays with us. No newsletter signup.
COMPLIANCE READY
What Each Rule Actually Says
Every statement below matches the primary text of the rule. Where a rule does not require a penetration test, we say so.
PCI DSS
Required: Requirement 11.4 internal and external testing at least every 12 months, where card data is in scope.
ISO 27001
Not required. Annex A 8.8 applies once you declare that control applicable.
SOC 2
Not required. Penetration testing is one example of an evaluation under CC4.1.
NHS DTAC
A buyer requirement: an independent test, a report from the last 12 months and an action plan.
UK GDPR
Article 32(1)(d) requires regular testing of your security measures; the method is not named.
Cyber Essentials Plus
An assessor-led audit, not a penetration test. Certified directly by us as an IASME certification body.
PRICING
What a Penetration Test Costs
Pricing depends on what you need tested: the number of applications, roles and integrations, or the size of your network. Every quote is a fixed price, and every figure matches our published pricing page.
Depends on app complexity
Single user role, basic CRUD application, marketing website with auth. Around 5 working days from kickoff to report.
Get a fixed quoteDepends on app complexity
Multi-role SaaS, business application with payment integration. Around 8 to 12 working days from kickoff to report.
Get a fixed quoteDepends on app complexity
Multi-tenant platform, complex authorisation matrix, integration-heavy applications. Around 15 to 20 working days from kickoff to report.
Get a fixed quoteWHY EJN LABS
What You Get From an EJN Labs Penetration Test
Six concrete differentiators competitors don’t all match.
CREST-Certified Testers, Verifiable
Every test by a CREST-certified pen tester (CRT, CCT APP, CCT INF where applicable). Verify our company status at crest-approved.org.
24-Hour Startup, Where Required
From signed scope to active testing in a single business day for incident response, audit deadlines, or regulator-driven timelines.
Live Findings, Not 4-Week PDFs
Critical issues reported during testing through your client portal. Your team remediates while testing continues.
Audit-Ready Reports
Executive summary plus full technical report with CVSS scores and explicit framework mappings (ISO 27001, SOC 2, PCI DSS, FCA SYSC).
Free Retests, Standard
Verify remediation of every finding before close-out. Letter of attestation for audit submission included. Most competitors charge £1,500-£3,000 per retest.
UK-Based CREST Testers
Every engagement performed by vetted, UK-based CREST-certified testers, matched to your needs, security clearance, and compliance scope.
FAQ
Frequently Asked
Is a vulnerability scan the same as a penetration test?
No. A scan is automated and lists known weaknesses. A penetration test is done by hand, proves which weaknesses an attacker can actually use, and finds logic flaws a scanner cannot see. Some requirements, such as PCI DSS, ask for both.
Is Cyber Essentials Plus a penetration test?
No. Cyber Essentials Plus is an assessor-led technical audit of your devices and settings. It does not test your web application or API. If a buyer asks for a penetration test, Cyber Essentials Plus does not replace it. See our Cyber Essentials Plus page.
How often do I need one?
It depends on who asked. PCI DSS says at least every 12 months and after significant change; NHS buyers applying DTAC look for a report from the last 12 months. Most others expect a test each year and after major changes to your system.
What should I test first?
The system the person asking cares about. For a customer or tender that is usually your web application and its API; for PCI DSS it is your cardholder data environment; for an ISO 27001 audit it is the systems in your scope. We help you decide on the scoping call.
How do I choose a penetration testing provider?
Look for CREST accreditation, testers based in the UK, a fixed price agreed before work starts, a free retest, and a sample report you can read before you buy. See our sample report.
What do I need to prepare?
The URLs or systems in scope, test accounts for each user role, any API documentation, and a contact who can answer questions during testing. For production systems we agree limits on anything disruptive.
How much does a penetration test cost?
It depends on scope. Every figure is published on our pricing page, and the quote you receive within 24 hours is a fixed price.
What’s in the report?
Executive summary (board-ready), technical report with CVSS 3.1 scores, reproduction steps, screenshots, specific remediation guidance, and a 60-minute walkthrough call. Letter of attestation issued after free retest.
Do you sign NDAs?
Yes. We sign client-supplied NDAs as standard. Engagement data is protected under our ISO 27001 (BSI-audited) information security management system.
How quickly can you start?
From signed scope to active testing in 24 hours where required. Standard pipeline is 3-5 business days from initial scoping call to test start.
Are your testers UK-based and what certifications do they hold?
Every engagement is performed by vetted UK-based CREST-certified testers matched to your engagement based on security clearance, compliance scope, and sector specialism. Testers hold CREST certifications relevant to their discipline (CRT, CCT APP, CCT INF, CCSAM).
20+ CREST-accredited testing services in one place
Web, mobile, API, cloud, AI, infrastructure, red team. Pick the test that fits your environment.
Not sure what you need? Ask us
Send us the requirement or questionnaire. A CREST-certified pen tester will tell you within one business day what it needs, and give you a fixed price if it needs a test.



