Network Penetration Testing Cost: Internal vs External Pricing (UK 2026)

Network Penetration Testing Cost: Internal vs External Pricing (UK 2026)

By EJN Labs · 14 Jun 2026 · 9 min read

Network penetration testing cost in the UK typically runs from £2,400 to £18,000 in 2026, driven by whether the test is external (internet-facing IP ranges and exposed services) or internal (assumed-breach, Active Directory and lateral movement). A small external perimeter is often £2,400 to £4,800, while a multi-subnet internal test commonly reaches £7,200 to £12,000 or more. Scope to the quote form for an exact figure.

Working out a fair network penetration testing cost means separating two very different engagements that buyers often lump together. External and internal network tests probe opposite sides of your perimeter, use different methods, and price on different scope drivers. This guide breaks down internal vs external penetration testing cost so you can budget accurately, brief suppliers properly, and avoid paying for the wrong scope. All figures are typical UK ranges for 2026; your exact price comes from a scoped quote.

External vs internal network testing: what you are actually buying

An external network penetration test assesses everything reachable from the public internet: your live IP ranges, the firewall and perimeter, and any exposed services such as web servers, mail, VPN gateways, remote desktop and management interfaces. The tester works from the position of an unauthenticated attacker on the internet with no prior access. This is the lens covered by our external infrastructure penetration testing service, and it is where most organisations begin.

An internal network penetration test starts from inside the perimeter. The standard approach is assumed breach: we are given a foothold (a network connection, or a low-privileged domain account) and we model what an attacker does next. That means enumerating Active Directory, hunting for privilege-escalation paths, testing lateral movement between hosts, and probing network segmentation to see whether a compromised workstation can reach servers, backups or the domain controller. The two tests answer different questions, so the external penetration testing cost and the internal penetration testing cost are calculated separately.

What drives external penetration testing cost

External infrastructure penetration testing cost is dominated by the size and complexity of your internet-facing footprint. The main drivers are:

  • Number of live IPs and hosts. A handful of public IPs is quick to enumerate; a /24 range or several blocks across multiple sites takes proportionally longer.
  • Exposed services per host. Ten hosts each running a web app, VPN and mail interface is far more work than ten hosts exposing a single port.
  • Cloud-hosted vs on-premise. Public IPs spread across AWS, Azure and on-prem data centres add enumeration and authorisation overhead, and cloud providers require advance notice for some testing.
  • Web applications on the perimeter. A full application test is a separate discipline; a network test fingerprints the service but stops short of deep application logic (see our companion guide on web application penetration testing cost).

A typical small-business external test, with a single site and a modest number of live IPs, is usually a focused 2 to 4 day engagement. Larger perimeters with multiple sites, cloud estates and dozens of exposed services move into the 5 to 10 day band.

What drives internal penetration testing cost

Internal penetration testing cost scales with the size and structure of your internal estate, not your public footprint. The key drivers are:

  • Host and subnet count. More live hosts and more network segments mean more to enumerate, scan and validate.
  • Active Directory complexity. A single domain is straightforward; multiple domains, forests and trust relationships add significant analysis time.
  • Network segmentation. Testing whether segments are genuinely isolated (workstation VLANs from server VLANs, for example) is a deliberate, time-boxed exercise.
  • VPN and remote access. Remote-working and VPN entry points expand the attack surface and often warrant their own validation.
  • Cloud-hosted vs on-prem infrastructure. Hybrid estates with on-prem AD synced to a cloud identity provider need both sides assessed for lateral movement.

Because internal tests follow attack paths rather than a flat host list, they are usually larger than external tests for the same organisation. A single-domain network with a few subnets is typically 4 to 6 days; a multi-domain, multi-site or hybrid-cloud estate frequently runs 8 to 15 days.

Authenticated internal testing: what is in scope

Internal network tests are normally authenticated to some degree. Under the assumed-breach model we request a standard low-privileged domain user account, matching the access a phished employee or compromised contractor would have. From there our testers attempt to escalate to local admin, then to domain admin, demonstrating the realistic blast radius of a single compromised device. Authenticated testing produces far more actionable findings than an unauthenticated scan, because it surfaces the misconfigurations (weak service accounts, excessive privileges, unpatched internal hosts, insecure protocols) that attackers actually exploit once inside. We confirm the exact account level, host list and any out-of-scope systems during scoping so there are no surprises on either side. Full methodology, scoping detail and deliverables are on our internal network penetration testing service page.

Network penetration testing cost table (UK 2026)

The table below maps scope tiers to a typical day-range and a typical price band. Pricing uses a typical UK day rate of around £1,200 to £1,300, all testing is delivered by senior and principal testers, and the price is driven by the complexity of the scope (the number of tester days). The table uses a £1,200 day rate as the baseline. See the full breakdown on the penetration testing cost hub.

Test type and scope Typical day range Typical UK cost (2026)
External, small perimeter (handful of live IPs, single site) 2-4 days £2,400-£4,800
External, medium perimeter (multiple sites or cloud, dozens of services) 4-7 days £4,800-£8,400
External, large perimeter (large IP ranges, hybrid cloud) 7-10 days £8,400-£12,000
Internal, single domain (few subnets, one site) 4-6 days £4,800-£7,200
Internal, multi-subnet (segmentation testing, larger host count) 6-10 days £7,200-£12,000
Internal, multi-domain or hybrid-cloud (forests, trusts, remote access) 10-15 days £12,000-£18,000

These are guide ranges, not fixed quotes. A combined external plus internal engagement is priced as the sum of both scopes, often with a small efficiency saving when run back-to-back. For infrastructure penetration testing cost on bespoke or very large estates, the figure is set entirely by the scoped day count.

How EJN Labs scopes and prices network testing

We price every network test from a short scoping conversation, never a guess. For an external test we ask for your in-scope IP ranges and domains, confirm cloud versus on-prem hosting, and run a light passive footprint review so the day estimate reflects your real attack surface rather than a headcount. For an internal test we ask for approximate host and subnet counts, the number of AD domains, whether segmentation and VPN access are in scope, and the account level you can provide for authenticated testing.

From there our CREST-certified testers translate scope into a day count and return a fixed, itemised quote with no day-rate ambiguity. As a CREST-accredited firm that also holds Cyber Essentials Plus and ISO 27001, we scope to recognised methodologies, so the deliverable stands up to client, insurer and regulator scrutiny. A typical mid-size organisation commissioning both an external perimeter test and a single-domain internal test should budget in the region of £8,400 to £12,000, confirmed against the live scope. For published bands across all test types see our pricing page, and for a tailored figure use the CREST pentesting quote form.

Frequently Asked Questions

How much does network penetration testing cost in the UK?

Network penetration testing costs £2,400 to £18,000 in the UK in 2026. A small external perimeter test is usually £2,400 to £4,800, while a larger internal Active Directory test can reach £12,000 to £18,000 or more, depending on the size and complexity of the estate in scope.

The exact figure depends on your IP ranges, host and subnet counts, and how many Active Directory domains are in scope.

What is the difference between internal and external penetration testing cost?

External penetration testing cost is driven by your internet-facing footprint, while internal penetration testing cost is driven by your internal estate, so the two are calculated as separate scopes. Internal tests are usually larger, and therefore cost more, because they follow lateral-movement attack paths through the network.

For the external scope the drivers are the number of live IPs, exposed services and whether hosts are cloud-hosted or on-premise. For the internal scope they are host and subnet counts, Active Directory complexity, segmentation and remote access.

Is internal network testing authenticated?

Yes, internal network testing is normally authenticated, run under an assumed-breach model. Testers start with a low-privileged domain account, matching what a phished employee would have, and attempt to escalate to domain admin. This approach surfaces far more real findings than an unauthenticated scan of the same network.

The reason is simple: authenticated access reveals the misconfigurations attackers exploit once they are inside the network.

Do I need both an external and an internal test?

Most organisations benefit from both, because they answer different questions. An external test shows what an internet-based attacker can reach, while an internal test shows the damage once an attacker is inside. Compliance frameworks and cyber-insurance applications increasingly expect both tests rather than one alone.

When commissioned together, the combined infrastructure penetration testing cost is the sum of the two scopes, sometimes with a small saving for running them back-to-back.

How long does a network penetration test take?

A network penetration test takes 2 to 4 days for a small external test, 4 to 6 days for a single-domain internal test, and 10 to 15 days for a large multi-domain or hybrid-cloud internal engagement. The day count depends on the size and complexity of the scope.

The day count is also the main driver of cost, so an accurate scope is the fastest route to an accurate price. Our quote form captures the detail needed to set the day range precisely.

How does network testing cost compare to web app or API testing?

Network testing is priced on infrastructure scope, the IPs, hosts and domains in range, whereas web app and API testing is priced on functionality and user roles. A focused web-app or API test often falls in a similar price band to a small network test, but the two assess different layers.

See our guides on API penetration testing cost and how to get an accurate penetration testing quote for the full picture.

Get an exact network penetration testing quote

Every estate is different, so the only way to a precise number is a scoped quote. Tell us your external IP ranges, internal host and subnet counts, and how many Active Directory domains are in play, and our CREST-certified testers will return a fixed, itemised price within one working day. Start with the CREST pentesting quote form, review typical bands on the penetration testing cost hub, or explore our external infrastructure penetration testing service to see what is included.

Leave a Reply

Your email address will not be published. Required fields are marked *