New ICAEW Cyber Guidance: Where Penetration Testing Fits for Accountancy SaaS Platforms

New ICAEW Cyber Guidance: Where Penetration Testing Fits for Accountancy SaaS Platforms

By EJN Labs · 6 Aug 2026 · 8 min read

The ICAEW cyber security guidance does not mandate penetration testing by name. It expects a risk-based approach to technical assurance, and it expects firms to hold their suppliers, including accountancy SaaS platforms, to the same standard. In practice, an annual CREST-accredited penetration test is the clearest evidence a platform can offer. A typical UK platform test runs 5 to 8 days, £5,500 to £11,200.

What the ICAEW cyber guidance says about penetration testing

The ICAEW cyber guidance never mandates a penetration test. It is professional guidance, not legislation, and no clause says a member firm or its software supplier must commission one. What it establishes is an expectation of risk-based technical assurance and proportionate evidence that controls actually work.

Searches for ICAEW cyber penetration testing requirements have grown since the institute refreshed its cyber security and client data guidance, so it is worth being precise, and we will not pretend the guidance asks for more. In practice it means firms should understand where client data lives and assess the threats to it.

That framing matters for two audiences. Accountancy practices are expected to carry out supplier due diligence on the platforms that hold their client records, tax data and working papers. And the SaaS vendors serving those practices increasingly find that “we take security seriously” no longer survives a due diligence questionnaire. The guidance turns technical assurance into a market requirement even though it is not a statutory one. Penetration testing is the most widely recognised form of that assurance, which is why it appears in almost every security schedule that accountancy firms now attach to software contracts.

Why this matters for accountancy SaaS platforms

This matters because an accountancy SaaS platform concentrates exactly the data an attacker wants, and a platform-level breach cascades across hundreds of practices and thousands of end clients at once. Every affected firm then has ICO notification duties under UK GDPR alongside its professional obligations to ICAEW.

The data at stake includes payroll records, bank feeds, VAT and self assessment submissions, company financials and the personal details of every director and employee those firms serve. A single tenant breach at a mid-sized practice is bad enough on its own.

The commercial pressure runs in the same direction. Managing partners, COOs and compliance officers reading the ICAEW guidance are being told, in plain terms, that outsourcing a system does not outsource the responsibility. So they push the question down the supply chain: when was your last independent test, who performed it, and can we see the summary? Platforms that can answer with a recent report from a CREST-accredited firm shorten their sales cycles. Platforms that cannot lose deals they never hear about. We see the same dynamic in adjacent regulated sectors, and our work on penetration testing for law firms and cyber security in financial services shows how quickly professional guidance hardens into contractual demand.

What to test on an accountancy SaaS platform

The ICAEW guidance is deliberately technology-neutral, so scope should follow risk rather than a checklist. For the accountancy platforms we test, four areas carry most of that risk.

The multi-tenant web application

Tenant isolation is the single most important control in an accountancy SaaS product. When we scope these engagements we always provision at least two test tenants, because the highest-impact findings are almost never on the login page: they are authorisation flaws that let one practice’s user read another practice’s client ledger by manipulating an identifier. Role separation inside a tenant matters too, since a bookkeeper’s account should not reach partner-level exports.

APIs and integrations

Modern accountancy platforms are integration hubs: HMRC Making Tax Digital endpoints, Open Banking feeds, Companies House lookups, payroll engines and document portals. Each integration is a trust boundary. Dedicated API penetration testing examines authentication between services, token scope and lifetime, rate limiting and whether the API enforces the same tenant boundaries as the user interface, which it frequently does not.

The cloud estate

Most platforms run on AWS or Azure, and most serious exposures we find there are configuration issues: storage buckets holding client document uploads without proper access controls, over-privileged service roles, or database snapshots reachable from the wrong network segment. A cloud penetration test reviews the account configuration, identity model and network segmentation that the application relies on.

The external perimeter

Admin panels, staging environments, VPN endpoints and forgotten subdomains form the perimeter an opportunistic attacker scans first. External infrastructure testing maps and probes everything the platform exposes to the internet, including the assets the engineering team no longer remembers deploying.

How an engagement runs

An engagement runs in five stages: scoping, scheduling, testing, reporting and a free retest of remediated critical and high findings. Scoping is a short call to map the platform, its tenancy model, integrations and hosting, from which we produce a fixed proposal in days.

Testing is scheduled to avoid your peak periods, usually steering clear of January self assessment season and quarter-end VAT deadlines, and is performed by UK-based testers working under CREST methodology against agreed test tenants rather than live client data wherever possible. The report separates the executive summary, written for the partners and compliance officers who will read it during due diligence, from the technical detail your engineers need to reproduce and fix each finding. Our penetration testing checklist covers how to prepare before day one.

What it costs and how scope drives the price

Penetration testing is priced on effort, with a day rate of £1,100 to £1,400 depending on the engagement. The number of days is driven by the size of the application, the number of API endpoints and integrations, and whether the cloud estate is in scope.

Typical UK ranges for accountancy SaaS platforms look like this.

EngagementTypical effortTypical UK cost
External infrastructure and cloud configuration review4 to 6 days£4,400 to £8,400
Web application and API test of the platform5 to 8 days£5,500 to £11,200
Full platform assessment: application, APIs, cloud and perimeter8 to 12 days£8,800 to £16,800

These are typical ranges rather than quotes; an exact price follows a short scoping call. For a broader view of how UK pricing works across engagement types, see our guide to penetration testing cost in the UK, or go straight to the quote form for a scoped figure.

How EJN Labs approaches ICAEW-aligned testing

EJN Labs is a UK firm delivering CREST-accredited penetration testing, and we hold Cyber Essentials Plus and ISO 27001 ourselves. When we test for the accountancy sector we anchor scope to the risk-based language of the ICAEW guidance: the report maps findings to client data exposure, so a compliance officer or trustee can read it without translation. Because the guidance also covers supplier assurance, we structure reports so a SaaS vendor can share the summary with prospective practices without disclosing exploit detail. All testing is performed by UK-based testers, client data stays in the UK, and we never subcontract engagements internationally. That combination is what turns a technical exercise into evidence that satisfies a due diligence panel.

Frequently Asked Questions

Does the ICAEW cyber guidance require penetration testing?

No. The ICAEW cyber guidance is professional guidance, not legislation, and it does not name penetration testing as a mandatory control anywhere in its text. What it expects instead is a risk-based approach to protecting client data and proportionate evidence that technical controls actually work.

For platforms holding financial data for many practices, an independent penetration test is, in our experience, the most common way to produce that evidence, which is why accountancy firms routinely request one during supplier due diligence.

Who does the ICAEW guidance apply to?

The guidance applies directly to ICAEW member firms and the professionals within them. Indirectly, it reaches every supplier those firms rely on, because it makes clear that responsibility for client data does not transfer when a system is outsourced, so vendors feel its effect through their customers.

Accountancy SaaS vendors, case management providers and document portal suppliers all see this in the security questionnaires and contract schedules their practice customers now issue.

What does penetration testing an accountancy SaaS platform cost?

Between £6,000 and £16,800 for most platforms. A web application and API test runs 5 to 8 days at UK day rates of £1,100 to £1,400, which comes to £5,500 to £11,200, while a full assessment covering the application, APIs, cloud estate and external perimeter typically takes 8 to 12 days.

The 8 to 12 day full assessment comes to £8,800 to £16,800. Scope drives the price, so an exact figure follows a short scoping call via our quote form.

How often should an accountancy platform be tested?

Test annually as a baseline, plus targeted retesting after significant change: a new integration such as an Open Banking feed, a major release of the tenancy or permissions model, or a cloud migration. Annual testing matches what accountancy firms expect to see in due diligence.

Change-driven testing catches the periods when new vulnerabilities are most likely to have been introduced.

What evidence will accountancy firms ask their SaaS suppliers for?

Four things: the date and scope of the last independent penetration test, the accreditation of the firm that performed it, a summary of findings, and confirmation that critical issues were remediated and retested. A report from a CREST-accredited firm, with a shareable executive summary, answers all four.

These requests come through due diligence questionnaires, and certifications such as Cyber Essentials Plus and ISO 27001 are commonly requested alongside the test report.

Turn the ICAEW guidance into a competitive advantage

Whether you run a practice assessing suppliers or a platform answering their questions, an independent test from a CREST-accredited firm is the fastest route to credible evidence. Tell us about your platform and we will return a fixed, scoped proposal. Get a CREST penetration testing quote today.

Leave a Reply

Your email address will not be published. Required fields are marked *