By EJN Labs · 10 Aug 2026 · 8 min read
PECR security assurance is the evidence a SaaS supplier shows clients to prove its marketing, cookie and messaging features are lawful and technically secure. PECR does not mandate penetration testing, but due diligence teams expect independent proof. Suppliers typically commission a four to six day web application and API test, typically £4,400 to £8,400 at UK day rates of £1,100 to £1,400.
What PECR security assurance means for a SaaS supplier
PECR security assurance means the set of documents and test results a SaaS supplier hands over when client due diligence asks how the platform handles electronic marketing, cookies and messaging. It exists because clients carry regulatory risk for how your software behaves on their behalf.
The Privacy and Electronic Communications Regulations (PECR) sit alongside UK GDPR and are enforced by the Information Commissioner’s Office (ICO). The risk lands on your clients whenever your product sends emails or SMS for them, sets cookies, or manages consent data.
A platform that mishandles consent records, leaks a suppression list or lets an attacker fire messages through an exposed API creates an ICO problem for every client using it. Procurement and DPO teams therefore ask suppliers for a PECR evidence pack before signature and at renewal. This post covers what belongs in the pack, where testing fits, and the cost.
Why clients ask SaaS suppliers for PECR evidence
Under PECR the organisation sending the marketing or setting the cookie is usually the one the ICO pursues, with monetary penalties of up to £500,000 for serious breaches of the marketing rules. Your client cannot outsource that liability to you, so due diligence is how they manage the exposure your platform creates.
Three failure modes drive the questions in supplier questionnaires:
- Consent integrity. If consent records can be altered, deleted or fabricated, your client cannot demonstrate a lawful basis for the messages they sent.
- Suppression failures. If unsubscribe requests are lost or bypassed by a replayed API call, your client markets to people who opted out, exactly the behaviour the ICO fines.
- Data exposure. A breach of your contact databases is a personal data breach for every client tenant, with UK GDPR consequences layered on top of the PECR ones.
A supplier that answers these concerns with dated, independent evidence closes due diligence faster than one that answers with policy statements. The evidence pack is a sales asset as much as a compliance one.
The regulatory driver: what PECR actually requires
PECR does not contain a clause that says “carry out a penetration test”. Its rules are about conduct: consent before most electronic marketing, clear information and a genuine choice before non-essential cookies, honouring opt-outs, and identifying the sender. PECR is mandatory wherever those triggering activities apply, which for a marketing, analytics, CRM or messaging SaaS product is essentially always.
Technical testing enters through two routes. First, the conduct rules depend on technical controls working as described: a consent banner that fires tracking cookies before the user chooses is a PECR breach regardless of what the privacy notice says, and only technical inspection finds that. Second, UK GDPR’s security requirements apply to the same processing. A client asking “how do you know your consent and suppression logic cannot be bypassed?” is asking a question only independent testing can answer credibly. Say this plainly in your pack: the test is the evidence that the mandatory conduct rules are actually met by the software, not a legal requirement in itself.
What goes in a PECR evidence pack
Consent and cookie documentation
Start with the paper layer: how your platform captures, stores and timestamps consent; a cookie audit listing every cookie, its purpose and lifetime; and how opt-outs and suppression propagate across integrations. Include screenshots of the consent journey as shipped, because assessors compare them against the live product.
Independent technical testing evidence
This is the part clients weight most heavily: a recent penetration test report, or a summary letter from the testing firm, covering the application and APIs that process consent, contact and message data. API penetration testing matters particularly here, because bulk send, list import and webhook endpoints are where authorisation flaws let one tenant touch another tenant’s contacts. Evidence from a CREST-accredited penetration testing firm carries more weight than internal scanning output, because the assessor can rely on the accreditation rather than auditing your methodology.
Platform and organisational assurance
Round the pack out with your certifications (Cyber Essentials Plus, ISO 27001 where held), a summary of your cloud security testing for the environment hosting client data, breach notification commitments, and remediation evidence showing that findings were fixed and retested. A pack that shows the fix cycle tells a client your assurance is a process, not a one-off purchase. Our penetration testing checklist covers the preparation steps that make this cycle run smoothly.
How a supplier-side engagement runs
A supplier-side engagement starts from the consent journey rather than a URL list: how a contact enters the system, where consent is recorded, how a message is triggered, and how an unsubscribe propagates. That map is what drives the test plan.
The plan covers consent capture endpoints, the preference centre, suppression logic, bulk messaging APIs, tenant isolation, and the scripts your product asks client websites to embed. Testing runs against a staging environment with production-equivalent configuration, using authenticated tenant accounts you provision.
A typical engagement takes one to two weeks: scoping call, testing by UK-based testers, a draft report with severity-rated findings, a wash-up call, and a retest after remediation. You receive a full technical report for your engineers and a client-facing summary letter for due diligence responses, so you never share raw vulnerability detail with every prospect who asks.
What it costs and how scope drives the price
UK penetration testing is priced by tester days, at day rates in the £1,100 to £1,400 range. Days are driven by attack surface: application roles, API endpoints, tenant configurations, and whether the cloud environment is in scope. Typical ranges for a SaaS supplier building a PECR evidence pack:
| Scope | Typical effort | Typical cost |
|---|---|---|
| External infrastructure and perimeter of the platform | 3 to 5 days | £3,300 to £7,000 |
| Web application and API covering consent and messaging flows | 4 to 6 days | £4,400 to £8,400 |
| Application, API and cloud configuration review combined | 6 to 9 days | £6,600 to £12,600 |
These are typical UK ranges rather than a quotation; the exact figure depends on your scope. For a fuller breakdown of what moves the price, see our guide to penetration testing costs in the UK. Most suppliers treat the middle row as the core annual purchase and add the cloud review when a large client demands infrastructure evidence.
How EJN Labs approaches PECR evidence for SaaS platforms
EJN Labs is a CREST-accredited UK penetration testing firm, certified to Cyber Essentials Plus and ISO 27001, with all testing delivered by UK-based testers. For SaaS suppliers we test what a due diligence assessor actually asks about: whether consent state can be tampered with, whether suppression can be bypassed through the API, whether one tenant can reach another’s contact data, and whether your embed scripts behave as your cookie audit says. If you are comparing firms, our guide to the best UK penetration testing provider sets out the questions worth asking any supplier, including us.
Frequently Asked Questions
Does PECR require SaaS suppliers to have a penetration test?
No, PECR does not require SaaS suppliers to have a penetration test. It sets conduct rules on consent, cookies and electronic marketing without naming any testing. Client due diligence teams still treat an independent test as the standard way to evidence that consent and suppression logic cannot be bypassed.
The gap between the rules and the testing is practical: PECR’s conduct rules only hold if your platform’s technical controls work, and UK GDPR security duties apply to the same data.
What does a penetration test for a PECR evidence pack cost?
Expect £4,400 to £8,400 for a web application and API test covering consent and messaging flows, which typically takes 4 to 6 days at UK day rates of £1,100 to £1,400. A perimeter test runs £3,300 to £7,000, and larger combined scopes cost more.
Adding a cloud configuration review takes the combined engagement to £6,600 to £12,600. Exact pricing depends on scope, confirmed via a quote.
What should a PECR evidence pack contain?
Four layers make up a PECR evidence pack: consent and cookie documentation, independent technical testing evidence from a CREST-accredited firm, organisational assurance such as Cyber Essentials Plus or ISO 27001 certificates, and remediation evidence showing findings were fixed and retested.
The documentation layer should include a cookie audit of your product surfaces, and the testing evidence should cover the application and APIs. A client-facing summary letter lets you share proof without exposing raw vulnerability detail.
Who is liable under PECR, the SaaS supplier or the client?
The client is usually liable, because the ICO pursues the organisation instigating the marketing or setting the cookie, which is normally your client rather than you as the SaaS supplier. That is precisely why clients scrutinise suppliers so hard before signing.
A platform fault that sends messages to opted-out contacts or leaks consent records creates regulatory exposure the client cannot pass back to you contractually after the event, so they demand evidence up front.
How often should the testing evidence be refreshed?
Refresh the evidence annually as a baseline, and after significant changes to consent capture, messaging or API functionality. Most due diligence questionnaires ask for a test dated within the last twelve months, so an annual cycle keeps the pack aligned with what client reviewers expect to see.
Some larger clients also specify testing after major releases. Pairing an annual test with retesting of remediated findings keeps the pack current without paying for full-scope testing twice a year.
Turn due diligence questions into a closed deal
If client questionnaires about PECR, cookies or marketing security are slowing your sales cycle, a scoped test from a CREST-accredited UK firm gives you an evidence pack that answers them once and reuses everywhere. Get a penetration testing quote today.




Leave a Reply