CREST · UK · TRANSPARENT

UK Penetration Testing Prices · 2026

Pen testing prices have been kept vague for too long. Here is exactly what we charge, what the UK market typically charges, and what determines the final number for every type of test in 2026.

How Pricing Scales
3 Tiers
01
Small
from £3k
03
Enterprise
from £15k

Tier sized at the scoping call. Most teams land in Standard.

Free retests Fixed price No callouts
Independently Accredited · Verifiable
FLAT VIEW · ALL SERVICES · SCANNABLE

UK pen testing prices, side by side.

Starting price = entry tier. Typical = the tier most clients commission for that service. Click any service name to jump to the full tier card with scope details.

Service Starting Typical Duration Best For Action
Web Application £5,000 £8,000–£18,000 6–12 days SaaS, customer portals, e-commerce Quote →
Mobile Application £4,500 £7,500–£14,000 5–10 days iOS / Android with API backends Quote →
API Penetration £4,000 £7,000–£12,000 4–9 days REST / GraphQL / partner-facing APIs Quote →
AWS Cloud Security £4,500 £8,000–£14,000 4–5 days AWS-hosted production estates Quote →
External Infrastructure £3,500 £6,500–£12,000 3–5 days Internet-facing perimeter Quote →
VAPT (Vuln + Pen) £4,000 £7,000–£12,000 3–5 days Compliance baseline (ISO / PCI / SOC 2) Quote →
Red Teaming (focused) £15,000 £15,000–£35,000 2–3 weeks Realistic adversary simulation Quote →
Phishing / Social Eng. £3,000 £6,000–£15,000 7–10 days Awareness + control efficacy Quote →
Secure Code Review £3,500 £7,000–£12,000 4–7 days Pre-release validation Quote →
AI / LLM Pen Test £6,000 £6,000–£12,000 5–7 days LLM apps, RAG pipelines, agents Quote →
Cyber Essentials Plus £1,200 £1,200–£3,500 5–15 days CE+ certification (by org size) Quote →
Cyber Essentials (basic) £300 £300–£600 1–2 weeks Self-assessment + IASME certificate Quote →
PEN TESTING PRICES AT A GLANCE

The fast answer to “how much does a UK pen test cost?”

Four scannable facts you can take to a budget meeting today. Detail and per-service tiers follow below.

01 · UK MARKET RANGE
£4,000 (small SMB scope) to £75,000+ (full red team).

A standard web application pen test sits around £8,000 to £18,000. Network and API tests run lower, red team and continuous programmes run higher.

02 · WHAT IS INCLUDED FREE
Retest, rescheduling, attestation. Always.

Every engagement includes one free retest of fixed findings, free rescheduling around release windows, no callout or cancellation fees, plain-English reporting, and a signed letter of attestation.

03 · FIXED-PRICE GUARANTEE
One scope, one number, no follow-up invoices.

We scope your engagement, send a single fixed-price quote within 24 hours, and we hold to it. No “additional day” surprises once the statement of work is signed.

04 · WHAT DRIVES THE NUMBER
Scope, depth, urgency, reporting needs.

Final price is set by the size of what is tested, the depth of the test (black box vs grey box vs white box), the lead time you need, and whether the deliverable must be auditor-grade.

DAY-RATE DISCLOSURE · FOR TRANSPARENCY

What our consultants cost per day.

Our CREST-registered consultants are priced at a fair-market £1,100 to £1,400 per day, scaled by the rarity of the engagement. We do not bill day rates to clients. The numbers across this page are scope-based fixed prices, and once we have signed the statement of work, that number does not move. This day-rate disclosure is here so you can sanity-check our quotes against the broader UK CREST market and confirm we are neither over-charging nor cutting corners.

ALWAYS · ON EVERY TIER · NO EXCEPTIONS

Six things that never change.

Whatever tier you commission, small, standard, or enterprise, these come with it. Bundled into the fixed price, not bolted on.

01

Free retests

Re-test until every finding is closed. No extra fee, no time limit.

02

Free rescheduling

Move the engagement, before or after kick-off. No penalty fees, no minimum notice period.

03

No cancellation fees

Cancel for any reason, at any stage. We don’t bill for engagements that don’t run.

04

CREST certified

Every consultant CREST-registered. EJN Labs is a verified Member firm.

05

Live findings

Critical issues land in your client portal the moment we exploit them.

06

Letter of attestation

Signed proof of testing, accepted by auditors, regulators, and insurers.

01

Application Penetration Testing

Manual exploitation of web, mobile, API, and desktop applications. OWASP-led methodology, CREST consultants, fixed-price after scoping.

Web Application Penetration Testing

OWASP Top 10 + ASVS, manual exploitation, business-logic flaws, authorisation matrix testing.

Indicative ranges
Small / SMB
£5,000–£8,000
Single role, basic CRUD or marketing app · 5-day engagement
Enterprise
£18,000–£35,000
Multi-tenant, complex auth, integration-heavy · 15–20 day engagement

Mobile Application Penetration Testing

iOS + Android against OWASP MASVS. Static + dynamic analysis, runtime instrumentation, jailbreak/root detection bypass.

Indicative ranges
Small / SMB
£4,500–£7,500
Single platform, basic auth, lightweight client · 5-day engagement
Enterprise
£14,000+
Complex logic, MASVS L2, banking-grade · 12–15 day engagement

API Penetration Testing

OWASP API Top 10. REST + GraphQL + gRPC, schema-aware testing, fintech and multi-tenant focus.

Indicative ranges
Growth / Mid-Market
£7,000–£12,000
REST + GraphQL, 25–100 endpoints, OAuth flows · 6–9 day engagement
Enterprise
£12,000+
Microservice mesh, 100+ endpoints, regulated · 10–15 day engagement

Thick Client / Desktop Application Testing

Windows, macOS, Linux native applications. IPC interfaces, binary protocol analysis, deserialisation attacks.

Indicative ranges
Growth
£9,000–£18,000
Multi-platform, custom protocols, multiple IPC · 8–12 day engagement
Enterprise
£18,000+
Win + macOS + Linux, custom binary protocols · 14–18 day engagement
02

Cloud Security Reviews

Configuration review and exploitation testing of AWS, Azure, and Google Cloud environments. CIS Benchmark + provider Well-Architected aligned.

AWS Cloud Security Review

IAM, S3, EKS, Lambda, Organizations, landing zone, multi-region data perimeter, CIS AWS Benchmark.

Indicative ranges
Growth / Mid-Market
£8,000–£14,000
3–10 accounts, EKS / Lambda, CI/CD · 4–5 day engagement
Enterprise
£14,000–£22,000
10+ accounts, multi-region, landing zone · 5–8 day engagement

Azure Cloud Security Review

Entra ID, AKS, Functions, multi-subscription tenants, hybrid AD, CIS Azure Benchmark.

Indicative ranges
Growth / Mid-Market
£8,000–£14,000
3–10 subscriptions, AKS / Functions, hybrid AD · 4–5 day engagement
Enterprise
£14,000–£22,000
Enterprise tenant, multi-region, AKS + MS Purview · 5–8 day engagement

GCP Cloud Security Review

GKE, Cloud Functions, Resource Manager, VPC Service Controls, multi-project Organisation, CIS GCP Benchmark.

Indicative ranges
Growth / Mid-Market
£8,000–£14,000
3–10 projects, GKE / Cloud Functions, CI/CD · 4–5 day engagement
Enterprise
£14,000–£22,000
10+ projects, GKE Autopilot, VPC Service Controls · 5–8 day engagement
03

Network & Infrastructure

External attack surface, internal network testing, vulnerability assessment combined with manual exploitation, social engineering campaigns.

External Infrastructure Pen Testing

OSINT-led external attack surface review. Public IPs, VPN / RDP / SaaS exposure, edge of cloud, regulated workloads.

Indicative ranges
Growth / Mid-Market
£6,500–£12,000
60–100 IPs, multi-subnet, cloud edge · 3–5 day engagement
Enterprise
£12,000–£22,000
100–200 IPs, hybrid cloud, multi-region · 5–10 day engagement

VAPT: Vulnerability Assessment + Pen Test

Combined automated vulnerability scanning and manual exploitation across infrastructure, web, and AD. ISO 27001 + PCI-DSS aligned.

Indicative ranges
Mid-Market
£7,000–£12,000
200–500 IPs, multi-app · 3–5 day engagement
Enterprise
£12,000–£22,000
500–1,000 IPs, AD + cloud · 5–10 day engagement

Phishing & Social Engineering Assessments

Email, vishing, smishing, OAuth phishing, MFA fatigue, AitM, BEC, physical pretext. SOC coordination throughout.

Indicative ranges
Multi-Channel
£6,000–£15,000
Email + vishing + smishing + OAuth, ≤500 targets · ~7–10 days of work, delivered over 3–5 weeks
Enterprise / Red-Team Adjunct
£15,000+
All channels + physical pretext, BEC, supply-chain · 12+ days of work, multi-week cycle, integrated with red team or DORA TLPT
04

Adversary Simulation

Goal-driven red teaming and detection-engineering purple teaming. STAR / TIBER-UK structured delivery available for regulated firms.

Red Teaming

End-to-end adversary simulation: phishing, initial access, lateral movement, exfiltration. MITRE ATT&CK-aligned.

Indicative ranges
Focused
£15,000–£35,000
1–2 attack vectors · 2–3 week engagement
STAR / TIBER-UK
£75,000+
Threat-intel-led, regulator-structured · 5–6 week engagement

Purple Teaming

Collaborative attack-and-detect cycle to harden your SIEM rules, EDR coverage, and SOC playbooks. Atomic Red Team + Sigma rules.

Indicative ranges
Full Coverage
£20,000–£40,000
Full MITRE ATT&CK coverage · 3–4 week engagement
Continuous Programme
£40,000+
Quarterly 1-week sprints, year-round detection-engineering
05

Audit, AI & Speciality Testing

Secure code review, AI / LLM red-teaming, smart-contract audit. Specialist consultants for each discipline.

Secure Code Review

Manual line-by-line review + SAST. Java, Python, JavaScript / TypeScript, Go, Ruby. OWASP ASVS-mapped findings.

Indicative ranges
Application
£7,000–£12,000
2,000–4,000 LOC, 1–2 languages · 4–7 day engagement
Enterprise / Microservice
£12,000–£20,000
4,000–5,000+ LOC, polyglot, ASVS L3 · 7–14 day engagement

AI / LLM Penetration Testing

OWASP LLM Top 10. Prompt injection, jailbreaks, RAG poisoning, agent tool abuse, model exfiltration, multi-tenant data leaks.

Indicative ranges
Agent System
£12,000–£25,000
Multi-tool agent, complex RAG, fine-tuned model · 8–12 day engagement
Enterprise AI
£25,000+
Production AI platform, multi-agent, regulated use case

Blockchain & Smart Contract Audit

Solidity, Vyper, Rust (Solana). Manual review + Slither / Mythril / Echidna. DeFi mechanics, oracle integrations, governance systems.

Indicative ranges
DeFi / Integration
£20,000–£50,000
DeFi protocol with oracle integration, AMM, lending, governance · 2–3 week audit
Enterprise
£50,000+
Layer-1 / Layer-2 protocol, cross-chain bridges, novel cryptography · 4+ week audit
06

Continuous Monitoring · Monthly Pricing

Always-on services billed monthly. Annual contracts with monthly billing. A one-off setup fee covers asset baseline and sector profiling.

Attack Surface Monitoring

Continuous external attack surface discovery, exposed-service alerting, credential breach monitoring, M&A target discovery.

Service detail

Pricing scoped per engagement

Continuous monitoring is bespoke to your environment, alert volume, integration depth, and reporting cadence. We don’t publish indicative ranges because every engagement is genuinely tailored.

Get my fixed quote in 24h →

Threat Intelligence

Dark-web monitoring, ransomware leak-site monitoring, executive credential monitoring, sector threat-actor reports.

Service detail

Pricing scoped per engagement

Threat intelligence is scoped to your sector, threat-actor focus, monitoring breadth, and alert SLA. We don’t publish indicative ranges because every engagement is genuinely tailored.

Get my fixed quote in 24h →
07

Programmes & Compliance Certification

Bug bounty programme management and government-recognised compliance certifications. We are an active IASME Cyber Essentials Certifying Body.

Cyber Essentials & CE Plus Certification

IASME-accredited Certifying Body. Self-assessment, CE+ technical test, IASME Cyber Assurance. Pre-audit gap analysis included.

Indicative ranges
CE Self-Assessment
£300–£600
IASME-issued certificate, gap review · 1–2 week turnaround
IASME Cyber Assurance
£3,500+
Higher-tier IASME accreditation for orgs needing more than CE+

Bug Bounty Programme Management

Programme design, scoping, triage, payout management on HackerOne / Bugcrowd / Intigriti or private VDP. Pre-bounty hardening assessments.

Indicative ranges
Annual SaaS Programme
£30k–£150k / year
Typical SaaS bounty pool + triage / programme management
Annual Fintech Programme
£100k–£500k / year
Higher-stakes scope, larger pool, regulated-sector triage

Pre-bounty hardening assessment (5–10 day pen test before launch) reduces payouts by 30–50% across the first 12 months.

08

Pen testing for compliance.

Auditors and compliance frameworks have specific requirements for what a pen test must cover. We scope every engagement so the deliverable is auditor-acceptable on the first pass. ISO 27001, PCI DSS, SOC 2, and Cyber Essentials all have their own evidence bar. Below is what we charge against each.

ISO 27001 Penetration Testing

Annual penetration test of in-scope systems with evidence of remediation tracking. Methodology aligned to OWASP, PTES, and your ISO 27001 control set. Auditor-grade report and signed attestation included.

Get a quote
Small / SMB
£5,000–£8,000
Single in-scope system, basic auth, limited integrations
Standard
£8,000–£18,000
Multi-role SaaS or core application, payment or PII handling, multi-environment
Enterprise
£18,000–£35,000
Multi-tenant, complex auth, full ISMS-scoped estate

PCI DSS Penetration Testing

Segmentation testing, CDE-scoped network and application test, post-change retest, methodology stated in the report. Aligned to PCI DSS v4.0 requirement 11.4. QSA-ready deliverable.

Get a quote
Small / SMB
£5,000–£8,000
Limited CDE, single segmentation boundary, lightweight payment flow
Standard
£8,000–£18,000
Defined CDE with multiple segmentation points, web + API in scope
Enterprise
£18,000–£35,000
Large CDE, multi-channel acquiring, tokenisation gateway, complex flows

SOC 2 Penetration Testing

CC7.1 vulnerability scanning plus annual penetration test. Documented methodology and control-aligned evidence for SOC 2 Type II readiness. Mapped findings to Trust Services Criteria.

Get a quote
Small / SMB
£5,000–£8,000
Single product, limited control set in scope
Standard
£8,000–£18,000
Multi-product or multi-tenant SaaS, common SOC 2 Type II scope
Enterprise
£18,000–£35,000
Multi-product platform, cross-cloud, all five Trust Services Criteria
WORKED EXAMPLE · WHAT YOU ACTUALLY PAY FOR

A SaaS web application pen test, broken down.

Consider a standard SaaS web application with multi-role authentication and payment integration. Here is what the work and the price look like in practice.

  • 8 days of manual testing by a CREST-registered consultant. Authenticated. Business-logic. Multi-role privilege boundaries.
  • 1 day of report writing, triage, and risk-prioritised remediation guidance.
  • Free retest once the fixes ship. One additional day, no charge. Letter of attestation reissued.
  • Free rescheduling if a code freeze or release blocker delays kickoff.
Standard tier · typical
£12,000
Range: £8,000 to £18,000 depending on scope
For comparison, the same scope at a budget firm typically lands at £4,000 to £6,000 but skips authenticated business-logic testing, returns a tool-generated report, and excludes any retest.
What Influences the Final Quote

Four factors influence your final pen test cost. Nothing else.

1

Scope size

Endpoints, IPs, accounts, lines of code, target population. The single biggest driver: more surface area means more days of manual testing.

2

Complexity

Multi-role authorisation matrices, microservice mesh, custom binary protocols, novel cryptography, multi-tenant data perimeters. Adds review depth.

3

Regulatory framework

FCA, DORA, NIS2, NHS DSPT, PCI-DSS, SOC 2: each adds structured evidence, mapped controls, and report formatting. Higher tiers include this.

4

Delivery model

Remote, on-site at HQ, distributed across regions, integrated with red team or TIBER-UK cycle. London / Canary Wharf on-site available within next business day.

CHEAP PEN TESTING · WHAT TO WATCH OUT FOR

Why the cheapest quote is often the most expensive one.

Pen testing has a wide price floor because the work itself can be done well or badly with almost no visible difference at the moment of delivery. A vulnerability scan with a report cover page costs about £400 to produce. A real test of business logic in your application costs about £10,000. To the untrained eye, both deliver a PDF.

A 2024 TechUK industry survey found 37% of UK businesses that chose budget penetration testing later discovered serious unreported vulnerabilities. Common shortcuts at the budget end of the market include:

A pen test is a piece of evidence you take to a board, an auditor, an enterprise customer, or an insurer. The cost of getting it wrong is paying twice: once for the cheap test, once for a real one when the cheap one fails to satisfy whoever asked for it.

WHAT HAPPENS AFTER YOU REQUEST A QUOTE

From scope to kickoff in four steps.

No discovery-call gauntlet, no “we will get back to you within two weeks”. One scoping conversation, a fixed-price proposal in 24 hours, and a date in the diary.

01 · SUBMIT
Tell us what you want tested.

Fill the form or send a one-paragraph email with the asset and any deadline. Two minutes.

02 · SCOPE
30-minute scoping call.

We confirm technical scope, compliance context, and constraints. Booked within one business day.

03 · PROPOSAL
Fixed-price proposal in 24 hours.

One page. One number. One statement of work. No callout fees and no “additional day” caveats.

04 · KICKOFF
Schedule and start.

Once approved we pencil in a start date within 5 to 10 business days. Faster if you need it.

Pricing & Cost FAQ

Honest answers about cost, billing, and what changes the number.

How much does a penetration test cost in the UK?

Indicative UK pen test costs range from £3,000 for a small-scope external infrastructure or phishing engagement, up to £75,000+ for STAR-aligned or TIBER-UK red teaming. Most standard application, API, and cloud security pen tests land in the £6,000–£18,000 range. Every quote is fixed-price after a 30-minute scoping call. Never billed on day rates after kickoff.

Are these prices fixed or do you bill by the day?

Every quote is fixed-price after a free 30-minute scoping call. You’ll never see day rates on an invoice. If we finish faster than expected, the price doesn’t change. If something takes longer because we found more, we absorb it.

What’s included in every engagement?

Every tier (small, standard, enterprise) includes: free retests until issues are resolved, free rescheduling, no callout or out-of-hours fees, no cancellation fees, 24-hour scope-to-active-testing turnaround, live findings delivered to a client portal, executive + technical reports, a 60-minute walkthrough call with the lead consultant, and a letter of attestation for procurement / audit / insurance.

How accurate are these ranges?

Within ±15% for ~80% of engagements. The ranges reflect real 2026 UK pricing data across applicable services. Outliers exist: a 500-endpoint API with 6 user roles is going to land at the top of the Standard band or into Enterprise; a 10-endpoint internal-only tool may land below Small. The 30-minute scoping call resolves this in one conversation.

What’s not included that I should budget for?

The price quoted is the price you pay. There are no third-party costs we hide. We own the tooling (Burp Suite Pro, Nessus, Tenable, etc.) and pass nothing through. The only things outside scope are: (1) remediation work by your developers, (2) third-party retest of vendor-controlled systems if your scope includes them, (3) bounty payouts on bug-bounty programmes (these are not consulting fees).

Do you offer multi-engagement / annual discounts?

Yes. Customers committing to an annual programme (e.g., quarterly application testing, or a year of attack surface monitoring) typically receive 5–10% off list price. Multi-service bundles (web + mobile + API in one engagement) typically see 5–15% off. Public sector framework rates available via Crown Commercial Service.

How quickly can you start?

Scope-to-active-testing within 24 hours for most engagements. Same-week start for standard pen tests. Red team engagements involve a 1–2 week threat-intelligence phase before active operations. London / Canary Wharf on-site engagements available within next business day.

What if my scope doesn’t fit any of these tiers?

Most scopes do, but if yours genuinely doesn’t (extreme scale, novel technology stack, regulator-specific requirements), we’ll quote against the closest tier and explain the delta in the scoping call. Examples: Layer-1 blockchain protocols, novel AI agent architectures, TIBER-UK Threat-Led Penetration Testing, M&A target due diligence.

Are reports accepted by auditors, regulators, and insurers?

Yes. Our reports are submitted directly to FCA, NCSC, NHS DSPT, ICO, ISO 27001 auditors, SOC 2 auditors, and the major cyber-insurance underwriters without translation work. CREST member status, IASME Certifying Body status, ISO 27001 + ISO 9001 certification on file. Verifiable on the public registries.

One quote. One fixed price. No surprises.

We’ll size your engagement and land you in the right tier within one business day, then start within 24 hours of approval.

EXPLORE EVERY SERVICE

20+ CREST-certified testing services in one place

Web, mobile, API, cloud, AI, infrastructure, red team. Pick the test that fits your environment.

Our penetration testing services