Processing Public Sector Data? The Pen Test Assurance DPA 2018 Buyers Expect

Processing Public Sector Data? The Pen Test Assurance DPA 2018 Buyers Expect

By EJN Labs · 18 Aug 2026 · 8 min read

The Data Protection Act 2018 does not name penetration testing anywhere in its text. It requires appropriate technical measures and a process for regularly testing their effectiveness. Public sector buyers translate that into a concrete ask: a recent penetration test report from a CREST-accredited firm. Typical DPA 2018 security assurance testing for a supplier runs 4 to 6 days, around £4,400 to £8,400.

What DPA 2018 security assurance means when you supply the public sector

DPA 2018 security assurance is the evidence a supplier produces to show the personal data it processes is protected by appropriate technical and organisational measures. The controllers you sell to, councils, NHS bodies and government departments, may only use processors who can demonstrate that protection.

If your SaaS platform, managed service or agency handles citizen data for a council, an NHS body or a government department, you are almost always a processor under the Data Protection Act 2018 and UK GDPR, which is what puts that demonstration duty on your side of the contract.

That word, demonstrate, is where penetration testing enters the picture. A policy says what you intend to do; a test report shows what an attacker could actually reach. Procurement teams know the difference, which is why questionnaires increasingly ask for test evidence by name rather than a self-declared checklist.

Why public sector buyers ask suppliers for pen test evidence

Buyers ask because their own legal exposure depends on you. Under the DPA 2018 framework, enforced by the Information Commissioner’s Office, a controller remains accountable for personal data even when a processor holds it, so due diligence on suppliers is how a council or department discharges its own duty.

If your platform is breached, the council or department that appointed you answers to the ICO, to affected residents and often to the press.

In practice this surfaces in three places. Procurement questionnaires ask when your last independent security test took place and who performed it. Data processing agreements bind you contractually to maintain appropriate measures and often to test them at a defined frequency. And framework onboarding routinely requests certification evidence such as Cyber Essentials Plus alongside a recent test report. Suppliers who can attach a current report from a CREST-accredited firm move through these gates quickly. Suppliers who cannot get stuck in clarification rounds while a competitor closes the deal.

Honesty matters here. The Data Protection Act 2018 is a mandatory legal framework for every UK organisation processing personal data, but neither the Act nor UK GDPR mandates a penetration test in so many words. Article 32 of UK GDPR requires security appropriate to the risk, including a process for regularly testing and evaluating the effectiveness of your technical measures. How you meet that is risk-based.

For a supplier processing public sector data, the risk calculus points one way. The datasets are sensitive, often covering health, benefits, housing or safeguarding, and the consequences of a breach include ICO enforcement, contract termination and exclusion from future public sector work. ICO guidance on security discusses vulnerability scanning and penetration testing as ways to meet the regular testing expectation, and public sector controllers take the hint. The law does not force you to buy a pen test, but the buyers who hold your revenue have decided it is the evidence they trust.

What public sector buyers expect you to test

Scope should follow where the personal data lives. For most suppliers selling into the public sector, that means four areas.

  • The web application and its APIs, where citizen or staff data is created, read and exported. API penetration testing matters even for suppliers with a thin front end, because integrations with the buyer’s systems usually run over APIs.
  • The cloud environment underneath. Misconfigured storage, over-permissive roles and exposed management interfaces cause a large share of real public sector data incidents. A cloud penetration test reviews the configuration your certifications never look at.
  • The external perimeter: anything internet-facing under your control, from VPN endpoints to admin panels, is what an opportunistic attacker sees first.
  • Authentication and tenant separation. If you serve several public bodies from one platform, buyers will ask directly whether one tenant can reach another’s data.

A sensible first engagement covers the application, its APIs and the cloud configuration that hosts them, because that combination answers the questions a Data Protection Officer or procurement lead will actually ask. Our penetration testing checklist walks through how to prepare before testers arrive.

How a DPA 2018 assurance engagement runs

Engagements run in five steps: scoping, a signed authorisation covering the systems to be tested, a testing window of usually one to two weeks, a report that separates the executive summary from the technical findings, and a free retest of fixed findings so the final document shows closure.

Scoping is a short call mapping where personal data flows through your platform, which environments are in scope and what the report needs to satisfy, whether that is a buyer’s questionnaire or a data processing agreement clause. Testing runs against a staging environment that mirrors production, or against production with agreed safeguards. The executive summary is written for the buyer who will read it, the severity-rated technical findings for the engineers who will fix them.

What it costs and how scope drives the price

Penetration testing is priced by effort in days, driven by the number of applications, API endpoints, user roles and cloud accounts in scope. UK day rates are £1,100 to £1,400, and the ranges below are typical for suppliers processing public sector data.

ScopeTypical effortTypical cost
External perimeter only2 to 4 days£2,200 to £5,600
Web application and APIs4 to 6 days£4,400 to £8,400
Cloud configuration review3 to 5 days£3,300 to £7,000
Application, APIs and cloud combined6 to 9 days£6,600 to £12,600

These are typical UK ranges rather than a quotation. A single-tenant application with two roles sits at the bottom of its band; a multi-tenant platform with complex integrations sits at the top. For a fuller breakdown see our guide to penetration testing costs in the UK, and for an exact figure use the quote form below.

How EJN Labs approaches DPA 2018 assurance for suppliers

EJN Labs is a UK firm delivering CREST-accredited penetration testing with UK-based testers, and we hold Cyber Essentials Plus and ISO 27001 ourselves, so we sit on your side of supplier questionnaires as well as testing against them. When we scope a supplier estate, we start from the data processing agreement and the buyer’s questionnaire rather than a generic test plan: the scope maps to the clause your contract commits you to, and the report is structured so a procurement reviewer can find their answer without reading forty pages of technical detail.

One first-hand pattern from testing multi-tenant platforms that serve public bodies: the finding that matters most is rarely an exotic exploit. It is usually an authorisation gap, one tenant’s identifier accepted in another tenant’s session, or an export endpoint that skips the permission check the UI enforces. We test those boundaries with paired accounts across tenants and roles, because that is the failure a public sector buyer fears most. The same buyer-first logic runs through our work in financial services cyber security: test what the accountable party actually worries about.

Frequently Asked Questions

Does the Data Protection Act 2018 require penetration testing?

No, not explicitly. The DPA 2018 and UK GDPR Article 32(1)(d) require appropriate technical measures and a process for regularly testing their effectiveness, with the method left risk-based. For suppliers processing sensitive public sector data, penetration testing is how that regular testing requirement gets met in practice.

It is the evidence ICO guidance points towards, and the evidence controllers request.

What does a DPA 2018 assurance penetration test cost?

Expect £2,200 to £5,600 for an external perimeter test over 2 to 4 days, £4,400 to £8,400 for a web application and API test over 4 to 6 days, and £6,600 to £12,600 for a combined engagement over 6 to 9 days, at a day rate of £1,100 to £1,400.

A cloud configuration review runs 3 to 5 days at £3,300 to £7,000. Scope drives the exact figure.

What evidence will a public sector buyer actually accept?

Three things: an independent CREST-accredited firm’s report dated within the last twelve months, confirmation that findings were remediated and retested, and certifications such as Cyber Essentials Plus or ISO 27001. An internal scan or a self-assessment in our experience rarely satisfies a procurement reviewer.

The reason internal scans and self-assessments fall short is that they do not demonstrate independence.

How often should a public sector supplier test?

Test annually as a baseline, plus after significant changes such as a new integration with a buyer’s systems, a major release or a cloud migration. An annual cycle keeps your report inside the twelve-month window most questionnaires ask about, avoiding a scramble at renewal.

Many data processing agreements specify the frequency, so check your contracts first.

Our platform runs on a certified cloud provider. Do we still need our own test?

Yes. Your cloud provider’s certifications cover their infrastructure, not your configuration, your application code or your access controls. Under the shared responsibility model, the storage bucket permissions, identity roles and application logic that expose personal data are yours, and they are where most real incidents originate. Buyers understand this distinction and will ask about your layer specifically.

Get the assurance evidence your public sector buyers expect

If a questionnaire, a data processing agreement or an upcoming bid is asking for security testing evidence, we can scope it in one short call. Request a penetration testing quote, tell us which contract the evidence needs to satisfy, and we will come back with a fixed scope and price.

Leave a Reply

Your email address will not be published. Required fields are marked *