Supplying Regulated Payment Firms? Where Penetration Testing Sits in FCA Assurance

Supplying Regulated Payment Firms? Where Penetration Testing Sits in FCA Assurance

By EJN Labs · 12 Aug 2026 · 8 min read

If you supply regulated payment or e-money firms, penetration testing will appear in their FCA security assurance requests. Under the FCA’s SYSC rules, those firms remain responsible for operational and security risk across outsourced services, so suppliers are routinely asked for recent, independent test evidence. A CREST-accredited test of a customer-facing supplier estate typically takes 4 to 6 days at £1,100 to £1,400 per day, around £4,400 to £8,400.

Why FCA payment security assurance reaches you as a supplier

FCA payment security assurance reaches suppliers because payment and e-money institutions must manage operational and security risk across the services they rely on. When you sit inside the delivery chain for a regulated payment service, your customer has to evidence that the whole chain is secure, including you.

That is the assurance regime working as designed: you are not authorised by the FCA, yet your customers keep asking for penetration test reports, because the regulator does not accept “our supplier handles that” as an answer, whether the supplier is a fintech vendor, a payment processor or a cloud provider.

In practice, that responsibility flows downhill as contractual security clauses, due diligence questionnaires and annual evidence requests, and the most common technical ask is a recent, independent penetration test of the systems that touch the customer’s payment flows. Suppliers who can produce a credible report from a CREST-accredited firm move through procurement quickly; those who cannot end up on remediation plans, or lose the renewal.

The regulatory driver: what the FCA actually requires

The obligation sits on your customer, not on you. Under the Payment Services Regulations 2017 and the FCA’s rules and guidance for payment and e-money firms, in-scope firms must establish and maintain effective operational and security risk management, report major operational or security incidents to the FCA, and assure the resilience of their important business services. The FCA’s operational resilience framework extends this to services delivered through third parties: a firm cannot outsource an activity and outsource the accountability with it.

It is worth being precise here. The FCA does not publish a clause that orders suppliers to commission penetration tests. Its position is risk-based: regulated firms are expected to test the security of the systems supporting their payment services in proportion to the risk, and to hold assurance over material third parties. Penetration testing is the standard mechanism firms use to discharge that expectation, on their own estate and, through contract, on yours. The driver you feel is contractual, but it is anchored in a regulatory duty your customer cannot waive.

Incident reporting sharpens this further. If a security failure at a supplier disrupts a regulated payment service, the firm may have a reportable incident, and the FCA will ask what assurance it held over that supplier beforehand. A dated or absent penetration test is a difficult answer to give a regulator, which is why evidence requests increasingly specify test recency, independence and accreditation. We cover the wider sector picture in our guide to cyber security for financial services.

What payment firms will ask you to test

Evidence requests usually target the systems that sit in the path of the customer’s payment flows or hold their data. Four areas come up in almost every supplier assurance exercise.

The APIs your customers integrate with

If regulated firms call your APIs to initiate payments, check balances or pull transaction data, those endpoints are the first thing their security teams will ask about. An API penetration test should cover authentication and token handling, object-level authorisation, rate limiting, webhook validation and the business logic of the payment operations themselves, not just the OWASP basics.

Your cloud platform

Payment-adjacent suppliers commonly run on AWS, Azure or GCP. A cloud penetration test examines identity and access management, network segmentation between customer tenants, storage exposure, secrets handling and the blast radius of a compromised workload. Multi-tenant isolation is a specific line of questioning from payment firm security teams, because your other customers’ incidents can become their incidents.

Your external perimeter

An external infrastructure test maps and probes everything you expose to the internet: portals, VPN gateways, mail infrastructure and forgotten staging systems. Payment firms ask for this because perimeter compromise is still the most common route into supplier estates.

Mobile apps, if you ship them

Suppliers providing white-label or companion mobile apps should expect those binaries in scope too, covering local data storage, certificate pinning and the app-to-API channel.

How a supplier assurance engagement runs

A supplier assurance engagement starts by scoping against the customer’s evidence request, not your whole estate. The test is shaped around the specific questions the regulated firm is asking, so the report answers them directly and proportionately rather than covering systems nobody asked about.

In practice, we ask for the customer’s security questionnaire or contractual security schedule, then identify which of your systems their payment flows touch and scope the test around those.

Testing runs against agreed windows, with production-safe rules of engagement for anything carrying live payment traffic. You receive findings as they emerge, so critical issues can be fixed while the test is still running, and a retest of remediated findings produces the clean evidence you actually hand over. Our penetration testing checklist walks through what to have ready before day one.

What it costs and how scope drives the price

Expect UK day rates of £1,100 to £1,400 for CREST-accredited testing, with the total price set by effort. The number of days is driven by the size of the estate in scope: how many API endpoints, how many external hosts, and how many cloud accounts and tenants.

Typical ranges for supplier assurance work look like this.

ScopeTypical effortTypical UK price
External infrastructure test3 to 4 days£3,300 to £5,600
API penetration test4 to 6 days£4,400 to £8,400
Cloud configuration review and penetration test5 to 7 days£5,500 to £9,800
Combined API, cloud and external package6 to 9 days£6,600 to £12,600

These are typical UK ranges rather than quotes; the exact price depends on your scope. For a fuller breakdown of what moves the number, see our guide to penetration testing costs in the UK. A combined package tested annually usually costs less than separate engagements commissioned reactively per customer request.

How EJN Labs approaches testing for payment-chain suppliers

EJN Labs is a CREST-accredited UK penetration testing firm, certified to ISO 27001 and Cyber Essentials Plus, and all testing is delivered by UK-based testers. That matters here because FCA-regulated customers look at the accreditation of the firm behind the report; a CREST penetration test is a format their security teams recognise.

When we scope supplier estates, we start from the payment flow rather than the asset list: we trace how a regulated customer’s transaction moves through your APIs, workloads and third-party dependencies, then test the trust boundaries that flow crosses. On multi-tenant platforms we specifically attempt cross-tenant access with a low-privilege test account, because that is the finding a payment firm’s security team most wants ruled out. Reports are written to be forwarded: your customer’s compliance director should be able to read the summary, see the scope, the methodology, the findings and the retest outcome, and close their assurance item without a follow-up call.

Frequently Asked Questions

Does the FCA require suppliers to carry out penetration testing?

Not directly. The FCA regulates payment and e-money firms, not their suppliers, and publishes no clause ordering suppliers to test. In practice the requirement reaches you anyway, passed down through customer contracts and due diligence, so credible, independent penetration test evidence is still expected.

The mechanism is the regulated firm’s own duties: regulation 98 of the Payment Services Regulations 2017 requires it to establish a framework with appropriate mitigation measures and control mechanisms to manage the operational and security risks relating to the payment services it provides, and outsourcing part of that service does not move the duty, which is what turns your customer’s compliance obligation into your evidence request.

What evidence do regulated payment firms usually accept?

A recent penetration test report from an independent, CREST-accredited firm is the evidence most regulated payment firms accept, provided it covers the systems that touch their payment flows or data. Self-assessments and automated scan exports rarely satisfy an FCA-driven assurance request on their own.

Within the report, security teams look for a clear scope statement, the methodology used, findings with severity ratings, and evidence of remediation or a retest.

How often should a supplier to payment firms get tested?

Test annually, because most regulated customers refresh supplier assurance on a yearly cycle and ask for a report no older than twelve months. Retest sooner after significant changes, such as a new payment API version, a cloud re-architecture or a major release.

The reason changes matter as much as the calendar is assurance weight: a report that predates the current platform tells your customer little about the system they actually depend on.

What does a penetration test for a payment-chain supplier cost?

Expect around £4,400 to £8,400 for an API penetration test, which usually takes 4 to 6 days at CREST-accredited UK day rates of £1,100 to £1,400. A combined API, cloud and external package runs 6 to 9 days, around £6,600 to £12,600.

Scope drives the price in every case, so an exact figure comes from a short scoping call via our quote form.

Can one test satisfy several regulated customers at once?

Yes, one test can usually satisfy several regulated customers at once. If the scope covers your full customer-facing estate, the same report can be shared with each of them, which is far cheaper than commissioning a separate penetration test every time a new assurance request arrives.

Check each customer’s contractual wording first. A few specify their own scope or recency requirements, and it is easier to fold those into one annual engagement than to bolt on extra tests later.

Turn your next assurance request into a closed item

If a regulated payment customer has asked for penetration test evidence, or you want a report ready before the next questionnaire lands, we can scope a test around your APIs, cloud platform and perimeter and deliver a report their security team will accept first time. Get a CREST penetration testing quote and we will come back with a scoped proposal within one working day.

Leave a Reply

Your email address will not be published. Required fields are marked *