By EJN Labs · 30 Jul 2026 · 8 min read
PRA SS2/21 security assurance is the evidence banks and insurers gather to meet the Prudential Regulation Authority’s outsourcing expectations. It does not regulate suppliers directly, but expects firms to secure audit, access and security testing rights through contracts, so vendor reviews demand recent independent penetration test reports. A supplier-ready pack typically rests on an annual CREST test, 4 to 6 days at £1,200 to £1,400 per day, £4,800 to £8,400.
Why PRA SS2/21 security assurance decides whether you win the bank contract
PRA SS2/21 assurance decides the contract because the bank cannot sign you without evidence your service will not undermine its resilience, and the fastest evidence is a penetration test report you already hold. For fintech vendors, cloud providers and payment processors it is the hurdle before signature.
Supervisory Statement 2/21, Outsourcing and third party risk management, is the Prudential Regulation Authority’s rulebook for how the UK banks, building societies and insurers it supervises must manage suppliers, and it is a mandatory expectation for PRA firms in scope.
In practice a vendor review questionnaire lands mid-procurement with a short deadline, asking when your platform was last independently tested, by whom, and what happened to the findings. Suppliers who answer in one email keep the deal moving; suppliers who cannot force the bank’s risk team to escalate, and escalation is where deals stall.
What SS2/21 actually expects, and where penetration testing sits
SS2/21 expects PRA-regulated firms, not their vendors, to carry out proportionate due diligence before contracting, embed rights and obligations in written agreements, and monitor their suppliers throughout the arrangement. It contains no sentence directly ordering suppliers to commission penetration tests.
Honesty matters here: the statement makes those firms responsible for the risks their outsourcing arrangements introduce, with the sharpest expectations reserved for arrangements classed as material.
Penetration testing enters through the contract. SS2/21 expects firms to secure audit and access rights and to address information security in their agreements, which in the real world becomes contract schedules requiring independent security testing of the supplier’s service, evidence on request, and sometimes the right for the firm to commission testing itself. The statement does not name your platform, but the contracts written under it almost always do. For a supplier, the question is never whether testing evidence will be requested, only when.
The three points in a bank vendor review where testing evidence is checked
Across the vendor reviews we support suppliers through, SS2/21-driven scrutiny lands at three predictable points:
- Pre-contract due diligence. The bank’s risk team asks for a penetration test report on the service it will consume, dated within the last 12 months and produced by an independent CREST-accredited firm. For API-first platforms, reviewers increasingly want dedicated API penetration testing rather than a generic web assessment.
- Contract negotiation. The agreement carries clauses on audit and access rights, information security requirements and, for material arrangements, commitments to periodic independent testing with findings remediated to agreed timescales. These are far easier to accept when you already run an annual testing cycle.
- Ongoing monitoring. SS2/21 treats outsourcing risk as a through-life obligation, so expect annual evidence refreshes, retest confirmation for serious findings, and fresh scrutiny after any major release. A stale report at renewal is treated like a missing one.
Two attributes carry as much weight as the report: independence, because self-assessed scans rarely satisfy a bank’s risk team, and hosting-layer coverage. If your service runs on AWS, Azure or GCP, reviewers want the shared-responsibility boundary tested, which is where a cloud penetration test and an external infrastructure penetration test complete the picture. The wider expectations banking buyers bring to security are covered in our guide to cyber security for financial services.
How a bank-ready testing engagement runs
An engagement built to survive an SS2/21 vendor review is shaped for the person who will actually read the report: the bank’s third-party risk analyst.
- Scoping. We map the boundary of the service the bank will consume: the application, its APIs, the hosting environment and the admin planes that could reach the bank’s data. One well-scoped test serves every client review. Scoping is free.
- Testing. UK-based testers work the agreed scope against recognised methodologies, combining automated coverage with manual attack paths such as authentication bypass, cross-tenant authorisation flaws and injection.
- Reporting. You receive a full technical report plus a client-shareable executive summary, so the detailed findings never leave your control.
- Remediation and retest. After fixes, we verify closure and issue a retest letter, the most persuasive document in a vendor review because it proves the loop was closed.
Before test day, our penetration testing checklist walks through the access, credentials and approvals to line up so no testing days are wasted.
What it costs and how scope drives the price
UK penetration testing is priced on effort. Typical day rates run from £1,200 to £1,400, and the day count follows the size and complexity of what the bank consumes: applications, APIs, roles, tenants and the external and cloud footprint. Typical UK ranges:
| Scope | Typical effort | Typical UK cost |
|---|---|---|
| External infrastructure test of the hosting perimeter | 2 to 4 days | £2,400 to £5,600 |
| Web application and API test of the service banks consume | 4 to 6 days | £4,800 to £8,400 |
| Cloud configuration review (AWS, Azure or GCP) | 3 to 5 days | £3,600 to £7,000 |
| Combined annual assurance pack with retest letter | 6 to 10 days | £7,200 to £14,000 |
The application and API test, at £4,800 to £8,400 for a typical platform, is the document most bank reviews ask for first. Rolling the workstreams into one annual engagement is usually cheaper and gives you a single evidence date every review can reference. For what moves the numbers, see our guide to penetration testing cost in the UK, and use the quote form for an exact price.
How EJN Labs approaches PRA SS2/21 supplier assurance
EJN Labs is a UK firm delivering CREST-accredited penetration testing, and we hold Cyber Essentials Plus, ISO 27001 and ISO 9001 ourselves, so we answer the same due diligence questionnaires our clients do. When we scope a supplier estate we start from the reviewer’s question rather than the technology: which systems touch the bank’s data, and where could one client’s data reach another’s. Tenant isolation, API authorisation and cloud identity boundaries get manual attention on every engagement instead of being left to scanners.
All testing is carried out by UK-based testers, reports come with a shareable executive summary as standard, and retest verification is built in rather than sold as an extra. The outcome is a pack you can hand to any PRA-regulated client and expect zero follow-up questions.
Frequently Asked Questions
Does PRA SS2/21 require suppliers to have a penetration test?
Not directly. SS2/21 addresses PRA-regulated firms, not their vendors, and contains no clause ordering suppliers to test. Testing still becomes commercially unavoidable, because the written agreements those firms must put in place almost always require independent penetration test evidence from the supplier.
The statement expects firms to conduct due diligence, secure audit and access rights, and address information security through written agreements, especially for material arrangements, even though it never names your platform.
What does materiality mean under SS2/21 and why does it affect testing?
Materiality means an outsourcing arrangement whose failure could threaten the firm’s safety and soundness, its ability to meet regulatory obligations or its continuity of service. Material arrangements attract the fullest SS2/21 expectations, including deeper due diligence and stronger contractual rights.
If your service is classed as material, expect annual independent testing commitments, retest evidence for serious findings and scrutiny after major releases, rather than a one-off report at onboarding.
How much does penetration testing for a PRA SS2/21 vendor review cost?
Expect £4,800 to £8,400 for a web application and API test of the service banks consume, based on 4 to 6 days at UK day rates of £1,200 to £1,400. An external infrastructure test runs 2 to 4 days, £2,400 to £5,600.
A cloud configuration review takes 3 to 5 days (£3,600 to £7,000), and a combined annual assurance pack 6 to 10 days (£7,200 to £14,000). Exact pricing depends on scope, so request a quote.
What security testing clauses should we expect in a contract with a PRA firm?
Expect audit and access rights, an obligation to maintain defined information security controls, and a commitment to periodic independent security testing, with serious findings remediated to agreed timescales and evidence shared on request. Some agreements also reserve the firm’s right to test the service itself.
That reserved right can cover testing the firm runs directly or testing it commissions. Suppliers already running an annual CREST testing cycle can accept these clauses without taking on new obligations.
Will ISO 27001 or SOC 2 satisfy a bank instead of a penetration test?
Usually not on their own. Certifications show your management system exists and is audited, but they do not prove the specific service the bank consumes resists attack. In our experience vendor reviews ask for both: certification for the management layer and an independent penetration test for the technical layer.
Holding ISO 27001 plus an annual CREST test dated within 12 months answers the security section of most questionnaires without follow-up.
Get bank-ready before the next vendor review lands
Every week spent chasing security evidence is a week your competitor can use to close the deal. Tell us what your banking clients consume and we will scope a CREST assurance pack with a fixed price and a shareable summary built in. Request a penetration testing quote and we will come back with days, cost and the earliest start date.




Leave a Reply