Quick reference: penetration testing cost by type
| Test type | Typical cost | Duration |
|---|---|---|
| Web application pentest (single app) | £3,000 – £8,000 | 3–5 days |
| API penetration test | £2,500 – £6,000 | 2–4 days |
| Internal / external infrastructure test | £4,000 – £12,000 | 3–6 days |
| Cloud configuration review (AWS/Azure/GCP) | £3,500 – £9,000 | 3–5 days |
| Social engineering / phishing simulation | £2,000 – £5,000 | 1–2 weeks |
| Full-scope multi-asset engagement | £10,000 – £30,000+ | 2–4 weeks |
These figures assume a manual, human-led test by a UK-based tester. Automated vulnerability scans dressed up as “penetration tests” can undercut this by 70–90%, but they find a fraction of what a real test finds and won’t satisfy most compliance requirements.
What you're actually paying for
A penetration test is a manual, time-boxed simulation of a real attacker, carried out by a human tester who chains weaknesses together the way an attacker would — not a tool that matches version numbers against a CVE database. The deliverable is a report with reproduction steps, business-impact ratings, and remediation guidance, usually followed by a debrief call.
A vulnerability scan is a different, cheaper product: automated, fast, and useful as a first pass, but it won’t catch business-logic flaws, chained exploits, or anything that requires understanding how your specific application actually works. The two get sold under the same name more often than they should.
Cost by testing scope
| Scope | What testers get | Best for |
|---|---|---|
| Black box | No credentials or internal knowledge, external view only | Simulating a real outside attacker; slower to find deep issues |
| Grey box | Standard user credentials, some architecture context | Most engagements — realistic and efficient use of test time |
| White box | Full source code, architecture diagrams, admin access | High-assurance or pre-launch reviews where depth matters most |
Grey box is the default for good reason: black box spends a disproportionate share of the budget on reconnaissance that credentials would have skipped, and white box costs more per day than most businesses need for a routine annual test. Reserve white box for a new product before a major launch or a system holding especially sensitive data.
What actually drives the price
1. Number of assets and attack surface
A single web app with a handful of user roles is a different job from an app with 40 API endpoints, three user tiers, and a payment flow. Scope is usually priced per day, and testers estimate days from the number of pages, endpoints, roles, and integrations — get a rough inventory ready before you ask for a quote.
2. CREST accreditation and tester seniority
CREST-certified consultants in the UK typically charge £800–£1,500 per day; non-accredited testers charge £500–£900. CREST isn’t a legal requirement, but it’s the standard most compliance frameworks and enterprise customers expect to see on the report’s cover page.
3. Compliance framework requirements
PCI DSS, Cyber Essentials Plus, ISO 27001, and SOC 2 each have specific expectations for scope, methodology, and reporting format. A test built to satisfy PCI DSS segmentation requirements, for example, takes longer and costs more than a general security health check covering the same infrastructure.
4. Retesting
Fixing findings and confirming the fix are two different pieces of work. A properly scoped engagement includes one free retest within 30–60 days of the report; if it doesn’t, budget for a second smaller engagement, or negotiate it into the original quote.
Rule of thumb: if a quote is priced per asset rather than per day with a clear day count, ask exactly how many tester-days that translates to. Day count is what actually predicts depth.
How often you actually need one
Minimum testing cadence:
Businesses handling card data, health records, or financial information often test twice a year — once on a fixed annual schedule and once tied to a major release, rather than bundling both into one large test that goes stale the moment the next release ships.
Red flags in penetration testing quotes
Question the quote if it:
Summary
UK penetration testing costs £3,000–£8,000 for a single web app, £2,500–£6,000 for an API, £4,000–£12,000 for infrastructure, £3,500–£9,000 for a cloud configuration review, and £10,000–£30,000+ for a full-scope engagement. Grey box is the right default scope for most businesses, CREST accreditation is worth paying for once compliance or enterprise customers are involved, and a free retest should be part of the original quote, not an upsell.
The lowest-risk way to start is a single, clearly scoped web app or API test with a named CREST-certified tester and a sample report in hand before you sign — that alone filters out most of the quotes that aren’t worth the price.