Book a Security Assessment letstalk@networklondon.co.uk · London Bridge
Penetration testing

How much does a penetration test
cost in the UK?

By Cyber Security London · · 2 min read

In short

The cost of a penetration test in the UK depends mainly on how much is being tested and how deeply. Most testers price by the number of tester days a scope needs. A focused test of one web application needs far fewer days than an internal network test across several sites, so always agree scope first, then get a fixed quote.

How is a penetration test priced?

Most UK penetration testing is priced on effort: the number of days a qualified tester needs to cover the agreed scope properly, plus time to write the report. That is why two quotes for “a pen test” can look very different. They are often quoting for different amounts of work.

Ask any provider for a written scope that lists exactly what is included. Comparing quotes without one is comparing guesses.

What affects the price?

FactorPushes the cost upKeeps it down
ScopeMany applications, IP ranges or user rolesOne clearly defined target
Type of testInternal network, cloud and application togetherExternal-only test
ComplexityCustom apps with complex logic and integrationsStandard, well-documented systems
Access levelTesting as several authenticated rolesUnauthenticated testing only
TimingOut-of-hours windows to protect live servicesFlexible testing during the working day
RetestingSeveral rounds of fixes to checkFixes completed in one round

Which type of penetration test do you need?

  • Web application test: for customer portals, online services and APIs.
  • External network test: for anything facing the internet, such as firewalls, VPNs and mail servers.
  • Internal network test: assumes an attacker is already inside, for example through a phishing email.
  • Cloud test: for configuration and access in Microsoft 365, Azure, AWS or Google Cloud.

If a client or tender has asked for a test, check whether they specify a type or an accreditation before you request quotes.

How can you keep the cost under control?

  1. Run a vulnerability scan first and fix the obvious issues, so testing time goes on deeper problems.
  2. Define the scope tightly around what matters most to the business.
  3. Have test accounts and contacts ready before testing starts.
  4. Fix findings promptly so one retest covers them.

Frequently asked questions

Only if it covers the scope you need. A low price often means less testing time or an automated scan presented as a pen test. Ask how many tester days are included and whether the testing is manual.

Testing usually takes from a few days to two weeks depending on scope, followed by the report. Your provider should confirm the timeline before starting.

At least once a year, and after major changes such as a new application, a cloud migration or a significant network change.

Sources

  1. Cyber Security Breaches Survey 2025, Department for Science, Innovation and Technology
Contact

Start with
an assessment.

Tell us a little about your business. We'll arrange a short, no-obligation conversation and suggest a sensible first step.

Studio

The Leather Market
London Bridge

Dealing with a live incident? Put “urgent” in your message or email letstalk@networklondon.co.uk. We use your details only to reply, see our privacy notice.