# How much does a penetration test cost in the UK?

> What decides the cost of a penetration test in the UK: scope, type, depth and retesting. How pricing works and how to get an accurate quote.

Canonical: https://cybersecuritylondon.com/how-much-does-a-pen-test-cost-in-uk


By Cyber Security London, published 8 October 2026.

**In short:** The cost of a penetration test in the UK depends mainly on how much is being tested and how deeply. Most testers price by the number of tester days a scope needs. A focused test of one web application needs far fewer days than an internal network test across several sites, so always agree scope first, then get a fixed quote.

## How is a penetration test priced?

Most UK penetration testing is priced on effort: the number of days a qualified tester needs to cover the agreed scope properly, plus time to write the report. That is why two quotes for “a pen test” can look very different. They are often quoting for different amounts of work.

Ask any provider for a written scope that lists exactly what is included. Comparing quotes without one is comparing guesses.

## What affects the price?

| Factor | Pushes the cost up | Keeps it down |
| --- | --- | --- |
| Scope | Many applications, IP ranges or user roles | One clearly defined target |
| Type of test | Internal network, cloud and application together | External-only test |
| Complexity | Custom apps with complex logic and integrations | Standard, well-documented systems |
| Access level | Testing as several authenticated roles | Unauthenticated testing only |
| Timing | Out-of-hours windows to protect live services | Flexible testing during the working day |
| Retesting | Several rounds of fixes to check | Fixes completed in one round |

## Which type of penetration test do you need?

- **Web application test:** for customer portals, online services and APIs.
- **External network test:** for anything facing the internet, such as firewalls, VPNs and mail servers.
- **Internal network test:** assumes an attacker is already inside, for example through a phishing email.
- **Cloud test:** for configuration and access in Microsoft 365, Azure, AWS or Google Cloud.

If a client or tender has asked for a test, check whether they specify a type or an accreditation before you request quotes.

## How can you keep the cost under control?

1. Run a vulnerability scan first and fix the obvious issues, so testing time goes on deeper problems.
2. Define the scope tightly around what matters most to the business.
3. Have test accounts and contacts ready before testing starts.
4. Fix findings promptly so one retest covers them.

## Frequently asked questions

### Is a cheap penetration test worth it?

Only if it covers the scope you need. A low price often means less testing time or an automated scan presented as a pen test. Ask how many tester days are included and whether the testing is manual.

### How long does a penetration test take?

Testing usually takes from a few days to two weeks depending on scope, followed by the report. Your provider should confirm the timeline before starting.

### How often should a business have a penetration test?

At least once a year, and after major changes such as a new application, a cloud migration or a significant network change.

## Sources

- [Cyber Security Breaches Survey 2025, Department for Science, Innovation and Technology](https://www.gov.uk/government/statistics/cyber-security-breaches-survey-2025/cyber-security-breaches-survey-2025)

## How we can help

- [Penetration Testing](https://cybersecuritylondon.com/penetration-testing)
- [Vulnerability Management](https://cybersecuritylondon.com/vulnerability-management)

## Contact

Email enquiry@cybersecuritylondon.com or use the enquiry form at https://cybersecuritylondon.com/#contact. Cyber Security London, The Leather Market, London Bridge, London.
