Your questions, answered
Common questions about penetration testing
Prices start from £750 for website security testing, £1,700 for Wi-Fi assessments and from £2,400 for external network, internal infrastructure, web applications and API testing. Final pricing depends on target scope, complexity, and testing approach (black-box, grey-box, or white-box).
We provide fixed-price proposals with a defined scope and no hidden costs. You can view our pricing guide or request a quote for a tailored estimate.
Typical timelines are:
- Web application testing: 3-6 days
- API testing: 3-7 days
- Mobile application testing: 3-6 days
- External network testing: 2-5 days (depending on size)
- Internal network testing: 3-8 days (depending on size)
- Website security testing: 1-2 days
- Red team engagements (on request): 2-6 weeks or longer, depending on scope and objectives
Indicative timings for other services are available on their service pages. We confirm timelines during scoping so you know exactly what to expect before testing starts.
All testing is carried out in-house, and nothing is outsourced or subcontracted. Your assigned consultant is confirmed before testing begins and remains your direct point of contact from scoping through to debrief.
Every engagement is led by a consultant holding the OSCP (Offensive Security Certified Professional) and OSCE (Offensive Security Certified Expert) certifications from Offensive Security.
Yes. Exploitr is a CREST member company, accredited for penetration testing. You can verify our membership on the CREST Marketplace, and read more about our CREST membership and what it means for buyers.
Every engagement includes testing by a qualified consultant and a pentest report containing:
- Executive summary for non-technical stakeholders
- Technical findings with reproduction steps and evidence
- Risk ratings (CVSS where appropriate)
- Prioritised remediation guidance
You also get a debrief session, an attestation of testing and access to the Exploitr platform to track findings in real time.
Yes. Every engagement includes an attestation letter confirming that the penetration test was carried out to the agreed scope and methodology, which you can download as a PDF from the Exploitr platform once the assessment is complete. It's useful for compliance evidence or for assuring customers and stakeholders without sharing the full report.
Yes. We include a free focused retest on remotely delivered web application, API, website, and external network engagements, covering the vulnerabilities your team has remediated.
You can request the retest from the finding itself in the Exploitr platform, and we pick it up as an extension of the original engagement. The window is usually 30 days from the date your report is issued, with the exact terms set out in your engagement contract.
Ahead of testing we confirm the rules of engagement and avoid destructive techniques unless explicitly authorised.
Where needed, we can schedule higher-impact testing windows outside business hours to minimise operational risk.
Yes. Internet-facing cloud assets are covered by external penetration testing, and cloud-hosted applications by our application testing services.
Configuration reviews of IAM, storage and network policies on AWS, Azure and GCP are scoped on request. We align testing to provider policies and real-world attack paths relevant to your deployment model.
These terms describe how much information is shared with the tester before the engagement begins:
- Black-box testing simulates an external attacker with no prior knowledge of your environment.
- Grey-box testing provides partial information, typically credentials or authenticated access, and is the most common approach for web application and API testing.
- White-box testing gives full access to source code, architecture documentation and credentials, for the deepest coverage.
The approach is agreed during scoping. For more detail, see our glossary entries for black-box, grey-box and white-box testing.
We can test any part of your environment you want. We don't require you to test everything, and we don't believe in a one-size-fits-all approach.
We'd recommend including all relevant assets for network testing, and all user roles and critical functionality for application testing, but ultimately it's your choice. During scoping, we'll discuss your environment and objectives in detail to help you determine the most effective scope for your engagement.
Scoping lets us price accurately, without over- or under-scoping the assessment. We need to understand your business, the systems in scope and what you want the test to achieve.
It's usually a short questionnaire or a call with the consultant who'll carry out the testing, and a call allows quick walkthroughs of applications or infrastructure. If you'd rather keep it to email, that's fine too.
We reply to every enquiry within one business day to confirm your scope, usually with a short questionnaire or a call, and send a fixed quote once we understand your requirements. Our standard lead time from agreement to testing is 2-3 weeks.
Start by requesting a quote or contacting us to arrange a scoping call.
If you're evaluating options, these guides are a good starting point:
- What is Penetration Testing?
- Vulnerability Scanning vs Penetration Testing
- What to Expect During a Web Application Penetration Test
If you'd rather discuss your environment directly, we can recommend the most suitable assessment during a short scoping call.
Yes. We can provide a discount for multi-service engagements and repeat, long-term engagements. If you are a charity, start-up, or public services organisation, let us know and we can discuss how we can work together within your budget.
Yes, Exploitr is VAT registered under GB VAT 476701277. Prices displayed or provided within a quote exclude VAT unless otherwise noted.
Yes. We hold public and products liability, professional indemnity and cyber insurance, and certificates are available through our Trust Centre.
