How much does a
penetration test cost?

It’s the first question most organisations ask, and one the industry has historically been reluctant to answer clearly. We think that needs to change.

Below you’ll find typical pricing ranges across all our services, an explanation of what affects cost, and everything that’s included in every engagement.
CREST Pathway Accreditation Logo for Exploitr Limited
UK Cyber Security Council membership logo
Cyber Essentials Certification Logo for Exploitr Limited
Service pricing

Penetration testing costs by service type

Costs vary based on scope, complexity, and testing duration. The ranges below reflect typical engagements – your fixed quote will be confirmed after a scoping conversation.

ServiceStarting PriceTypical DurationRecommended For
Web Application TestingFROM £1,1002-7 daysSaaS platforms, e-commerce, customer portals
API Penetration TestingFROM £1,2003-5 daysAPI-first companies, microservices, mobile backends
Mobile Application TestingFROM £2,8004-10 daysMobile apps, fintech, healthcare applications
Desktop Application TestingFROM £2,1003-8 daysEnterprise software, financial platforms
Embedded Device & IoT TestingFROM £4,2005+ daysIoT Devices, consumer devices and platforms
External Network TestingFROM £1,3502-7 daysAll organisations, compliance requirements
Internal Network TestingFROM £2,2003-10 daysAll organisations, assumed compromise simulation, enterprise networks
Wi-Fi Security TestingFROM £1,2001-2 daysOffices, retail, hospitality, healthcare
Vulnerability AssessmentFROM £5001-3 daysRegular security checks, baseline scanning
Pentest as a Service (PTaaS)FROM £3,000/moOngoingSecurity conscious organisations, fast-moving dev teams,
continuous deployment

Not sure which testing you need?

Pricing factors

What affects the cost of a penetration test?

Penetration test pricing varies significantly based on scope and complexity. Understanding these variables helps you get a more accurate quote and ensures your testing budget is spent where it matters most.

01

Scope size

The number of URLs, IP addresses, API endpoints, or application functions in scope is the primary driver of cost. A larger scope requires more testing time, and we price that transparently. Defining scope clearly at the start keeps costs predictable.
02

Application complexity

A static brochure site and a multi-role SaaS platform require very different levels of effort. Authenticated testing, multiple user roles, complex workflows, and custom business logic all increase the depth, and duration, of testing required.
03

Test type & methodology

Web application, external network, internal network, mobile, and API testing each requires a different methodology and skillset. The testing approach also matters: black box, grey box, and white box engagements vary in setup time and depth of coverage.
04

Compliance requirements

Testing scoped for ISO 27001, PCI DSS, or SOC 2 may require specific methodology, evidence collection, or reporting formats beyond a standard engagement. Communicating your compliance context upfront ensures accurate scoping.
05

Number of user roles

For web and mobile application testing, the number of distinct user roles in scope directly affects testing time. Each role may expose different functionality, access levels, and vulnerabilities that need to be assessed independently.
06

Timeframe & scheduling

Standard engagements are scheduled based on consultant availability, typically with a 1-2 week lead time. If you have a specific compliance deadline or preferred testing window, let us know during scoping and we’ll do our best to accommodate it.

Request a free quote

Our team are on hand to discuss your security requirements and provide an assessment scope that meets your needs.
Speak with our security team directly
Experts in providing thorough testing coverage
Professional services you can trust
Compliance-driven testing

Penetration testing for compliance requirements

Many organisations require penetration testing as part of a compliance framework. We scope and deliver testing that meets the specific requirements of the most common standards, with reporting that supports your audit process.

ISO

ISO 27001 Penetration Testing

ISO 27001 recommends that organisations to regularly test their security controls. Our testing is scoped to satisfy Annex A requirements and produces reporting suitable for your ISMS audit, with clear evidence of methodology and findings.
PCI

PCI DSS Penetration Testing

PCI DSS Requirement 11.4 mandates penetration testing of cardholder data environments at least annually. We scope testing to cover your CDE, both internally and externally, provide methodology documentation, and deliver reports aligned to PCI DSS requirements.
CE+

Cyber Essentials Plus

Cyber Essentials Plus requires independent technical verification of your controls. While the CE+ assessment itself is conducted by a certification body, many organisations use penetration testing to identify and remediate issues before their assessment — improving first-time pass rates.
SOC2

SOC 2 Penetration Testing

SOC 2 Type II audits increasingly expect evidence of penetration testing as part of the security availability and confidentiality trust service criteria. We provide testing and reporting that satisfies auditor expectations and supports your SOC 2 programme.
Process

What happens after you request a quote?

Getting from quote request to completed assessment is straightforward. Here’s what to expect at each stage.

Step 1

Submit your requirements

Use the quote form or book a scoping call. Tell us what you need tested, any compliance requirements, and your preferred timeframe. The more context you can provide, the more accurate your quote will be.
Step 2

Receive a fixed-price proposal

Our team will review your requirements, typically within one business day, and provide a written, fixed-price proposal. No obligation to proceed.
Step 3

Schedule your testing

Once you’re happy with the proposal, we’ll schedule a call to discuss further testing plans, like the rules of engagement and any access requirements, and plan a testing window that fits your schedule.
Step 4

Testing, reporting & debrief

Testing is conducted by an experienced consultant with direct communication throughout. Your report is delivered within 2 business days of testing completion, followed by a debrief call with your team.

Penetration testing pricing – common questions

Everything you need to know about how penetration testing is priced, scoped, and delivered before you request a quote.

Penetration test costs in the UK typically range from £1,500 for a small-scope web application assessment to £10,000+ for complex network or red team engagements. At Exploitr, we provide fixed pricing based on your specific scope.

View our services for typical pentest pricing costs or request a quote from us to get an accurate figure for your environment.

We work by providing fixed prices. We scope each engagement individually and provide a written, fixed-price proposal before any testing begins. There are no day-rate overruns or scope creep surprises, and what we quote is what you pay, regardless of how long testing takes us.

If you would prefer a day-rate based quote or are working to a budget, please let us know during the scoping call and we’ll make every effort to work towards your requirements.

Every engagement includes: a scoping session, manual consultant-led testing, a detailed technical report with evidence and reproduction steps, an executive summary with risk ratings and business impact, tailored remediation guidance, a debrief call with your team, and complimentary access to the Attack Surface Center platform. There are no additional charges for reporting, the debrief, or platform access.

Most engagements run between 2 and 5 days of active testing, depending on scope and complexity. Reports are delivered within 2 business days of testing completion. Live findings are available in real time throughout testing via the Attack Surface Center platform, so you don’t have to wait for the final report to start understanding your risk.

We regularly scope penetration testing engagements for ISO 27001, PCI DSS, and SOC 2. Compliance-driven testing may require specific methodology, evidence collection, or reporting formats. Letting us know your compliance context during scoping ensures we deliver exactly what your auditor or certification body needs.

Combined engagements, for example web application testing alongside an external network assessment, are scoped as a single proposal and typically offer better value than booking separately. If you have multiple testing requirements, include them all in your quote request and we’ll scope them together.

If you have a strict budget, are a start-up, or are concerned about costs – let us know your requirements during a scoping call or through the quote request form and we’ll ensure to help where we can.

None whatsoever. All enquiries are treated as strictly confidential and you are under no obligation to proceed at any stage. We’ll provide a quote and you can take as much time as you need. If you have questions before requesting a quote, you’re welcome to book an informal scoping call instead – in fact, we’d prefer to speak with you.