Penetration Testing Pricing

How much does a penetration test cost?

Penetration testing in the UK typically costs between £1,350 and £12,000+ depending on the type of assessment and size of scope. Most engagements for small and mid-sized organisations fall between £3,000 and £8,000.

Pricing is driven by scope size, the number of assets or user roles in testing, and the depth of manual work required. Explore typical costs across our services and see what's included before you request a quote.

Penetration testing pricing and cost information for UK organisations

Pentest Service Pricing

Penetration testing costs by service type

Our pricing is fixed and scoped to the defined assessment rather than time-based billing. This provides upfront cost certainty and removes variability associated with day-rate utilisation or scope expansion.

Engagements are priced based on the size and complexity of the environment in scope, including the number of assets, authentication states, and the depth of manual testing required across the attack surface. A fixed-price is confirmed following an initial scoping call.

Pricing is structured to prioritise manual, consultant-led testing within the agreed scope rather than non-technical delivery overheads.

ServicePriceRecommended ForTypical Duration
Web Application TestingFrom £2,7003-6 days
Website Security TestingFrom £7501-2 days
API Penetration TestingFrom £1,8002-4 days
Mobile Application TestingFrom £2,8003-6 days
Desktop Application TestingFrom £2,7003-5 days
Embedded Device & IoT TestingFrom £4,5005+ days
External Network TestingFrom £1,8002-5 days
Internal Network TestingFrom £2,8503-8 days
Wi-Fi Security TestingFrom £1,7001-2 days
Vulnerability AssessmentFrom £7001-3 days
Pentest as a Service (PTaaS)From £3,800/moOngoing

All prices shown are indicative starting points and exclude VAT. Your fixed-price quote will be confirmed following a scoping call.

Not sure which testing you need?

Pricing Factors

What affects the cost of a penetration test?

Penetration test pricing varies significantly based on scope and complexity. Understanding these variables helps you get a more accurate quote and ensures your testing budget is spent where it matters most.

Scope Size

The number of URLs, IP addresses, API endpoints, or application functions in scope is the primary cost driver. A larger scope requires more testing time, and we price that transparently.

Application Complexity

A static brochure site and a multi-role SaaS platform require very different levels of effort. Authenticated testing, multiple user roles, complex workflows, and custom business logic all increase depth and duration.

Test Type & Methodology

Web application, external network, internal network, mobile, and API testing each requires a different methodology and skill set. Black-box, grey-box, and white-box engagements also vary in setup time and depth.

Compliance Requirements

Testing scoped for ISO 27001, PCI DSS, or SOC 2 may require specific methodology, evidence collection, or reporting formats beyond a standard engagement. Communicating your compliance context upfront ensures accurate scoping.

Number of User Roles

For web and mobile application testing, the number of distinct user roles in scope directly affects testing time. Each role may expose different functionality, access levels, and vulnerabilities that need independent assessment.

Timeframe & Scheduling

Standard engagements are scheduled based on consultant availability, typically with a 2-3 week lead time. If you have a specific compliance deadline or preferred testing window, let us know during scoping.

Real scoping examples across common assessment types

How much does penetration testing cost?

The best way to understand penetration testing costs is to see how real engagements are scoped. The examples below are drawn from common scenarios across our client base.

Your environment will differ, but these give a realistic starting point before you request a quote. You can also use our penetration testing cost calculator to get an instant indicative range based on your scope.

Marketing Website (WordPress / CMS)

A typical brochureware or company website that's been built using WordPress, Drupal, or a similar CMS. This is usually an unauthenticated assessment, which covers the public facing side of server configuration, exposed admin interfaces, and common web application vulnerabilities.

Where we can, we also attempt to identify insecure plugin versions and misconfigurations that could lead to compromise.

  • Typical price range: £750-£1,900

  • Average Testing time: 1 day

  • What factors into the cost: number of URLs (pages), presence of custom code or plugins

Multi-tenant SaaS Application or Customer Portal

A custom-built web application with multiple user roles, authentication, and complex business logic. This is a more in-depth assessment that includes authenticated testing, role-based access control testing, and logic flaw analysis across the application.

API testing is often included in this type of engagement, but if you have a separate API that requires testing, that would be scoped as an additional engagement.

  • Typical price range: £3,600-£7,000+

  • Average Testing time: 4-7 days

  • What factors into the cost: number of user roles, complexity of workflows, amount of functionality and business logic in scope

External Network

An assessment of externally-facing infrastructure, including firewalls, VPNs, and internet accessible services. This involves port and vulnerability scanning, manual probing and interaction with exposed services, and exploitation attempts to identify vulnerabilities that could lead to an external compromise.

  • Typical price range: £1,800-£3,600+

  • Average Testing time: 2-4 days

  • What factors into the cost: scope size (number of IPs), complexity and number of exposed services

Internal Network

An assessment of internal infrastructure, including workstations, servers, and network devices. This is a more complex engagement that involves lateral movement, privilege escalation, and post-exploitation activities to identify vulnerabilities that could lead to a significant internal compromise.

  • Typical price range: £2,850-£8,000+

  • Average Testing time: 3-8 days

  • What factors into the cost: scope size (number of IPs), complexity of the environment, presence of Active Directory or other directory services, and the testing approach

Key Deliverables

What's included in the assessment?

Every penetration test includes a defined set of deliverables to support both technical remediation and executive decision-making.

Each engagement with Exploitr includes the following as standard:

01

Executive Report

Our primary deliverable is an executive-focused assessment report providing a non-technical summary of findings, with recommendations suitable for board and senior management stakeholders.
02

Technical Report

A detailed supplementary report covering each vulnerability discovered, including reproduction steps, severity scoring, remediation guidance, and mappings to CVE, CVSS, and MITRE ATT&CK where applicable.
03

Debrief Session

Every engagement includes the offer of a debrief session to present findings, discuss remediation strategies and priorities, and run an open Q&A with your team.
04

Retesting

For web application, API, and external network engagements, our team offers free focused retesting of vulnerabilities remediated post-engagement. This allows us to confirm your fixes are effective and provides supporting evidence for compliance or audit purposes.
05

Attack Surface Center Access

Complimentary access to our Attack Surface Center ASM platform to review, track, and collaboratively remediate findings in real time throughout and beyond the engagement.
06

Experienced, Consultant-led Testing

All engagements are delivered by experienced, certified in-house consultants. Your consultant works with you from initial scoping through to the debrief and remediation phase, and nothing is outsourced or subcontracted.

Compliance-Driven Testing

Penetration testing for compliance requirements

Many organisations require penetration testing as part of a compliance framework. We scope and deliver testing that meets the specific requirements of common standards, with reporting that supports your audit process.

ISO

ISO 27001 Penetration Testing

ISO 27001 recommends that organisations regularly test their security controls. Our testing is scoped to satisfy Annex A requirements and produces reporting suitable for your ISMS audit, with clear evidence of methodology and findings.

PCI

PCI DSS Penetration Testing

PCI DSS Requirement 11.4 mandates penetration testing of cardholder data environments at least annually. We scope testing to cover your CDE internally and externally, provide methodology documentation, and deliver reports aligned to PCI DSS requirements.

CE+

Cyber Essentials Plus

Cyber Essentials Plus requires independent technical verification of your controls. Many organisations use penetration testing to identify and remediate issues before their CE+ assessment to improve first-time pass rates.

SOC2

SOC 2 Penetration Testing

SOC 2 Type II audits increasingly expect evidence of penetration testing as part of the security, availability, and confidentiality trust service criteria. We provide testing and reporting that satisfies auditor expectations and supports your SOC 2 programme.

Get a fixed-scope price for your penetration test

Share a few details about your environment and we'll confirm a fixed-scope price with a full breakdown of what's included, no day-rate surprises.

Pricing FAQs

Pentest pricing - frequently asked questions

Everything you need to know about how penetration testing is priced, scoped, and delivered before you request a quote.

Penetration test costs in the UK typically range from £1,350 for a smaller website assessment to £12,000+ for internal network or red-team engagements.

Typical price ranges for common assessment types:

  • External network penetration testing: £1,800 - £9,000+
  • Mobile application testing: £2,800 - £9,500+
  • Internal network penetration testing: £2,850 - £12,000+
  • Web application penetration testing: £2,700 - £8,000+
  • API penetration testing: £1,800 - £8,500+

At Exploitr, we provide fixed pricing based on your specific scope. All engagements are delivered by an experienced in-house consultant and nothing is outsourced.

Yes. We provide penetration testing services to organisations outside the UK. Our consultants can work remotely, and we can accommodate different time zones for scoping calls, testing, and debrief sessions.

We have experience working with international clients from the US and Europe.

The typical day rate for accredited penetration testing is between £1,200 - £1,600 per day, and when those days run out their testing stops whether the scope is fully covered or not.

We work on fixed-scope prices, not day rates. Every engagement is individually scoped, and a written fixed-scope proposal is agreed before testing begins. Our fixed-price engagements are scoped to an outcome, and not a timeframe, and testing continues until every agreed area has been assessed - you're paying for coverage, not a countdown.

If you would prefer a day-rate based quote or are working to a budget, let us know during the scoping call and we'll do our best to accommodate your requirements.

Every penetration test includes:

  • A scoping call to define objectives, scope, and rules of engagement

  • Experienced consultant-led testing

  • A detailed technical report with risk-rated findings, evidence, and reproduction steps

  • An executive report with a summary covering risk, business impact, and remediation priorities

  • A post-engagement debrief call

  • Access to the Attack Surface Center platform for ongoing vulnerability management, remediation tracking, and secure report delivery

  • Free focused retesting of remediated vulnerabilities for web application, API, and external network engagements

We stay connected with you throughout the engagement and beyond, so you can ask questions, get clarification, and ensure you have everything you need to understand and remediate your risks.

A mid-sized SaaS application with multiple user roles, authentication, and complex business logic typically costs between £3,600 and £7,000+.

The final price depends on the number of user roles, the complexity of workflows, and the amount of functionality in scope.

API testing is often included in this type of engagement, but if you have a separate API that requires testing, that would be scoped as an additional engagement.

For more on the approach and what's included, see our SaaS penetration testing service page.

For network penetration testing, we typically price based on the number of IP addresses in scope with an external perimeter assessment, or the number of networks, servers, and user workstations for an internal network pentest. For example, an external network with 20 IP addresses will require more time than one with 5 IP addresses.

For web application and API testing, we price based on the functionality, complexity, and scale of API endpoints. This is because the cost is driven by the amount of testing time required to thoroughly assess each asset, and these metrics provide a useful baseline for estimating the time required. For example, a web application with file upload, user management with multiple roles or permission features, and unique business logic functionality will require more testing time than one with simple read-only reporting output.

During our scoping call, we'll discuss your environment in detail to determine the most appropriate pricing based on your specific assets and testing requirements.

Yes. Our penetration testing services provide thorough assessment of your assets to help support ISO 27001, PCI DSS, and SOC 2 evidence. Letting us know your compliance context requirements during scoping ensures we deliver exactly what your auditor or certification body needs.

Combined engagements, for example a web application testing alongside an external network assessment, are scoped as a single proposal and typically offer better value than booking separately. If you have multiple testing requirements, include them all in your quote request and we'll scope them together.

If you have a strict budget, are a start-up, or are concerned about costs, let us know during a scoping call or through the quote request form and we'll help where we can.

Yes. Smaller engagements, such as website security testing from £750 or external network testing from £1,800, are scoped for exactly this kind of budget.

If you're a start-up or working to a tight budget, let us know during scoping and we'll help identify the highest-priority areas to test first, so testing can be phased as your budget allows.

Our standard lead time is 2-3 weeks from the point of agreement.

If you have a compliance deadline, audit date, or product launch driving your timeline, let us know during scoping and we'll do our best to accommodate it. Urgent engagements may be possible depending on our availability.

Penetration Testing as a Service (PTaaS) pricing is typically subscription-based and depends on the number of assets, frequency of testing, and level of support required. PTaaS provides continuous security assurance with regular testing and reporting, which can be more cost-effective for organisations with dynamic environments or ongoing development cycles.

With Exploitr, subscribing to Penetration Testing as a Service (PTaaS) gives you access to our Attack Surface Center platform, where you can track vulnerabilities, manage remediation, receive real-time updates on your security posture, and alert us instantly when an issue needs retesting.

Our PTaaS subscription pricing is based on the the volume of testing time contracted each month, but we can discuss your specific requirements during a scoping call to ensure you get the right level of coverage for your environment.