Penetration Testing Pricing
How much does a penetration test cost?
Penetration testing in the UK typically costs between £1,350 and £12,000+ depending on the type of assessment and size of scope. Most engagements for small and mid-sized organisations fall between £3,000 and £8,000.
Pricing is driven by scope size, the number of assets or user roles in testing, and the depth of manual work required. Explore typical costs across our services and see what's included before you request a quote.

Pentest Service Pricing
Penetration testing costs by service type
Our pricing is fixed and scoped to the defined assessment rather than time-based billing. This provides upfront cost certainty and removes variability associated with day-rate utilisation or scope expansion.
Engagements are priced based on the size and complexity of the environment in scope, including the number of assets, authentication states, and the depth of manual testing required across the attack surface. A fixed-price is confirmed following an initial scoping call.
Pricing is structured to prioritise manual, consultant-led testing within the agreed scope rather than non-technical delivery overheads.
| Service | Price | Recommended For | Typical Duration |
|---|---|---|---|
| Web Application Testing | From £2,700 | SaaS platforms, e-commerce, customer portals, authenticated testing | 3-6 days |
| Website Security Testing | From £750 | Corporate websites, brochureware, WordPress and CMS sites, marketing sites | 1-2 days |
| API Penetration Testing | From £1,800 | API-first companies, microservices, mobile backends | 2-4 days |
| Mobile Application Testing | From £2,800 | Mobile apps, fintech, healthcare applications | 3-6 days |
| Desktop Application Testing | From £2,700 | Enterprise software, financial platforms | 3-5 days |
| Embedded Device & IoT Testing | From £4,500 | IoT devices, consumer devices and platforms | 5+ days |
| External Network Testing | From £1,800 | All organisations, compliance requirements | 2-5 days |
| Internal Network Testing | From £2,850 | All organisations, assumed compromise simulation, enterprise networks | 3-8 days |
| Wi-Fi Security Testing | From £1,700 | Offices, retail, hospitality, healthcare | 1-2 days |
| Vulnerability Assessment | From £700 | Regular security checks, baseline scanning | 1-3 days |
| Pentest as a Service (PTaaS) | From £3,800/mo | Security-conscious organisations, fast-moving dev teams, continuous deployment | Ongoing |
All prices shown are indicative starting points and exclude VAT. Your fixed-price quote will be confirmed following a scoping call.
Not sure which testing you need?
Pricing Factors
What affects the cost of a penetration test?
Penetration test pricing varies significantly based on scope and complexity. Understanding these variables helps you get a more accurate quote and ensures your testing budget is spent where it matters most.
Scope Size
The number of URLs, IP addresses, API endpoints, or application functions in scope is the primary cost driver. A larger scope requires more testing time, and we price that transparently.
Application Complexity
A static brochure site and a multi-role SaaS platform require very different levels of effort. Authenticated testing, multiple user roles, complex workflows, and custom business logic all increase depth and duration.
Test Type & Methodology
Web application, external network, internal network, mobile, and API testing each requires a different methodology and skill set. Black-box, grey-box, and white-box engagements also vary in setup time and depth.
Compliance Requirements
Testing scoped for ISO 27001, PCI DSS, or SOC 2 may require specific methodology, evidence collection, or reporting formats beyond a standard engagement. Communicating your compliance context upfront ensures accurate scoping.
Number of User Roles
For web and mobile application testing, the number of distinct user roles in scope directly affects testing time. Each role may expose different functionality, access levels, and vulnerabilities that need independent assessment.
Timeframe & Scheduling
Standard engagements are scheduled based on consultant availability, typically with a 2-3 week lead time. If you have a specific compliance deadline or preferred testing window, let us know during scoping.
Real scoping examples across common assessment types
How much does penetration testing cost?
The best way to understand penetration testing costs is to see how real engagements are scoped. The examples below are drawn from common scenarios across our client base.
Your environment will differ, but these give a realistic starting point before you request a quote. You can also use our penetration testing cost calculator to get an instant indicative range based on your scope.
Marketing Website (WordPress / CMS)
A typical brochureware or company website that's been built using WordPress, Drupal, or a similar CMS. This is usually an unauthenticated assessment, which covers the public facing side of server configuration, exposed admin interfaces, and common web application vulnerabilities.
Where we can, we also attempt to identify insecure plugin versions and misconfigurations that could lead to compromise.
Typical price range: £750-£1,900
Average Testing time: 1 day
What factors into the cost: number of URLs (pages), presence of custom code or plugins
Multi-tenant SaaS Application or Customer Portal
A custom-built web application with multiple user roles, authentication, and complex business logic. This is a more in-depth assessment that includes authenticated testing, role-based access control testing, and logic flaw analysis across the application.
API testing is often included in this type of engagement, but if you have a separate API that requires testing, that would be scoped as an additional engagement.
Typical price range: £3,600-£7,000+
Average Testing time: 4-7 days
What factors into the cost: number of user roles, complexity of workflows, amount of functionality and business logic in scope
External Network
An assessment of externally-facing infrastructure, including firewalls, VPNs, and internet accessible services. This involves port and vulnerability scanning, manual probing and interaction with exposed services, and exploitation attempts to identify vulnerabilities that could lead to an external compromise.
Typical price range: £1,800-£3,600+
Average Testing time: 2-4 days
What factors into the cost: scope size (number of IPs), complexity and number of exposed services
Internal Network
An assessment of internal infrastructure, including workstations, servers, and network devices. This is a more complex engagement that involves lateral movement, privilege escalation, and post-exploitation activities to identify vulnerabilities that could lead to a significant internal compromise.
Typical price range: £2,850-£8,000+
Average Testing time: 3-8 days
What factors into the cost: scope size (number of IPs), complexity of the environment, presence of Active Directory or other directory services, and the testing approach
Key Deliverables
What's included in the assessment?
Every penetration test includes a defined set of deliverables to support both technical remediation and executive decision-making.
Each engagement with Exploitr includes the following as standard:
Executive Report
Technical Report
Debrief Session
Retesting
Attack Surface Center Access
Experienced, Consultant-led Testing
Compliance-Driven Testing
Penetration testing for compliance requirements
Many organisations require penetration testing as part of a compliance framework. We scope and deliver testing that meets the specific requirements of common standards, with reporting that supports your audit process.
ISO 27001 Penetration Testing
ISO 27001 recommends that organisations regularly test their security controls. Our testing is scoped to satisfy Annex A requirements and produces reporting suitable for your ISMS audit, with clear evidence of methodology and findings.
PCI DSS Penetration Testing
PCI DSS Requirement 11.4 mandates penetration testing of cardholder data environments at least annually. We scope testing to cover your CDE internally and externally, provide methodology documentation, and deliver reports aligned to PCI DSS requirements.
Cyber Essentials Plus
Cyber Essentials Plus requires independent technical verification of your controls. Many organisations use penetration testing to identify and remediate issues before their CE+ assessment to improve first-time pass rates.
SOC 2 Penetration Testing
SOC 2 Type II audits increasingly expect evidence of penetration testing as part of the security, availability, and confidentiality trust service criteria. We provide testing and reporting that satisfies auditor expectations and supports your SOC 2 programme.
Get a fixed-scope price for your penetration test
Share a few details about your environment and we'll confirm a fixed-scope price with a full breakdown of what's included, no day-rate surprises.
Pricing FAQs
Pentest pricing - frequently asked questions
Everything you need to know about how penetration testing is priced, scoped, and delivered before you request a quote.
Penetration test costs in the UK typically range from £1,350 for a smaller website assessment to £12,000+ for internal network or red-team engagements.
Typical price ranges for common assessment types:
- External network penetration testing: £1,800 - £9,000+
- Mobile application testing: £2,800 - £9,500+
- Internal network penetration testing: £2,850 - £12,000+
- Web application penetration testing: £2,700 - £8,000+
- API penetration testing: £1,800 - £8,500+
At Exploitr, we provide fixed pricing based on your specific scope. All engagements are delivered by an experienced in-house consultant and nothing is outsourced.
Yes. We provide penetration testing services to organisations outside the UK. Our consultants can work remotely, and we can accommodate different time zones for scoping calls, testing, and debrief sessions.
We have experience working with international clients from the US and Europe.
The typical day rate for accredited penetration testing is between £1,200 - £1,600 per day, and when those days run out their testing stops whether the scope is fully covered or not.
We work on fixed-scope prices, not day rates. Every engagement is individually scoped, and a written fixed-scope proposal is agreed before testing begins. Our fixed-price engagements are scoped to an outcome, and not a timeframe, and testing continues until every agreed area has been assessed - you're paying for coverage, not a countdown.
If you would prefer a day-rate based quote or are working to a budget, let us know during the scoping call and we'll do our best to accommodate your requirements.
Every penetration test includes:
A scoping call to define objectives, scope, and rules of engagement
Experienced consultant-led testing
A detailed technical report with risk-rated findings, evidence, and reproduction steps
An executive report with a summary covering risk, business impact, and remediation priorities
A post-engagement debrief call
Access to the Attack Surface Center platform for ongoing vulnerability management, remediation tracking, and secure report delivery
Free focused retesting of remediated vulnerabilities for web application, API, and external network engagements
We stay connected with you throughout the engagement and beyond, so you can ask questions, get clarification, and ensure you have everything you need to understand and remediate your risks.
A mid-sized SaaS application with multiple user roles, authentication, and complex business logic typically costs between £3,600 and £7,000+.
The final price depends on the number of user roles, the complexity of workflows, and the amount of functionality in scope.
API testing is often included in this type of engagement, but if you have a separate API that requires testing, that would be scoped as an additional engagement.
For more on the approach and what's included, see our SaaS penetration testing service page.
For network penetration testing, we typically price based on the number of IP addresses in scope with an external perimeter assessment, or the number of networks, servers, and user workstations for an internal network pentest. For example, an external network with 20 IP addresses will require more time than one with 5 IP addresses.
For web application and API testing, we price based on the functionality, complexity, and scale of API endpoints. This is because the cost is driven by the amount of testing time required to thoroughly assess each asset, and these metrics provide a useful baseline for estimating the time required. For example, a web application with file upload, user management with multiple roles or permission features, and unique business logic functionality will require more testing time than one with simple read-only reporting output.
During our scoping call, we'll discuss your environment in detail to determine the most appropriate pricing based on your specific assets and testing requirements.
Yes. Our penetration testing services provide thorough assessment of your assets to help support ISO 27001, PCI DSS, and SOC 2 evidence. Letting us know your compliance context requirements during scoping ensures we deliver exactly what your auditor or certification body needs.
Combined engagements, for example a web application testing alongside an external network assessment, are scoped as a single proposal and typically offer better value than booking separately. If you have multiple testing requirements, include them all in your quote request and we'll scope them together.
If you have a strict budget, are a start-up, or are concerned about costs, let us know during a scoping call or through the quote request form and we'll help where we can.
Yes. Smaller engagements, such as website security testing from £750 or external network testing from £1,800, are scoped for exactly this kind of budget.
If you're a start-up or working to a tight budget, let us know during scoping and we'll help identify the highest-priority areas to test first, so testing can be phased as your budget allows.
Our standard lead time is 2-3 weeks from the point of agreement.
If you have a compliance deadline, audit date, or product launch driving your timeline, let us know during scoping and we'll do our best to accommodate it. Urgent engagements may be possible depending on our availability.
Penetration Testing as a Service (PTaaS) pricing is typically subscription-based and depends on the number of assets, frequency of testing, and level of support required. PTaaS provides continuous security assurance with regular testing and reporting, which can be more cost-effective for organisations with dynamic environments or ongoing development cycles.
With Exploitr, subscribing to Penetration Testing as a Service (PTaaS) gives you access to our Attack Surface Center platform, where you can track vulnerabilities, manage remediation, receive real-time updates on your security posture, and alert us instantly when an issue needs retesting.
Our PTaaS subscription pricing is based on the the volume of testing time contracted each month, but we can discuss your specific requirements during a scoping call to ensure you get the right level of coverage for your environment.
