Penetration Testing
CREST-accredited testing, delivered personally by the tester rather than passed to a junior analyst with a scanner. Fixed-fee options for tightly scoped work, and honest scoping for everything else.
A penetration test is a person attempting to compromise your systems the way a real attacker would, then telling you exactly how they did it and what to change. It is not a scan, it is not a questionnaire, and the quality of it depends almost entirely on who is doing the work. Every Solusec engagement is delivered personally by a CREST-qualified tester.
Fixed-fee penetration tests
Two tightly scoped tests you can buy online at a fixed price, with no quote needed. Everything else we scope and quote to your environment, because pretending otherwise produces either a padded price or a test that misses the point.
- External IP test, £3,000 + VAT. Up to 10 public IP addresses, unauthenticated.
- CMS website test, £2,500 + VAT. WordPress, Joomla and similar. Not shops.
What a test costs, and what moves the number
Four things set the price: the number of distinct user roles, the volume of distinct functionality, how much information you can supply up front, and whether testing is authenticated. Everything else is detail. These are realistic UK market ranges rather than our price list, so you can sanity-check any quote you receive, including ours.
| Test type | Typical days | Typical UK price |
|---|---|---|
| Small web application, 1 to 2 user roles | 3 to 5 | £1,500 to £4,000 |
| Large web application, multiple roles, payments, API | 8 to 15 | £6,000 to £15,000 |
| External infrastructure, up to ~64 live hosts | 3 to 6 | £2,000 to £6,000 |
| Internal network, single site | 5 to 10 | £4,000 to £10,000 |
| Cloud configuration review, single tenant | 3 to 6 | £2,500 to £6,000 |
| Mobile application, one platform | 5 to 8 | £3,500 to £8,000 |
| AI or LLM application assessment | 4 to 10 | £3,000 to £10,000 |
| Retest of previous findings | 1 to 2 | Included with us; otherwise £600 to £2,000 |
If a quote comes in far below these ranges, the question to ask is how many days of human testing it buys. What a cheap test actually buys you is worth reading before you compare on price alone, and the full cost guide breaks down day rates by provider type.
How an engagement runs
Scoping that does not waste your budget
We scope on a call, not through a forty-field web form. If your environment is smaller than you think, we will tell you and quote less. If a proposed scope leaves an obvious gap, an unauthenticated admin portal nobody mentioned or a forgotten staging environment sitting on the same subnet, we will say so before you sign anything rather than find it on day two and raise a change request.
Rules of engagement
Before anything starts we agree in writing what is in scope, what must not be touched, the testing window, who to contact out of hours, and what happens if we find something critical at nine on a Friday evening. This is the document that protects both of us, and it is also the document your insurer will ask about if anything ever goes wrong.
Testing
Work is carried out against a documented methodology aligned to CREST, OWASP and NCSC guidance. You get a named tester, an agreed window and a direct channel for the duration. Critical findings are reported the moment we confirm them rather than held back for the final report. If we find something that puts you at immediate risk, you hear about it that day and you can start fixing it that day.
Reporting
Two audiences, one document. An executive summary a non-technical director can read and act on, and technical detail with full reproduction steps, evidence and remediation guidance your developers or IT provider can work straight from. No two-hundred-page scanner dump, no padding, and no severity inflation to make the report look more impressive than the findings warrant.
Retesting
Retest of remediated issues is included as standard rather than sold as an extra. You get an updated report reflecting the closed items, which is the document your client, insurer or auditor actually wants, because a report full of open criticals proves only that you had a test.
Types of testing we deliver
Most organisations need a combination, and the order matters. We will help you work out which and in what sequence, based on where your real exposure sits rather than what is easiest to sell.
Web application and API testing
Authenticated and unauthenticated, covering business logic, access control between roles and between tenants, injection, session handling and authentication flows. The findings that matter here are rarely the ones a scanner reports; they are the ones where the application does exactly what it was built to do, for the wrong person. More on web application testing.
Infrastructure and network testing
External perimeter and internal, including Active Directory attack paths, credential exposure, service misconfiguration and lateral movement. An internal test answers the question every board eventually asks: if one laptop is compromised, what happens next. More on infrastructure testing.
Cloud security assessment
AWS and Azure configuration, identity and privilege escalation paths. Cloud findings are overwhelmingly about identity rather than infrastructure: over-permissive roles, long-lived keys, and trust relationships nobody has reviewed since they were created. More on cloud assessment.
AI and LLM testing
Prompt injection, data leakage through model responses, excessive agency in tool-using agents, and guardrail bypass. Solusec holds the CREST AI-Enabled Penetration Testing accreditation, among the first ten organisations worldwide. More on AI and LLM testing.
Mobile application testing
iOS and Android, including local storage, certificate handling, and the API the application talks to, which is usually where the real issues are.
Build and device reviews
Laptop, server and workstation gold-image assessment against a hardened baseline. Cheaper than a full test and often the highest-value thing an organisation can do before rolling out three hundred machines.
Why CREST accreditation matters
CREST accredits the company, not just the individual. Our methodology, reporting standards, data handling, insurance and staff competence have all been independently audited against the CREST Penetration Testing Accreditation Standard. Solusec also holds the CREST AI-Enabled accreditation, and the tester is CREST registered as an individual, so both layers are covered.
That matters in three specific places. Public sector and enterprise procurement frameworks frequently mandate it outright. Cyber insurance underwriters use it to judge whether an engagement was carried out to an acceptable standard. And if you ever have to demonstrate due diligence after an incident, "we used a CREST accredited provider" is a materially stronger position than "we used a consultant". Every accreditation we hold is published with the register you can verify it on.
Testing for a specific reason
Most tests are commissioned because somebody asked for one, and what they asked for shapes what you actually need. For a tender, the report has to satisfy an evaluator who will not read the technical section. For a client contract, the scope has to match what the contract says, which is often narrower than you would test by choice. For cyber insurance, the underwriter cares about accreditation and about whether findings were closed. Tell us which of these you are in and we will scope for it rather than around it.
How often to test
Annually as a baseline, and after any significant change: a new application, a major release, a migration, a merger, or a change to how users authenticate. Organisations with a fast release cycle increasingly move to testing as a service or a retainer, which spreads the same budget across the year and catches things closer to when they were introduced. The full answer, including what regulators and insurers expect.
Talk to us about testing
Tell us what you need looked at and we will tell you what the work actually involves, what it costs and when we can do it. CREST accredited, and the testing is done by the person you speak to.
Common questions
How much does a penetration test cost?
Cost is driven by scope and complexity rather than a price list. In practice the number is set by how many user roles there are, how much distinct functionality exists, and how much information you can give us up front. As a guide, a small web application with one or two roles is typically £1,500 to £4,000, external infrastructure up to around 64 live hosts is £2,000 to £6,000, and a large application with payments and an API is £6,000 to £15,000. We will always tell you if a smaller scope would serve you better.
What is a realistic day rate for a UK penetration test?
A large consultancy typically charges £1,000 to £1,500 a day, which pays for offices, account managers and a sales function alongside the testing. A small or mid-size CREST provider is usually £800 to £1,200, which is mostly the tester’s time. Anything at £250 to £500 a day is, in our experience, an automated scan with a cover page on it.
How long does a test take?
Most engagements run three to five days of testing, with the report delivered within five working days of testing completing. Lead time from agreeing scope to starting is usually two to three weeks. If you are against a contractual or audit deadline, say so at the first conversation and we will be honest about whether we can meet it. Where the requirement names CREST specifically, see urgent CREST penetration test.
What is the difference between a penetration test and a vulnerability scan?
A scan is automated, runs in minutes, and matches what it finds against a signature database. A penetration test is a human attempting to compromise your systems the way an attacker would, including chaining several individually minor issues into a serious one. A scanner will not work out that your booking system lets one customer read another’s records because the object reference is predictable. Most compliance requirements that specify penetration testing will not accept a scan in its place.
Will testing disrupt our systems?
Rules of engagement are agreed in advance, including any systems that must not be touched and any windows to avoid. Denial-of-service testing is never carried out unless you explicitly ask for it and it is scoped. We keep a direct line open throughout so anything unexpected can be stopped immediately.
Do you test production or staging?
Both are viable and each has a trade-off. Production gives the most accurate picture but needs more care. Staging is safer but only useful if it genuinely mirrors production, which it often does not once you look at the data, the integrations and the configuration. We will discuss which is appropriate during scoping rather than assume.
Is retesting included?
Yes, as standard rather than as a chargeable extra. Fixing the findings is the point of the exercise, and you get an updated report reflecting the closed items, which is what your client, insurer or auditor actually wants to see.
Do we need CREST, or is CHECK required?
They are different schemes and they are not interchangeable. CREST accredits companies and certifies individuals across the commercial market. CHECK is an NCSC scheme required for some central government and critical national infrastructure work specifically. We are CREST accredited at company level and CREST registered at individual level. We do not hold CHECK, and if your contract specifies it we will tell you so rather than argue the equivalence. The difference is set out in full here.
How often should we test?
Annually as a baseline, and after any significant change: a new application, a major release, a migration, a merger, or a change to how users authenticate. Testing once and filing the report is the pattern that leaves organisations exposed, because the estate moves and the report does not. There is a longer answer here.
Who will actually do the testing?
A named CREST-qualified tester, and you will speak to them before, during and after. There is no sales layer translating your requirements badly and no handover to somebody junior once the contract is signed. The credentials are published and verifiable.
Can you test AI and LLM systems?
Yes. Solusec holds the CREST AI-Enabled Penetration Testing accreditation and was among the first ten organisations worldwide to do so. That covers prompt injection, data leakage through model responses, excessive agency in tool-using agents, and guardrail bypass. See AI and LLM testing.
Will the report be accepted by our client or insurer?
In our experience yes, and the accreditation is usually the reason. Buyers and underwriters look for a named accredited provider, a documented methodology, evidence and reproduction steps, a severity rating with a rationale, and a retest confirming closure. Our reports carry all five. What buyers actually check in a report goes through it in detail.
Related
Penetration testing guides
Ready to talk?
Scoping conversations are free and there is no sales team to get past. Tell us what you're dealing with and we'll tell you honestly what you need.