- Priced on
- Day rate × scoped days
- Scoping call
- Free
- Quotes
- Fixed for defined scope
- Retest
- Included, not extra
How testing is priced
Almost universally: a day rate multiplied by the number of days a competent tester needs. The day rate varies between providers, largely reflecting overhead rather than tester quality — a large consultancy has offices, account managers and a sales function to fund, and that is in the number.
So the figure that actually determines your bill is the day count. That is where quotes diverge most, and where your attention is best spent when comparing.
We quote on a call rather than through a form, and the quote is fixed for the scope agreed. If the scope changes materially we will tell you before doing the work, not afterwards.
What genuinely moves the number
User roles
The single biggest driver on application testing, and the one most often understated. Each additional role multiplies access control testing, because every combination of who-can-reach-what has to be checked. An application with one user type and one with five are not remotely the same job.
Distinct functionality, not page count
Two hundred near-identical product pages add almost nothing. A payment flow, a file upload, a reporting engine and an admin console each add real time, because each is a genuinely different attack surface.
Live hosts and service diversity
For infrastructure testing, the number of live IP addresses matters less than what is running on them. Thirty hosts running the same hardened build is a faster job than eight running eight different things.
How much information you provide
Grey-box testing with credentials and documentation finds substantially more per day than black-box. Insisting on black-box means paying skilled people to spend a day on reconnaissance that a real attacker would happily spend for free — and you get less security for the same money. There are good reasons to test black-box, but "it is more realistic" usually is not one of them.
Environment readiness
Credentials that do not work, an environment that falls over on day one, or a test system that has diverged from production all cost days. This is the most avoidable cost in the whole process and it is entirely within your control.
Onsite requirements
Travel and accommodation are real costs. Across the West Midlands and Shropshire we charge neither. Elsewhere in the UK and internationally, travel is quoted as a separate transparent line rather than folded into an inflated day rate.
Comparing quotes properly
A cheaper quote is very often a smaller quote. Before comparing totals, check each one for:
- Days of actual testing — and whether reporting time is inside that figure or added to it.
- Retest — included, or a separate line item you discover later.
- Who tests — the qualified person named in the proposal, or somebody else entirely.
- Manual versus automated — a quote dramatically below the others is usually a scan with a report template wrapped around it.
- Accreditation — CREST accredits the company against an audited standard. An individual holding a certification is a different claim, and proposal wording sometimes blurs the two deliberately.
- What you get at the end — a report you can hand to a client or auditor, or a tool export.
Compliance work
Cyber Essentials carries a fixed certification body fee banded by organisation size, plus whatever support you need on top. Cyber Essentials Plus costs more because it involves hands-on assessor time. IASME Cyber Assurance varies by level. We quote these separately and transparently, and we will tell you where you could reasonably do it yourselves.
What we will tell you for free
If a scoping conversation suggests you do not need a penetration test yet — because you have no multi-factor authentication, unsupported operating systems in production, or backups nobody has ever tested — we will say so. Testing an environment with obvious foundational gaps produces a report telling you what you already know, at a cost better spent fixing them.
Common questions
Why do you not publish a price list?
Because a fixed price for unknown scope is either padded to protect us or too low and renegotiated later, and neither is a good start. A short scoping call produces a firm quote for defined scope, and we hold it.
Can you give a ballpark before we talk?
On a call, yes, quickly. Most people know enough about their own systems within ten minutes of conversation for us to give a realistic range. What we will not do is put a number against a description we have not interrogated.
Is a cheaper provider worse?
Not necessarily. A smaller firm has genuinely lower overhead, which is part of why our rates sit below the large consultancies. But if a quote is dramatically below the others, look at the day count and the methodology rather than the total — it is usually an automated scan presented as a penetration test.
Do you charge for scoping?
No. Scoping calls, quotes, and honest advice about whether you need testing at all are free.
Are there payment terms for smaller organisations?
We work with SMEs, schools and charities regularly and will discuss staging work across a financial year where that makes a necessary programme achievable. Ask.
Related
Solusec
Typically replies within one business day
Hi 👋 Need a hand with pen testing, Cyber Essentials, or something urgent? Pick whichever suits you:
💬 WhatsApp usQuick questions, quick answers 📞 Call us
+44 (0)1902 288763 ✉️ Email us
info@solusec.co.uk 📝 Leave a message
We'll reply within one business day