What Does a Penetration Test Cost?

Almost nobody in this industry explains how the number is arrived at. Here is what actually drives it, and what to check before you compare two quotes.

Priced on
Day rate × scoped days
Scoping call
Free
Quotes
Fixed for defined scope
Retest
Included, not extra

How testing is priced

Almost universally: a day rate multiplied by the number of days a competent tester needs. The day rate varies between providers, largely reflecting overhead rather than tester quality — a large consultancy has offices, account managers and a sales function to fund, and that is in the number.

So the figure that actually determines your bill is the day count. That is where quotes diverge most, and where your attention is best spent when comparing.

We quote on a call rather than through a form, and the quote is fixed for the scope agreed. If the scope changes materially we will tell you before doing the work, not afterwards.

What genuinely moves the number

User roles

The single biggest driver on application testing, and the one most often understated. Each additional role multiplies access control testing, because every combination of who-can-reach-what has to be checked. An application with one user type and one with five are not remotely the same job.

Distinct functionality, not page count

Two hundred near-identical product pages add almost nothing. A payment flow, a file upload, a reporting engine and an admin console each add real time, because each is a genuinely different attack surface.

Live hosts and service diversity

For infrastructure testing, the number of live IP addresses matters less than what is running on them. Thirty hosts running the same hardened build is a faster job than eight running eight different things.

How much information you provide

Grey-box testing with credentials and documentation finds substantially more per day than black-box. Insisting on black-box means paying skilled people to spend a day on reconnaissance that a real attacker would happily spend for free — and you get less security for the same money. There are good reasons to test black-box, but "it is more realistic" usually is not one of them.

Environment readiness

Credentials that do not work, an environment that falls over on day one, or a test system that has diverged from production all cost days. This is the most avoidable cost in the whole process and it is entirely within your control.

Onsite requirements

Travel and accommodation are real costs. Across the West Midlands and Shropshire we charge neither. Elsewhere in the UK and internationally, travel is quoted as a separate transparent line rather than folded into an inflated day rate.

Comparing quotes properly

A cheaper quote is very often a smaller quote. Before comparing totals, check each one for:

  • Days of actual testing — and whether reporting time is inside that figure or added to it.
  • Retest — included, or a separate line item you discover later.
  • Who tests — the qualified person named in the proposal, or somebody else entirely.
  • Manual versus automated — a quote dramatically below the others is usually a scan with a report template wrapped around it.
  • Accreditation — CREST accredits the company against an audited standard. An individual holding a certification is a different claim, and proposal wording sometimes blurs the two deliberately.
  • What you get at the end — a report you can hand to a client or auditor, or a tool export.

Compliance work

Cyber Essentials carries a fixed certification body fee banded by organisation size, plus whatever support you need on top. Cyber Essentials Plus costs more because it involves hands-on assessor time. IASME Cyber Assurance varies by level. We quote these separately and transparently, and we will tell you where you could reasonably do it yourselves.

What we will tell you for free

If a scoping conversation suggests you do not need a penetration test yet — because you have no multi-factor authentication, unsupported operating systems in production, or backups nobody has ever tested — we will say so. Testing an environment with obvious foundational gaps produces a report telling you what you already know, at a cost better spent fixing them.

Common questions

Why do you not publish a price list?

Because a fixed price for unknown scope is either padded to protect us or too low and renegotiated later, and neither is a good start. A short scoping call produces a firm quote for defined scope, and we hold it.

Can you give a ballpark before we talk?

On a call, yes, quickly. Most people know enough about their own systems within ten minutes of conversation for us to give a realistic range. What we will not do is put a number against a description we have not interrogated.

Is a cheaper provider worse?

Not necessarily. A smaller firm has genuinely lower overhead, which is part of why our rates sit below the large consultancies. But if a quote is dramatically below the others, look at the day count and the methodology rather than the total — it is usually an automated scan presented as a penetration test.

Do you charge for scoping?

No. Scoping calls, quotes, and honest advice about whether you need testing at all are free.

Are there payment terms for smaller organisations?

We work with SMEs, schools and charities regularly and will discuss staging work across a financial year where that makes a necessary programme achievable. Ask.

Related

Ready to talk?

Scoping conversations are free and there is no sales team to get past. Tell us what you're dealing with and we'll tell you honestly what you need.