Pricing
How we price our work — testing, certification and monitoring — in plain terms. Scoping calls are free, quotes are fixed for the scope we agree, and we’ll tell you honestly where you could spend less.
Cyber security isn’t one product, so it isn’t one price. This page sets out how we cost each part of what we do — penetration testing, certification and compliance, and monitoring and response. Two things hold across all of it: the scoping call is free, and the quote we give is fixed for the scope we agree.
Penetration testing
Testing is the least predictable to price up front, because it’s quoted on the days a competent tester needs rather than a fixed sticker price. Here is what actually drives that number.
How testing is priced
Almost universally: a day rate multiplied by the number of days a competent tester needs. The day rate varies between providers, largely reflecting overhead rather than tester quality: a large consultancy has offices, account managers and a sales function to fund, and that is in the number.
So the figure that actually determines your bill is the day count. That is where quotes diverge most, and where your attention is best spent when comparing.
We quote on a call rather than through a form, and the quote is fixed for the scope agreed. If the scope changes materially we will tell you before doing the work, not afterwards.
What genuinely moves the number
User roles
The single biggest driver on application testing, and the one most often understated. Each additional role multiplies access control testing, because every combination of who-can-reach-what has to be checked. An application with one user type and one with five are not remotely the same job.
Distinct functionality, not page count
Two hundred near-identical product pages add almost nothing. A payment flow, a file upload, a reporting engine and an admin console each add real time, because each is a genuinely different attack surface.
Live hosts and service diversity
For infrastructure testing, the number of live IP addresses matters less than what is running on them. Thirty hosts running the same hardened build is a faster job than eight running eight different things.
How much information you provide
Grey-box testing with credentials and documentation finds substantially more per day than black-box. Insisting on black-box means paying skilled people to spend a day on reconnaissance that a real attacker would happily spend for free, and you get less security for the same money. There are good reasons to test black-box, but "it is more realistic" usually is not one of them.
Environment readiness
Credentials that do not work, an environment that falls over on day one, or a test system that has diverged from production all cost days. This is the most avoidable cost in the whole process and it is entirely within your control.
Onsite requirements
Travel and accommodation are real costs. Across the West Midlands and Shropshire we charge neither. Elsewhere in the UK and internationally, travel is quoted as a separate transparent line rather than folded into an inflated day rate.
Comparing quotes properly
A cheaper quote is very often a smaller quote. Before comparing totals, check each one for:
- Days of actual testing, and whether reporting time is inside that figure or added to it.
- Retest: included, or a separate line item you discover later.
- Who tests: the qualified person named in the proposal, or somebody else entirely.
- Manual versus automated: a quote dramatically below the others is usually a scan with a report template wrapped around it.
- Accreditation: CREST accredits the company against an audited standard. An individual holding a certification is a different claim, and proposal wording sometimes blurs the two deliberately.
- What you get at the end: a report you can hand to a client or auditor, or a tool export.
Cyber Essentials & certification
Certification is far more predictable than testing, because the core fee is set by IASME and banded by organisation size. For Cyber Essentials the assessment fee is:
- Micro (0–9 staff): £320 + VAT
- Small (10–49): £440 + VAT
- Medium (50–249): £500 + VAT
- Large (250+): £600 + VAT
On top of the fee is whatever support you need to get the controls right and pass the assessment — for many organisations the larger part of the cost, and the part we’re straight about before you commit. Eligible UK organisations under £20m turnover also get cyber-liability insurance included. Our full breakdown is on the Cyber Essentials cost page.
Cyber Essentials Plus costs more because it adds a hands-on technical audit, and is priced by the number of devices in scope — commonly £1,500–£8,000 + VAT on top of the base fee. IASME Cyber Assurance is priced by level (verified self-assessment or independent audit), and DSPT support is quoted by provider size and where you’re starting from. We quote each strand separately and transparently, and we’ll tell you where you could reasonably do it yourselves.
Monitoring & response
Ongoing services — SOC consulting and support, vulnerability management and incident response — are scoped to your environment (users, endpoints, log sources) rather than sold as a fixed shrink-wrapped package. For a live incident we can work on a retainer or an emergency basis; tell us what’s happening and we’ll be straight about cost and priorities.
Common questions
How is certification priced compared with a penetration test?
Very differently. A penetration test is quoted on scoped days, so it moves with what’s being tested. Certification is far more fixed: Cyber Essentials has a set IASME fee banded by size (from £320 + VAT) with support on top, while Cyber Essentials Plus, IASME Cyber Assurance and DSPT support are quoted separately. We price each strand transparently.
Why do you not publish a price list?
Because a fixed price for unknown scope is either padded to protect us or too low and renegotiated later, and neither is a good start. A short scoping call produces a firm quote for defined scope, and we hold it.
Can you give a ballpark before we talk?
On a call, yes, quickly. Most people know enough about their own systems within ten minutes of conversation for us to give a realistic range. What we will not do is put a number against a description we have not interrogated.
Is a cheaper provider worse?
Not necessarily. A smaller firm has genuinely lower overhead, which is part of why our rates sit below the large consultancies. But if a quote is dramatically below the others, look at the day count and the methodology rather than the total: it is usually an automated scan presented as a penetration test.
Do you charge for scoping?
No. Scoping calls, quotes, and honest advice about whether you need testing at all are free.
Are there payment terms for smaller organisations?
We work with SMEs, schools and charities regularly and will discuss staging work across a financial year where that makes a necessary programme achievable. Ask.
Related
Ready to talk?
Scoping conversations are free and there is no sales team to get past. Tell us what you're dealing with and we'll tell you honestly what you need.