Skip to content
ResourcesPricing

What a penetration test costs in the UK, and what each price band buys

20 July 20267 min read
UK PRICE BANDS // WHAT EACH ONE BUYSUnder £1,500An automated scan with a report attached£2,500 to £8,000Human led web application test£8,000 to £15,000Complex platform, customer financial data£15,000 upwardTechnical due diligence for an acquirerSOURCES: PRECURSOR, AARDWOLF, FORTBRIDGE, SECFORCE

A UK web application penetration test costs roughly £2,500 to £8,000, rising to £8,000 to £15,000 where customer financial data is involved. Below about £500 a day you are buying an automated scan with a report stapled to it.

The bands, and what sits in each

Under £1,500: not a test

At this price nobody is spending human days on your application. You are buying an automated vulnerability scan, formatted. Scanners are genuinely useful for catching known issues in known software, and they find nothing that requires understanding your business logic.

Every finding that has ever mattered on a tax platform has been business logic. Whether a non paying account can file. Whether one customer can read another. A scanner does not know what a customer is.

£2,500 to £8,000: a real web application test

Two to five days of human testing, plus write up. This is the normal band for a SaaS product with a login, user roles and an API. Aardwolf publishes £2,500 to £8,000 for two to five days; Fortbridge publishes £3,000 to £8,000; Precursor starts at £2,500.

£8,000 to £15,000: complex, or handling money

More roles, more integrations, payment flows, and a higher bar because the consequences are worse. Anything holding customer financial records sits here on paper.

£15,000 and above: due diligence

UK technical due diligence for an acquirer runs £15,000 to £100,000. Different product, different buyer, usually private equity rather than the company itself.

The day rate underneath it all

  • CREST accredited firms: roughly £1,000 to £1,500 a day. SecForce publishes about £1,250 per consultant day, so a five day web application test lands near £6,250.
  • Experienced freelance testers: roughly £700 to £1,250 a day.
  • Below £500 a day: not a human led test. See above.

What actually moves the number

If a quote arrives without these questions being asked, it was not scoped.

  • How many distinct user roles are there, and can they see different data
  • Do you take payments, and is there a paid tier to bypass
  • How many API endpoints, and is there a public API
  • What do you integrate with that holds real authority, such as HMRC or a bank feed
  • Are we testing production or a staging copy with realistic data
  • Is a re-test of the fixes included, or quoted separately

The re-test question is the one people forget

A report of unfixed problems is not security, it is a list. The value arrives when someone independent confirms the fixes are real. Ask whether a re-test is included before you compare two quotes, because a cheaper test without one is not cheaper.

On one engagement we re-tested after the client's developers had shipped a fix, confirmed it was genuine, and found five more endpoints of the same class they had missed. That sequence is written up here. None of it would exist without the re-test.

Does it need to be CREST?

Not for ISO 27001 or SOC 2. Neither standard requires CREST accreditation. What an auditor expects is a qualified tester following a recognised methodology, such as the OWASP Testing Guide, PTES or NIST SP 800-115, with evidence in the report.

CREST does matter where a contract names it: some public sector work, and NHS DTAC guidance steers buyers towards it. Read your actual clause before paying the premium for a badge your contract does not ask for.

FAQ

Quick answers

How much does a penetration test cost in the UK?
Roughly £2,500 to £8,000 for a web application, rising to £8,000 to £15,000 where customer financial data is involved. The price is driven by days, and days by scope: user roles, payment flows, API size and integrations.
Why are some penetration tests only a few hundred pounds?
Because they are automated scans with a report attached, not human led tests. Scanners find known issues in known software. They cannot find business logic flaws, such as a non paying account reaching paid features, which is where the findings that matter usually live.
Should a re-test be included in the price?
Ask before comparing quotes. A report of unfixed problems is a list, not security. The value lands when someone independent confirms the fixes are genuine, and a cheaper test without a re-test is not actually cheaper.
Do I need a CREST accredited penetration tester?
Not for ISO 27001 or SOC 2, neither of which requires it. Auditors expect a qualified tester following a recognised methodology such as OWASP, PTES or NIST SP 800-115. CREST matters where a contract names it specifically, including some public sector work and NHS DTAC.

Who checks what your developers ship?

An independent security and build review of what your agency delivered. £2,500, about two weeks, with a re-test of their fixes included.