AEO Answer

How Much Does Penetration Testing Cost in the UK?

Penetration testing in the UK typically costs £2,000 to £15,000+, depending on scope. A small external network test sits at the lower end; complex web-application or multi-environment testing reaches the top.

Quick answer

Penetration testing in the UK typically costs £2,000 to £15,000+, depending on scope. A small external network test sits at the lower end; complex web-application or multi-environment testing reaches the top. Price tracks the size of your attack surface, the test type, and whether social engineering is included. AMVIA scopes every test to your real risk, not a template.

Key Points

What UK businesses pay for penetration testing and what drives the price.

£2,000–£15,000+ depending on scope

A basic external network test for an SME runs £2,000–£5,000. Web application testing runs £3,000–£10,000 depending on application complexity.

Scope and test type drive the cost

Price is set by the number of IPs, applications and environments, by complexity (cloud, hybrid or on-premise), and by whether social engineering is included.

Use an accredited provider

Accreditation such as CREST (or CHECK for public sector) signals recognised standards for methodology, ethics and data handling. Many cyber insurers and compliance frameworks now expect accredited testers.

Annual testing for sensitive data

Annual pen testing is recommended for businesses handling sensitive data or pursuing certifications. With 22% of breaches involving compromised credentials (Verizon DBIR 2025), testing authentication controls pays back.

Quick Comparison

Feature
Option A
Option B

If you are weighing up a pen test as part of a wider security budget, read it alongside our managed cybersecurity guide for UK SMEs — a pen test is a point-in-time check, not a substitute for continuous monitoring. This guide breaks down what you actually pay, what changes the number, and how to tell a real test from an automated scan dressed up as one.

What does a penetration test cost in the UK?

A penetration test in the UK costs £2,000 to £15,000+ as of 2026, depending on what is in scope. A basic external network test for a typical SME is the cheapest engagement; web-application testing and full-scope work cost considerably more because they take more skilled tester days. The figures below are market ranges, not a fixed price list — always get a scoped quote.

Test typeTypical UK cost (2026)Best for
Basic external network test (SME)£2,000–£5,000Validating your internet-facing perimeter
Web application test£3,000–£10,000Apps handling logins, payments or customer data
Full / complex scope£2,000–£15,000+Cloud, hybrid or multi-environment estates

The single biggest lever on cost is tester time. A perimeter with a handful of public IPs is a couple of days' work; a bespoke web application with dozens of authenticated user journeys can run to a week or more. The NCSC's guidance on penetration testing is clear that a test is only as good as its scope — a cheap test against the wrong targets tells you nothing useful.

What drives the price of a penetration test?

Price is set by how much there is to test and how hard it is to test safely. The number of in-scope IP addresses, applications and environments sets the baseline; complexity and the type of test then move the number up or down. Social engineering and physical testing add cost because they need extra planning and sign-off.

The main cost drivers:

  • Scope — the count of IP addresses, applications and environments in the engagement.
  • Complexity — cloud, hybrid or on-premise; a single estate is cheaper than three.
  • Test type — external, internal, web application, wireless or red team.
  • Social engineering — phishing or pretext calling adds planning and reporting time.
  • Retesting — a re-test to confirm fixes have landed is often quoted separately.

Authentication is where attackers win, so it is worth paying to test it properly. With 22% of breaches involving compromised credentials (Verizon DBIR 2025), a test that exercises your login flows, MFA and privilege boundaries earns its fee. Pair pen testing with continuous vulnerability management so issues found are tracked and closed, not filed and forgotten.

What types of penetration test are there?

There are several test types, and most SMEs do not need all of them. The right mix depends on where your risk actually sits — a software business lives or dies by its web application, while a professional-services firm worries more about its perimeter and email. Scope to the assets that would hurt most if breached.

  • External network test — probes your internet-facing systems the way an opportunistic attacker would.
  • Internal network test — assumes a foothold (a stolen laptop, a phished account) and tests how far an intruder could move.
  • Web application test — examines a specific app for flaws like broken access control and injection.
  • Wireless test — checks your Wi-Fi segmentation and authentication.
  • Social engineering — tests your people and processes, not just your technology.

If you are not sure which applies, our penetration testing service page sets out how AMVIA scopes an engagement before any quote is issued.

Do you need an accredited penetration testing provider?

Look for recognised accreditation. CREST (or CHECK for public-sector work) signals that a testing firm meets agreed standards for methodology, ethics and data handling, and that its testers follow a structured approach rather than running an automated scanner and exporting the results. Many cyber insurers and compliance frameworks now expect tests to be carried out by accredited providers.

Accreditation matters because "penetration test" is an unregulated label. Anyone can sell one. The difference between a skilled manual test and an automated vulnerability scan with a nicer cover page is the difference between finding the chained flaw that actually gets someone in and producing a list of low-severity noise. Ask any prospective provider who will run the test, what methodology they follow, and how they handle your data during and after the engagement.

How does a pen test compare to Cyber Essentials Plus?

They do different jobs. Cyber Essentials Plus includes a hands-on technical audit that verifies five core controls are in place and working — it is a baseline assurance certification. A penetration test goes deeper, actively trying to exploit weaknesses across your real attack surface. Most businesses handling sensitive data want both.

Cyber Essentials PlusPenetration test
PurposeVerify five baseline controlsFind and exploit real weaknesses
DepthDefined audit checklistOpen-ended, attacker-led
OutputPass / fail certificationRanked findings + remediation
RenewalAnnualAfter major change or annually

Cyber Essentials is government-backed and worth holding regardless — see the official Cyber Essentials scheme for what it covers. The certification carries real insurance weight too: organisations certified with Cyber Essentials are 92% less likely to claim on cyber insurance (IASME). A pen test then gives auditors and insurers the granular, real-world evidence that certification alone does not. AMVIA holds Cyber Essentials Plus and uses it as the floor, not the ceiling.

How often should you run a penetration test?

Annually at minimum, and again after any major change. Annual pen testing is recommended for businesses handling sensitive data or pursuing certifications. A test is a snapshot — a new web feature, a cloud migration or a network redesign can introduce a flaw the day after a clean report, so re-test when your attack surface changes materially.

The UK threat picture makes the case on its own: the government's Cyber Security Breaches Survey 2025 shows cyber attacks remain a routine hazard for British businesses. Between annual tests, lean on continuous controls — managed detection and response catches what a point-in-time test cannot, because attackers do not wait for your testing window.

What should a penetration test report include?

A good report is written for two audiences. Leadership needs an executive summary that explains business risk in plain English; your technical team needs findings ranked by severity, evidence of exploitation, and prioritised, specific remediation steps. A report that is just a tool's raw output is not worth paying for.

A thorough report includes:

  • An executive summary for non-technical leadership.
  • Technical findings ranked by severity (critical, high, medium, low).
  • Evidence of exploitation — proof each finding is real, not theoretical.
  • Prioritised remediation guidance mapped to each finding.
  • A clear path to re-testing so you can prove fixes worked.

If you would rather spend on continuously closing gaps than on a once-a-year document, compare the cost of testing with the cost of managed protection in our guide to how much managed cybersecurity costs.

Frequently Asked Questions

Need More Detail?

Speak to an AMVIA expert for advice tailored to your business.