Field Notes / Buying Security
What a Penetration Test Costs in the UK: Nine Published Day Rates, From £525 to £2,885
Nine UK suppliers print their penetration testing day rate on the government’s Digital Marketplace, where commercial buyers rarely look. BAE Systems Applied Intelligence publishes £525 a day. KPMG publishes a band running to £2,885. Published day counts for the same test type vary four times over. Here is the arithmetic behind a quote, the published ranges by test type, and the scope lines that move the number before anyone starts testing.
01 A quote is a day rate times a day count
Intruder puts it plainly: penetration tests are "usually quoted on a 'day-rate' basis" Intruder, Jan 2026 . JUMPSEC adds that "day rates are typically flat, or tiered based on the seniority of the consultant carrying out the test" JUMPSEC, Sep 2025 . EJN Labs sells the opposite arrangement and says so: every figure on its page is a scope-based fixed price agreed before work starts, rather than a day rate multiplied by a day count EJN Labs, Aug 2026 . Precursor Security does the same, quoting a fixed price after a free scoping call Precursor Security, Aug 2026 .
Either way, two numbers built the figure you are looking at. Ask for both. The published day counts are easier to find than the rates. Precursor lists three to five days for an external network test, five to eight for an internal network test, and ten to twenty for a full assessment Precursor Security, Aug 2026 . SECFORCE says a typical web application test takes "around 6 days and cost £6,000" SECFORCE, Apr 2025 . EJN Labs lists six to twelve days for the same web application test EJN Labs, Aug 2026 .
Now multiply. Five days at BAE Systems Applied Intelligence's published £525 costs £2,625 BAE Systems AI, G-Cloud 14 . The same five days at Dionach's published £1,000 costs £5,000 Dionach, G-Cloud 14 . At the top of PureCyber's published band it costs £7,000 PureCyber, G-Cloud 14 . Change the day count from five to twelve and the same rates produce £6,300, £12,000 and £16,800. That is market arithmetic from published sources, not a survey. Two suppliers selling you the same five days can land £4,375 apart before anyone argues about scope.
02 Nine UK suppliers publish their day rate
Nine suppliers already print the number, on a government procurement platform where commercial buyers rarely go. Every G-Cloud service page prints one price line, and the URLs are stable, so you can open each of these and read the figure yourself. All nine sit under G-Cloud 14, Lot 3 Cloud Support.
| Supplier | Listing | Published day rate |
|---|---|---|
| BAE Systems Applied Intelligence | Penetration Testing Services | £525 |
| Periculo | CREST Network Penetration Test | £750 |
| PureCyber | Infrastructure Penetration Testing | £750 to £1,400 |
| DigitalXRAID | Penetration Testing | £800 to £1,150 |
| DigitalXRAID | CHECK Penetration Testing | £800 to £1,250 |
| Armadillo Sec | Web Application Penetration Testing | £800 to £1,350 |
| Dionach | Penetration Testing | £1,000 |
| Worknest Cyber | Penetration Testing (PTaaS) | £1,000 |
| KPMG | Cyber Security Penetration Testing and Continuous Security Testing and Assurance | £400 to £2,885 |
Nine listings, opened on 21 September 2026 Digital Marketplace, G-Cloud 14 . Treat them as nine real prices, not as a UK average, because nine suppliers are not a market. None of the nine pages states VAT treatment. The pricing documents behind them are dated between 2022 and 2024, which is what publication on G-Cloud 14 means.
These listings also settle an argument the price guides keep having. SECFORCE marks anything under £500 a day "Risky. Likely not a real pen test" SECFORCE, Apr 2025 , and Precursor Security writes that day rates under £500 "typically indicate automated scanning, not manual testing" Precursor Security, Aug 2026 . Both are vendors, and both sell above that line. BAE Systems Applied Intelligence publishes £525 a day on a government framework, and KPMG's published band starts at £400 KPMG, G-Cloud 14 . The procurement record cuts against the rule. Judge the day count and the reporting standard instead. Those are the parts a thin quote actually cuts.
03 What the price guides say, by test type
Five of the published UK guides carry numbers by test type. They agree on the shape and disagree on the numbers, sometimes by a factor of three for the same words in a scope line. Read them as five opinions from people selling the service, each with a date attached.
| Test type | JUMPSEC (14 Sep 2025) | Precursor (Aug 2026) | Fortbridge (Jun 2026) | EJN Labs (Aug 2026) |
|---|---|---|---|---|
| Web application | £2,500 to £8,000 | £3,750 to £6,250+ (3 to 5 days) | £4,000 to £25,000+ by size | £8,000 to £18,000 (6 to 12 days) |
| External network | £3,000 to £6,000 | £3,750 to £6,250+ (3 to 5 days) | £3,000 to £5,000 | £6,500 to £12,000 (3 to 5 days) |
| Internal network | £5,000 to £12,000 | £6,250 to £10,000+ (5 to 8 days) | £5,000 to £10,000 | Not listed separately |
| Full assessment, large or complex estate | £10,000 to £20,000+ | £12,500 to £25,000+ (10 to 20 days) | Standard £4,000 to £30,000+, larger above £40,000 | Standard tests £6,000 to £18,000 |
| Red teaming | £20,000 to £50,000+ | Not listed | Not listed | £15,000 to £35,000 focused; intelligence-led from £75,000 |
Cyphere runs wider than all of them, putting web application testing at £2,500 to £30,000, network testing at £3,500 to £30,000 with an average of £5,000 to £15,000, and stating that the maximum cost of penetration testing "exceeds £100,000" Cyphere, Apr 2026 . Cyphere also puts the useful floor in one sentence: "The minimum cost for pen testing is £2,000 for limited-scope assessments."
Pick the row you are buying and look across it. A web application test has a published floor of £2,500 and a published ceiling above £25,000, for a scope line that reads the same either way. An external network test runs from £3,000 to £12,000 depending only on whose page you opened. The number on your quote sits inside that spread because of choices made during scoping, and those choices are the next chapter.
04 The scope lines that move the day count
The NCSC last reviewed its penetration testing guidance on 10 January 2022, and the scoping list in it has not aged NCSC penetration testing . A scoping document should set out the technical boundaries of the test, the types of test expected, the timeframe and the amount of effort necessary, the scenarios or use cases to be covered, the testing team's requirements, the compliance and reporting requirements, and any time constraints. Each of those lines has a day count attached to it.
- The technical boundary. One external range and one web application is a different estate from the same web application plus its APIs, its staging environment and the identity provider behind it. The NCSC calls this the technical boundaries of the test. A buyer calls it the thing that doubled the quote.
- The type of test expected. An unauthenticated test looks at what an anonymous attacker reaches. Adding credentialed roles means the tester works through each privilege level and the paths between them. Same systems, more days.
- The effort, written down. The NCSC asks for the timeframe and the amount of effort necessary in the scoping document itself. That is the day count, on paper, before anyone quotes. Ask for it in those words and the two quotes in front of you become comparable.
One more line decides more of the price than any other: whether you are buying a scan or a test. The PCI Security Standards Council draws it precisely. A vulnerability scan is "typically a variety of automated tools combined with manual verification of identified issues" and takes "several seconds to several minutes per scanned host". A penetration test is "a manual process that may include the use of vulnerability scanning or other automated tools" and lasts days or weeks PCI SSC, Sep 2017 . Minutes against weeks is the gap between the two prices, and we wrote the longer version of that distinction in penetration testing versus vulnerability scanning.
05 How to read the quote when it arrives
CREST published a standard for this in June 2023, and most buyers have never seen it. The CREST Defensible Penetration Test sets out three phases, scoping, delivery and sign off, and a minimum set of things the report must contain CREST CDPT, Jun 2023 . Scoping "must be undertaken by a suitably skilled individual that has signed the CREST Code of Conduct". Sign off is "a formal attestation that the CDPT was conducted in accordance with the CREST Defensible Penetration Tester's methodology, and that the assessment was delivered against the agreed scope". Hold your quote against the reporting list:
- The goals and objectives of the assignment, and the scope, including exclusions, restrictions and the coverage actually gained.
- Full results, with "sufficient information...to allow the client to understand and replicate the issue themselves".
- A timeline of the key activities conducted, with logs available on request, covering accounts modified, binaries executed and access attempts.
- Each vulnerability risk-assessed against an agreed methodology with a CVSS severity rating, and remediation advice for each one.
- A statement of totality against the defined scope, and the CREST IDs of the people who scoped and delivered the test.
- Any deviation from scope during delivery, formally documented in the sign-off.
Two more questions come from the PCI guidance PCI SSC, Sep 2017 . First, independence: the tester "must be organizationally separate from the management of the target systems". PCI spells out the case that bites hardest. A third party running your PCI DSS assessment cannot perform the penetration test if they were involved in the installation, maintenance or support of the target systems. Second, qualifications. PCI lists OSCP, CEH, GIAC, CREST and CHECK as examples and then says plainly that "appropriate penetration testing experience and qualifications cannot be met by certifications alone". Treat a logo on a proposal as the start of the question. Ask what the named tester has done.
06 If the number is wrong for what you need
Some buyers open a price guide, see red teaming at £20,000 to £50,000 or more JUMPSEC, Sep 2025 , and assume the expensive product is the serious one. The NCSC published guidance on adversary simulation on 17 September 2026 that says otherwise, and it is the only regulator-voice answer to the question NCSC adversary simulation . Before you qualify to buy one you need your risks "identified, assessed, and be regularly reviewing their risks", "well-established mitigations and defences in place", and "robust network monitoring and detection systems". Organisations with "relatively small and simple networks, or still developing an understanding of risk" are told to use other NCSC-assured schemes such as Cyber Essentials or Cyber Advisors instead.
The NCSC publishes the effort too, and that explains the price. It puts a typical adversary simulation at eight to twelve weeks, and a full spectrum engagement in the region of sixteen weeks NCSC adversary simulation . Sixteen weeks of operator time at any of the day rates in the table above lands in six figures, which is where the published red team ranges sit. We wrote up that guidance in full in what the NCSC says a red team is. If you are below the bar, the cheaper answer is the correct one: Cyber Essentials first, then a scoped penetration test of the estate that matters.
One note on CHECK, since it appears on price pages as a premium tier. The NCSC states that CHECK "has been developed specifically for" central government, public sector bodies and critical national infrastructure, and that penetration testing "can be undertaken by any organisation" NCSC CHECK . A private company paying a CHECK premium is buying a scheme built for somebody else's procurement rules.
We do not publish a rate card, and this article is not a disguised one. What we publish instead is the arithmetic, because a buyer who knows the day count, the day rate and the reporting standard can compare any two quotes in the market, including ours. Our continuous penetration testing runs one CREST-certified engagement, then unlimited human-verified re-tests for twelve months as the estate changes. Re-testing is the line in this market most worth reading twice on any quote, ours included.
If you do not yet know what your estate needs, price is the wrong question to start with. Book the free audit. Thirty minutes with a CREST-certified operator, and you leave with where an attacker would start on your systems, what a test of that estate has to cover, and a plain-language list of what to fix first. Then go and collect quotes, with the day count written down.
References
Sources
- Crown Commercial Service, Digital Marketplace. BAE Systems Applied Intelligence Ltd, "Penetration Testing Services", G-Cloud 14, Lot 3 Cloud Support. £525 a unit a day. applytosupply.digitalmarketplace.service.gov.uk
- Crown Commercial Service, Digital Marketplace. Periculo Ltd, "CREST Network Penetration Test", G-Cloud 14. £750 a unit a day. applytosupply.digitalmarketplace.service.gov.uk
- Crown Commercial Service, Digital Marketplace. PureCyber Ltd, "Infrastructure Penetration Testing", G-Cloud 14. £750 to £1,400 a unit a day. applytosupply.digitalmarketplace.service.gov.uk
- Crown Commercial Service, Digital Marketplace. DigitalXRAID Ltd, "Penetration Testing", G-Cloud 14. £800 to £1,150 a unit a day. applytosupply.digitalmarketplace.service.gov.uk
- Crown Commercial Service, Digital Marketplace. DigitalXRAID Ltd, "CHECK Penetration Testing", G-Cloud 14. £800 to £1,250 a unit a day. applytosupply.digitalmarketplace.service.gov.uk
- Crown Commercial Service, Digital Marketplace. Armadillo Sec Ltd, "Web Application Penetration Testing", G-Cloud 14. £800 to £1,350 a unit a day. applytosupply.digitalmarketplace.service.gov.uk
- Crown Commercial Service, Digital Marketplace. Dionach Ltd, "Penetration Testing", G-Cloud 14. £1,000 a unit a day. applytosupply.digitalmarketplace.service.gov.uk
- Crown Commercial Service, Digital Marketplace. Worknest Cyber Ltd, "Penetration Testing (PTaaS)", G-Cloud 14. £1,000 a unit a day, including one remediation check on five internet-facing vulnerabilities within six months. applytosupply.digitalmarketplace.service.gov.uk
- Crown Commercial Service, Digital Marketplace. KPMG LLP, "Cyber Security Penetration Testing and Continuous Security Testing and Assurance", G-Cloud 14. £400 to £2,885 a unit a day. applytosupply.digitalmarketplace.service.gov.uk
- SECFORCE. "Pen Testing Price List UK and EU Guide", published 24 April 2025. secforce.com
- Precursor Security. "Penetration Testing Cost UK", page updated August 2026. precursorsecurity.com
- JUMPSEC. "How Much Does Penetration Testing Cost in the UK?", published 14 September 2025. jumpsec.com
- Cyphere. "Penetration Testing Cost in UK 2026", published 7 April 2026. thecyphere.com
- Fortbridge. "Penetration Testing Cost UK: Pricing Guide 2026", published 23 March 2026, updated 30 June 2026. fortbridge.co.uk
- EJN Labs. "Penetration Testing Cost UK: 2026 Pricing Guide", published 28 April 2026, updated 7 August 2026. ejnlabs.com
- Intruder. "How much does penetration testing cost?", updated 2 January 2026. intruder.io
- NCSC. "Penetration testing" guidance, last reviewed 10 January 2022. ncsc.gov.uk
- NCSC. "CHECK: penetration testing". ncsc.gov.uk
- CREST. "CREST Defensible Penetration Test", guidance for commercially reasonable assurance activity, June 2023 (v5-2). crest-approved.org
- PCI Security Standards Council. "Information Supplement: Penetration Testing Guidance", version 1.1, September 2017. listings.pcisecuritystandards.org
- NCSC. "Adversary simulation: what you need to know", published 17 September 2026. ncsc.gov.uk
- DSIT and Home Office. Cyber Security Breaches Survey 2025/2026. Official statistics, 30 April 2026. gov.uk
- DSIT. Cyber Security Sectoral Analysis 2026, published 12 May 2026. gov.uk