Penetration testing costs vary because no two assessments are quite the same. The time required depends on what is being tested, the complexity of the environment, the level of access available and, importantly, what you need the testing to give you confidence in.
Penetration testing is therefore, usually priced in tester days. The scope determines how many days are needed, and those days determine the cost. A penetration test should be scoped around the question you need answered, not forced into a predefined package.
At Malwise, penetration testing is charged at £800 + VAT per tester day, with a minimum engagement of two tester days (£1,600 + VAT). A small external infrastructure assessment typically requires 2 to 3 tester days, while an authenticated web application with multiple roles will commonly require around 5 to 15 days depending on complexity. Larger internal, multi-site or combined assessments can extend considerably beyond this and may require multiple testers.
Why nobody publishes a single price
Because there is no single product. “A penetration test” can mean an external infrastructure assessment of eight addresses, or an authenticated test of a web application with five user roles and a payments flow, or an internal network engagement across three sites. Those are days apart in effort.
That is a real reason, not an excuse. The unhelpful part is stopping there, so here is what actually determines the number.
What drives the day count
- What is being tested. External infrastructure, an internal network, a web application, an application programming interface (API), a mobile application, a cloud tenant, or a combination. Each has its own methodology and its own realistic minimum.
- Size of the target. Live addresses for infrastructure. For an application, the number of distinct functions and user journeys, which correlates far better with effort than page count.
- Authenticated or unauthenticated. Testing as an anonymous attacker is one exercise. Testing as each user role increases the work and can uncover more serious issues such as privilege escalation or access-control weaknesses.
- Number of user roles. Every additional role adds permutations. Two roles is not twice one role, but it is not the same either.
- Complexity rather than size. A small application handling payments, personal data and third party integrations takes longer than a large brochure site.
- Retesting. Verifying fixes is part of the value. If retesting is excluded, the quote may be cheaper, but the engagement ends before the fixes are independently verified.
- Reporting and debrief. Writing findings so they can be acted on, and presenting them, takes time. A quote that looks cheap has often shortened this rather than the testing.
Typical engagement lengths
Penetration testing scoping is nuanced. Two environments that appear similar at first glance can require very different levels of effort once factors such as architecture, authentication, user roles, network segmentation, integrations, number of sites and the level of assurance required are understood.
The figures below are therefore, indicative rather than a price list. They are intended to give you a realistic flavour of likely effort and cost before a proper scoping conversation takes place.
| Engagement | Indicative tester days |
|---|---|
| Small external infrastructure, a handful of live addresses | 2 to 3 |
| Larger or more complex external infrastructure | 3 to 7 |
| Web application, unauthenticated or a single role | 3 to 5 |
| Web application, authenticated with multiple roles | 5 to 15+ |
| Small to medium internal network assessment | 3 to 10 |
| Larger, segmented or multi-site internal network assessment | 10 to 30+ |
| Combined external and internal assessment | 5 to 15+ |
| Larger or complex combined assessment | 10 to 30+ |
Multiply by the day rate and you have the shape of the cost. At £800 + VAT per tester day, a two day engagement is £1,600 + VAT, a five day engagement is £4,000 + VAT and a ten day engagement is £8,000 + VAT.
The amount of time allocated matters. More tester time allows greater depth of investigation, more manual testing and more opportunity to investigate and validate genuine security issues. It does not guarantee that more vulnerabilities will be found, but it gives the tester the time required to test the agreed scope properly.
Larger or more complex assessments may require multiple testers working in parallel. This increases the total number of tester days and therefore, the overall cost, without necessarily increasing the calendar duration by the same amount.
The right number of tester days should be driven by the scope and the level of assurance required, rather than by the lowest available price. The table gives a useful indication of cost, but the real price comes from understanding the scope properly rather than selecting a package from a menu.
What the price should include
Whatever the number, these belong inside it rather than beside it:
- A scope agreed and written down before work starts, with a fixed price
- Testing carried out by named, suitably qualified and experienced testers, with all testers identified in the final report
- A report with evidence, business context and prioritised remediation, not tool output with a cover page
- A debrief delivered by the person who did the testing
- Retesting of the findings within an agreed window
If a proposal is missing several of those, comparing it on price alone is comparing different things.
The underlying point is time. A well-scoped test gives the tester enough time and access to investigate the areas that matter, validate findings properly and produce results that can be acted upon. Compress that too far and the engagement still produces a report; it simply produces one with less behind it.
Ask every provider for the number of days, who is spending them, and what arrives at the end. A cheaper quote that buys fewer tester days, uses less experienced resource and produces little more than a scanner export has not saved you money. It may have bought you a report, but not necessarily the level of assurance you thought you were buying.
Why quotes differ so much
Days. The commonest cause. One provider scoped four days, another scoped one and a half.
Who does the work. Tester experience and competence matter. Recognised qualifications provide evidence of capability, but methodology and real-world experience matter too. We cover what the credentials actually mean in CHECK, CREST and The Cyber Scheme explained.
Manual against automated. Automated scanning can be completed relatively quickly; a penetration test requires manual investigation, validation and judgement. Both have value; only one of them is a penetration test. That distinction is set out in vulnerability assessment or penetration test.
What the deliverable is. Report quality is the largest hidden variable in any quote. What a penetration test report should contain sets out the standard to hold a provider to.
Whether retesting is included. Ask explicitly. It is frequently the difference.
Getting the cost down honestly
Scope precisely. A vague scope gets priced defensively. Knowing exactly which addresses, applications and roles are in play usually reduces the estimate.
Prepare the environment. Credentials ready, test accounts working, the right people available. Days lost to access problems are days you paid for.
Fix the obvious first. Running a vulnerability assessment and dealing with what it finds means the tester spends their time on business logic and attack paths rather than reporting missing patches. Better value, better findings.
Check whether a test is the right instrument. If the assessment is focused on your organisation’s wider IT environment, Cyber Essentials may be an appropriate first step to establish whether core security controls such as patching, secure configuration, multi-factor authentication and administrator access are in place. For a web application, API or other product-specific assessment, Cyber Essentials does not replace penetration testing, because it assesses the organisation rather than the product itself.
How we price it
We scope first and quote second. A short conversation about what you want tested and why, then a written proposal setting out the days, the scope, the deliverable and a fixed price. Testing is delivered by testers certified through The Cyber Scheme, and the report and debrief are part of the engagement rather than extras.
We scope engagements around what you need to understand, which systems need to be assessed, and what decisions the findings need to support. Those questions form the starting point for scoping and help us determine the level of effort required, alongside the technical complexity of the environment. That tends to produce a more useful engagement than starting from a number and working backwards.
The objective is not simply to complete a test. It is to make sure the engagement is capable of producing useful assurance and findings that can be acted upon. Where a smaller piece of work would answer the question properly, we will say that too.
If a scoping conversation shows that testing is not the right next step at all, we will say so.
Get in touch or call 01722 445972 for a scoped quote. More detail is on our penetration testing page.