Most UK penetration testing firms will not print a price. You fill in a form, take a call, and wait for a quote. That makes it hard to budget and harder to compare.
This page prints the numbers that are already public. Every figure below carries a link to the page it came from and the date shown on that page. Nothing here is an estimate we made up. Where the public record is thin, we say so.
Figures checked on 19 August 2026.
The clearest UK price data is on a government website
UK suppliers who sell to the public sector must publish a price to appear on the G-Cloud framework. The listings sit on applytosupply.digitalmarketplace.service.gov.uk, a Crown Commercial Service site. Anyone can read them.
These are supplier-declared day rates, not a market average. Read each one as that supplier's own number.
| Supplier |
Service as listed |
Published day rate |
Source |
| Reply Limited |
Penetrating Testing Services |
£410 a unit a day |
G-Cloud listing |
| Periculo Limited |
CREST Network Penetration Test |
£750 a unit a day |
G-Cloud listing |
| Periculo Limited |
CREST Web Application Penetration Test |
£750 a unit a day |
G-Cloud listing |
| Cyber Security Specialists Limited |
CREST Penetration Testing |
£700 to £1,250 a unit a day |
G-Cloud listing |
| Incursion Cyber Security Ltd |
Penetration Testing |
£800 to £1,200 a unit a day |
G-Cloud listing |
| Armadillo Sec Ltd |
Mobile Application Penetration Testing |
£800 to £1,350 a unit a day |
G-Cloud listing |
| Razorthorn Security Ltd |
Internal / External Infrastructure Penetration Testing |
£850 to £1,150 a unit a day |
G-Cloud listing |
| Claranet Limited |
Internal Infrastructure Penetration Testing |
£1,000 to £1,500 a unit a day |
G-Cloud listing |
All eight rows come from the G-Cloud 14 framework, which opened in 2024. The listing pages carry no visible update stamp. The attached service documents are dated between April and May 2024.
What the table shows: declared day rates across these eight listings run from £410 to £1,500. Do not read that as one market rate. Read it as the spread between a large systems integrator and a specialist firm.
Vendor rate cards that print a price
A small number of UK firms publish a fixed starting price by scope. These are list prices set by one seller. They are useful anchors. They are not market data.
Precursor Security, a CREST member, publishes a full rate card. The page is marked "Updated August 2026".
| Test type |
Precursor Security list price |
| External network penetration test |
Starting at £2,500 |
| API security assessment |
Starting at £2,500 |
| Wireless penetration testing |
Starting at £2,500 |
| Web application penetration test |
Starting at £3,750 |
| Mobile application test |
Starting at £3,750 |
| Cloud penetration testing |
Starting at £3,750 |
| Internal network penetration test |
Starting at £6,250 |
| NCSC IT Health Check |
Starting at £8,750 |
Source: Precursor Security penetration testing, updated August 2026.
On its cost page, the same firm states "approximately £1,200 per CREST-accredited consultant day" and a project spread "from £2,500 (external network, 2-3 days) to £25,000+ (full security assessment, 10-20 days)". It also warns that "Day rates under £500 typically indicate automated scanning". Source: Precursor Security pentest cost, updated August 2026.
SECFORCE publishes a day rate benchmark and a worked example. It states "£1000–£1500(€1200- €1800)/day -Typical range for thorough manual pen testing" and "A typical web application pen test might take around 6 days and cost £6,000". Source: SECFORCE pen testing price list, published 24 April 2025.
Aardwolf Security, a CREST member, publishes its own day rate: "Aardwolf Security starts from £750 per day". It also states that you should "Expect to pay roughly 15 to 25 per cent more for a CREST-accredited provider". Source: Aardwolf Security pentest cost guide, 16 June 2026.
A warning about UK cost guides. Several UK vendor blogs repeat the same numbers word for word. The "£1,200 fair day rate" line and the "under £500 means automated scanning" line appear on page after page. Treat any vendor cost guide as that vendor's marketing, not as a survey. The G-Cloud listings above are stronger because the supplier had to declare the price to win public work.
What drives the price up
Five things move the number, in this order.
- Scope. Count the applications, the API endpoints, the IP ranges and the hosts. One web application costs far less than a whole estate.
- Days. Almost every UK firm prices by consultant day. Scope sets the days. Days set the price.
- Depth. An unauthenticated black-box test is cheaper. An authenticated test with source code review finds more and costs more.
- Accreditation. CREST membership carries a premium. Aardwolf Security puts it at 15 to 25 per cent.
- Re-tests. Ask whether the re-test after you fix the findings is in the price or billed again. Many firms bill it again.
What the NCSC says about the limits of a pentest
The National Cyber Security Centre is blunt about what you buy.
"A penetration test can only validate that your organisation's IT systems are not vulnerable to known issues on the day of the test."
Source: NCSC penetration testing guidance, published 8 August 2017, last reviewed 10 January 2022.
The same guidance notes that "It's not uncommon for a year or more to elapse between penetration tests". That gap is the real cost. You pay once, you get one day of assurance, and then you ship code for another twelve months.
Do you need CREST or CHECK?
This is where UK buyers get bad advice. Here is the position.
CHECK is an NCSC scheme, and it is scoped to public work. The NCSC states that CHECK is "the scheme under which NCSC assured companies can conduct authorised penetration tests of public sector and CNI systems". Its audience is "central government departments, public sector bodies, UK critical national infrastructure (CNI)". Source: NCSC CHECK.
For those systems, the NCSC guidance is strong: "All systems processing data protectively marked OFFICIAL and above (up to Top Secret but excluding STRAP systems) should be assessed by companies assured under CHECK". Source: NCSC using a CHECK provider.
If you are not public sector or CNI, the NCSC does not tell you to use CHECK. The CHECK page says so directly and points private organisations to the general commissioning guidance instead.
No UK law requires CREST. CREST is a private accreditation body. It describes itself as "a global community of cyber security businesses and professionals". It is a delivery partner for NCSC CHECK and for the Bank of England CBEST scheme, the Cabinet Office GBEST scheme and the UK CAA ASSURE scheme. Source: CREST.
Cyber Essentials Plus does not require CREST. IASME requires the assessor to hold a listed qualification or pass the IASME and NCSC Vulnerability Assessment Plus exam, and to work for an IASME-accredited certification body. Source: IASME Cyber Essentials.
One deadline worth knowing. CREST states that "From 31 March 2025, CHECK Team Leaders (CTLs) must obtain a UK CSC Professional Title in the Security Testing specialism", and that "By 31st March 2026, all CTMs must achieve the UK CSC Security Testing Title at the 'Practitioner' level". Source: CREST CHECK.
So the honest answer is this. You need CREST or CHECK when your buyer, your regulator or your contract asks for it. Public sector work, CNI work, CBEST and ASSURE work all ask for it. A private SaaS company selling to other private companies usually does not need it, but an enterprise customer may still write it into a security schedule. Read the contract before you shop.
Only 13 per cent of UK businesses run a penetration test
The government's own survey puts the adoption rate low. The Cyber Security Breaches Survey 2025/2026 found penetration testing was carried out by 13% of businesses and 7% of charities, while 43% of UK businesses reported breaches or attacks in the past 12 months. Source: DSIT Cyber Security Breaches Survey 2025/2026, published 30 April 2026.
That survey does not publish cost data. It measures adoption only.
What we could not source
We list the gaps because a price guide that hides them is not honest.
- No major named UK consultancy publishes a day rate on its own website. We checked Pentest People, Bulletproof, JUMPSEC, Prism Infosec, AppCheck, Nettitude/LRQA, Redscan and Evalian. Every one routes to a quote form.
- No UK trade body publishes a rate card. CREST publishes no price data. The NCSC publishes no price data.
- No official CHECK or CREST price list exists. The G-Cloud listings are the only government-hosted price data we found.
- We found no UK red team day rate from 2025 or 2026. The one G-Cloud red team listing we found carries 2022 documents, so we left it out.
- We did not convert any figure. Some UK vendor pages quote USD. We do not print a converted number as a UK price.
Where Matproof Sentinel fits, and where it does not
Matproof Sentinel is an AI penetration testing platform. Prices are public, in euros, with no quote call: €149 per single run, €299 per month, €1,490 per month, and Custom for enterprise. See pricing.
Sentinel runs ten specialised AI agents in stages. Recon maps the surface with nmap, amass and httpx. Web, API, Infra, Cloud and Mobile agents run in parallel with nuclei, sqlmap, OWASP ZAP, testssl.sh, Prowler and MobSF. Source-code and supply-chain agents read your repositories with Semgrep, Gitleaks and Trivy. A ValidatorAgent then re-runs every finding and stamps it VALIDATED, UNVERIFIED or FALSE_POSITIVE. The full method is public at docs.matproof.com.
Be clear about what Sentinel is not.
- There is no human penetration tester. Every finding comes from an AI agent and is checked by another AI agent.
- Matproof holds no CREST membership and no CHECK approval. Our people hold no OSCP badge that we advertise.
- Sentinel does no social engineering, no physical intrusion and no zero-day research.
- Sentinel cannot give you a CREST-signed report.
So do not buy Sentinel if your customer contract, your regulator or a public tender names CREST, CHECK, CBEST, GBEST or ASSURE. Hire an accredited UK firm. That is the right call and we will say so.
Buy Sentinel if you ship code often, you need current evidence between annual tests, and your auditor wants proof that testing runs all year rather than once. That is the gap the NCSC describes, and it is the gap we fill.
Most mature teams run both. One accredited engagement a year for the signature. Continuous automated testing in between for the evidence.
Frequently asked questions
How much does a penetration test cost in the UK?
Published UK day rates run from £410 to £1,500 across the eight G-Cloud listings above. Vendor list prices for a project start around £2,500 for an external network test and around £3,750 for a web application test, per Precursor Security in August 2026. Your price depends on scope and days.
What is a fair UK day rate?
Two UK vendors publish a number. SECFORCE gives £1,000 to £1,500 per day for thorough manual testing, in April 2025. Precursor Security gives about £1,200 per CREST-accredited consultant day, in August 2026. Neither is an independent survey.
Does a CREST provider cost more?
Aardwolf Security says yes, by roughly 15 to 25 per cent. That is one vendor's view, published in June 2026. We found no independent study.
Is CREST required by law in the UK?
No. CHECK is required in practice for UK public sector and CNI systems at OFFICIAL and above, under NCSC guidance. Private organisations are not told to use CHECK. CREST is a private accreditation, not a legal requirement.
Why do so few firms publish prices?
Because the work is priced per day against a custom scope. A published price commits the seller before the scope is known. The cost to the buyer is friction. You cannot compare or budget without several calls.
Related reading
Ready to act on this? Matproof runs continuous AI penetration testing with public pricing. Book a demo.