The UK market is crowded. Boutiques, large consultancies, freelancers and platforms all sell "penetration testing", and most of them will not print a price.
This guide sorts the market into four types, explains which UK accreditations are mandatory and which are marketing, and lists the questions that decide the outcome. Every claim about a scheme links to the body that runs it.
Checked on 19 August 2026.
The four types of UK provider
1. Specialist penetration testing boutiques
Small to mid-sized teams. Deep technical work, often founder-led. Many hold CREST membership. Lead times are usually the longest in the market because capacity is fixed.
Buy from a boutique when you need one deep engagement, a named tester, and a report your auditor will accept without argument.
2. Large consultancies and managed security providers
Big firms with a testing practice inside a wider security business. They scale, they integrate with your ISMS and SOC, and their name carries weight with a board.
The trade-offs are price and staffing. Large mandates are often delivered by junior testers under senior review.
The public price record shows the spread. On the government G-Cloud framework, Claranet Limited lists internal infrastructure penetration testing at "£1,000 to £1,500 a unit a day" (G-Cloud listing), while Reply Limited lists penetration testing services at "£410 a unit a day" (G-Cloud listing). Both are large firms. The day rate alone tells you very little.
3. Freelancers and one-person firms
Often ex-boutique consultants. Flexible and cheap. The risks are capacity, key-person dependency and insurance cover.
Check the professional indemnity and cyber liability cover before you let anyone attack a production system.
4. Platforms and PTaaS
Software-delivered testing. Continuous rather than once a year. Findings arrive in a platform or straight into your issue tracker. Prices are usually public.
Platforms cover web, API and external infrastructure well. They do not replace a human red team.
Which UK accreditation actually matters
This is where buyers waste money. Here is the real position, from the bodies that run each scheme.
CHECK is an NCSC scheme, and it is scoped to public work
The NCSC defines CHECK as "the scheme under which NCSC assured companies can conduct authorised penetration tests of public sector and CNI systems". Source: NCSC CHECK.
For those systems the guidance is firm: "All systems processing data protectively marked OFFICIAL and above (up to Top Secret but excluding STRAP systems) should be assessed by companies assured under CHECK". Source: NCSC using a CHECK provider.
If you are not public sector and not critical national infrastructure, the NCSC does not tell you to use CHECK. The CHECK page points private organisations to its general commissioning guidance instead.
CREST is a private accreditation, not a law
CREST describes itself as "a global community of cyber security businesses and professionals working to keep our information safe in a digital world", and says members go through "rigorous audit and accreditation processes". Source: CREST.
CREST is a delivery partner for several UK schemes: NCSC CHECK, Bank of England CBEST, Cabinet Office GBEST and UK Civil Aviation Authority ASSURE.
No UK statute requires CREST. Your customer's contract might. Read the security schedule before you shop.
CREST has also tightened its CHECK requirements. It states that "From 31 March 2025, CHECK Team Leaders (CTLs) must obtain a UK CSC Professional Title in the Security Testing specialism", and that "By 31st March 2026, all CTMs must achieve the UK CSC Security Testing Title at the 'Practitioner' level". Source: CREST CHECK.
CBEST applies to systemically important financial firms
CBEST is the Bank of England's threat-led testing framework for firms and financial market infrastructures. It is run with the Prudential Regulation Authority and the Financial Conduct Authority. Source: Bank of England CBEST implementation guide.
If you are in a CBEST scope, no platform and no boutique outside the accredited pool will do. Hire an accredited provider.
IASME requires the assessor to hold a listed qualification or pass the IASME and NCSC Vulnerability Assessment Plus exam, and to work for an IASME-accredited certification body. CREST is not the gate. Source: IASME Cyber Essentials.
Individual certificates
OSCP, CREST CRT and CREST CCT sit with the person, not the company. A firm with fifty managers holding management-level certificates and three hands-on testers is not the right firm for a technical test. Ask who will actually do the work and what they hold.
Price transparency is a real selection signal
Most UK firms will not publish a number. We checked Pentest People, Bulletproof, JUMPSEC, Prism Infosec, AppCheck, Nettitude/LRQA, Redscan and Evalian in August 2026. None published a day rate or a fixed price on a marketing page. Every one routes to a quote form.
A minority do publish. Precursor Security lists an external network test "Starting at £2,500" and a web application test "Starting at £3,750" (Precursor Security, updated August 2026). Aardwolf Security states "Aardwolf Security starts from £750 per day" (Aardwolf Security, 16 June 2026). SECFORCE publishes a benchmark of "£1000–£1500(€1200- €1800)/day" for thorough manual testing (SECFORCE, 24 April 2025).
For a fuller price breakdown with the government-hosted figures, see penetration testing cost UK 2026.
Twelve questions to ask before you sign
- Who will do the testing, and what do those people hold?
- Are you CHECK approved, and does my system even need it?
- Which method do you follow: OWASP Testing Guide, PTES, or NIST SP 800-115?
- Do you prove each finding with a working exploit, or list theoretical risk?
- Can I see a sample report before I commit?
- Does the report map findings to my framework, or must I do that myself?
- Is the re-test after remediation in the price, or billed again?
- How do you report a critical finding mid-test, and how fast?
- What is your professional indemnity and cyber liability cover?
- Where will my report be stored, for how long, and who can read it?
- Who pays if the test takes down a production system?
- What is your lead time from signature to first test day?
Question seven catches more budget overruns than any other.
What a penetration test does not give you
The NCSC is direct about the limit.
"A penetration test can only validate that your organisation's IT systems are not vulnerable to known issues on the day of the test."
Source: NCSC penetration testing guidance, published 8 August 2017, last reviewed 10 January 2022. The same page notes that "It's not uncommon for a year or more to elapse between penetration tests".
That is the structural gap. One test proves one day. Your code changes every week.
Where Matproof Sentinel fits
Matproof Sentinel is an AI penetration testing platform. Pricing is public, in euros: €149 per single run, €299 per month, €1,490 per month, and Custom for enterprise. See pricing.
Sentinel runs ten specialised AI agents in stages. Recon maps the surface with nmap, amass and httpx. Web, API, Infra, Cloud and Mobile agents run in parallel with nuclei, sqlmap, OWASP ZAP, testssl.sh, Prowler and MobSF. Source-code and supply-chain agents read your repositories with Semgrep, Gitleaks and Trivy. A ValidatorAgent re-runs every finding and stamps it VALIDATED, UNVERIFIED or FALSE_POSITIVE. Findings map to SOC 2, ISO 27001, DORA, NIS2, PCI DSS and HIPAA controls. Reports export as PDF, JSON and SARIF 2.1.0.
The full method, every agent and every tool, is public at docs.matproof.com.
What Sentinel is not
We would rather lose the sale than mislead you.
- There is no human penetration tester. AI agents find the issues. Another AI agent checks them.
- Matproof holds no CREST membership and no CHECK approval.
- Sentinel does no social engineering, no physical intrusion and no zero-day research.
- Sentinel cannot produce a CREST-signed or CHECK-signed report.
Choose an accredited UK firm instead when
- Your system is public sector or CNI at OFFICIAL or above. Use a CHECK company.
- You are in scope for CBEST, GBEST or ASSURE. Use an accredited provider.
- A customer contract or tender names CREST. Meet the contract.
- You need social engineering, physical entry or a full red team.
- You run bespoke legacy technology such as SCADA or a mainframe.
Choose Sentinel when
- You ship code weekly and an annual test leaves fifty-one weeks untested.
- Your auditor wants evidence that testing ran all year, not once.
- You want a price before a sales call.
- You need findings in your issue tracker, not a PDF in a shared drive.
Most mature teams run both. One accredited engagement for the signature. Continuous automated testing for the evidence in between.
Frequently asked questions
Do I need a CREST provider in the UK?
Only if your contract, tender or regulator asks for it. No UK law requires CREST. For public sector and CNI systems at OFFICIAL and above, the NCSC guidance points to CHECK, not CREST.
What is the difference between CHECK and CREST?
CHECK is the NCSC's own assurance scheme for testing public sector and CNI systems. CREST is a private accreditation body that acts as a delivery partner for CHECK and other UK schemes.
How much do UK penetration testing providers charge?
Published day rates on the government G-Cloud framework run from £410 to £1,500. Vendor list prices start near £2,500 for an external network test. See penetration testing cost UK 2026 for the sourced table.
Is an AI penetration test as good as a human one?
For web applications, APIs and external infrastructure, an AI platform that proves each finding covers the ground that most audits check, and it runs all year. For social engineering, physical entry, red teaming and bespoke legacy systems, hire a human team. Do not let anyone tell you one replaces the other everywhere.
Should I switch providers?
Switch between audit cycles, not during one. Give the new provider the last report as a baseline and ask them to re-test the old findings. That tells you how good they are.
Related reading
Ready to act on this? Matproof runs continuous AI penetration testing with public pricing. Book a demo.