Penetration Testing Cost in 2026: Real Prices, With the Source on Every Number
Almost every penetration testing firm hides its price behind a quote form. We publish ours, and we publish the market figures we could verify. Every number on this page links to the page it came from and the date shown there. In the UK, day rates that suppliers declared on the government Digital Marketplace run from £410 to £1,500 a day, and published project prices start at £2,500 for an external network test. In the US, published vendor prices start at $1,999 a year, and Synack puts most engagements at $10,000 to $30,000. Matproof Sentinel costs €149 for a single run. We also say plainly what Sentinel is not, because that matters more than the price.
What actually sets the price
UK and US firms price a penetration test the same way. They count the days and multiply by a rate. Scope sets the days. That is why one web application costs a fraction of a full estate test, and why nobody can quote you without asking what you have. Five things move the number. Scope comes first: applications, API endpoints, IP ranges and hosts. Depth comes second: an unauthenticated black-box test costs less than an authenticated test with source code review, and finds less. Accreditation comes third: one UK vendor puts the CREST premium at 15 to 25 per cent. Frequency comes fourth, and it is the one buyers forget. If your customers or your auditor want current evidence, an annual engagement is a bill you pay every year and it is stale for most of that year. Hidden extras come fifth: re-tests after remediation are often billed again, lead times run to weeks, and anything found outside the agreed scope needs a new engagement. The NCSC states the limit plainly: a penetration test can only validate that your systems are not vulnerable to known issues on the day of the test. The real question is not the day rate. It is what a current answer costs you over a year.
- Scope drives days, and days drive price. Count applications, endpoints, IP ranges and hosts before you ask for a quote.
- Depth changes the number. Authenticated testing with source review costs more and finds more than an unauthenticated scan.
- Accreditation carries a premium. Aardwolf Security puts it at roughly 15 to 25 per cent for a CREST provider.
- Ask whether the re-test after remediation is in the price. Many firms bill it a second time.
- Frequency multiplies everything. An annual engagement is an annual bill, and the report is out of date within weeks of delivery.
- The NCSC says a penetration test validates known issues on the day of the test. Anything you ship after that day is untested.
- Only 13% of UK businesses ran a penetration test in the year covered by the 2025/2026 government survey, while 43% reported a breach or attack.
- In the US, PCI DSS v4.0 requirements 11.4.2 and 11.4.3 force internal and external testing at least once every 12 months, so the bill repeats whether or not anything changed.
- US rules name no tester certification. PCI DSS asks for a qualified party with organizational independence. NYDFS Part 500 asks for a qualified internal or external party. Certifications are a market signal, not a legal test.
What Matproof Sentinel costs, and what you get
- Single run, €149. One full Sentinel pentest. PDF, JSON and SARIF 2.1.0 report. Control mapping included.
- Starter, €299 per month. Three full pentests a month, up to 50 target URLs per scan, findings raised as GitHub issues.
- Growth, €1,490 per month. Twenty pentests a month, Cloud and Mobile agents, authenticated scanning, hourly to weekly schedules.
- Enterprise, Custom price. Unlimited targets, supply-chain agent, SSO and SAML, custom control mapping, dedicated manager.
- Every plan: ten AI agents plus a ValidatorAgent that stamps each finding VALIDATED, UNVERIFIED or FALSE_POSITIVE.
- Every plan: re-run the scan after you fix things. A re-test is not a separate invoice.
- Every plan: the method is public at docs.matproof.com, including what Sentinel does not do.
- No plan includes a human penetration tester, a CREST-signed report, social engineering or physical entry.
Sample finding
Compare the annual cost, not the sticker price
Take a UK web application test at the published Precursor Security list price of £3,750, or the SECFORCE worked example of six days at £6,000. That buys you one report. The NCSC is explicit that the report covers known issues on the day of the test, and notes that a year or more often passes between tests. If you deploy weekly, you get one tested day and fifty-one untested ones. Matproof Sentinel at €299 a month runs three full tests every month for the year. That is a different product, not a cheaper version of the same one: there is no human tester and no accreditation behind it. It answers the question 'is my current build clean', not the question 'can I show a client a CREST-signed report'.
Fix: Decide which question you are buying an answer to. If a contract, tender or regulator names CREST, CHECK, CBEST or a US framework auditor, hire an accredited firm and budget the published project prices above. If you need current evidence between those engagements, run continuous automated testing. Most mature teams do both: one accredited engagement a year for the signature, continuous testing for the evidence in between.
Reference: Precursor Security rate card (August 2026) · SECFORCE price list (24 April 2025) · NCSC penetration testing guidance (reviewed 10 January 2022) · Matproof pricing at matproof.com/pricing
What the money buys: free scan, Matproof Sentinel, and a traditional firm
| — | Free scan | Matproof Sentinel | Traditional consultancy |
|---|---|---|---|
| Price published before a sales call | ✓ | ✓ €149 / €299 / €1,490 | Rare. Most UK firms quote only |
| Human penetration tester | ✗ | ✗ AI agents only | ✓ |
| CREST or CHECK accreditation | ✗ | ✗ Matproof holds neither | Available from accredited firms |
| Proof of exploit per finding | ✗ | ✓ ValidatorAgent re-runs each one | ✓ |
| Social engineering and physical entry | ✗ | ✗ Out of scope | ✓ On a red team engagement |
| Time from order to first report | About 3 minutes | About 30 minutes | Weeks, after a scoping call |
| Re-test after you fix findings | ✗ | ✓ Run it again at no extra cost | Often billed again |
| Testing between annual engagements | ✗ | ✓ Continuous | ✗ Point in time |
| Control mapping in the report | ✗ | ✓ ISO 27001, SOC 2, NIS2, DORA, PCI DSS | Sometimes. Often manual |
| Machine-readable output | ✗ | ✓ SARIF 2.1.0 and JSON | Usually PDF only |
UK day rates suppliers declared on the government Digital Marketplace
Market: United Kingdom · Figures checked on 19 August 2026. Every row links to the page the number comes from.
| Scope | Published price | What it covers | Source |
|---|---|---|---|
| Penetration testing services (Reply Limited) | £410 a unit a day | Large systems integrator, public sector listing | UK Digital Marketplace (G-Cloud): Reply Limited, Penetration Testing Services |
| CREST web application penetration test (Periculo Limited) | £750 a unit a day | CREST member, single flat rate | UK Digital Marketplace (G-Cloud): Periculo Limited, CREST Web Application Penetration Test |
| CREST penetration testing (Cyber Security Specialists Limited) | £700 to £1,250 a unit a day | Band covers junior to senior tester | UK Digital Marketplace (G-Cloud): Cyber Security Specialists Limited, CREST Penetration Testing |
| Mobile application penetration testing (Armadillo Sec Ltd) | £800 to £1,350 a unit a day | iOS and Android specialist listing | UK Digital Marketplace (G-Cloud): Armadillo Sec Ltd, Mobile Application Penetration Testing |
| Internal infrastructure penetration testing (Claranet Limited) | £1,000 to £1,500 a unit a day | Top of the public-sector band we found | UK Digital Marketplace (G-Cloud): Claranet Limited, Internal Infrastructure Penetration Testing |
These are supplier-declared rates on the G-Cloud 14 framework, not a market average. UK suppliers must publish a price to list. Read each row as that supplier's own number. The listings carry no visible update stamp; the dates shown are on the attached service documents.
UK project prices that vendors publish openly
Market: United Kingdom · Figures checked on 19 August 2026. Every row links to the page the number comes from.
| Scope | Published price | What it covers | Source |
|---|---|---|---|
| External network penetration test | Starting at £2,500 | Precursor Security list price | Precursor Security, penetration testing rate card |
| API security assessment | Starting at £2,500 | Precursor Security list price | Precursor Security, penetration testing rate card |
| Web application penetration test | Starting at £3,750 | Precursor Security list price | Precursor Security, penetration testing rate card |
| Mobile application test | Starting at £3,750 | Precursor Security list price | Precursor Security, penetration testing rate card |
| Cloud penetration testing | Starting at £3,750 | Precursor Security list price | Precursor Security, penetration testing rate card |
| Internal network penetration test | Starting at £6,250 | Precursor Security list price | Precursor Security, penetration testing rate card |
| NCSC IT Health Check | Starting at £8,750 | Precursor Security list price | Precursor Security, penetration testing rate card |
| Typical web application engagement | About 6 days at £6,000 | SECFORCE worked example | SECFORCE, pen testing price list UK and EU |
| CREST-accredited consultant day | About £1,200 per day | Precursor Security stated benchmark | Precursor Security, penetration testing cost guide |
| Manual testing day rate band | £1,000 to £1,500 per day | SECFORCE stated benchmark | SECFORCE, pen testing price list UK and EU |
| CREST premium | Roughly 15 to 25 per cent more | Aardwolf Security stated view, one vendor only | Aardwolf Security, UK penetration test cost buyer's guide |
These are list prices set by one seller, not survey data. We print them because most UK firms publish nothing at all. Several UK cost guides repeat each other word for word, so treat any vendor guide as marketing rather than research.
US prices that vendors publish on their own pricing pages
Market: United States · Figures checked on 19 August 2026. Every row links to the page the number comes from.
| Scope | Published price | What it covers | Source |
|---|---|---|---|
| Astra Security, pentest plan | $1,999 per year | Lower of two published plans | Synack, penetration testing cost guide |
| Astra Security, higher pentest plan | $5,999 per year | Upper of two published plans | Synack, penetration testing cost guide |
| Cobalt, Autonomous Pentest | $3,500 per test | Marked a limited time offer, AI test only | Astra Security, pricing |
| Synack, AI Sara Pentest | Starts at $4,181 | AI-led product | Sprocket Security, pricing |
| Synack, Standard Pentest | Starts at $10,283 | Researcher-led product | Sprocket Security, pricing |
| Synack, Synack14 Pentest | Starts at $27,120 | Extended researcher-led product | Sprocket Security, pricing |
| Sprocket Security, Starter package | $15,000 | Continuous testing on up to 20 external hosts, period not stated | Cobalt, platform pricing |
| Sprocket Security, internal network testing | $13,000 add-on | Add-on to the package above | Cobalt, platform pricing |
Only a handful of US vendors print a number. None of these pages shows a publication date. Cobalt marks its figure a limited time offer covering the autonomous AI test, not human-led work. Sprocket does not state a billing period. Astra's page is script-driven and its plan labels moved between fetches, so trust the price and not the label.
US price ranges by scope, from two dated vendor guides
Market: United States · Figures checked on 19 August 2026. Every row links to the page the number comes from.
| Scope | Published price | What it covers | Source |
|---|---|---|---|
| External network | $4,000 to $12,000 | Synack guide, 25 June 2026 | Compass IT Compliance, penetration testing cost |
| Web application | $5,000 to $30,000 | Synack guide, 25 June 2026 | Compass IT Compliance, penetration testing cost |
| API | $5,000 to $30,000 | Synack guide, 25 June 2026 | Compass IT Compliance, penetration testing cost |
| Internal network | $5,000 to $35,000 | Synack guide, 25 June 2026 | Compass IT Compliance, penetration testing cost |
| Mobile application | $7,000 to $35,000 | Synack guide, 25 June 2026 | Compass IT Compliance, penetration testing cost |
| Cloud | $10,000 to $50,000 | Synack guide, 25 June 2026 | Compass IT Compliance, penetration testing cost |
| Red team / adversary simulation | $30,000 to $150,000+ | Synack guide, 25 June 2026 | Compass IT Compliance, penetration testing cost |
| External network, 1 to 25 IPs | $5,000 to $10,000 | Compass IT Compliance, 3 June 2025 | Triaxiom Security, complete guide to external penetration testing |
| External network, 50 to 100+ IPs | $15,000 to $30,000+ | Compass IT Compliance, 3 June 2025 | Triaxiom Security, complete guide to external penetration testing |
| Web application, simple static | $3,500 to $6,000 | Compass IT Compliance, 3 June 2025 | Triaxiom Security, complete guide to external penetration testing |
| Web application, complex custom | $15,000 to $35,000+ | Compass IT Compliance, 3 June 2025 | Triaxiom Security, complete guide to external penetration testing |
| PCI DSS penetration test | $12,000 to $25,000 | Compass IT Compliance, 3 June 2025 | Triaxiom Security, complete guide to external penetration testing |
| Consulting, hourly | $250 to $400 per hour | Compass IT Compliance, 3 June 2025 | Triaxiom Security, complete guide to external penetration testing |
| External network, fewer than 10 hosts | About $5,000 | Triaxiom Security, 3 April 2026 | PCI Security Standards Council, PCI DSS v4.0 SAQ D for Merchants |
| External network, 10 to 50 hosts | $8,000 to $15,000 | Triaxiom Security, 3 April 2026 | PCI Security Standards Council, PCI DSS v4.0 SAQ D for Merchants |
Two US firms publish a dated range table. They disagree in places, which is why we show both rather than blending them into one number. Synack states that most organizations spend $10,000 to $30,000 per engagement, with an all-types average near $18,300.
Sources
- UK Digital Marketplace (G-Cloud): Reply Limited, Penetration Testing Services — G-Cloud 14 listing, supporting documents dated 7 May 2024
- UK Digital Marketplace (G-Cloud): Periculo Limited, CREST Web Application Penetration Test — G-Cloud 14 listing, supporting documents dated 6 May 2024
- UK Digital Marketplace (G-Cloud): Cyber Security Specialists Limited, CREST Penetration Testing — G-Cloud 14 listing, supporting documents dated 25 April 2024
- UK Digital Marketplace (G-Cloud): Armadillo Sec Ltd, Mobile Application Penetration Testing — G-Cloud 14 listing, supporting documents dated 2 May 2024
- UK Digital Marketplace (G-Cloud): Claranet Limited, Internal Infrastructure Penetration Testing — G-Cloud 14 listing, supporting documents dated 7 May 2024
- Precursor Security, penetration testing rate card — Page marked updated August 2026
- Precursor Security, penetration testing cost guide — Page marked updated August 2026
- SECFORCE, pen testing price list UK and EU — Published 24 April 2025
- Aardwolf Security, UK penetration test cost buyer's guide — 16 June 2026
- NCSC, penetration testing guidance — Published 8 August 2017, last reviewed 10 January 2022
- DSIT, Cyber Security Breaches Survey 2025/2026 — Published 30 April 2026
- Synack, platform pricing — No date shown on page
- Sprocket Security, pricing — No date shown on page, footer carries a 2026 copyright
- Cobalt, platform pricing — No date shown on page, marked a limited time offer
- Astra Security, pricing — No date shown on page
- Synack, penetration testing cost guide — Published 25 June 2026
- Compass IT Compliance, penetration testing cost — Published 3 June 2025
- Triaxiom Security, complete guide to external penetration testing — Published 3 April 2026
- PCI Security Standards Council, PCI DSS v4.0 SAQ D for Merchants — Publication date April 2022
- Matproof pricing — Checked 19 August 2026
Matproof Sentinel pricing (public, no quote required)
- 10 specialised AI agents + ValidatorAgent
- Web + API + Infra + DNS/TLS coverage
- Up to 50 target URLs per scan
- PDF + SARIF 2.1.0 + JSON export
- SOC 2 / ISO 27001 / DORA / NIS2 mapping
- Open methodology (docs.matproof.com)
- 3 full Sentinel pentests per month
- All 10 agents (Web / API / Infra / Source-Code)
- GitHub App + auto-created GitHub Issues
- Up to 50 target URLs per scan
- Remediation-diff metric across re-tests
- SOC 2 / ISO 27001 / DORA / NIS2 evidence
- 20 Sentinel pentests per month
- Additional scans at €149 each
- All 10 agents incl. Cloud (Prowler) + Mobile (MobSF)
- Continuous schedules — hourly / daily / weekly
- Authenticated scanning (session cookies, bearer tokens)
- Webhook delivery + priority support
- Everything in Growth + unlimited targets
- SupplyChain agent on (Trivy: deps + containers + IaC)
- SSO / SAML, role-based access
- Custom compliance mapping (PCI DSS, HIPAA, BaFin MaRisk, NEN 7510)
- Dedicated success manager + SLA
- Private deployment options
Frequently asked questions about penetration testing cost
How much does a penetration test cost in the UK?
Day rates that suppliers declared on the UK government Digital Marketplace run from £410 to £1,500 a day across the listings we checked in August 2026. On published vendor rate cards, an external network test starts at £2,500 and a web application test at £3,750 (Precursor Security, August 2026). SECFORCE gives a worked example of about six days at £6,000 for a web application test (April 2025). Your own price depends on scope and days.
What is a fair penetration testing day rate?
Two UK vendors publish a benchmark. SECFORCE gives £1,000 to £1,500 a day for thorough manual testing (April 2025). Precursor Security gives about £1,200 per CREST-accredited consultant day (August 2026). Neither is an independent survey, and we found no UK trade body that publishes a rate card. Read them as vendor statements.
Does a CREST provider cost more?
Aardwolf Security says yes, by roughly 15 to 25 per cent (June 2026). That is one vendor's published view. We found no independent study of the CREST premium, so treat the figure as an indication and not a market rate.
Do I need a CREST or CHECK provider?
Only when something asks for it. The NCSC CHECK scheme covers UK public sector and critical national infrastructure systems, and its guidance says systems at OFFICIAL and above should be assessed by a CHECK company. If you are not public sector or CNI, the NCSC does not tell you to use CHECK. No UK law requires CREST. Your customer's security schedule might, so read the contract before you shop.
Why do most providers hide their prices?
Because the work is priced per day against a custom scope, and a published price commits the seller before the scope is known. We checked Pentest People, Bulletproof, JUMPSEC, Prism Infosec, AppCheck, Nettitude/LRQA, Redscan and Evalian in August 2026. None published a day rate or a fixed price. Every one routes to a quote form. Matproof publishes €149, €299, €1,490 and Custom because the testing is a product, not a project.
Is a cheaper automated test as good as a manual one?
It is a different product. For web applications, APIs and external infrastructure, an AI platform that proves each finding covers the ground most audits check, and it runs all year rather than once. It does not do social engineering, physical entry or zero-day research, and it does not come with an accreditation. Precursor Security warns that day rates under £500 usually mean automated scanning, which is fair: do not pay consultancy rates for a scanner, and do not expect a platform to replace a red team.
How much does a penetration test cost in the US?
Synack's dated guide puts most engagements at $10,000 to $30,000, with an all-types average near $18,300 (25 June 2026). Compass IT Compliance breaks it down by size, from $3,500 for a simple static web application to $40,000 or more for a large internal network (3 June 2025). On vendor pricing pages, Astra Security publishes $1,999 and $5,999 per year, Cobalt publishes $3,500 per autonomous test, Synack starts at $10,283 for a standard pentest, and Sprocket Security publishes a $15,000 starter package. No US vendor we checked publishes a day rate.
Which US rules actually require a penetration test?
PCI DSS v4.0 does, under requirements 11.4.2 and 11.4.3, at least once every 12 months and after significant change. CMMC Level 3 does, under 32 CFR 170.14, at least annually. NYDFS Part 500 does, under section 500.5(a)(1), at least annually from inside and outside the boundary. FedRAMP requires testing by an accredited 3PAO. HIPAA does not: 45 CFR 164.308(a)(8) asks for a periodic evaluation and never says penetration. SOC 2 does not either, because the Trust Services Criteria do not name it, though auditors and buyers usually ask for one anyway.
Will an AI-only test satisfy PCI DSS 11.4?
That is your QSA's call, not ours. PCI DSS 11.4 names no certification. It asks for a qualified internal resource or qualified external third party, and for organizational independence of the tester. An independent platform can meet the independence part. Whether your QSA treats an AI-only test as the 11.4 penetration test depends on your QSA. Ask before you rely on it. We are not going to tell you it is settled.
How often do I need to pay for a penetration test?
Frameworks generally expect at least an annual test. The NCSC notes that a year or more often passes between tests, and that a test only validates known issues on the day it runs. If your customers or auditor want current evidence, continuous testing usually costs less per year than repeated annual engagements and keeps the evidence fresh. Matproof Sentinel Starter runs three full tests a month for €299.
What Matproof Sentinel does not replace
Sentinel is an AI penetration testing platform. Ten agents test, and a ValidatorAgent re-runs every finding before it ships. That is the whole of it. There is no human penetration tester on the other side, and Matproof holds no accreditation of its own. If you need a signature, buy the signature from someone who holds one.
- No human penetration tester. AI agents find the issues. Another AI agent checks them.
- No CREST membership and no NCSC CHECK approval. Matproof cannot issue a CREST-signed or CHECK-signed report.
- No social engineering, no phishing simulation and no physical intrusion.
- No zero-day research and no bespoke business-logic red teaming.
- Hire an accredited firm when a customer contract, a tender, or a scheme such as CHECK, CBEST, GBEST or ASSURE names one.
- Hire a human team for OT and SCADA estates, mainframes, and anything where a person has to improvise.
See your attack surface first, then decide
Run a free scan to see what is exposed. A full report costs €149. Continuous testing costs €299 a month. Prices are public and there is no sales call. If you need a CREST-signed report, we will tell you to hire an accredited firm.
Run free scan