SEE MATPROOF ON YOUR STACK — BOOK A 30-MINUTE DEMO

Penetration Testing Cost in 2026: Real Prices, With the Source on Every Number

Almost every penetration testing firm hides its price behind a quote form. We publish ours, and we publish the market figures we could verify. Every number on this page links to the page it came from and the date shown there. In the UK, day rates that suppliers declared on the government Digital Marketplace run from £410 to £1,500 a day, and published project prices start at £2,500 for an external network test. In the US, published vendor prices start at $1,999 a year, and Synack puts most engagements at $10,000 to $30,000. Matproof Sentinel costs €149 for a single run. We also say plainly what Sentinel is not, because that matters more than the price.

MW
Written by Malte Wagenbach
Founder of Matproof Security. Specialized in AI-driven penetration testing and EU compliance (DORA, NIS2, ISO 27001, SOC 2).
Last reviewed: 19 August 2026

What actually sets the price

UK and US firms price a penetration test the same way. They count the days and multiply by a rate. Scope sets the days. That is why one web application costs a fraction of a full estate test, and why nobody can quote you without asking what you have. Five things move the number. Scope comes first: applications, API endpoints, IP ranges and hosts. Depth comes second: an unauthenticated black-box test costs less than an authenticated test with source code review, and finds less. Accreditation comes third: one UK vendor puts the CREST premium at 15 to 25 per cent. Frequency comes fourth, and it is the one buyers forget. If your customers or your auditor want current evidence, an annual engagement is a bill you pay every year and it is stale for most of that year. Hidden extras come fifth: re-tests after remediation are often billed again, lead times run to weeks, and anything found outside the agreed scope needs a new engagement. The NCSC states the limit plainly: a penetration test can only validate that your systems are not vulnerable to known issues on the day of the test. The real question is not the day rate. It is what a current answer costs you over a year.

  • Scope drives days, and days drive price. Count applications, endpoints, IP ranges and hosts before you ask for a quote.
  • Depth changes the number. Authenticated testing with source review costs more and finds more than an unauthenticated scan.
  • Accreditation carries a premium. Aardwolf Security puts it at roughly 15 to 25 per cent for a CREST provider.
  • Ask whether the re-test after remediation is in the price. Many firms bill it a second time.
  • Frequency multiplies everything. An annual engagement is an annual bill, and the report is out of date within weeks of delivery.
  • The NCSC says a penetration test validates known issues on the day of the test. Anything you ship after that day is untested.
  • Only 13% of UK businesses ran a penetration test in the year covered by the 2025/2026 government survey, while 43% reported a breach or attack.
  • In the US, PCI DSS v4.0 requirements 11.4.2 and 11.4.3 force internal and external testing at least once every 12 months, so the bill repeats whether or not anything changed.
  • US rules name no tester certification. PCI DSS asks for a qualified party with organizational independence. NYDFS Part 500 asks for a qualified internal or external party. Certifications are a market signal, not a legal test.

What Matproof Sentinel costs, and what you get

  • Single run, €149. One full Sentinel pentest. PDF, JSON and SARIF 2.1.0 report. Control mapping included.
  • Starter, €299 per month. Three full pentests a month, up to 50 target URLs per scan, findings raised as GitHub issues.
  • Growth, €1,490 per month. Twenty pentests a month, Cloud and Mobile agents, authenticated scanning, hourly to weekly schedules.
  • Enterprise, Custom price. Unlimited targets, supply-chain agent, SSO and SAML, custom control mapping, dedicated manager.
  • Every plan: ten AI agents plus a ValidatorAgent that stamps each finding VALIDATED, UNVERIFIED or FALSE_POSITIVE.
  • Every plan: re-run the scan after you fix things. A re-test is not a separate invoice.
  • Every plan: the method is public at docs.matproof.com, including what Sentinel does not do.
  • No plan includes a human penetration tester, a CREST-signed report, social engineering or physical entry.

Sample finding

Info

Compare the annual cost, not the sticker price

Take a UK web application test at the published Precursor Security list price of £3,750, or the SECFORCE worked example of six days at £6,000. That buys you one report. The NCSC is explicit that the report covers known issues on the day of the test, and notes that a year or more often passes between tests. If you deploy weekly, you get one tested day and fifty-one untested ones. Matproof Sentinel at €299 a month runs three full tests every month for the year. That is a different product, not a cheaper version of the same one: there is no human tester and no accreditation behind it. It answers the question 'is my current build clean', not the question 'can I show a client a CREST-signed report'.

Fix: Decide which question you are buying an answer to. If a contract, tender or regulator names CREST, CHECK, CBEST or a US framework auditor, hire an accredited firm and budget the published project prices above. If you need current evidence between those engagements, run continuous automated testing. Most mature teams do both: one accredited engagement a year for the signature, continuous testing for the evidence in between.

Reference: Precursor Security rate card (August 2026) · SECFORCE price list (24 April 2025) · NCSC penetration testing guidance (reviewed 10 January 2022) · Matproof pricing at matproof.com/pricing

What the money buys: free scan, Matproof Sentinel, and a traditional firm

Free scanMatproof SentinelTraditional consultancy
Price published before a sales call✓ €149 / €299 / €1,490Rare. Most UK firms quote only
Human penetration tester✗ AI agents only
CREST or CHECK accreditation✗ Matproof holds neitherAvailable from accredited firms
Proof of exploit per finding✓ ValidatorAgent re-runs each one
Social engineering and physical entry✗ Out of scope✓ On a red team engagement
Time from order to first reportAbout 3 minutesAbout 30 minutesWeeks, after a scoping call
Re-test after you fix findings✓ Run it again at no extra costOften billed again
Testing between annual engagements✓ Continuous✗ Point in time
Control mapping in the report✓ ISO 27001, SOC 2, NIS2, DORA, PCI DSSSometimes. Often manual
Machine-readable output✓ SARIF 2.1.0 and JSONUsually PDF only

UK day rates suppliers declared on the government Digital Marketplace

Market: United Kingdom · Figures checked on 19 August 2026. Every row links to the page the number comes from.

ScopePublished priceWhat it coversSource
Penetration testing services (Reply Limited)£410 a unit a dayLarge systems integrator, public sector listingUK Digital Marketplace (G-Cloud): Reply Limited, Penetration Testing Services
CREST web application penetration test (Periculo Limited)£750 a unit a dayCREST member, single flat rateUK Digital Marketplace (G-Cloud): Periculo Limited, CREST Web Application Penetration Test
CREST penetration testing (Cyber Security Specialists Limited)£700 to £1,250 a unit a dayBand covers junior to senior testerUK Digital Marketplace (G-Cloud): Cyber Security Specialists Limited, CREST Penetration Testing
Mobile application penetration testing (Armadillo Sec Ltd)£800 to £1,350 a unit a dayiOS and Android specialist listingUK Digital Marketplace (G-Cloud): Armadillo Sec Ltd, Mobile Application Penetration Testing
Internal infrastructure penetration testing (Claranet Limited)£1,000 to £1,500 a unit a dayTop of the public-sector band we foundUK Digital Marketplace (G-Cloud): Claranet Limited, Internal Infrastructure Penetration Testing

These are supplier-declared rates on the G-Cloud 14 framework, not a market average. UK suppliers must publish a price to list. Read each row as that supplier's own number. The listings carry no visible update stamp; the dates shown are on the attached service documents.

UK project prices that vendors publish openly

Market: United Kingdom · Figures checked on 19 August 2026. Every row links to the page the number comes from.

ScopePublished priceWhat it coversSource
External network penetration testStarting at £2,500Precursor Security list pricePrecursor Security, penetration testing rate card
API security assessmentStarting at £2,500Precursor Security list pricePrecursor Security, penetration testing rate card
Web application penetration testStarting at £3,750Precursor Security list pricePrecursor Security, penetration testing rate card
Mobile application testStarting at £3,750Precursor Security list pricePrecursor Security, penetration testing rate card
Cloud penetration testingStarting at £3,750Precursor Security list pricePrecursor Security, penetration testing rate card
Internal network penetration testStarting at £6,250Precursor Security list pricePrecursor Security, penetration testing rate card
NCSC IT Health CheckStarting at £8,750Precursor Security list pricePrecursor Security, penetration testing rate card
Typical web application engagementAbout 6 days at £6,000SECFORCE worked exampleSECFORCE, pen testing price list UK and EU
CREST-accredited consultant dayAbout £1,200 per dayPrecursor Security stated benchmarkPrecursor Security, penetration testing cost guide
Manual testing day rate band£1,000 to £1,500 per daySECFORCE stated benchmarkSECFORCE, pen testing price list UK and EU
CREST premiumRoughly 15 to 25 per cent moreAardwolf Security stated view, one vendor onlyAardwolf Security, UK penetration test cost buyer's guide

These are list prices set by one seller, not survey data. We print them because most UK firms publish nothing at all. Several UK cost guides repeat each other word for word, so treat any vendor guide as marketing rather than research.

US prices that vendors publish on their own pricing pages

Market: United States · Figures checked on 19 August 2026. Every row links to the page the number comes from.

ScopePublished priceWhat it coversSource
Astra Security, pentest plan$1,999 per yearLower of two published plansSynack, penetration testing cost guide
Astra Security, higher pentest plan$5,999 per yearUpper of two published plansSynack, penetration testing cost guide
Cobalt, Autonomous Pentest$3,500 per testMarked a limited time offer, AI test onlyAstra Security, pricing
Synack, AI Sara PentestStarts at $4,181AI-led productSprocket Security, pricing
Synack, Standard PentestStarts at $10,283Researcher-led productSprocket Security, pricing
Synack, Synack14 PentestStarts at $27,120Extended researcher-led productSprocket Security, pricing
Sprocket Security, Starter package$15,000Continuous testing on up to 20 external hosts, period not statedCobalt, platform pricing
Sprocket Security, internal network testing$13,000 add-onAdd-on to the package aboveCobalt, platform pricing

Only a handful of US vendors print a number. None of these pages shows a publication date. Cobalt marks its figure a limited time offer covering the autonomous AI test, not human-led work. Sprocket does not state a billing period. Astra's page is script-driven and its plan labels moved between fetches, so trust the price and not the label.

US price ranges by scope, from two dated vendor guides

Market: United States · Figures checked on 19 August 2026. Every row links to the page the number comes from.

ScopePublished priceWhat it coversSource
External network$4,000 to $12,000Synack guide, 25 June 2026Compass IT Compliance, penetration testing cost
Web application$5,000 to $30,000Synack guide, 25 June 2026Compass IT Compliance, penetration testing cost
API$5,000 to $30,000Synack guide, 25 June 2026Compass IT Compliance, penetration testing cost
Internal network$5,000 to $35,000Synack guide, 25 June 2026Compass IT Compliance, penetration testing cost
Mobile application$7,000 to $35,000Synack guide, 25 June 2026Compass IT Compliance, penetration testing cost
Cloud$10,000 to $50,000Synack guide, 25 June 2026Compass IT Compliance, penetration testing cost
Red team / adversary simulation$30,000 to $150,000+Synack guide, 25 June 2026Compass IT Compliance, penetration testing cost
External network, 1 to 25 IPs$5,000 to $10,000Compass IT Compliance, 3 June 2025Triaxiom Security, complete guide to external penetration testing
External network, 50 to 100+ IPs$15,000 to $30,000+Compass IT Compliance, 3 June 2025Triaxiom Security, complete guide to external penetration testing
Web application, simple static$3,500 to $6,000Compass IT Compliance, 3 June 2025Triaxiom Security, complete guide to external penetration testing
Web application, complex custom$15,000 to $35,000+Compass IT Compliance, 3 June 2025Triaxiom Security, complete guide to external penetration testing
PCI DSS penetration test$12,000 to $25,000Compass IT Compliance, 3 June 2025Triaxiom Security, complete guide to external penetration testing
Consulting, hourly$250 to $400 per hourCompass IT Compliance, 3 June 2025Triaxiom Security, complete guide to external penetration testing
External network, fewer than 10 hostsAbout $5,000Triaxiom Security, 3 April 2026PCI Security Standards Council, PCI DSS v4.0 SAQ D for Merchants
External network, 10 to 50 hosts$8,000 to $15,000Triaxiom Security, 3 April 2026PCI Security Standards Council, PCI DSS v4.0 SAQ D for Merchants

Two US firms publish a dated range table. They disagree in places, which is why we show both rather than blending them into one number. Synack states that most organizations spend $10,000 to $30,000 per engagement, with an all-types average near $18,300.

Sources

  1. UK Digital Marketplace (G-Cloud): Reply Limited, Penetration Testing ServicesG-Cloud 14 listing, supporting documents dated 7 May 2024
  2. UK Digital Marketplace (G-Cloud): Periculo Limited, CREST Web Application Penetration TestG-Cloud 14 listing, supporting documents dated 6 May 2024
  3. UK Digital Marketplace (G-Cloud): Cyber Security Specialists Limited, CREST Penetration TestingG-Cloud 14 listing, supporting documents dated 25 April 2024
  4. UK Digital Marketplace (G-Cloud): Armadillo Sec Ltd, Mobile Application Penetration TestingG-Cloud 14 listing, supporting documents dated 2 May 2024
  5. UK Digital Marketplace (G-Cloud): Claranet Limited, Internal Infrastructure Penetration TestingG-Cloud 14 listing, supporting documents dated 7 May 2024
  6. Precursor Security, penetration testing rate cardPage marked updated August 2026
  7. Precursor Security, penetration testing cost guidePage marked updated August 2026
  8. SECFORCE, pen testing price list UK and EUPublished 24 April 2025
  9. Aardwolf Security, UK penetration test cost buyer's guide16 June 2026
  10. NCSC, penetration testing guidancePublished 8 August 2017, last reviewed 10 January 2022
  11. DSIT, Cyber Security Breaches Survey 2025/2026Published 30 April 2026
  12. Synack, platform pricingNo date shown on page
  13. Sprocket Security, pricingNo date shown on page, footer carries a 2026 copyright
  14. Cobalt, platform pricingNo date shown on page, marked a limited time offer
  15. Astra Security, pricingNo date shown on page
  16. Synack, penetration testing cost guidePublished 25 June 2026
  17. Compass IT Compliance, penetration testing costPublished 3 June 2025
  18. Triaxiom Security, complete guide to external penetration testingPublished 3 April 2026
  19. PCI Security Standards Council, PCI DSS v4.0 SAQ D for MerchantsPublication date April 2022
  20. Matproof pricingChecked 19 August 2026

Matproof Sentinel pricing (public, no quote required)

Pentest Single
€149 / run
  • 10 specialised AI agents + ValidatorAgent
  • Web + API + Infra + DNS/TLS coverage
  • Up to 50 target URLs per scan
  • PDF + SARIF 2.1.0 + JSON export
  • SOC 2 / ISO 27001 / DORA / NIS2 mapping
  • Open methodology (docs.matproof.com)
Buy single run
Recommended
Pentest Starter
€299 / mo
  • 3 full Sentinel pentests per month
  • All 10 agents (Web / API / Infra / Source-Code)
  • GitHub App + auto-created GitHub Issues
  • Up to 50 target URLs per scan
  • Remediation-diff metric across re-tests
  • SOC 2 / ISO 27001 / DORA / NIS2 evidence
Start Starter
Pentest Growth
€1,490 / mo
  • 20 Sentinel pentests per month
  • Additional scans at €149 each
  • All 10 agents incl. Cloud (Prowler) + Mobile (MobSF)
  • Continuous schedules — hourly / daily / weekly
  • Authenticated scanning (session cookies, bearer tokens)
  • Webhook delivery + priority support
Start Growth
Pentest Enterprise
Custom
  • Everything in Growth + unlimited targets
  • SupplyChain agent on (Trivy: deps + containers + IaC)
  • SSO / SAML, role-based access
  • Custom compliance mapping (PCI DSS, HIPAA, BaFin MaRisk, NEN 7510)
  • Dedicated success manager + SLA
  • Private deployment options
Book a call

Frequently asked questions about penetration testing cost

How much does a penetration test cost in the UK?

Day rates that suppliers declared on the UK government Digital Marketplace run from £410 to £1,500 a day across the listings we checked in August 2026. On published vendor rate cards, an external network test starts at £2,500 and a web application test at £3,750 (Precursor Security, August 2026). SECFORCE gives a worked example of about six days at £6,000 for a web application test (April 2025). Your own price depends on scope and days.

What is a fair penetration testing day rate?

Two UK vendors publish a benchmark. SECFORCE gives £1,000 to £1,500 a day for thorough manual testing (April 2025). Precursor Security gives about £1,200 per CREST-accredited consultant day (August 2026). Neither is an independent survey, and we found no UK trade body that publishes a rate card. Read them as vendor statements.

Does a CREST provider cost more?

Aardwolf Security says yes, by roughly 15 to 25 per cent (June 2026). That is one vendor's published view. We found no independent study of the CREST premium, so treat the figure as an indication and not a market rate.

Do I need a CREST or CHECK provider?

Only when something asks for it. The NCSC CHECK scheme covers UK public sector and critical national infrastructure systems, and its guidance says systems at OFFICIAL and above should be assessed by a CHECK company. If you are not public sector or CNI, the NCSC does not tell you to use CHECK. No UK law requires CREST. Your customer's security schedule might, so read the contract before you shop.

Why do most providers hide their prices?

Because the work is priced per day against a custom scope, and a published price commits the seller before the scope is known. We checked Pentest People, Bulletproof, JUMPSEC, Prism Infosec, AppCheck, Nettitude/LRQA, Redscan and Evalian in August 2026. None published a day rate or a fixed price. Every one routes to a quote form. Matproof publishes €149, €299, €1,490 and Custom because the testing is a product, not a project.

Is a cheaper automated test as good as a manual one?

It is a different product. For web applications, APIs and external infrastructure, an AI platform that proves each finding covers the ground most audits check, and it runs all year rather than once. It does not do social engineering, physical entry or zero-day research, and it does not come with an accreditation. Precursor Security warns that day rates under £500 usually mean automated scanning, which is fair: do not pay consultancy rates for a scanner, and do not expect a platform to replace a red team.

How much does a penetration test cost in the US?

Synack's dated guide puts most engagements at $10,000 to $30,000, with an all-types average near $18,300 (25 June 2026). Compass IT Compliance breaks it down by size, from $3,500 for a simple static web application to $40,000 or more for a large internal network (3 June 2025). On vendor pricing pages, Astra Security publishes $1,999 and $5,999 per year, Cobalt publishes $3,500 per autonomous test, Synack starts at $10,283 for a standard pentest, and Sprocket Security publishes a $15,000 starter package. No US vendor we checked publishes a day rate.

Which US rules actually require a penetration test?

PCI DSS v4.0 does, under requirements 11.4.2 and 11.4.3, at least once every 12 months and after significant change. CMMC Level 3 does, under 32 CFR 170.14, at least annually. NYDFS Part 500 does, under section 500.5(a)(1), at least annually from inside and outside the boundary. FedRAMP requires testing by an accredited 3PAO. HIPAA does not: 45 CFR 164.308(a)(8) asks for a periodic evaluation and never says penetration. SOC 2 does not either, because the Trust Services Criteria do not name it, though auditors and buyers usually ask for one anyway.

Will an AI-only test satisfy PCI DSS 11.4?

That is your QSA's call, not ours. PCI DSS 11.4 names no certification. It asks for a qualified internal resource or qualified external third party, and for organizational independence of the tester. An independent platform can meet the independence part. Whether your QSA treats an AI-only test as the 11.4 penetration test depends on your QSA. Ask before you rely on it. We are not going to tell you it is settled.

How often do I need to pay for a penetration test?

Frameworks generally expect at least an annual test. The NCSC notes that a year or more often passes between tests, and that a test only validates known issues on the day it runs. If your customers or auditor want current evidence, continuous testing usually costs less per year than repeated annual engagements and keeps the evidence fresh. Matproof Sentinel Starter runs three full tests a month for €299.

Related

Go deeper — related blog articles

What Matproof Sentinel does not replace

Sentinel is an AI penetration testing platform. Ten agents test, and a ValidatorAgent re-runs every finding before it ships. That is the whole of it. There is no human penetration tester on the other side, and Matproof holds no accreditation of its own. If you need a signature, buy the signature from someone who holds one.

  • No human penetration tester. AI agents find the issues. Another AI agent checks them.
  • No CREST membership and no NCSC CHECK approval. Matproof cannot issue a CREST-signed or CHECK-signed report.
  • No social engineering, no phishing simulation and no physical intrusion.
  • No zero-day research and no bespoke business-logic red teaming.
  • Hire an accredited firm when a customer contract, a tender, or a scheme such as CHECK, CBEST, GBEST or ASSURE names one.
  • Hire a human team for OT and SCADA estates, mainframes, and anything where a person has to improvise.

See your attack surface first, then decide

Run a free scan to see what is exposed. A full report costs €149. Continuous testing costs €299 a month. Prices are public and there is no sales call. If you need a CREST-signed report, we will tell you to hire an accredited firm.

Run free scan