By the GR.IT Consultancy team. GR.IT delivers managed cyber security, IT support and cloud hosting to businesses across London and Kent, with more than 25 years of hands-on experience in UK SME environments.
TL;DR: The short answer
Penetration testing in the UK costs between £1,500 and £15,000 for most small and medium-sized businesses in 2026. The single biggest driver is scope. A basic external network test on a small internet-facing footprint typically costs £1,500 to £3,500 and takes two to three days. A combined external, internal and web application test usually lands between £8,000 and £15,000. Accredited UK testers charge roughly £1,000 to £1,500 per consultant day, so anything quoted below about £500 a day is almost certainly an automated vulnerability scan rather than a manual test.
If you only need to satisfy an insurer, a client questionnaire or a tender, you may not need a full penetration test at all. Read the section on Cyber Essentials Plus versus penetration testing before you spend anything.

What is a penetration test, in plain English?
A penetration test, or pen test, is an authorised simulated attack on your IT systems carried out by a qualified security professional. The tester tries to break in the way a real attacker would, then writes up exactly what they found, how they exploited it, and how to fix it.
The word “manual” matters. A vulnerability scan is a tool that lists known weaknesses. A penetration test is a human being chaining those weaknesses together to prove real-world impact, for example turning a forgotten test account into full domain administrator access. You are paying for the tester’s time and judgement, which is why pen testing is priced in consultant days.
UK penetration testing costs in 2026: the numbers
The figures below reflect current market pricing from UK providers for typical SME scopes. Treat them as planning ranges, not quotes.
| Test type | Typical SME scope | Typical duration | Typical UK cost (2026) |
|---|---|---|---|
| External network / infrastructure | Up to 20 public IPs, firewall, VPN, mail gateway | 2 to 3 days | £1,500 to £3,500 |
| Internal network / Active Directory | One office network, AD domain, privilege escalation and lateral movement | 4 to 8 days | £4,000 to £10,000 |
| Web application | One authenticated application, two or three user roles | 3 to 6 days | £3,000 to £8,000 |
| Cloud configuration review | Microsoft 365 and Azure tenant, identity and sharing controls | 2 to 4 days | £2,000 to £5,000 |
| Phishing and social engineering | Simulated campaign against 50 to 200 staff | 2 to 3 days | £1,500 to £4,000 |
| Combined external, internal and web app | The most common “annual test” package | 8 to 15 days | £8,000 to £15,000 |
| Red team engagement | Intelligence-led, objective-based, multi-vector | 20 days plus | £30,000 to £75,000 plus |
Day rates. Most UK penetration testing is sold on a consultant day rate. Expect £1,000 to £1,500 per tester per day from a CREST-accredited provider, with the broader market spanning roughly £800 to £2,500 depending on seniority, accreditation and how specialised the target is.
Why the ranges are so wide. Three things move the price more than anything else:
- Number of targets. Twenty IPs and one web app is a different job from four sites, three domains and six applications.
- Internal versus external. Internal tests almost always cost more, because Active Directory attack paths take longer to map and exploit than a hardened perimeter.
- The paperwork the report has to satisfy. A test that has to stand up to a PCI DSS assessor, an ISO 27001 auditor or a large client’s security team needs formal evidence and a structured report. That adds days.
What is normally included, and what is not
A credible quote should cover scoping, testing, a written report with a prioritised risk rating, a debrief call, and a retest of the critical and high findings once you have fixed them.
Watch for these common exclusions, which turn a cheap quote into an expensive one later:
- Retesting charged as a separate engagement. Ask whether one retest window is included and how long you have to use it.
- Remediation support. Some providers hand over a 60-page PDF and stop. If you do not have in-house engineers, you will need someone to actually apply the fixes.
- Out-of-hours testing. Testing outside business hours to avoid disruption often carries a premium.
- Attestation letters. A one-page summary you can share with clients or insurers is sometimes billed as an extra.
In our experience, the hidden cost is rarely the test. It is the remediation work sitting in the report afterwards, which is why we usually recommend pairing testing with an ongoing managed cyber security service rather than treating it as a once-a-year purchase.
Do you actually need a penetration test?
This is the question most buyers skip, and it is where the money is saved. Many UK SMEs are quoted for a pen test when what they were actually asked for is a certification or a scan.
| What you are being asked for | What it actually is | Typical UK cost |
|---|---|---|
| Cyber Essentials | Self-assessed questionnaire against five basic controls | £300 to £500 |
| Cyber Essentials Plus | Hands-on technical verification of the same five controls by an assessor. Not a penetration test | £1,500 to £3,000 plus |
| Vulnerability scan | Automated, tool-driven list of known weaknesses, often run monthly | £50 to £300 per month |
| Penetration test | Manual, human-led exploitation with proof of impact | £1,500 to £15,000 |
| Red team | Goal-based simulation of a real adversary over weeks | £30,000 plus |
If a client questionnaire or an insurer asks for “evidence of security testing”, Cyber Essentials Plus plus regular vulnerability scanning is often enough and costs a fraction of a pen test. We covered the certification route in detail in our guide to Cyber Essentials certification in 2026.
You need a penetration test when:
- A contract, tender or framework explicitly requires one, with a named standard such as CREST or CHECK.
- You handle cardholder data and fall under PCI DSS, which requires annual testing.
- You have built or heavily customised a web application that holds customer data.
- You have just completed a major change, such as a cloud migration, an office move or a merger.
How often should a UK business run a penetration test?
The working standard for most SMEs is once a year, plus after any significant change to your environment. Significant change means a new public-facing application, a move to a new cloud platform, a new office network, or an acquisition.
Annual testing on its own leaves an eleven-month blind spot. Pairing an annual test with continuous vulnerability scanning and monitoring gives you far better coverage for a similar total spend. That combination is also what most insurers and enterprise clients now expect to see.
Accreditation: what CREST and CHECK actually mean
CREST is an international accreditation body for security testing firms and testers. Most UK private-sector buyers who specify an accreditation specify CREST.
CHECK is the NCSC’s own scheme. CHECK-approved companies test public sector and critical national infrastructure systems. If you are bidding for central government or NHS work, you may be required to use a CHECK provider.
For a typical London or Kent SME, CREST is the relevant benchmark. It is worth noting that Tigerscheme, previously an NCSC-approved route to CHECK-equivalent status, is no longer continuing in that role, so treat older provider claims with care and verify current status directly.
Accreditation adds roughly 20 to 30 per cent to a day rate. It is worth paying for when the report has to satisfy a third party. It matters less when the test is purely for your own assurance.
Penetration testing in London and Kent: does location change the price?
Not much, and less than most buyers assume. External and web application tests are performed remotely, so the tester’s postcode is irrelevant to the cost.
Location starts to matter for internal network tests, where someone may need to be on site to plug into your network, and for physical security or social engineering assessments. If your provider has to travel from Manchester to Chatham for three days, travel and accommodation land on your invoice. A provider with people in London and Kent removes that line item.
Central London day rates do trend slightly higher than the national average, which is worth knowing when you compare a City firm’s quote against a regional one for identical scope.
How to get a quote you can actually compare
Most SMEs receive three quotes that are impossible to compare because each provider scoped the work differently. Send every provider the same scoping pack:
- Count your assets. Number of public IP addresses, internal hosts, domains, web applications and user roles per application.
- State the driver. Compliance requirement, client demand, insurer request or internal assurance. This determines report format.
- Specify the testing window. Business hours or out of hours, and any systems that must not be touched.
- Ask for days, not just a total. A £6,000 quote for four days and a £6,000 quote for eight days are very different products.
- Ask what happens after. Is retesting included? Is remediation support available? Who will explain the findings to your board?
- Check the testers, not just the firm. Ask which certifications the individuals hold and request a redacted sample report.
If your internal IT capacity is thin, budget for the fix work as well as the test. Our guide to IT support costs for UK small businesses sets out what ongoing support typically costs per user, which is the other half of this budget conversation.
Is a penetration test worth the money for a small business?
The government’s Cyber Security Breaches Survey 2025/2026 found that 43 per cent of UK businesses reported a breach or attack in the previous twelve months, equating to roughly 612,000 organisations, with phishing still the most common attack type.
For many of those businesses, the entry point was not an exotic zero-day. It was an exposed remote access service, a reused password or a missing multi-factor authentication policy. A £2,500 external test that finds an unpatched VPN appliance pays for itself many times over. A £12,000 red team engagement, commissioned by a 15-person firm that has not yet rolled out MFA, does not.
Start with the basics. Get identity controls right first, which we walk through in our multi-factor authentication plan for UK businesses, then test to prove the basics hold.
Frequently asked questions
How much does a basic penetration test cost in the UK? A basic external network penetration test on a small internet-facing footprint costs £1,500 to £3,500 and takes two to three days. Anything materially cheaper is usually an automated vulnerability scan.
What is the day rate for a UK penetration tester in 2026? Roughly £1,000 to £1,500 per consultant day for a CREST-accredited tester, with the wider market ranging from about £800 to £2,500 depending on specialism and seniority.
Is Cyber Essentials Plus the same as a penetration test? No. Cyber Essentials Plus is a hands-on technical verification that five specific basic controls are in place. A penetration test is an open-ended attempt to compromise your systems. Cyber Essentials Plus typically costs £1,500 to £3,000 plus, well below a full test.
How often should we run a penetration test? Annually as a baseline, and again after any significant change such as a cloud migration, a new web application or an office relocation. Continuous vulnerability scanning should run between tests.
Does penetration testing disrupt our systems? A well-scoped test rarely causes disruption. Higher-risk activities such as denial-of-service testing are excluded by default and only run with written agreement, usually out of hours.
Do we need a CREST-accredited provider? Only if a contract, insurer or regulator asks for it. Accreditation adds roughly 20 to 30 per cent to the day rate, which is money well spent when the report has to satisfy a third party.
What should the report include? An executive summary, a prioritised list of findings with CVSS or equivalent risk ratings, evidence of exploitation, clear remediation steps, and a retest of critical and high findings once fixed.
Talk to a UK team that does the fixing as well as the finding
A report is only useful if someone acts on it. GR.IT scopes testing around what your business actually needs, then handles the remediation with the same team, from firewall and identity hardening through to backup and monitoring.
Book a free cyber security scoping call with GR.IT and we will tell you whether you need a penetration test, a certification, or neither.
Explore our managed cyber security services in Kent and London or see our managed IT support packages.