THE HONEST ANSWER
Unlike Cyber Essentials - where pricing is set by IASME based on organisation size - penetration test pricing is driven by scope. The type of test, the number of targets, the complexity of your environment, and the depth of reporting required all affect the final cost.
Most UK providers will not publish a fixed price list because every engagement is different. What we can tell you is what to expect at each tier, what drives the cost up, and what is included as standard.
WHAT AFFECTS THE COST?
- Test type: Infrastructure, web application, cloud security review, MDM, and PCI DSS pen testing are all different exercises requiring different expertise and time
- Number of targets: More IP addresses, URLs, applications, or cloud tenants in scope means more assessor time
- Environment complexity: Legacy systems, segmented networks, hybrid cloud, and custom applications take longer to assess than a standard setup
- Depth of testing: A focused external surface assessment is faster than a full internal network compromise simulation
- Report requirements: Compliance-formatted reports for PCI DSS QSAs, ISO 27001 auditors, or SOC 2 assessors require additional structure and evidence documentation
- Urgency: Fast-track engagements for tender deadlines or urgent audit requirements may carry a premium
GUIDE PRICES BY TEST TYPE
The table below shows Vincent Cyber Defence's 2026 guide prices. All engagements are fixed-price after a scoping call - you know the full cost before work begins, with no hidden charges or scope creep.
| Test Type | What It Covers | From (+ VAT) |
|---|---|---|
| Infrastructure | External and internal network testing - perimeter, lateral movement, segmentation | £1,499 |
| Web App & API | Web applications and APIs assessed against OWASP Top 10 - logic flaws, auth bypass, data leakage | £1,999 |
| Cloud Security Review | Azure, AWS, and M365 tenant security posture - misconfiguration, access controls, identity | £1,999 |
| MDM Review | Mobile Device Management platform review - Android and iOS configuration against benchmarks | Scoped on enquiry |
| PCI DSS Pen Test | Requirement 11.4 compliant testing of cardholder data environments - internal, external, segmentation | Scoped on enquiry |
Final pricing depends on the number of targets and environment complexity agreed during the scoping call. Discuss your requirements →
WHAT IS INCLUDED IN THE PRICE?
At Vincent Cyber Defence, every penetration test engagement includes:
- CVSS-scored findings report: Every vulnerability is rated using the Common Vulnerability Scoring System - severity, exploitability, and business impact clearly documented
- Executive summary: A non-technical overview suitable for board reporting, client due diligence, or auditor submission
- Prioritised remediation guidance: Findings are ranked so you know what to fix first, with practical guidance on how to fix it
- Free 30-day retest: Once you have remediated the findings, we re-test the affected areas at no additional cost and issue a clean retest attestation
- Two hours of direct engineer time: To walk your IT team or developers through the findings and fixes - no extra charge
- Fixed-price guarantee: The price agreed at scoping is the price you pay. No day-rate overruns, no surprise invoices
Our approach: All engagements are scoped and fixed-price before work begins. A free 30-day retest window is included in every engagement. View our penetration testing service →
HOW DOES SCOPING WORK?
A scoping call is a short conversation - typically 20 to 30 minutes - to define exactly what will be tested. We ask about your environment: what IP ranges, applications, cloud services, or MDM platforms are in scope; what compliance framework you are working toward; and whether you have a specific deadline.
From this, we produce a fixed-price quote. There are no obligations and no cost for the scoping call. Once agreed, we schedule the engagement and begin testing - no retainers, no project management overhead.
If you have a tender deadline or audit date, tell us at scoping and we will confirm whether the timeline is achievable before you commit.
WHAT SHOULD YOU WATCH OUT FOR?
- Day-rate pricing with no ceiling: Some providers quote a day rate rather than a fixed price. Without a defined scope and ceiling, costs can escalate significantly - particularly on complex engagements. Always ask for a fixed-price quote
- Retest charged separately: Many providers charge for the retest as an additional engagement. At VCD, a free 30-day retest is included as standard - make sure you understand what you are getting before signing
- Generic reports: A pen test report that cannot be submitted to your QSA, ISO 27001 auditor, or enterprise client is not worth the cost. Ask upfront whether the report format meets your specific compliance requirement
- Vague scope: A quote without a clearly defined scope is a blank cheque. Make sure the agreement specifies exactly what is in scope - IP ranges, URLs, environments - before work begins
- No direct assessor access: The person who scoped the engagement should be involved in the test. If you are passed to a different team after signing, the context and quality can suffer
WHICH SECTORS NEED PENETRATION TESTING AND WHY?
Penetration testing is not industry-specific, but certain sectors face mandatory requirements or strong commercial pressure that makes it effectively non-negotiable.
Financial Services
Financial services firms handling card payments must meet PCI DSS Requirement 11.4, which mandates annual internal and external penetration testing of cardholder data environments. FCA-regulated firms are also expected to evidence regular technical security testing as part of their operational resilience obligations. Cyber insurers increasingly require pen test evidence before issuing or renewing policies. Cyber Essentials for financial services →
Healthcare and Life Sciences
Organisations handling NHS patient data must submit annual penetration test evidence through the NHS DSPT (Data Security and Protection Toolkit). UK GDPR Article 32 legally requires regular testing of technical security measures for any organisation processing personal data - in healthcare, where data sensitivity is highest, auditors and the ICO expect robust evidence. MedTech and health-tech companies seeking SOC 2 Type II or ISO 27001 certification also require pen test results as part of their audit trail. Cyber Essentials for healthcare →
Technology and Software Companies
SaaS and software businesses are routinely asked to provide pen test reports by enterprise clients and procurement teams. SOC 2 Type II - the most common trust framework for US and UK enterprise sales - requires penetration testing evidence to support the Security and Availability criteria. ISO 27001 certification bodies expect it as part of ISMS evidence. For tech companies selling into regulated sectors, a current pen test report is often a deal-breaker requirement. Cyber Essentials for technology businesses →
Government and Defence Supply Chain
MOD suppliers and prime contractors operating under DEFCON 658 must demonstrate cyber posture through DCC Level 0 certification, which increasingly sits alongside expectations for independent technical testing. Broader government supply chain contracts often require ISO 27001 or Cyber Essentials Plus - both of which are strengthened by penetration test evidence. For suppliers bidding on higher-value contracts, a pen test report demonstrates security maturity beyond the minimum certification requirements. Cyber Essentials for government and defence →
Law Firms and Professional Services
The SRA's cyber security guidance for law firms identifies penetration testing as a key control for firms handling client funds and sensitive legal data. Legal professional privilege data and client financial information make law firms high-value targets - and a breach carries both regulatory and reputational consequences. Enterprise and financial sector clients increasingly require their legal advisers to evidence a current pen test as part of supplier due diligence. Cyber Essentials for law firms →
Manufacturing and Supply Chain
Manufacturers supplying to automotive, aerospace, or defence primes face supply chain security requirements that include evidence of technical security testing. As IT and OT (operational technology) networks converge, the attack surface expands significantly - and pen testing of network segmentation between IT and production environments is increasingly required by enterprise customers and cyber insurers. Cyber Essentials for manufacturing →
IS IT WORTH THE COST?
For most UK businesses facing a compliance requirement or enterprise contract obligation, penetration testing is not optional - it is the only way to produce the evidence that auditors and clients require.
Beyond compliance, a well-scoped pen test finds vulnerabilities before attackers do. The cost of a single incident - regulatory fines, client notification, reputational damage, and downtime - typically dwarfs the cost of the test that would have prevented it.
Frameworks that explicitly require penetration testing include:
- PCI DSS Requirement 11.4 - annual internal and external testing of cardholder data environments
- ISO 27001 Annex A 8.8 - technical vulnerability management; auditors expect pen test evidence
- NHS DSPT - annual pen test evidence required for organisations handling NHS patient data
- SOC 2 Type II - penetration testing supports Security and Availability trust service criteria
- UK GDPR Article 32 - legally requires regular testing of technical security measures
Need a penetration test? Vincent Cyber Defence delivers fixed-price, CVSS-scored assessments with a free 30-day retest included as standard. Discuss your requirements →