Tools
Penetration Testing Cost Calculator UK: Days and Price
Penetration test quotes for the same job routinely differ by thousands, and the reason is almost never the day rate. It is the tester-days each supplier has quietly scoped behind the number. Enter what you actually want tested and this calculator turns it into days first, then a price, so you can hold every quote to the same scope.
Scope your penetration test
Leave a box at zero if you do not want that part tested.
How the estimate is built
Every line comes from a stated rule, so you can argue with it. The tool assumes hands-on manual testing by one tester, not an automated scan with a report template on top.
- External infrastructure: half a day to set up and verify the target list, plus a day per 10 live hosts, with a one-day minimum.
- Web applications: 2 days for a brochure site, 3 days for a standard app with a login and a handful of roles, 5 days where payments, many privilege levels or a large API surface are in play. Standalone APIs are 2 days each, mobile builds 3 days each.
- Internal network: 2 days as a floor, plus a day per 60 devices, plus a day for each office beyond the first.
- Add-ons: half a day of wireless testing per office, 2 days for a cloud and Microsoft 365 configuration review, 2 days for a phishing and social engineering exercise.
- Reporting: 20% of the testing days, never less than half a day. Writing up findings, evidence and remediation advice is real work and honest suppliers price it.
- Retest: 15% of the testing days if you tick it. Ask first, because some suppliers include one free retest within a set window after the report.
Days are rounded to the nearest half day and the price is the total multiplied by the low and high rates you entered.
Use the day count, not the price, to compare quotes
Ask every supplier for the same three things: how many tester-days are included, who the named tester is and what they are certified in (CREST, CHECK or OSCP), and whether exploitation is manual. Once you have tester-days on all three quotes, the cheap one usually stops looking cheap. A quote well under the days this tool suggests is either a narrower scope than you asked for or a vulnerability scan wearing a pen test label.
Two more things move a real invoice that this calculator deliberately leaves out: travel and accommodation for onsite work, which is billed at cost, and out-of-hours or weekend testing to avoid disrupting trading, which usually carries a premium. Get both written into the quote rather than discovered later.
Where testing sits next to certification and insurance
A penetration test is not a substitute for Cyber Essentials, and Cyber Essentials Plus is not a penetration test: it is an audit that checks a defined set of controls on a sample of devices. Price them separately with our Cyber Essentials cost calculator. Insurers anchor their questions on the certification baseline, though a recent test report strengthens an application and answers the harder questions in client security questionnaires. If you are preparing a renewal, run the cyber insurance readiness checklist alongside this, and if the test uncovers gaps worth quantifying, the downtime cost calculator puts a number on what those gaps could cost you per hour offline.