Home/Blog/Security Essentials
Security Essentials

Affordable Penetration Testing UK: What You Get From £1,500 (and What You Don’t)

"Affordable" should mean a clear scope at a fair price, not a race to the bottom. Attack Vector engagements start from £1,500 for a complete small job, including the report and debrief. It is a minimum project price, not a day rate, and it is real for tightly defined work. It is not a promise that a multinational estate, a multi-role SaaS platform, or a full PCI cardholder environment will fit in the same box.

This guide is for UK buyers who need honest expectations: what a lower-cost engagement can deliver, what it cannot, and how to avoid paying for a vulnerability scan with a penetration testing label.

The short version

  • From £1,500 is the minimum price for a whole small, well-bounded job, not a day rate.
  • Good lower-cost tests still include manual validation and a usable report.
  • Large IP ranges, many user roles, heavy API surfaces and on-site internal work cost more.
  • Ask what is excluded before you celebrate the number on the quote.
  • Use a scoped calculator, then confirm on a call; do not treat an instant estimate as a fixed contract.

What "from £1,500" typically buys

Entry-level fixed scopes in the UK market often look like one of these:

  • A small external infrastructure check against a handful of public IP addresses
  • A simple web application with one primary user role and a modest feature set
  • A narrowly defined API with a limited endpoint count and clear documentation
  • A focused retest of previously reported issues, quoted separately and often below a full engagement

At this level you should still expect:

  • Agreed rules of engagement and a written scope
  • Manual testing time, not only automated scanning
  • A report with evidence, severity and remediation guidance your team can prioritise
  • A debrief so findings are not left as unexplained tickets

Attack Vector identifies security weaknesses so you can prioritise remediation. Lower price points do not change that model: we report clearly; your organisation owns the fixes.

What £1,500 does not buy

Be explicit. An entry quote usually does not include all of the following at once:

Often out of entry scopeWhy it expands effort
Large external IP estates (dozens to hundreds)More hosts, more services, more false-positive triage
Full internal AD assessments across many VLANsLateral movement and identity work needs depth
Multi-role applications (admin, finance, customer, partner)Authorisation matrices multiply test cases
Large or undocumented API cataloguesEndpoint discovery and BOLA-class checks take time
Mobile apps on multiple platformsEach platform is its own client surface
Multiple cloud accounts with deep configuration reviewPer-provider and per-account effort
Red team / phishing / physical testingDifferent methodology and approvals
Unlimited free retesting foreverRetest days should be defined commercially
Guaranteed compliance certificationTests produce evidence; certification bodies decide pass/fail

If a supplier offers "unlimited web apps, unlimited IPs, next-day report" at the same entry price, treat the claim with caution. Something in quality, scope honesty or who actually performs the work is usually compromised.

How UK pricing actually behaves

Most reputable firms price from estimated consultant days, then convert to a fixed quote once scope is clear. At Attack Vector, £1,500 is the minimum price for a complete small job rather than a day rate. Typical small-to-medium projects run higher because they need more testing days.

Drivers that move you up the range:

  1. Attack surface size: hosts, apps, endpoints, cloud accounts
  2. Authentication depth: unauthenticated versus several privileged roles
  3. Environment access: remote versus on site; staging parity work
  4. Compliance paperwork: PCI-oriented evidence packs, customer questionnaires, attestation letters
  5. Turnaround: compressed timelines cost more than planned windows

For wider ranges and worked examples, see the UK pricing guide.

How to keep cost down without gutting quality

Tighten the question

"Test everything" is expensive and vague. "External test of these eight production IPs before cyber insurance renewal" is affordable and auditable.

Prefer grey box when it saves days

Providing authenticated roles and architecture notes often reduces time spent on guesswork and increases time spent on authorisation and logic flaws. That can improve value even if the day count stays similar.

Separate must-have from nice-to-have

For a first engagement, many organisations fund external infrastructure or the customer-facing application first, then schedule internal or API depth in the next quarter.

Do not confuse Cyber Essentials with a pentest

Cyber Essentials and Cyber Essentials Plus are valuable baseline schemes. They are not substitutes for a penetration test, and a pentest is not a substitute for those certifications. Budget for the assurance you actually need.

Insist on a human report

If the deliverable is indistinguishable from a scanner PDF, you did not buy penetration testing. You bought a scan.

Cheap tests that create expensive decisions

Common failure modes at the low end of the market:

  • Scope cutting: excluding the systems that actually matter so the quote looks cheap
  • Scan-as-pentest: no manual validation, no chaining, no business impact
  • Severity fog: everything marked critical, or nothing marked actionable
  • No retest path: findings sit open with no verification budget
  • Wrong audience report: engineers cannot reproduce; leadership cannot decide

An affordable test that surfaces three real, evidenced weaknesses on the systems you care about is worth more than an expensive binder that never leaves the GRC SharePoint.

What an entry-level test cannot cover

  • £1,500 is a starting point for limited scopes, not a typical price for larger estates.
  • Instant online estimates are indicative. Fixed quotes follow a scoping conversation.
  • No test guarantees you will pass an audit, win a tender, or obtain insurance cover.
  • We identify weaknesses and document them; we do not claim to remediate your systems as part of the test fee.
  • Aggressive discounting that depends on unnamed testers or fully automated pipelines should be disclosed by the supplier; ask who will touch your systems.

If you already know the rough size of the job, try the instant quote calculator. If you are unsure whether you need web, API, external or internal work first, email [email protected] for a short scoping discussion.

Service overviews sit under penetration testing services, including web application and infrastructure testing.

FAQ

Is a £1,500 penetration test legitimate?

It can be, when the scope is small and the days match the price. It is not legitimate if the marketing promises enterprise-wide coverage for the same fee.

Will an entry-level test satisfy my auditor?

Sometimes, if the auditor asked for independent testing of a specific system and your scope matches that system. It will not satisfy a requirement for full CDE internal and external testing under PCI DSS if you only bought a tiny external sample.

Can we start small and expand later?

Yes. Many organisations run a focused first test, remediate, retest, then widen scope. That is often healthier than one oversized engagement nobody remediates.

Do you price per vulnerability found?

No. Ethical testing is scoped by effort and attack surface, not by finding count. Paying per bug creates the wrong incentives.

Are evenings and weekends cheaper?

Out-of-hours windows can add cost because of staffing, not reduce it. Clarify timing in the statement of work.

What do we send to get an accurate quote?

Asset lists or URLs, whether authentication is required, environment (staging or production), deadline, and any compliance wording (ISO 27001 evidence, SOC 2 customers, PCI, insurer questionnaire). The calculator captures much of this; the call clears the rest.

Suggested Resources

#pricing#small-business#scoping#buyer-guide#penetration-testing

Ready to strengthen your security?

Talk to our consultants about your penetration testing requirements, or get a fast, transparent quote.