A penetration test quote is only as good as the scope behind it. Vague requests such as "test our website" produce vague prices, mismatched expectations and reports that miss the systems you actually worry about. A few facts gathered up front make the estimate faster, the price fairer and the testing more useful.
This guide lists what to prepare for each type of test, explains how our instant estimate and scoping call fit together, and covers the scoping mistakes that most often cause surprises later.
In short
- Start with the reason for testing: a customer request, compliance evidence, a product launch or an incident.
- Count what is in scope: IP addresses, applications, user roles, API endpoints, devices and cloud tenants.
- Decide which environment will be tested and when.
- Use the instant quote calculator for an indicative estimate without signing up.
- A short scoping call then confirms details and produces a fixed quote before any work starts.
How our scoping process works
- Instant estimate: the calculator asks for the main size drivers and returns an indicative effort estimate straight away. There is no account to create.
- Scoping call: we confirm what is in and out of scope, the environment, access arrangements, timing and any compliance wording you need the report to address.
- Fixed quote and rules of engagement: you receive a fixed price, the agreed scope, testing window, contacts and constraints in writing.
- Testing and report: testing runs in the agreed window, followed by a report and a debrief.
The estimate gets you a realistic budget quickly. The call makes sure the quote matches what you actually need tested.
What to prepare by test type
| Test type | What to have ready |
|---|---|
| External infrastructure | Number of public IP addresses and hostnames, including remote access and mail gateways |
| Internal infrastructure | Number of internal IP ranges or hosts, Active Directory domains, and whether testing is remote or on site |
| Web application | Number of applications, user roles to test, and the main user journeys |
| API | Number of APIs and approximate endpoint count, plus any OpenAPI, GraphQL or Postman documentation |
| Mobile application | Number of apps, platforms (iOS, Android) and user roles |
| Cloud and Microsoft 365 | Number of cloud accounts or subscriptions and Microsoft 365 tenants in scope |
| Server and device build review | Number of server and end-user device builds to review |
These are the same drivers the calculator asks about. Approximate numbers are fine at the estimate stage.
Questions to answer before the scoping call
- Why are you testing? Customer due diligence, ISO 27001, SOC 2, PCI DSS, NHS DSPT or DTAC, cyber insurance, or a new release. The driver shapes scope and reporting.
- Which environment? Production, staging or both. See staging or production for the trade-offs.
- What access will testers have? Test accounts for each role, VPN or jump host access for internal work, and documentation for APIs.
- When can testing happen? Preferred dates, change freezes, and any out-of-hours requirements.
- What is off limits? Fragile systems, third-party services you do not own, and techniques such as denial of service or phishing.
- Who are the contacts? A technical lead and an emergency contact who can pause testing if needed.
Scoping mistakes that cause surprises
- Leaving out the systems that matter: testing the marketing site while the customer portal or API stays untouched.
- No credentials for authenticated testing: most serious application flaws sit behind login.
- Forgetting third-party ownership: hosted platforms may need permission or have their own testing rules.
- Undocumented APIs: if testers have to discover endpoints first, either allow time for it or provide the documentation.
- Moving targets: releasing new code during the test window makes findings harder to reproduce.
What an instant estimate cannot know
- Unusual architecture, legacy systems or complex trust relationships can change effort once discussed.
- Compliance evidence packs, customer-facing summary letters or attestation wording may add reporting time.
- On-site work and compressed timelines affect cost.
- The estimate is indicative. The fixed quote follows the scoping call, before any work starts.
Attack Vector identifies security weaknesses within the agreed scope and reports them so your team can prioritise remediation. For typical UK budgets, read the UK penetration test cost guide. Engagements start from £1,500 for a small, well-defined job, and you can email [email protected] with any scoping questions.
FAQ
Do I need exact numbers to get an estimate?
No. Approximate counts are enough for the calculator. We confirm the detail on the scoping call.
Is the instant estimate a fixed price?
No. It is an indicative effort estimate. The fixed quote comes after a short scoping conversation.
Do I have to sign up to use the calculator?
No. You can get an estimate without creating an account.
How long does scoping take?
Usually a short call once you have the information above. Complex or multi-part engagements may need a follow-up.
Can we combine several test types in one engagement?
Yes. Combining, for example, a web application and its API, or external and internal infrastructure, is common and often more efficient than separate projects.
Suggested Resources
Ready to strengthen your security?
Talk to our consultants about your penetration testing requirements, or get a fast, transparent quote.