Live National Cyber Helpline · 0300 123 2040
Assured Cyber Protection Cyber & insurance briefing

Tools

Penetration Testing Cost Calculator UK: Days and Price

By the Assured Cyber Protection team · Updated 2026 · Reviewed

Penetration test quotes for the same job routinely differ by thousands, and the reason is almost never the day rate. It is the tester-days each supplier has quietly scoped behind the number. Enter what you actually want tested and this calculator turns it into days first, then a price, so you can hold every quote to the same scope.

Scope your penetration test

Leave a box at zero if you do not want that part tested.

External and application targets
Firewalls, mail, VPN, servers with a public address.
Marketing sites with a contact form at most.
Customer portal, booking system, intranet.
Anything taking card data or driving a large API.
APIs tested on their own, not as part of an app above.
Count iOS and Android separately.
Internal network
Zero for no internal test. Remote testing via a jump box counts as one.
Laptops, servers, printers, cameras. Only used if you test internally.
Add-ons
Day rates you have been quoted (£ per tester per day)

Defaults are the manual UK day rates set out in our penetration testing guide. Replace them with the rates in your own quotes.

How the estimate is built

Every line comes from a stated rule, so you can argue with it. The tool assumes hands-on manual testing by one tester, not an automated scan with a report template on top.

  • External infrastructure: half a day to set up and verify the target list, plus a day per 10 live hosts, with a one-day minimum.
  • Web applications: 2 days for a brochure site, 3 days for a standard app with a login and a handful of roles, 5 days where payments, many privilege levels or a large API surface are in play. Standalone APIs are 2 days each, mobile builds 3 days each.
  • Internal network: 2 days as a floor, plus a day per 60 devices, plus a day for each office beyond the first.
  • Add-ons: half a day of wireless testing per office, 2 days for a cloud and Microsoft 365 configuration review, 2 days for a phishing and social engineering exercise.
  • Reporting: 20% of the testing days, never less than half a day. Writing up findings, evidence and remediation advice is real work and honest suppliers price it.
  • Retest: 15% of the testing days if you tick it. Ask first, because some suppliers include one free retest within a set window after the report.

Days are rounded to the nearest half day and the price is the total multiplied by the low and high rates you entered.

Use the day count, not the price, to compare quotes

Ask every supplier for the same three things: how many tester-days are included, who the named tester is and what they are certified in (CREST, CHECK or OSCP), and whether exploitation is manual. Once you have tester-days on all three quotes, the cheap one usually stops looking cheap. A quote well under the days this tool suggests is either a narrower scope than you asked for or a vulnerability scan wearing a pen test label.

Two more things move a real invoice that this calculator deliberately leaves out: travel and accommodation for onsite work, which is billed at cost, and out-of-hours or weekend testing to avoid disrupting trading, which usually carries a premium. Get both written into the quote rather than discovered later.

Where testing sits next to certification and insurance

A penetration test is not a substitute for Cyber Essentials, and Cyber Essentials Plus is not a penetration test: it is an audit that checks a defined set of controls on a sample of devices. Price them separately with our Cyber Essentials cost calculator. Insurers anchor their questions on the certification baseline, though a recent test report strengthens an application and answers the harder questions in client security questionnaires. If you are preparing a renewal, run the cyber insurance readiness checklist alongside this, and if the test uncovers gaps worth quantifying, the downtime cost calculator puts a number on what those gaps could cost you per hour offline.

The Threat Brief

A calm, plain-English security update. Once a week.

New scams, breach lessons, and cyber insurance changes that affect UK businesses, explained without the jargon. No alarmism, no vendor spin.

Unsubscribe anytime. We never share your address.