Penetration testing cost UK buyers between £1,500 and £45,000 in 2026, and the gap between those two numbers is not a rounding error. It is the distance between a two-day external test of a single web application and a full-scope engagement covering networks, cloud, APIs, wireless and social engineering across a multi-site organisation. Both are sold as penetration testing, both produce a PDF, and both can be entirely defensible. The difference is what the number actually buys, and most UK buyers have never been shown the arithmetic behind it.
This guide sets out the real penetration testing cost UK prices for 2026, broken down by test type, scope and provider tier. It explains what drives a quote up or down, what a typical engagement includes at each price point, how testers count the thing they are counting, and how to compare two quotes that look nothing alike. It is written for UK businesses of roughly ten to five hundred staff, the range where this is usually a one-off compliance or due-diligence purchase rather than a standing line in the security budget.
One principle runs underneath all of it. A test is priced on scope, not on effort. The number on the invoice is a function of how many systems are in play, how deep the testers are allowed to go, and how much reporting and retest time is bundled in. Once you understand those three levers, the penetration testing cost UK market stops looking like a black box and starts looking like a menu you can shop.
The context is not academic. The government’s Cyber Security Breaches Survey 2025/2026 found that 43% of UK businesses identified a breach or attack in the previous twelve months, an estimated 612,000 organisations. The same survey found that only 13% of businesses carry out any penetration testing at all. The gap between those two figures is the reason this guide exists.
Table of contents
- What penetration testing actually is in 2026
- Penetration testing cost UK: the 2026 price table
- The day-rate arithmetic behind every penetration testing cost UK quote
- How testers count your scope, and how that sets the penetration testing cost UK total
- What drives the penetration testing cost UK number up or down
- Penetration testing cost UK by test type: which one you actually need
- What the penetration testing cost UK figure buys at each price point
- Penetration testing cost UK versus the cheaper and dearer alternatives
- Penetration testing cost UK in context: what the market actually spends
- Accreditation: what CREST, CHECK and the Cyber Scheme add to the penetration testing cost UK figure
- What compliance frameworks actually demand
- A worked penetration testing cost UK example
- What is not in the penetration testing cost UK quote: the hidden costs
- How to compare two penetration testing cost UK quotes
- How much penetration testing cost UK budget a business needs in 2026
- How to get a fair penetration testing cost UK quote
- Twelve questions to ask before you sign
- Common penetration testing cost UK mistakes to avoid
- Frequently asked questions
- References
What penetration testing actually is in 2026
Before the numbers, a calibration on what penetration testing actually delivers, because the penetration testing cost UK conversation is full of quotes for things that are not the same service at all.
The NCSC definition, and why it sets the penetration testing cost UK floor
The NCSC defines a test as “a method for gaining assurance in the security of an IT system by attempting to breach some or all of that system’s security, using the same tools and techniques as an adversary might”. Two words in that sentence carry the penetration testing cost UK buyers pay: attempting and adversary. You are paying for a skilled human to try, and to fail informatively when the control holds. Automated tooling cannot do the trying, which is why the floor sits where it does.
Penetration testing versus vulnerability scanning
A vulnerability scan is an automated pass over a set of assets that flags known weaknesses. It is fast, cheap and repeatable, and it is the right tool for continuous monitoring. A test is a human-led exercise in which testers take those findings and try to exploit them, chaining weaknesses into a realistic attack path and demonstrating impact.
The penetration testing cost UK gap between the two is large because one is machine time and the other is senior analyst time. As a working rule, anything quoted below roughly £500 per day is a scan with a report template wrapped around it. Vendors who publish their rates say the same thing in plainer language: day rates under £500 typically indicate automated scanning rather than manual testing.
Black box, grey box and white box
The access the testers are given changes both the price and the value. A black box test starts from the outside with no internal documentation, which is the most realistic and the most expensive per finding. A grey box test provides credentials and a network diagram, and it is the most common commercial arrangement. A white box test hands over source code and architecture, which is thorough but usually reserved for critical applications.
When you compare penetration testing cost UK quotes, line up the access model first. A black box quote is not a premium version of a grey box one; it is priced for the extra days that blind discovery takes, and it will usually find less inside the same budget.
What a test does not do
The NCSC is unusually blunt on this point. Its penetration testing guidance states that a test can only validate that systems are not vulnerable to known issues at the time of the test, and that it is “not a magic bullet”. It also warns that gaps between tests are “often a year or more”, during which nothing tested stays tested.
The same guidance is explicit that “risk assessment and decisions on the application of fixes are your responsibility”, not the testing team’s, and that organisations should not wholly outsource vulnerability mitigation to their testers. A test does not monitor, does not patch and does not certify you. Any vendor selling it as a standing guarantee is selling something else, and the penetration testing cost UK figure they quote should be read with that in mind.
Who actually pays a penetration testing cost UK bill
In practice UK testing is bought by three groups: organisations with a compliance obligation, organisations answering a customer’s security questionnaire, and organisations that have had a scare. The first two buy to a specification someone else wrote. The third buys to a specification they write themselves, and tends to get more from the money. Recognising which group you are in is the single most useful thing you can do before requesting a penetration testing cost UK quote, because it determines the scope, and the scope determines the price.
Penetration testing cost UK: the 2026 price table
The table below is the core of the guide. It reflects 2026 UK market rates across the three provider tiers that actually exist: boutique specialist firms, mid-market managed security providers, and the large global consultancies. Figures are typical engagement totals rather than hourly rates, because that is how the work is genuinely quoted.
| Test type | Boutique | Mid-market | Global firm | Typical days |
|---|---|---|---|---|
| External network (per site) | £1,500–£3,500 | £3,000–£6,000 | £4,000–£8,000 | 2–5 |
| Internal network | £2,500–£5,000 | £5,000–£12,000 | £7,000–£15,000 | 5–8 |
| Web application | £2,000–£6,000 | £2,500–£8,000 | £6,000–£15,000 | 2–5 |
| API testing | £2,500–£7,000 | £4,000–£10,000 | £7,000–£18,000 | 3–7 |
| Cloud configuration review | £3,000–£8,000 | £5,000–£12,000 | £9,000–£20,000 | 3–8 |
| Wireless / Wi-Fi | £1,500–£3,000 | £2,500–£5,000 | £4,000–£8,000 | 1–3 |
| Social engineering / phishing | £1,500–£4,000 | £2,500–£6,000 | £5,000–£10,000 | 2–5 |
| Mobile application | £3,000–£7,000 | £5,000–£11,000 | £8,000–£18,000 | 4–8 |
| Full-scope (multi-vector) | £8,000–£18,000 | £12,000–£25,000 | £20,000–£45,000 | 10–25 |
The spread within each row matters as much as the spread between rows. A web application test at the bottom of the boutique range is a small app with a handful of endpoints. At the top of the global range it is a multi-tenant platform with authentication, payments and a mobile backend. The penetration testing cost UK difference there is the number of distinct attack surfaces, not the calibre of the testers.
How published penetration testing cost UK prices compare
A useful sanity check is that several UK providers now publish their rates openly, and the published numbers sit squarely inside the table. One CREST-accredited firm lists a £2,500 minimum engagement for a two-to-three-day external network test, £3,750–£6,250 for a three-to-five-day web application or external network test, £6,250–£8,750 for a five-to-seven-day SaaS platform test, £6,250–£10,000 for a five-to-eight-day internal network test, and £12,500–£25,000 for a ten-to-twenty-day full assessment.
Those published figures land in the mid-market column. A boutique will often come in below them and a global firm above, for work that is genuinely comparable to the same penetration testing cost UK scope. When a penetration testing cost UK quote falls a long way outside that envelope in either direction, the scope is doing something the price list is not showing you.
How to read the table
Three things to notice. First, global firms are not twice as good as boutiques; they are priced for brand, insurance and the ability to staff work across time zones. For a single-site UK business, a strong boutique or mid-market provider is usually better value.
Second, the full-scope row is not the sum of the rows above it, because testers work vectors in parallel and consolidate the reporting into one document. Third, every figure is a starting point. Add a regulated environment, a production system with no maintenance window, or a named accreditation requirement, and the penetration testing cost UK number moves upward before anyone has touched a keyboard.
The day-rate arithmetic behind every penetration testing cost UK quote
Almost every quote in that table is a day rate multiplied by a day count, plus reporting time. Learn the rate and any total decomposes.
The day rate underneath every penetration testing cost UK number
In the 2026 UK market, certified testers are charged out between roughly £800 and £2,500 per day depending on seniority, accreditation and the buyer’s sector. The commercial midpoint for an experienced accredited tester sits around £1,200, and one CREST-accredited provider publishes exactly that figure as its standard consultant day rate. A junior at a smaller firm is typically £800 to £1,000, and specialist work such as hardware or automotive testing sits at the top of the range.
The ladder is worth internalising because it tells you what a discount really is. A firm quoting £700 a day is not being generous; it is staffing the work differently. The honest way to buy at the bottom of the penetration testing cost UK range is to reduce the day count, not the day rate. Every credible penetration testing cost UK saving is a day removed.
Decomposing a penetration testing cost UK quote into days
Once you know the rate, any total decomposes. A £6,000 engagement at £1,200 a day is five days: roughly four of testing and one of reporting. A £12,000 engagement is ten days, which is enough for two or three vectors with a proper write-up. A vendor who will not tell you the split is asking you to trust an unshown calculation, and that is the single most common way a penetration testing cost UK purchase goes wrong.
How reporting days are counted
Reporting is real work and it is properly chargeable, but it should be visible. A sensible ratio is one reporting day for every three to four testing days. If a quote is five days total and three of them are reporting, you are buying a document rather than a test. If reporting is not named as a line in the penetration testing cost UK breakdown, ask whether it is bundled or extra, because both answers exist in the market and only one of them is in the price you were shown.
Where the day count is negotiable
The penetration testing cost UK day count is negotiable in exactly two places: scope and depth. Removing an asset from the list removes days. Reducing the depth — perimeter only, no lateral movement — removes days. Everything else is haggling over the rate, which mostly buys you a less experienced tester. Larger engagements do attract volume treatment, and providers commonly indicate that rates become negotiable past around fifteen days, so if you are buying a full-scope programme the penetration testing cost UK figure has more give in it than a three-day test ever will.
Fixed price or time and materials
Most UK testing is sold fixed-price against a written scope, which is the right default for a buyer because it puts the estimating risk on the vendor. Time and materials makes sense only for genuinely exploratory work, such as a first look at an estate nobody has documented. If you are offered time and materials for a standard external test, ask why the penetration testing cost UK figure cannot be fixed, and read our comparison of fixed-price versus time-and-materials contracts before agreeing.
How testers count your scope, and how that sets the penetration testing cost UK total
Every provider prices from a unit count, and the units differ by test type. Knowing which unit is being counted is how you predict the quote before it arrives, and how you shrink it honestly.
External network: live hosts, not IP ranges, drive the penetration testing cost UK line
External testing is priced on responsive hosts and exposed services, not on the size of the range you own. A /24 with eleven live hosts is an eleven-host job. Buyers routinely hand over a whole range and get priced for 254 addresses. Send a current list of live external addresses and the penetration testing cost UK quote falls immediately, because the vendor no longer has to price the unknown.
Web application: roles, then endpoints
Applications drive the penetration testing cost UK line through the number of distinct user roles multiplied by the amount of functionality each role can reach. Three roles means three passes over the authorisation model. An application with one anonymous role and forty endpoints is far cheaper than one with four roles and the same forty endpoints, because the second one has to be tested four times over for access-control flaws.
API: endpoints and authentication flows
APIs are priced on endpoint count and the complexity of the authentication flow. A documented REST API with thirty endpoints and one OAuth flow is a predictable job. An undocumented API discovered by proxying the mobile app is not, and the quote will carry a discovery allowance to cover it. Handing over an OpenAPI specification is one of the cheapest ways to cut the penetration testing cost UK line for an API.
Cloud: subscriptions, tenants and identities
Cloud reviews set the penetration testing cost UK line from subscriptions or accounts, the number of identity boundaries, and whether the review covers configuration only or configuration plus exploitation. A single Azure subscription with one tenant is a two-to-three-day job. Three subscriptions across two tenants with federated identity is not three times the work, but it is not one times it either.
Internal network: sites, VLANs and device counts
Internal testing is priced on the number of physical or logical locations in your IT infrastructure and the segmentation between them. A flat single-site network of ninety devices is quick to traverse. A segmented estate with eight VLANs across three sites requires a decision about whether each segment is tested from inside or across the boundary, and that decision is worth several thousand pounds.
The scoping worksheet that controls your penetration testing cost UK quote
Fill this in before you ask anyone for a number. Every row you can answer precisely is a row the vendor does not have to price defensively, and defensive pricing is the largest avoidable component of any penetration testing cost UK quote.
| Test type | Unit the vendor counts | What to send with the RFQ | Effect on price |
|---|---|---|---|
| External network | Live, responsive hosts | Current list of live external IPs and open ports | Large reduction |
| Web application | User roles × functionality | Role matrix, page or feature count, test credentials | Large reduction |
| API | Endpoints and auth flows | OpenAPI or Postman collection | Moderate reduction |
| Cloud | Subscriptions and tenants | Subscription list, read-only reviewer access | Moderate reduction |
| Internal network | Sites, VLANs, device count | Network diagram and segment list | Large reduction |
| Wireless | SSIDs and physical sites | SSID list, site addresses, floor count | Small reduction |
| Social engineering | Target headcount and pretexts | Agreed target list and rules of engagement | Moderate reduction |
| Mobile | Platforms and backend reuse | Builds for each platform, backend scope note | Moderate reduction |
Notice that every “large reduction” row is information you already hold. That is the practical lesson of scoping: the penetration testing cost UK premium for vagueness is paid by the buyer, every time, and it is refundable only in advance.
What drives the penetration testing cost UK number up or down
Beyond the unit counts, a small number of levers move the total. Understanding them is the difference between accepting a number and negotiating one.
Scope breadth: how many systems are in play
The single biggest driver is the count of distinct assets. Each additional subnet, application, API, cloud subscription or site adds tester time and reporting surface. A common mistake is handing a vendor a vague “our whole environment” and receiving a quote priced at the worst-case interpretation. The penetration testing cost UK number drops sharply when the scope is a specific list.
Depth: how far the testers are allowed to go
A test that stops at the perimeter is cheaper than one that follows a foothold through the internal network to a domain controller. Depth is expressed as days of active testing, and it is the lever most buyers never see itemised. When one penetration testing cost UK figure is double another for an apparently similar scope, the answer is almost always that one includes more days of exploitation and lateral movement.
Access model and environment risk
Black box access costs more than grey box. Testing a live production system with no maintenance window costs more than testing a staging copy, because the testers must move more carefully and more slowly. Testing an environment where a finding could trigger a regulatory notification costs more again, because the reporting has to withstand scrutiny. These are real constraints on how the work can be done, not vendor comfort surcharges.
Reporting, retest and evidence format
The base test produces a report. What you pay extra for is the shape of that report and what happens afterwards. A retest to confirm fixes, an executive summary for the board, a technical appendix for engineers, and a mapping to a framework such as ISO 27001 or PCI DSS are usually separate line items. If you are buying to satisfy an auditor, the penetration testing cost UK figure should include the exact evidence format that auditor asks for.
Provider tier and overhead structure
The three tiers reflect different cost structures, not just different brands. Boutiques carry lower overheads and tend to put senior testers on every engagement. Global firms carry a sales organisation, a delivery platform and a liability structure that some enterprise buyers genuinely require. The right tier is a function of who is asking for the test.
Timing, rush fees and the calendar
Good testers are booked four to eight weeks out. Compressing that carries a premium, and expedited timelines commonly incur a rush charge on top of the base rate. Testing in the last fortnight of a quarter, or immediately before an audit deadline, is the most expensive time to buy. Booking a quarter ahead is a genuine discount that costs nothing but planning.
Penetration testing cost UK by test type: which one you actually need
Buying the wrong test is more expensive than buying an expensive test. The table below maps each type to the question it answers, so the scope follows the requirement rather than the brochure.
| Test type | Question it answers | Buy it when | Typical UK total |
|---|---|---|---|
| External network | What can an attacker reach from the internet? | Annual baseline, or a customer questionnaire asks | £1,500–£8,000 |
| Internal network | What happens after one laptop is compromised? | Post-incident, or before a segmentation project | £2,500–£15,000 |
| Web application | Can a user reach data they should not? | A customer-facing app holds regulated data | £2,000–£15,000 |
| API | Does the authorisation model hold without the UI? | Partners or a mobile app consume your API | £2,500–£18,000 |
| Cloud configuration | Is the tenant configured the way you think? | After a migration or a rapid build-out | £3,000–£20,000 |
| Wireless | Can someone in the car park get on the network? | Multi-tenant buildings, guest networks, retail | £1,500–£8,000 |
| Social engineering | Will staff hand over credentials? | Awareness programme needs a baseline | £1,500–£10,000 |
| Mobile application | What does the app leak on a lost device? | You ship an iOS or Android client | £3,000–£18,000 |
| Build and configuration review | Is the standard laptop or server build sound? | Before a rollout, or for Cyber Essentials Plus prep | £1,000–£4,000 |
Most UK mid-market buyers need two or three of these, not nine, and the penetration testing cost UK total should reflect that. The cheapest correct answer is usually an external network test plus whichever application actually holds the sensitive data, and the penetration testing cost UK total for that pair sits comfortably inside £6,000 to £12,000 at a mid-market provider.
Spend the penetration testing cost UK budget on the asset that would hurt most
If the budget forces a choice, test the system whose compromise would end the conversation with your largest customer. That is almost never the corporate network; it is the application or API through which customer data flows. Spending the penetration testing cost UK budget on the thing you would have to disclose is worth more than testing the thing that is easiest to scope.
The tests most often bought unnecessarily
Wireless testing at a single small office with one modern WPA3 network rarely repays its penetration testing cost UK line. Social engineering bought before any awareness training exists produces a predictable result and no new information. And a full internal test at an organisation that has never run an external one is out of order — you are checking the second door before the first.
What the penetration testing cost UK figure buys at each price point
Price is only meaningful against deliverables. The table below maps the three price bands to what a UK buyer can reasonably expect to receive, so a quote can be judged on value rather than on the number alone.
| Deliverable | Under £3,000 | £3,000–£10,000 | Over £10,000 |
|---|---|---|---|
| Active testing days | 1–2 | 3–5 | 5–10+ |
| Vectors covered | Single | 2–3 | 4+ / full scope |
| Tester seniority | Mid-level | Senior | Senior plus a named lead |
| Report depth | Findings list | Full technical report | Technical, executive and framework map |
| Retest included | Usually not | One retest | Multiple retests |
| Debrief | Email only | 30-minute call | On-site or structured workshop |
| Framework mapping | Rarely | On request | Standard (ISO / PCI) |
| Named tester CVs | No | On request | Provided up front |
The pattern is consistent. Below £3,000 you are buying a focused single-vector test with a findings list, which is right for a small business that needs to show one specific system has been examined. Between £3,000 and £10,000 you get a proper multi-day engagement with a full technical report and a retest, which is the sweet spot for most UK mid-market buyers. Above £10,000 the value sits in breadth, seniority and reporting structure.
The retest is the penetration testing cost UK line most buyers forget
A test without a retest is a photograph, not a process. Findings are only as useful as the confirmation that the fixes closed the gap. In the penetration testing cost UK market a single retest is commonly bundled into the mid-market band and charged separately at the boutique and global ends. When a quote is noticeably cheaper than its peers, check the retest first.
What a good report looks like
A strong report separates the executive summary a non-technical reader can act on from the technical appendix an engineer can reproduce. Every finding carries a severity rating, a clear statement of impact, the evidence that it was exploited, and a specific remediation. A report listing vulnerabilities without demonstrating exploitation is a scan dressed up as a test, and it is the most common way a penetration testing cost UK purchase underdelivers.
Judge the penetration testing cost UK quote against a sample report
Every serious provider will share a redacted sample. Read it the way your engineers will: can they reproduce a finding from the evidence given? Can your auditor find the framework mapping? Fifteen minutes with a sample report tells you more about what a penetration testing cost UK quote is worth than any amount of time on the vendor’s website.
The debrief is where the value lands
The report is the artefact; the debrief is where the penetration testing cost UK spend becomes action. A thirty-minute call in which the lead tester walks your engineers through the attack path is worth several pages of prose. Ask for it explicitly, ask that the person who did the testing attends, and put it in the diary before the engagement starts rather than after the invoice.
Penetration testing cost UK versus the cheaper and dearer alternatives
A test is one point on a spectrum of assurance, and the penetration testing cost UK figure only means something against that spectrum, and buying the wrong point on that spectrum is the most expensive mistake in this whole subject.
| Approach | What it proves | Typical UK cost | Cadence |
|---|---|---|---|
| Automated vulnerability scanning | Known weaknesses are present | £1,000–£4,000 per year | Continuous or monthly |
| Penetration test | Weaknesses are exploitable and chainable | £1,500–£45,000 per engagement | Annual, plus after change |
| Penetration testing as a service | Continuous testing with a platform view | £8,000–£30,000 per year | Rolling |
| Bug bounty programme | Real-world researchers find real bugs | Variable; payouts plus platform fee | Always on |
| Red team exercise | Whether detection and response work | £25,000–£100,000+ | Every one to three years |
| Threat-led testing (TLPT / CBEST) | Resilience against a modelled real adversary | Six figures | At least every three years |
Scanning is a complement to the penetration testing cost UK spend, not a substitute
Continuous scanning between annual tests is the highest-return security spend most mid-market businesses can make, precisely because it covers the gap the NCSC warns about. It is not a penetration testing cost UK saving, though; it answers a different question. Buy both, and size the test against the systems the scanner cannot reason about. Add threat intelligence on top only if your sector is actively targeted.
Where PTaaS genuinely helps
Penetration testing as a service suits organisations that ship code weekly and cannot wait a year for assurance. The annual figure often exceeds a single engagement’s penetration testing cost UK total, but it is buying a different cadence rather than a different depth. For a business releasing quarterly or slower, a conventional engagement plus scanning is usually better value.
Red teaming answers a different question
A red team exercise is not a bigger penetration test. It measures whether your detection and incident response function notices and reacts, and it presumes you already know the technical weaknesses. Commissioning one before you have run basic testing is spending £40,000 to learn something a £4,000 test would have told you. If you are considering it, our guide to running a cyber tabletop exercise is a far cheaper first step.
The cost of doing nothing
The cheapest option is always to skip the test, and for a great many UK businesses avoiding any penetration testing cost UK outlay is exactly what happens. The survey data below shows how few organisations test at all, and the disparity between how many are attacked and how many test is the real backdrop to every penetration testing cost UK conversation.
Penetration testing cost UK in context: what the market actually spends
The Cyber Security Breaches Survey is the only large-scale, government-run picture of UK practice, and it is unflattering.
Only 13% of businesses pay any penetration testing cost UK bill at all
Of the security activities the survey measures, formal risk assessments reach 30% of businesses, mock phishing exercises 22%, vulnerability audits 18%, penetration testing 13% and threat intelligence investment 11%. Testing is therefore a minority practice, and the penetration testing cost UK market is smaller than the breach numbers would suggest it should be.
Attack rates rise sharply with size
The same survey found 42% of micro businesses, 46% of small businesses, 65% of medium businesses and 69% of large businesses identified a breach or attack in the previous twelve months. Paying a penetration testing cost UK bill becomes more common with size too, but nothing like as steeply, which is why the mid-market is where the penetration testing cost UK question is most often asked and least often answered well.
Why the reported cost of a breach looks so low
The survey’s median perceived cost of a breach is £0, with an interquartile range of £0 to £200 for businesses. That number is often quoted as evidence that breaches are cheap. It is not. It reflects that most identified “breaches” are phishing attempts that went nowhere. The tail is what matters: the 95th percentile is £4,000 across all businesses and £10,000 for medium and large ones, and those figures exclude the reputational and contractual consequences that actually drive a penetration testing cost UK decision.
Board attention without board spending
Seventy-two per cent of businesses say senior management treat cyber security as a high priority, but only 31% assign board-level responsibility for it, rising to 68% at large businesses. Forty-seven per cent hold some cyber insurance but only 10% hold a specific cyber policy. That combination — high stated priority, thin ownership, thin cover — is precisely the environment in which a penetration testing cost UK budget gets approved once and never repeated.
Accreditation: what CREST, CHECK and the Cyber Scheme add to the penetration testing cost UK figure
Accreditation is one of the few price drivers that is verifiable before you buy, and it is worth understanding what each label means rather than treating them as interchangeable badges.
| Scheme | Who runs it | Who needs it | Effect on price |
|---|---|---|---|
| CHECK | NCSC | Central government, public sector, CNI | Highest |
| CREST | CREST (industry body) | Regulated and enterprise commercial buyers | Moderate premium |
| The Cyber Scheme | The Cyber Scheme | Commercial buyers; NCSC-approved for CHECK | Moderate premium |
| Individual UK CSC titles | UK Cyber Security Council | Anyone verifying a named tester | Reflected in day rate |
| Unaccredited boutique | — | Businesses where nobody asks for a certificate | Lowest |
CHECK sits at the top of the penetration testing cost UK range
CHECK is the NCSC-run scheme under which assured companies conduct authorised tests of public sector and CNI systems. For central government systems handling data marked OFFICIAL or above, a CHECK-assured assessment is mandatory, and the NCSC “strongly recommends” that all public sector systems be assessed by a CHECK company unless the risk owner explicitly advises otherwise.
The staffing overhead is real. The NCSC’s information for CHECK buyers states that CHECK Team Leaders hold the UK Cyber Security Council Security Testing title at Principal as a minimum, that Team Members hold an NCSC-approved CREST or Cyber Scheme qualification, and that all staff maintain at least SC clearance. Clearance takes months and does not transfer freely, so it lands squarely on the penetration testing cost UK figure, which is why a CHECK-delivered engagement sits at the upper end of any penetration testing cost UK range.
The 2026 title deadline is quietly tightening supply
The scheme is mid-transition. CHECK Team Leaders were required to hold a Council Security Testing title at Principal level or above from 31 March 2025, and CHECK Team Members must hold the title at Practitioner level by March 2026. CHECK companies are also expected to maintain Cyber Essentials Plus certification and to send staff to at least two NCSC events or masterclasses a year.
None of that is free, and it lands on the day rate that sets your penetration testing cost UK total. If your requirement genuinely needs CHECK, budget for it in 2026 rather than assuming last year’s number holds.
Do not pay the CHECK premium if you are not public sector
The NCSC could not be clearer: “If your organisation is not public sector, penetration testing does not need to be conducted by a CHECK service provider.” A private company buying CHECK because the label sounds authoritative is paying for security clearances that its engagement will never use. That is the single largest avoidable line in the penetration testing cost UK market.
CREST and the Cyber Scheme for commercial buyers
Most private-sector buyers need one of these instead. CREST accredits companies across security testing, red teaming, SOC, incident response, threat intelligence and secure design, assessing process and methodology rather than only individual skill. For financial services, healthcare and enterprise supply chains a CREST-accredited supplier is frequently a contractual requirement rather than a preference. Treat the delta over an unaccredited firm as the part of the penetration testing cost UK figure that buys an assurance you can evidence.
When accreditation is not worth paying for
If nobody is going to ask for the certificate, the accreditation premium buys process consistency rather than a better test. A small business testing one web application because it wants to know what an attacker could do is often better served by a strong unaccredited boutique than by an entry-level engagement from an accredited firm at the same price. Judge the penetration testing cost UK quote on who is on the keyboard.
How to verify an individual tester
Ask for the named testers and their current titles, then check them. The UK Cyber Security Council awards Security Testing titles at Practitioner, Principal and Chartered levels through licensed bodies including CREST and The Cyber Scheme. A named Principal on your engagement justifies a penetration testing cost UK premium far better than a company logo, and it is the only part of the accreditation story that tells you about the person who will actually test your systems.
What compliance frameworks actually demand
A large share of UK testing is bought to satisfy a specific requirement, and requirements differ far more than buyers expect. Getting this right is the difference between one correctly scoped test and two badly scoped ones.
| Framework | Does it demand a test? | Frequency | Typical scope driven |
|---|---|---|---|
| PCI DSS v4.0.1 | Yes, explicitly (11.4) | 12 months + after significant change | Internal, external and segmentation |
| ISO 27001 | No, but expects the evidence | Risk-based, usually annual | Whatever the risk assessment names |
| Cyber Essentials Plus | No — it is a sampled audit | Annual certification | Device sample, not a test |
| DORA (EU financial entities) | Yes, threat-led (Art. 26–27) | At least every three years | Live production critical functions |
| NIS2 (via EU customers) | Implied by risk management duties | Risk-based | Essential service systems |
| Customer questionnaire | Usually asks “when did you last test?” | Annual, in practice | Whatever the customer touches |
PCI DSS drives the most prescriptive penetration testing cost UK scope
PCI DSS v4.0.1 requirement 11.4 is explicit and itemised: a documented methodology (11.4.1), internal testing (11.4.2) and external testing (11.4.3) at least every twelve months and after any significant change, remediation and retest (11.4.4), and segmentation control testing (11.4.5 and 11.4.6) annually for merchants and every six months for service providers. Requirement 11.3 covers automated scanning and is a separate obligation.
If you take cards, that list is your scope document, and the penetration testing cost UK number follows directly from it. It also explains why card-handling businesses face a higher penetration testing cost UK bill than their size suggests: they are buying three test types, not one, plus a retest that is mandatory rather than optional.
ISO 27001 expects evidence, not a specific test
ISO 27001 does not mandate a penetration test by name. It expects you to demonstrate technical vulnerability management, and a test is the usual evidence an auditor accepts. That gives you latitude on the penetration testing cost UK scope that PCI DSS does not, and it is latitude worth using: scope the test to the systems your risk assessment actually names.
If you are weighing certifications, our comparison of Cyber Essentials Plus versus ISO 27001 sets out where each is worth the money, and the ISO 27001 certification cost breakdown covers the surrounding spend. The ISO 27001 readiness assessment checklist is the cheapest way to find out how much work sits in front of you.
Cyber Essentials Plus is an audit, not a test
This is the most common and most expensive confusion in the whole subject. Cyber Essentials Plus is a hands-on verification of the five technical controls — firewalls, secure configuration, security update management, user access control and malware protection — across a sample of devices. It is narrower than a penetration test and priced differently, commonly £1,399 plus VAT for a micro organisation, £1,699 for small, £2,399 for medium and £3,499 for large, with the base Cyber Essentials self-assessment starting from £320 plus VAT.
Buying Cyber Essentials Plus when a customer asked for a penetration test, or vice versa, wastes the whole penetration testing cost UK spend. Read the clause, then choose. Our Cyber Essentials guide walks through the certification itself.
What changed in Cyber Essentials for 2026
The scheme moved to Requirements for IT Infrastructure v3.3 on 27 April 2026, with the accompanying question set published earlier that year. The substantive changes matter to anyone scoping a test alongside certification: multi-factor authentication is now mandatory for cloud services where available, with no MFA an automatic fail; there is a formal definition of a cloud service as “an on-demand, scalable service, hosted on shared infrastructure, and accessible via the internet”; scoping language around excluded infrastructure now requires documented justification; and passwordless methods and passkeys are explicitly preferred.
If your estate is failing any of those, find out through a cheap configuration review rather than through a failed audit, and keep it out of the penetration testing cost UK scope. And if you are running end-of-life systems, read why unsupported software breaks both Cyber Essentials and ISO 27001 before you book anything.
DORA and threat-led testing at the top of the market
For EU financial entities, DORA Articles 26 and 27 require advanced testing by means of threat-led penetration testing at least every three years for identified entities, following the TIBER-EU framework, which the ECB updated on 11 February 2025 to align with DORA’s regulatory technical standards. TLPT runs against live production systems supporting critical functions; staged environments and vulnerability scans do not qualify.
This is six-figure work and it is not the penetration testing cost UK conversation a mid-market business is having. It is included here because vendors sometimes quote red-team-adjacent scopes to buyers who needed a standard external test, and the penetration testing cost UK difference between those two products is an order of magnitude.
Customer due diligence is the quiet driver
Increasingly the requirement arrives from a customer rather than a regulator, in the form of a security questionnaire with a line asking when you were last tested. That is a low bar in scope terms but a hard one in timing. The wider cybersecurity expectations buyers now write into contracts are worth reading alongside a third-party cybersecurity questionnaire template and our note on supplier contract security requirements, so you can see what the other side is grading. Scoping to the question actually asked keeps the spend proportionate.
If your customers are in the EU, the same conversation now arrives with a directive attached; our guide to NIS2 compliance for UK suppliers covers what changes.
A worked penetration testing cost UK example
Abstractions are easy to agree with and hard to budget from. Here is a concrete estate and the arithmetic that follows from it.
The business and the estate
A 45-person UK software business, single office, sells a subscription platform to mid-market customers. Its penetration testing cost UK question covers one external IP range with 12 live hosts, one customer-facing web application with 48 endpoints and 3 user roles, one REST API with 26 documented endpoints, two Azure subscriptions in a single tenant, and an office network of 95 devices on 4 VLANs. Two enterprise customers have asked for evidence of annual testing.
The full-scope penetration testing cost UK quote
A mid-market provider scopes it at 12 testing days: 3 for the external network, 4 for the web application, 3 for the API and 2 for the cloud configuration review. Add 2 days of reporting and 1 day of retest, and the engagement is 15 days. At the £1,200 accredited day rate the penetration testing cost UK total is £18,000.
| Line item | Days | At £1,200/day | Share of total |
|---|---|---|---|
| External network (12 live hosts) | 3 | £3,600 | 20% |
| Web application (48 endpoints, 3 roles) | 4 | £4,800 | 27% |
| API (26 endpoints) | 3 | £3,600 | 20% |
| Cloud configuration review (2 subscriptions) | 2 | £2,400 | 13% |
| Reporting | 2 | £2,400 | 13% |
| Retest | 1 | £1,200 | 7% |
| Total | 15 | £18,000 | 100% |
Where the money actually goes
Twelve of the fifteen days are testing, which is the penetration testing cost UK ratio to look for. Reporting is 13% of the penetration testing cost UK total and the retest 7%. If those two lines were absent from a competing quote, the comparison would be meaningless until you added them back.
The trimmed alternative
Now scope to the requirement rather than the estate. The two enterprise customers care about the platform they use, not the office network. Drop the cloud review and cut the internal-facing work: 3 days external, 4 days web application, 3 days API, 1.5 days reporting, 1 day retest — 12.5 days, or £15,000. Drop the API as well, if it is not customer-facing, and it is 9.5 days at £11,400.
That is a £6,600 swing, 37% of the original, and not one pound of it came from negotiating the rate. It came from deciding what the test was for. This is the whole argument of this guide in one worked example: the penetration testing cost UK figure is a scope decision wearing a price tag.
What would push it back up
Three things would move this business into a higher penetration testing cost UK band: taking card payments directly, which triggers the full PCI DSS 11.4 list; adding a second office, which makes internal testing a multi-site job; or a customer demanding a CREST-accredited supplier with a named Principal, which raises the day rate rather than the day count.
What is not in the penetration testing cost UK quote: the hidden costs
The invoice is not the whole penetration testing cost UK story. The table below is the part of the budget that arrives after the test and surprises people who only planned for the vendor’s number.
| Hidden cost | Who pays it | Typical size | How to control it |
|---|---|---|---|
| Internal scoping and coordination | Your IT lead | 2–5 days of internal time | Write the scope once, reuse it annually |
| Remediation engineering | Your developers or MSP | Often exceeds the test fee | Budget 1–2× the test cost for fixes |
| Retest, if not bundled | You | £1,000–£2,500 | Negotiate it into the original scope |
| Maintenance windows and out-of-hours | You, in premium rates | 15–30% uplift on affected days | Test staging where it is representative |
| Mid-engagement scope change | You, at short notice | Full day rate, no discount | Freeze the asset list before kick-off |
| Re-issuing the report for an auditor | You | £500–£1,500 | Specify the evidence format up front |
Remediation is the penetration testing cost UK line nobody budgets
The report is a work order. If the test finds twelve issues and four need engineering, that engineering has to be scheduled and paid for. A sensible planning assumption is that remediation costs one to two times the test itself for a first engagement, falling sharply thereafter. A penetration testing cost UK budget that funds the test but not the fixes buys a document and no improvement.
The cost of testing at the wrong moment
Spending a penetration testing cost UK budget three weeks before a major release means testing something that will not exist. Testing immediately after a migration, before configuration has settled, produces findings that are already being fixed. The cheapest engagement is the one scheduled at a stable point in the estate’s life, and that is a planning decision, not a procurement one.
How to compare two penetration testing cost UK quotes
Two penetration testing cost UK quotes for the same stated scope can differ by a factor of two and both be honest. Normalise the three levers before you look at the totals.
| Normalise | Quote A | Quote B | Comparable? |
|---|---|---|---|
| Headline price | £4,200 | £2,800 | Not yet |
| Active testing days | 3 | 2 | No — 50% more work |
| Access model | Grey box, credentials supplied | Black box | No — different depth |
| Retest | One included | £1,200 extra | No — add it back |
| Report | Technical + executive | Findings list | No — different product |
| Like-for-like total | £4,200 | £4,000 for less depth | Yes — A wins |
Normalise the scope first
Put both scopes side by side as a list of assets and vectors. If one covers “external network and web app” and the other covers “external network, web app, API and cloud”, they are not comparable, and the cheaper one is cheaper because it is smaller. The penetration testing cost UK comparison only becomes meaningful once the asset list is identical on both pages.
Normalise the depth and access
Check the active testing days and the access model on both. A five-day grey box test is not the same purchase as a two-day black box test even when the asset list matches. Once depth is normalised, the remaining gap is provider tier and reporting package, which is a far easier decision to reason about.
Normalise the reporting and retest
Line up what is in the box: number of retests, executive summary, framework mapping, debrief format. A quote including a retest and an ISO 27001 mapping is not more expensive than one that omits both; it is a different product. Once all three levers are normalised, the residual difference is brand premium, and you can decide consciously whether to pay it.
Reading the worked comparison
In the table above, Quote B looked £1,400 cheaper and finished £200 cheaper for a third less testing and no executive summary. That is the typical shape of the comparison. This penetration testing cost UK decision is not about saving £1,400; it is about whether the cheaper quote contains the evidence you need.
How much penetration testing cost UK budget a business needs in 2026
The right budget is a function of what is asking for the test, not of the market average. The chart below shows typical annual spend by business profile, which is a more useful planning number than any single engagement price.
Read the bars as multiples rather than absolutes: the mid-market profile is four times the small-business figure and the regulated profile is roughly eight times it. The penetration testing cost UK budget scales with the number of vectors and the reporting requirement, not with headcount. A small business with a complex cloud estate can easily spend more than a larger business with a simple on-premises one, because the work is priced on attack surface.
The compliance-driven purchase
When the trigger is ISO 27001, PCI DSS, a customer questionnaire or a contract clause, the budget is set by the requirement and the job is to map the spend exactly onto the evidence being asked for. Over-buying a full scope when a single vector is required is the most common waste in this category, and it is entirely avoidable by reading the clause before requesting the quote.
The risk-driven purchase
The other category is a business testing because it wants to know what an attacker could do, independent of any auditor. These purchases tend to return more, because the findings get acted on rather than filed. The penetration testing cost UK number is identical; the return is higher when the test is tied to a remediation plan with named owners and dates.
Frequency: how often to test
Most UK mid-market businesses test annually, and that is a defensible default. Test again after a material change to the estate, a new application going live, or a supply-chain incident. We cover the triggers in detail in our guide to penetration testing frequency, and for cloud-heavy estates a cloud security posture assessment between tests is a cheaper way to catch configuration drift.
Budget the penetration testing cost UK spend across three years, not one
A single annual line item hides the real pattern. Year one carries the heaviest remediation cost and often the widest scope. Year two is usually cheaper because the scope is written and the obvious findings are gone. Year three is where scope creep returns as the estate changes. Planning the penetration testing cost UK spend as a three-year envelope, with remediation funded alongside it, produces a far more accurate number than repeating last year’s invoice.
How to get a fair penetration testing cost UK quote
The quality of the quote you receive is a direct function of the quality of the scope you send.
Write the scope before you ask for a penetration testing cost UK price
Produce a one-page scope: the IP ranges, URLs, cloud subscriptions and credentials the testers may use, the access model, the maintenance window, and the reporting format you need. Vendors turn a written scope into a penetration testing cost UK number far more accurately than a phone call, and the penetration testing cost UK figure that comes back is comparable to the next one because both were priced against the same document.
Ask for the day count and the retest explicitly
A penetration testing cost UK quote that does not state active testing days or the number of retests is incomplete. Ask for both in writing. The number only means something with those two figures attached, and a vendor who resists stating them is usually protecting a scope that will expand once work starts.
Ask what is excluded
Every scope has exclusions: systems that will not be tested, techniques that will not be used, environments that are out of bounds. A fair quote lists them. If a penetration testing cost UK quote does not say what is out of scope, assume the exclusions are whatever the vendor finds inconvenient, and ask for them in writing.
Check who is actually on the keyboard
Ask who will do the testing, not just who will sign the report, because seniority is most of the penetration testing cost UK day rate. A test delivered by a junior and reviewed by a senior is a different purchase from one where the senior is testing. Ask for names and current certifications, and check the title level if the engagement depends on it. Our cybersecurity services team scopes this for clients regularly, and the answer is usually visible in five minutes of questions.
Get three penetration testing cost UK quotes, and send all three the same document
Three is enough to see the shape of the penetration testing cost UK market and few enough to compare properly. Send an identical scope to all three. If one comes back dramatically lower, the useful question is not “why are you cheap?” but “what did you assume that the others did not?” The answer is almost always a smaller day count or an excluded vector.
Ask about the methodology by name
A serious provider will name the methodology behind its penetration testing cost UK quote. For web work that means the OWASP Web Security Testing Guide; for infrastructure, an equivalent published standard. Naming the methodology in the scope document is free, and it converts “we will test your app” into a defined body of work that a penetration testing cost UK quote can be measured against.
Twelve questions to ask before you sign
| # | Question | What a good answer sounds like |
|---|---|---|
| 1 | How many active testing days? | A specific number, separate from reporting |
| 2 | How many reporting days? | Roughly one per three to four testing days |
| 3 | Is a retest included? | Yes, with a stated window |
| 4 | Who are the named testers? | Names, titles and current certifications |
| 5 | What is explicitly out of scope? | A written list, not a shrug |
| 6 | What methodology do you follow? | A named published standard |
| 7 | Can I see a redacted sample report? | Sent without hesitation |
| 8 | Will findings be demonstrated, not just listed? | Evidence of exploitation per finding |
| 9 | What happens if you break something? | Named contacts, stop conditions, insurance |
| 10 | How is our data handled after the test? | Stated retention period and deletion |
| 11 | Will you map findings to our framework? | Yes, named framework, included or priced |
| 12 | What would make this quote go up? | Specific triggers, agreed in advance |
Question twelve is the one that separates a fixed price from an opening bid. A vendor who can list the triggers has thought about your estate and your penetration testing cost UK exposure; one who cannot will discover them at your expense.
Common penetration testing cost UK mistakes to avoid
The same errors show up in almost every UK engagement that ends up feeling like poor value. None of them are really about the vendor; all of them are about how the purchase was specified.
Paying for a scan and calling it a test
The cheapest way to underdeliver is to buy an automated scan and receive something that looks like a test report. If the penetration testing cost UK quote sits at the very bottom of the range and the report shows no demonstrated exploitation, you bought a scan. Require evidence of exploitation in the report specification before you sign, and name a methodology such as the OWASP Top Ten as the reference.
Vague scope, worst-case price
A scope reading “our whole environment” gets priced at the most expensive interpretation available. The number falls when the scope is a specific list, and the fall is usually larger than the buyer expects. Writing the scope down remains the single highest-leverage cost control available to any buyer.
Forgetting the retest
A test without a retest leaves the business holding a list of findings and no confirmation the fixes worked. In this market the retest is the line item most often absent from a cheap quote and discovered late. Specify it up front and compare quotes on a retest-included basis.
Buying the wrong tier
A global firm is not automatically right and a boutique is not automatically wrong. The tier should match the requirement. For a single vector at a mid-market business, penetration testing cost UK value sits in the boutique or mid-market band. If IT is outsourced, your managed IT services provider should sanity-check the scope before you commit.
Treating the test as the security programme
A penetration testing cost UK line is a measurement, not a control. Businesses that buy one annually and change nothing in between are paying for an annual reminder. Pair the test with the day-to-day controls — patching, MFA, monitoring, backup — set out in our cyber security checklist, and the test starts confirming progress instead of repeating itself.
Not budgeting for the fixes
The most common budgeting failure is funding the penetration testing cost UK line and not the remediation. If the findings cannot be fixed this financial year, the money bought a risk register entry. Approve the fix budget at the same time as the test budget, or defer both.
Frequently asked questions
How much does a penetration test cost in the UK in 2026?
A single-vector test for a small business typically runs between £1,500 and £5,000. A multi-vector engagement for a mid-market business is usually £8,000 to £25,000, and a full-scope programme at a global firm can reach £45,000. The penetration testing cost UK figure is driven by scope, depth and reporting rather than headcount, so a small business with a complex estate can pay more than a large one with a simple estate.
What is the day rate for a penetration tester in the UK?
Published UK day rates run from about £800 to £2,500, with £1,200 a common published rate for a CREST-accredited consultant and £800 to £1,000 typical for a junior at a smaller firm. Anything under about £500 a day is automated scanning rather than manual testing. Knowing the rate lets you decompose any penetration testing cost UK quote into days, which is the only reliable way to compare two of them.
What is the difference between a vulnerability scan and a penetration test?
A scan is automated and flags known weaknesses. A test is human-led and attempts to exploit them to demonstrate impact. The gap between the two reflects machine time versus senior analyst time, and a scan is not a substitute when the requirement is to demonstrate exploitability, as PCI DSS makes explicit by separating requirements 11.3 and 11.4.
How often should a UK business be penetration tested?
Annually is the defensible default for most UK mid-market businesses. Test again after a material change to the estate, a new application launch, or a supply-chain incident. PCI DSS requires internal and external testing at least every twelve months and after significant change, so a regulated penetration testing cost UK budget should assume one test a year plus a provision for change-driven retesting.
Does the price include a retest?
Not always. A single retest is commonly bundled in the mid-market band and charged separately at the boutique and global ends, typically at £1,000 to £2,500. When comparing quotes, confirm whether the retest is in or out, because a cheap test with a separately priced retest often totals the same as a mid-priced test with it included.
What should a penetration test report include?
An executive summary a non-technical reader can act on, a technical appendix an engineer can reproduce, and for every finding a severity rating, a statement of impact, evidence of exploitation and a specific remediation. A report that lists vulnerabilities without demonstrating exploitation is a scan dressed up as a test, and it is the commonest way a penetration testing cost UK purchase disappoints.
Is a CREST or CHECK provider worth the extra cost?
If a regulator, auditor or customer asks for it, yes, because an unaccredited report will not satisfy them and you will pay twice. If nobody is asking, the accreditation premium buys process consistency rather than a better test. Note that the NCSC states plainly that non-public-sector organisations do not need a CHECK provider, so that part of the penetration testing cost UK premium is avoidable, so paying the CHECK premium commercially is usually wasted.
Is Cyber Essentials Plus the same as a penetration test?
No. Cyber Essentials Plus is a sampled, hands-on audit of five technical controls, priced from roughly £1,399 plus VAT for a micro organisation up to about £3,499 for a large one. A penetration test is an open-ended attempt to compromise a defined scope. Buying one when a customer asked for the other is the most expensive confusion in this subject.
How far in advance should we book?
Four to eight weeks is normal for a good provider, and expedited work carries a rush premium. Booking a quarter ahead is effectively a penetration testing cost UK discount, and it also lets you schedule the test at a stable point in the estate’s life rather than immediately after a migration.
How much should we budget for fixing what the test finds?
Plan for remediation to cost one to two times the test itself in the first year, falling sharply in subsequent years once the structural findings are closed. A penetration testing cost UK budget that funds the test but not the engineering produces a document and no improvement.
Can we reduce the price without reducing the value?
Yes, in three ways: send a precise asset list so nothing is priced defensively, supply credentials and documentation so testers spend days testing rather than discovering, and book early enough to avoid a rush premium. All three cut days rather than rate, which is the only honest way to reduce a penetration testing cost UK number.
Who should own the test internally?
Someone who can approve remediation, not only someone who can approve the penetration testing cost UK invoice. The most wasted engagements are those commissioned by a compliance function with no authority over the engineers who must act on the findings. If you outsource IT, agree in advance who is accountable for closing each finding, and read our note on supplier contract security requirements before the report lands.
References
NCSC — Penetration testing guidance
NCSC — CHECK: information for buyers
NCSC — Cyber Essentials overview
GOV.UK — Cyber Security Breaches Survey 2025/2026
GOV.UK — Cyber Security Breaches Survey collection
PCI Security Standards Council
OWASP — Web Security Testing Guide
CREST — Membership and accreditation
IASME — Cyber Essentials changes, April 2026
ISO27k — ISO/IEC 27001 reference
EIOPA — Digital Operational Resilience Act (DORA)
NIST — Cybersecurity Framework
NIST SP 800-115 — Technical Guide to Information Security Testing
PortSwigger — Web Security Academy
NIST — National Vulnerability Database
NCSC — Vulnerability management
NCSC — Cyber Security Board Toolkit
NCSC — 10 Steps to Cyber Security
NCSC — Assured cyber security services
ICO — A guide to data security
Bank of England — Financial stability and operational resilience
FCA — Operational resilience
NCSC — Cyber Essentials scheme site
NCSC — Vulnerability scanning tools and services