Solusec: Solutions for Cyber Security

Operated by Solusec Ltd
CREST accredited · IASME Certification Body

Penetration testing on a budget

Can you get CREST penetration testing cheaply?

Less than you have been quoted, quite possibly. Cheaper than the accreditation allows, no. The useful question is which parts of the cost are actually yours to control.

Accredited and recognised

CREST accredited penetration testing providerCREST AI-Enabled Penetration Testing accreditationCREST member company

The floor, and why it is where it is

CREST-accredited day rates in the UK run roughly £800 to £1,200. Work quoted at £250 to £500 a day is almost always an automated vulnerability scan with a report wrapper. That is a legitimate product with real uses, and it is not a penetration test. If a clause asks for one, the cheaper number is not a saving, because you will buy the test again.

The floor exists because accreditation obliges a provider to do specific things: follow a documented methodology on every engagement, evidence each finding, have a second person review the report before it reaches you, and handle your data to a standard. Those hours are real and they do not compress. A provider competing below the floor has stopped doing one of them, and it is usually the review.

What you can cut, and what happens when you do

Legitimate ways to reduce a penetration testing quote
CutWhat it savesWhat you give up
Narrow the scope to the system that mattersThe most, by a distanceAssurance about everything else, stated plainly in the report
Fewer user roles testedSubstantial on an applicationAccess control findings between the untested roles, which is where the serious ones live
Fix your own findingsModestA written remediation plan. Fine if you have developers, painful if you do not
Flexible datesModestControl over when it happens
Remote rather than on siteTravel and time, where it appliesNothing, for most external and application testing
Fewer tester-days on the same scopeLooks like the mostCoverage. This is the one that is not a saving

Everything above the last row reduces what is tested and says so. The last row keeps the scope and quietly reduces how thoroughly it is examined, which produces a document rather than an assessment. An honest report will name the gap; a cheap one will not.

Contained scope and a fixed budget? These two are the cheapest honest route to CREST-accredited testing, with no scoping call in the price.

The two tests you can buy outright

The cheapest honest route to accredited testing is a tightly scoped fixed-fee test, because there is no scoping call, no proposal and no quoting time in the price.

External infrastructure, up to ten IP addresses, £3,000. Your internet-facing perimeter: exposed services, patch levels, configuration, authentication surfaces. CMS website, £2,500. An unauthenticated test of a WordPress, Drupal, Joomla or similar site including its plugins and theme, which is where these sites are actually broken into.

Both are delivered by a CREST-registered tester at a CREST-accredited company and peer reviewed before the report reaches you. Both are deliberately narrow. Anything with user roles, an internal network, a cloud tenant or a mobile app needs scoping, and we will quote that properly rather than sell you the wrong test cheaply.

Spend the cheap money first

The single biggest waste in a small penetration testing budget is paying a tester at £900 a day to find things a £0 scan would have told you about.

Run your own vulnerability scan before the test. Patch what it finds. Turn on multi-factor authentication everywhere. Remove the accounts belonging to people who left. Take the admin interface off the public internet. None of that costs money, all of it is within your control, and every hour the tester does not spend writing up a missing patch is an hour spent on the business logic flaw that no scanner will ever find.

Clients who do this get more out of the same spend, consistently and by a wide margin. It is the closest thing to a free lunch in this market.

Three things never worth cutting

The peer review. If one person writes the report and nobody else reads it, you are getting one person's judgement on severity with nothing checking it. This is the first thing a provider drops to hit a price and you will not see it in the quote.

The authorisation and rules of engagement. The document that makes the engagement lawful, defines what is in scope, and says what happens when something breaks at four on a Friday. A provider who treats it as optional paperwork is telling you something.

The retest. Whoever asked for the test usually wants evidence the findings were closed, not a list of what was open. Check whether it is included and within what window, because a retest priced separately six weeks later at full day rate is a common and avoidable surprise.

When you should not buy a penetration test at all

If the budget only stretches to something that is not really a test, buy something else honestly rather than a test dishonestly. A vulnerability scan, clearly labelled as one, has genuine value and costs a fraction. Cyber Essentials certification evidences five baseline controls and satisfies a great many requirements that people mistakenly think need a penetration test.

And if you have had an actual incident, testing is the wrong purchase this week. A penetration test tells you what could happen. It does not tell you what did.

Can this scope come down honestly?

Tick what is true. Each one is a legitimate way to spend less without buying a worse test of what remains.

Further reading on this site

Four guides going deeper than this page does. All free, no sign-up.

The cheapest honest route: buy a fixed-fee test

No scoping call and no proposal time in the price, which is most of why these are cheaper than a quoted engagement. Both are delivered by a CREST-registered tester at a CREST-accredited company and peer reviewed before the report reaches you. Wider than this needs scoping, so tell us the budget and we will say honestly what it covers.

Delivered by a CREST-registered tester at a CREST-accredited company. Verify us on the CREST marketplace.

Optional add-ons
Additional IP addressesIn blocks of 5, beyond the first 10 × £500

Total: £3,000 + VAT

Payment is taken by Stripe. We never see or store your card details. Rules of engagement are agreed in writing before any testing starts.

Send the scope and the budget

Tell us what needs testing and what you have to spend. If the two do not meet we will tell you what a reduced scope would honestly cover, rather than quietly thinning the days and handing you a report that looks complete. No obligation and no sales call.

Your details are handled by a real person, never fed into AI.