Accredited and recognised



The floor, and why it is where it is
CREST-accredited day rates in the UK run roughly £800 to £1,200. Work quoted at £250 to £500 a day is almost always an automated vulnerability scan with a report wrapper. That is a legitimate product with real uses, and it is not a penetration test. If a clause asks for one, the cheaper number is not a saving, because you will buy the test again.
The floor exists because accreditation obliges a provider to do specific things: follow a documented methodology on every engagement, evidence each finding, have a second person review the report before it reaches you, and handle your data to a standard. Those hours are real and they do not compress. A provider competing below the floor has stopped doing one of them, and it is usually the review.
What you can cut, and what happens when you do
| Cut | What it saves | What you give up |
|---|---|---|
| Narrow the scope to the system that matters | The most, by a distance | Assurance about everything else, stated plainly in the report |
| Fewer user roles tested | Substantial on an application | Access control findings between the untested roles, which is where the serious ones live |
| Fix your own findings | Modest | A written remediation plan. Fine if you have developers, painful if you do not |
| Flexible dates | Modest | Control over when it happens |
| Remote rather than on site | Travel and time, where it applies | Nothing, for most external and application testing |
| Fewer tester-days on the same scope | Looks like the most | Coverage. This is the one that is not a saving |
Everything above the last row reduces what is tested and says so. The last row keeps the scope and quietly reduces how thoroughly it is examined, which produces a document rather than an assessment. An honest report will name the gap; a cheap one will not.
Contained scope and a fixed budget? These two are the cheapest honest route to CREST-accredited testing, with no scoping call in the price.
The two tests you can buy outright
The cheapest honest route to accredited testing is a tightly scoped fixed-fee test, because there is no scoping call, no proposal and no quoting time in the price.
External infrastructure, up to ten IP addresses, £3,000. Your internet-facing perimeter: exposed services, patch levels, configuration, authentication surfaces. CMS website, £2,500. An unauthenticated test of a WordPress, Drupal, Joomla or similar site including its plugins and theme, which is where these sites are actually broken into.
Both are delivered by a CREST-registered tester at a CREST-accredited company and peer reviewed before the report reaches you. Both are deliberately narrow. Anything with user roles, an internal network, a cloud tenant or a mobile app needs scoping, and we will quote that properly rather than sell you the wrong test cheaply.
Spend the cheap money first
The single biggest waste in a small penetration testing budget is paying a tester at £900 a day to find things a £0 scan would have told you about.
Run your own vulnerability scan before the test. Patch what it finds. Turn on multi-factor authentication everywhere. Remove the accounts belonging to people who left. Take the admin interface off the public internet. None of that costs money, all of it is within your control, and every hour the tester does not spend writing up a missing patch is an hour spent on the business logic flaw that no scanner will ever find.
Clients who do this get more out of the same spend, consistently and by a wide margin. It is the closest thing to a free lunch in this market.
Three things never worth cutting
The peer review. If one person writes the report and nobody else reads it, you are getting one person's judgement on severity with nothing checking it. This is the first thing a provider drops to hit a price and you will not see it in the quote.
The authorisation and rules of engagement. The document that makes the engagement lawful, defines what is in scope, and says what happens when something breaks at four on a Friday. A provider who treats it as optional paperwork is telling you something.
The retest. Whoever asked for the test usually wants evidence the findings were closed, not a list of what was open. Check whether it is included and within what window, because a retest priced separately six weeks later at full day rate is a common and avoidable surprise.
When you should not buy a penetration test at all
If the budget only stretches to something that is not really a test, buy something else honestly rather than a test dishonestly. A vulnerability scan, clearly labelled as one, has genuine value and costs a fraction. Cyber Essentials certification evidences five baseline controls and satisfies a great many requirements that people mistakenly think need a penetration test.
And if you have had an actual incident, testing is the wrong purchase this week. A penetration test tells you what could happen. It does not tell you what did.
Can this scope come down honestly?
Tick what is true. Each one is a legitimate way to spend less without buying a worse test of what remains.
Further reading on this site
Four guides going deeper than this page does. All free, no sign-up.
- How to cut a penetration test scope without hollowing it outThere are two ways to make a quote smaller and only one of them leaves you with a test worth having. The difference is invisible in the price and obvious in the report.
- The fortnight before the test is the cheapest part of itEvery hour a tester spends writing up a missing patch is an hour not spent on the logic flaw underneath it. Most of that hour is avoidable and none of it costs money.
- Reading a cheap report: did you buy a test or a scan?The report is the only part of a penetration test most buyers ever see. It is also the part that tells you, if you know where to look, exactly how it was produced.
- Read the clause before you buy the testA good share of the penetration tests bought in the UK are bought because a document said something that was never read carefully. Some of them were not needed at all.