Affordable penetration testing for a small app means a targeted manual test: a named tester, a few agreed surfaces, a price in tester days, and a retest. A scanner report with a person’s name on it costs less and proves less. Buy a full test from an accredited firm when a contract names one, such as CREST or CHECK.
What you are actually buying with affordable penetration testing
A penetration test is sold in four shapes: a scanner run with a person’s name on the report, a targeted manual test of agreed surfaces, a full external test from an accredited firm, and a testing platform subscription. For one small app, the targeted manual test is the affordable shape that still tests the logged-in app.
This page is the buying end of production hardening: which shape to pay for, what it should cost, and what to ask before you sign. Whether you need a test at all, and what the person asking for one usually wants, is the job of do I need a pen test. If you are not sure the request is for a pen test rather than a scan, a code audit or a certification, start with which kind of security review you are being asked for.
The table is my reading of how each shape is sold, cell by cell, not any vendor’s definition.
| Shape | Who does the work | What you get back | What it does not include |
|---|---|---|---|
| Named scanner report | Automated tools; a person formats the output | A list of scanner alerts, ranked by the tool | Logic testing, and proof that a flagged issue can be exploited |
| Targeted manual test | A named tester, for an agreed number of days | A report of confirmed findings, then a retest of the fixes | Anything outside the written list of surfaces |
| Accredited full test | A team from a firm that holds the accreditation the contract names | A report a contract’s reviewer accepts | A small-app price or a quick start |
| Platform subscription, sold as penetration testing as a service | Scanners, human testers or both, depending on the platform | Scheduled scans or tests and a dashboard, priced by a base fee plus a fee per target on one platform | Logic testing, unless a person tests the app |
If your product is a SaaS app, what you are shopping for is web application penetration testing services in one of these four shapes. How a tester works through an app once the test starts is covered in web application penetration testing; this page stays with the buying.
The label on the offer tells you little. A penetration testing consultant working alone can sell you the first shape or the second, so ask which one the quote describes before you compare it with another. VAPT is a vulnerability assessment and a penetration test sold together, so I’d treat a VAPT service as anything from the first shape to the third until the quote says which. The line between the two halves is drawn in pen test vs vulnerability assessment.
Third-party penetration testing only means the tester is not the team that built the app. Outsourcing penetration testing is buying any of the four shapes from outside. When a quote is labeled penetration testing for startups, check that it is the second shape and not the first with a friendlier name.
Small business penetration testing sometimes means the office network and staff laptops rather than the product. Network penetration testing services cover that infrastructure, not the logic of your web app, and this page leaves them out.
What CREST, CHECK and the other accreditations mean
Penetration testing accreditations vouch for a company or a person, not for your scope. CREST is a not-for-profit membership body for the security industry, CHECK is the UK scheme for authorized tests of public sector and critical national infrastructure systems, and OSCP certifies an individual. Buy what a contract names; otherwise buy a named tester and a written scope.
In the NCSC’s own words, “CHECK is the scheme under which NCSC assured companies can conduct authorised penetration tests of public sector and CNI systems and networks”, and it was “developed specifically for” central government, public sector bodies and critical national infrastructure. You can read who it is for on the NCSC’s CHECK scheme page.
A request for CHECK accredited penetration testing can come from the GOV.UK Service Manual on penetration testing, which tells government services that use a third party to “use a CHECK certified team or staff accredited to equivalent CHECK levels to carry out penetration testing”. A private customer’s contract may copy that line; that is my reading of where the wording comes from, not a rule.
The NCSC also lists CREST as “a commercial organisation assured under one or more NCSC assurance schemes” on the NCSC’s page on CREST. OSCP is different in kind: it is the certification a person earns by passing the exam attached to OffSec’s PEN-200 course, and passing it earns “both the OSCP and OSCP+”.
An accreditation tells you who is testing, not what they will test. The scope you sign decides that. When no contract asks for a particular badge, I’d weigh the name of the tester and a sample of their report above the firm’s logo.
Penetration testing cost: what sets the price
Penetration testing cost is tester days multiplied by a day rate, then moved by scope, authenticated access, a retest and any accreditation the buyer demands. One scanning platform prices by a base fee plus a fee per target instead, so a platform’s subscription and a manual test’s tester days buy different things.
The table takes public figures where a page prints them. Sellers are named as the source of a dated figure, not as a recommendation.
| Shape | Price basis | Published figure | Source and date |
|---|---|---|---|
| Targeted or full manual test, CREST accredited | Day rate times tester days | ”£700 to £1,200 a unit a day” | Arcanum Information Security, “CREST Accredited Pen Testing”, UK Digital Marketplace, G-Cloud 14, 2026-09-27 |
| Manual test, G-Cloud 15 rate card | A rate per role; the listing prints no unit | ”Lead cyber security penetration testing” £895.00 (Fortis Cyber Security) and £1,200.00 (DigitalXRAID) | UK Digital Marketplace, G-Cloud 15 listings, 2026-09-27 |
| Penetration testing as a service | Credits: one credit is “the equivalent of 8 hours of offensive security testing”, sold in annual packages | Plan prices not published (“get a quote”); a promotional “$3,500 per test” for its Autonomous Pentest, marked “Limited time offer” | Cobalt pricing page, 2026-09-27 |
| Testing platform subscription | ”a base fee plus a small fee-per-target”, monthly rolling or annual | Plan prices set by a target calculator on the page: Cloud $239 and Pro $399 a month on annual billing for its default five infrastructure targets; the same page sells “AI-powered web application pentests” “Starting from $3,500 / test” | Intruder pricing page, 2026-09-29 |
| Scanner run with a name on the report | Not published | Not published | No fetched page |
Prices checked on each page named in the table, on the date in its row.
As an illustration only, a three-day test at the Arcanum listing’s range comes to £2,100 to £3,600, and a five-day test to £3,500 to £6,000. The question “how much does a penetration test cost” has no answer without the number of days, which is why the day count is the first line to read in any pen testing quote.
What moves the price, in my reading, is six things: how many surfaces are in the written list, whether the tester logs in as your users, how many tester days that takes, whether a retest is included, who the report is written for, and which accreditation the buyer demands. When a pen test cost looks low next to the table, I’d look first for fewer days or fewer surfaces; the quote should show which.
If you are comparing penetration testing cost per hour, convert first: the Arcanum listing quotes days, not hours, and Cobalt’s credit is “the equivalent of 8 hours”. For penetration testing cost in the UK, the G-Cloud rows are a public benchmark, since they come from the UK government’s own Digital Marketplace. How much an external penetration test costs is the same arithmetic, applied to the internet-facing surfaces only. An average cost of penetration testing taken across all four shapes mixes scanner runs with multi-day team engagements, so I’d give it little weight against your own quote.
Pen test pricing on the two platform pages in the table does not give a manual test’s days and rate: Cobalt prints no plan prices, and Intruder’s printed plan prices are for its scanning plans, by target. So ask for the penetration test price broken into days and rate, whoever is selling.
A pen test quote you can compare names tester days, the named surfaces, whether testing is authenticated, the retest, a sample report and the day rate. If a penetration testing quote gives one total and none of those lines, ask for them before you set it beside anything else. When the seller is a platform, a pentest quote needs two more answers: how many targets it covers, and whether a person tests the logged-in app. Once two quotes cover the same written list of surfaces, you can compare them as days times rate.
What a cheap pen test leaves out
A cheap penetration test usually leaves out five things: the logged-in half of the app, its business logic, a person checking each finding, a retest after the fixes, and a report a customer’s reviewer can read. The written quote shows which ones are missing before you pay.
The “how to tell from the quote” column is my reading of the line that goes missing. The categories come from the OWASP Web Security Testing Guide, which lists authentication, authorization and business logic testing as test categories of their own.
| What is left out | Why it matters | How to tell from the quote |
|---|---|---|
| The logged-in half of the app | OWASP lists “4.4 Authentication Testing” and “4.5 Authorization Testing” as their own categories | No authenticated testing in the written list, and no test accounts requested |
| Business logic | OWASP lists “4.10 Business Logic Testing” as its own category: a stranger spending your money, a customer reading another’s data | No tester days quoted, only a scan |
| A person checking each finding | Without a person, every alert reaches you unconfirmed | No tester named |
| A retest after the fixes | Without one you have no evidence the fixes worked | No retest line |
| A report the customer’s reviewer can follow | The GOV.UK Service Manual asks for a report summary that explains the risks “in language that a non-technical audience can understand” | No sample report offered |
Whether a scanner stayed logged in during a test is its own question, answered under authenticated scanning. Why a scanner’s list and a list of confirmed problems differ so much is explained in scanner output and verified findings. What a readable report contains is in penetration test report format.
Two kinds of failure show what the logged-in half and the business logic can hide. In my June and July 2026 audits, 7 of the 21 third-party apps had confirmed cross-user or cross-tenant authorization failures, where a logged-in user could read or write another customer’s data. In the same audits, 12 of the 14 AI apps had a confirmed denial-of-wallet path, where a stranger or free account can burn the owner’s paid AI or compute bill without limit. Those apps are a selected set I audited, not a random sample, so neither figure is a rate for apps in general.
Both failures sit behind the login or inside how the app spends money. My reading is that finding them takes a person working through the app’s roles and flows, which is the part cheap penetration testing drops first.
There is an opposite mistake too. In one app I audited, the scanner’s loudest alerts arrived only under an AI library used in offline export scripts, and the live web server never loaded them; the full account is in web application security testing services. A scanner’s loudest alert is a lead, and what you pay a tester for is the check that the flagged code actually runs.
A low price is not always the wrong buy: low cost penetration testing can still cover all five rows if the days are there. A cheap pen testing offer whose quote shows none of the five lines is the first shape, whatever it is called.
When to pick each
Buying well starts with who will read the result, not with the vendor, and for one small app that is most of what best practices for purchasing a pen test come to. Each shape below gets a fits-when line and a does-not-fit line; together they are the penetration testing best practices I would apply before signing anything.
A scanner with a report
This fits when a security questionnaire asks whether you scan, not whether you have been tested. A named person’s scanner report answers that question. The difference between those two requests is covered in the do I need a pen test guide linked at the top of this page.
It does not fit when a reviewer will read the report. A customer’s security team, an auditor or an investor’s adviser will look for confirmed findings, and I would not expect a list of raw alerts with a name on the cover to satisfy them.
A targeted manual test
This fits one app, a first enterprise security questionnaire, or a customer who asks for a recent penetration test without naming an accreditation. A named tester spends agreed days on the surfaces you list, confirms what is real, and retests after you fix it. I’d pick it first for a small SaaS product: it puts a person inside the logged-in app without paying for a full accredited engagement.
It does not fit a contract that names an accreditation, or one that requires the tester to be independent of anyone who worked on the app.
Deliverable 3.10 of the Production Hardening Sprint, targeted external penetration testing, is a targeted test of this kind: test the five highest-risk externally reachable attack surfaces, remediate findings, and deliver the methods and evidence.
A full external test by an accredited firm
This fits a UK government customer, because the GOV.UK Service Manual’s line on third-party testing asks for a CHECK certified team or staff at equivalent CHECK levels. It also fits an enterprise contract that names CREST, and a SOC 2 auditor who wants an independent test; the SOC 2 route is laid out in SOC 2 compliance consultants.
It does not fit, in my reading, an app whose own launch checklist has never been run. The tester’s days then go on findings the team could have fixed first, and the report you pay for fills up with them.
How to compare providers without a ranking
There is no honest answer here to which is the best pen testing company, and a list of top pen testing companies cannot see your app. What you can compare is quotes: the same written list of surfaces, turned into tester days times day rate, with the same retest and the same kind of report.
Penetration testing companies that will not quote on those terms are hard to compare with anyone. I’d also ask each penetration testing vendor for its smallest engagement in days; a firm on a list of the best penetration testing companies can still be the wrong buy if that smallest engagement is bigger than your app needs.
The coverage questions to put to each provider, from testing approach to how findings are evidenced, are in the comparison list of the do I need a pen test guide linked above. If you want the best pentest company for a SaaS startup, the answer is the same, plus the accreditation your first enterprise customer names.
For one app, the practical difference between penetration testing providers is which of the four shapes they sell, and the web application security testing services guide linked in the section above sorts them that way. A security testing company that also offers to fix what it finds is selling two jobs; whether to buy a test or an engineer’s time is the subject of fractional CTO vs agency. Where the test sits among the other launch work is in the go live checklist.
Questions to ask before you pay
These are the contract and quote questions. The technical coverage questions, including which authenticated roles are tested, whether a retest is included and which requirement the report is meant to satisfy, are in the do I need a pen test comparison list, and I will not repeat them here.
- 01 Who tests, by name and certification? The answer that should satisfy you is a named person and the certification they hold, not only the firm's badge.
- 02 How many tester days, at what day rate? Both numbers, in writing. A single total with no days cannot be compared with anything.
- 03 Which surfaces are named in writing? A list of the URLs, APIs and user roles in the test, attached to the contract.
- 04 Is the test authorized in writing by the system owner, and does your host's own testing policy allow it? A signed authorization from you, and a yes on the host policy (the do I need a pen test guide covers host policies).
- 05 Can you see a sample report? A redacted report from an earlier test, with a summary a non-technical reader can follow.
- 06 What happens to your data and credentials after the test? Test accounts removed, any credentials you shared rotated, and the retention of your data stated in writing.
The scope and report questions follow the NCSC’s penetration testing guidance, which says “a well-scoped penetration test can give confidence” that there are “no common or publicly known vulnerabilities in the tested components, at the time of the test”. The same guidance tells buyers to state “any specific reporting requirements” before the test, so the report you get is the one your reviewer needs.
Where the sprint fits
The sprint’s version of a penetration test is the targeted test described above, not the accredited kind. The targeted security tests cover the five priority attack surfaces documented in the report, and the package also includes an OWASP review and a controls checklist with evidence. Deliverable 3.10 is verified this way: record the five surfaces, authorized tests, findings, fixes, and retest outcomes; AxonBuild performs this targeted test. Formal third-party certifications and independent audit opinions are separate from the sprint deliverables, so a contract that requires an independent tester or a named accreditation needs that test as well. Every item lands in deliverable 13.1, the production readiness report, which accounts for all 123 IDs, keeps failures visible until resolved and explains genuine non-applicable items. Every deliverable is listed in the published scope.
Common questions about buying a penetration test
How much should a penetration test cost?
A penetration test should cost the tester days it needs multiplied by a day rate. One UK government marketplace listing for CREST accredited testing, checked on 27 September 2026, priced it at £700 to £1,200 per unit per day, so the number of days in the quote decides most of the total.
Is pentesting illegal?
Testing a system without its owner’s permission can be a crime. In the UK, section 1 of the Computer Misuse Act 1990 makes it an offense to cause a computer to perform a function to secure access you know is unauthorized; in the US, 18 U.S.C. 1030 covers anyone who “intentionally accesses a computer without authorization or exceeds authorized access, and thereby obtains” information from any protected computer. A test the owner has authorized in writing, within the agreed scope, is the normal practice. Other countries have their own laws, and this is not legal advice.
How often should a pen test be done?
The GOV.UK Service Manual tells government services to test “frequently as you build, not as a one-off check”. For a small app, my rule is a test after any material change to what the internet can reach, and at whatever interval a contract or auditor names.
What are the top 5 penetration testing companies?
No ranking of five firms would hold for your app, so this page does not give one. The better filter is the quote: the same surfaces, tester days and day rate, a retest, a sample report, and the accreditation your contract names, asked of every firm you consider.
If you have a working app built with these tools and need it ready for real customers, this is what we do.
Built it with AI. Now it has to hold up for real customers.
The Production Hardening Sprint takes the app you already have and builds the production foundation underneath it. Authentication and access rules, payments that stay consistent, error handling, monitoring, backups, automated tests and a documented handover. Our engineers work inside your existing codebase for ten working days. All 123 deliverables are included, and you get the evidence for each one.
See the Production Hardening Sprint →
$2,500 fixed price · 10 working days · One codebase