Metaluxo
← Insights

vCISO

Penetration Testing: What You Get for £3,000 vs £15,000

For the same scope — here is what drives it.

The quote arrives: £3,000. Then another: £8,000. Then a Big Four firm quotes £22,000. All three say they are quoting for a “penetration test of a web application and infrastructure.”

At Metaluxo we scope and manage penetration tests for SMEs. The price variance is not arbitrary. It reflects scope, methodology, and deliverables. This post explains what you are actually buying at each tier.


Tier 1: £2,000–£4,000 — Automated plus light manual

What you get:

  • Automated vulnerability scanning (Nessus, OpenVAS, or equivalent)
  • Manual validation of the top 10–15 findings
  • A standard PDF report with CVSS scores and remediation advice
  • 1–2 days of tester time

Best for: Small companies with a single web application, internal compliance requirements, or a first-time test to establish a baseline.

Limitations: Limited depth, no business logic testing, no social engineering, and minimal retesting.


Tier 2: £5,000–£10,000 — Full manual testing

What you get:

  • Everything in Tier 1
  • Deep manual testing of the application (authentication, session management, business logic)
  • Infrastructure testing (network segmentation, privilege escalation)
  • API testing if applicable
  • A detailed report with exploit demonstrations and proof-of-concept
  • 3–5 days of tester time
  • One retest of critical findings included

Best for: Most SMEs preparing for ISO 27001, customer security questionnaires, or annual security review.


Tier 3: £12,000–£25,000 — Advanced adversarial simulation

What you get:

  • Everything in Tier 2
  • Social engineering (phishing, pretexting)
  • Physical security testing (tailgating, access control bypass)
  • Wireless network testing
  • Red team exercise (goal-based, e.g., “exfiltrate customer data”)
  • A board-level presentation and strategic risk report
  • 1–2 weeks of tester time

Best for: Banks, insurers, critical infrastructure, and companies with mature security programmes that need to test their detection and response capabilities.


What drives the price

FactorLow impact on priceHigh impact on price
Scope1 app, 5 serversMultiple apps, cloud + on-prem
MethodologyAutomated + manualRed team, physical, social eng
Tester credentialsCREST PractitionerCREST Certified, OSCP
DeliverablesPDF reportBoard presentation, retest
UrgencyStandard bookingNext-week turnaround

What most SMEs need

For a 20-person company with a SaaS product and AWS infrastructure, Tier 2 is the sweet spot. It provides the depth to satisfy ISO 27001 auditors and customer security teams without the cost of advanced adversarial testing.

Key questions to ask when scoping:

  1. What is included in the scope? (Apps, APIs, infrastructure, cloud config)
  2. What methodology do you follow? (OWASP, PTES, or custom)
  3. What credentials do the testers hold? (CREST, OSCP, or equivalent)
  4. Is retesting included? (Critical findings should be retested)
  5. Will we get a letter of attestation? (Useful for customer questionnaires)

At Metaluxo we scope and manage penetration tests for SMEs, typically delivering a Tier 2 assessment in 3–5 days with a report that passes ISO 27001 and customer audits. If you need a pen test and are not sure what to buy, book a free 30-minute consultation and we will scope exactly what you need.

Common questions

How often should a small company do penetration testing?

Annual penetration testing is the standard. Biennial testing may suffice for very low-risk companies. After significant infrastructure changes, test immediately.

What is the difference between a vulnerability scan and a penetration test?

A vulnerability scan is automated and identifies known weaknesses. A penetration test includes manual exploitation by a human tester to demonstrate real impact.

Do we need penetration testing for ISO 27001?

Not for Stage 1, but most auditors expect it between Stage 1 and Stage 2. It is effectively mandatory for certification.

Related reading

Send us a message
Message us Book now