Guide
Web application penetration testing cost: 2026 UK prices
Updated
Web application tests are the most commonly commissioned penetration test, and the price is almost entirely a function of how many days the application takes to cover properly.
Typical prices
| Scope | Typical days | Typical price |
|---|---|---|
| Brochure site with a contact form | 1–2 | £700–£2,400 |
| Standard business application, one user role | 3–4 | £2,100–£4,800 |
| Application with multiple roles plus an API | 5–7 | £3,500–£8,400 |
| Complex platform, several apps and integrations | 8+ | £5,600+, scoped per asset |
Each price is the day count multiplied by the typical £700–£1,200 day rate, which is how providers themselves build quotes. These are typical 2026 quote ranges, not fixed prices; provider seniority, accreditation and reporting depth move you within the range.
What adds days to a web application test
- User roles: each authenticated role (customer, staff, admin) multiplies the access-control testing surface.
- APIs: a REST or GraphQL API behind the app is effectively a second test target.
- Business logic: payment flows, file uploads and workflow states need manual, human testing, which is the point of a penetration test over a scan.
- Retesting: verifying your fixes afterwards is often included, or quoted as one extra day. Ask before you compare quotes.
Getting a like-for-like quote
- Write one paragraph describing the app: user roles, whether there is an API, and roughly how many screens or endpoints.
- State the driver (customer requirement, ISO 27001, PCI DSS), because it sets the reporting format providers quote for.
- Ask every provider for the day count, the day rate and whether retesting is included, so quotes compare cleanly. Our form gets accredited providers quoting your scope directly.