Pricing guide

How much does a web application penetration test cost?

A straight answer to the question every buyer asks first — what UK web application penetration testing actually costs, and what drives the price.

In the UK, a web application penetration test from an independent consultancy typically ranges from around £3,000 to £10,000+ per application, usually billed as a day rate (commonly £700–£1,200 per day) over a 5–10 day engagement. Larger firms with sales overhead and certifications often sit at the higher end.

Vesperis Security works differently: fixed pricing from £1,000 per web application, with no day rates and no hidden fees. You see the price before you commit, and it doesn't change because a test took a day longer.

Our pricing at a glance

ApplicationsPrice per app
1–2 applications£1,000
3–5 applications (10% off)£900
6+ applications (15% off)£850

Volume discounts apply automatically — the more applications in the engagement, the lower the per-app price. You can build an exact quote with the calculator in a few seconds.

Why fixed pricing?

Day-rate pricing pushes the risk of a slow estimate onto you and makes budgeting hard. A fixed per-application price means you know the cost up front, it's easy to get sign-off internally, and there's no incentive for anyone to pad the hours. For most small-to-mid-size applications, it also works out cheaper than a traditional consultancy.

What affects the cost of a pen test?

  • Number of applications — the main driver, and where volume discounts help.
  • Size and complexity — a large app with many distinct modules, or separate admin and customer portals, may be scoped as more than one application. We always confirm this during scoping, before any charge.
  • User roles — more privilege levels mean more access-control testing.
  • Retesting — with us, one retest of your fixes is included free, so it isn't an extra line item.

What's included in the price

Every engagement includes manual, expert-led testing, an executive and technical report, risk-rated findings, remediation guidance, and a free retest of fixes. There are no separate charges for the report or the retest. See exactly what a web application penetration test covers.

Is there a discount available right now?

Yes — as we build out our client portfolio we're running a limited introductory launch offer of 50% off every quote, and it stacks on top of the volume discounts above. The price shown in the calculator already reflects it.

Get your instant quote

See your price in seconds

Transparent, fixed pricing with no day rates. Build a quote or talk to us about a larger engagement.