Pentesys pricing

Choose the outcome.
Shape the scope.

Four distinct product families, transparent commercial routes and an indicative builder before technical scoping.

Trusted experience

Independent expertise organisations rely on.

Recognised organisations trust Pentesys for practical guidance, clear evidence and independently accredited security testing.

Royal Ballet and Opera logoBigBear.ai logoRightmove logoFortis logoGumtree logoOrange logo
CREST member companyCyber Essentials certifiedCREST AI Charter signatoryCREST approved security testing
01Certification readinessFoundationCyber Essentials and Cyber Essentials Plus preparation, certification support and managed readiness.
Cyber Essentials

Cyber Essentials

Build the evidence and controls needed for assessment.

  • Readiness and evidence review
  • Prioritised remediation plan
  • Guidance through assessment
  • Clear next steps if gaps remain
i
What’s included?

Pentesys reviews the organisation boundary, questionnaire evidence and core technical controls, then provides practical actions and support through assessment.

Cyber Essentials Plus

Cyber Essentials Plus

Prepare for the independently verified technical assessment.

  • Technical pre-assessment
  • Device and control sampling
  • Remediation workshop
  • Assessment preparation pack
i
What’s included?

Preparation for hands-on technical assessment, including agreed sampling, control checks, evidence readiness and remediation guidance.

M

Foundation Managed

Keep evidence and readiness moving throughout the year.

  • Scheduled readiness checks
  • Advice sessions and action tracking
  • Maintained evidence status
  • Renewal planning
i
What’s included?

Ongoing support to maintain readiness between assessments and avoid a last-minute evidence exercise.

Build your Foundation route

Match support to your organisation.

02External attack surface management (EASM)ExposeContinuous visibility of what is publicly exposed, what has changed and what needs attention.

Continuous CTEM visibility

Find the assets attackers can see.

Expose continuously discovers internet-facing assets, monitors change, prioritises weaknesses and supports remediation through the Pentesys Portal.

  • Continuous discovery and change monitoring
  • Prioritised exposure and vulnerability findings
  • Threat and leaked-credential visibility
  • Portal access and actionable reporting
i
What’s included?

Continuous external discovery, exposure and vulnerability monitoring, change alerts, threat context, leaked-credential visibility and prioritised findings.

What is a root domain?

The main registered address owned by your organisation—for example, pentesys.com. Addresses such as portal.pentesys.com and api.pentesys.com are subdomains beneath it.

What is an internet-facing asset?

Anything reachable from the public internet, such as a website, application, API, VPN gateway, mail service, cloud service, public IP address or development environment.

Estimate your Expose coverage

Before you build a test

Choose how you want to buy.

The right route depends on whether you need a single answer now or continuing assurance as your environment changes.

i
What’s included?

Who it suits: A compliance deadline, customer request, procurement requirement or specific change needing independent assurance.

i
What’s included?

Who it suits: Teams concerned that their environment will change after a point-in-time test or new public assets may appear unnoticed.

i
What’s included?

Who it suits: Changing, regulated or high-trust organisations that need continuing evidence rather than isolated reports.

Expose and Annual CTEM routes create a 12-month contract. Human inspections are scheduled through the year; scope can be increased through the Portal at any time and reduced for the next term at renewal. Agreements renew automatically unless cancelled with at least 30 days’ notice.

“Clear, prioritised actions built around real-world attack scenarios—not another generic report.”
CREST accreditedHuman expertise where judgement matters.
One platformScope, findings, remediation and evidence together.
03Penetration testing and continuous validationValidateAI-assisted or Human CREST testing of applications, APIs, networks, cloud and code.
TYPICAL STARTING POINTS

Which looks most like your service?

Choose an example to load its indicative scope, then refine the bands and testing method below.

Public content and enquiry journeys

Brochure website

A public marketing website with a CMS, contact forms and no authenticated customer area.

  • Public pages and forms
  • CMS-facing behaviour
  • Core enquiry journeys
  • Common web security controls
Application plus documented API

Simple SaaS service

A straightforward SaaS product with user authentication, one main role and a documented API.

  • Registration and login
  • Authenticated application journeys
  • Up to 25 documented API endpoints
  • Basic role and session controls
Login, account data and payment journeys

Customer portal with payments

A customer-facing service with account recovery, sensitive profile data, payment flows and a larger API.

  • Login and account recovery
  • Customer and profile journeys
  • Payment and checkout flows
  • Up to 50 documented API endpoints

Choose scope components

Enter the number of coverage bands required. For example, enter 1 for up to 25 API endpoints, 2 for 26–50 or 3 for 51–75. Every change updates scope effort and price immediately.

Web application

i
What’s included?

Testing for one web application, one environment, up to 10 core user journeys and two authenticated roles. Each selected band includes prioritised findings and practical remediation guidance.

One web application and up to 10 user journeys per band.

API / web services

i
What’s included?

Testing of documented APIs and web services. Each selected band covers up to 25 endpoints and includes prioritised findings and remediation guidance.

Up to 25 documented endpoints per band. Enter 1 for 1–25, 2 for 26–50, and so on.

External network

i
What’s included?

Testing of internet-facing network services. Each selected band covers up to 25 public IP addresses and includes prioritised findings and remediation guidance.

Up to 25 public IP addresses per band. Enter 1 for 1–25, 2 for 26–50, and so on.

Internal network

i
What’s included?

Consultant-led testing for the agreed internal network. Each selected band covers up to 50 devices and assesses exploitable weaknesses, access paths and control effectiveness.

Human CREST testing onlyUp to 50 devices per band. Enter 1 for 1–50, 2 for 51–100, and so on. Human-led only.

Mobile application

i
What’s included?

Testing of one iOS or Android application. Each selected band covers one application on one platform and includes prioritised findings and remediation guidance.

One iOS or Android application on one platform per band.

Cloud Security Review

i
What’s included?

A security review of one cloud account or subscription, covering the agreed identity, configuration and exposure controls with prioritised findings and practical remediation guidance.

One Azure, AWS or Google Cloud account or subscription per band.

Social engineering

i
What’s included?

An authorised social-engineering assessment. Each selected band covers up to 25 recipients. Scenarios, safeguards, exclusions and success criteria are agreed before delivery.

Human CREST testing onlyUp to 25 recipients per band. Enter 1 for 1–25, 2 for 26–50, and so on. Human-led only.

Wireless security

i
What’s included?

A consultant-led wireless security assessment for one physical site per selected band, covering agreed networks, authentication controls and exposure paths.

Human CREST testing onlyOne physical site per band. Human-led only.

Code review / SAST

i
What’s included?

A source-code security review covering up to 50,000 lines per selected band, with prioritised findings mapped to affected code and practical remediation guidance.

Up to 50,000 lines of supplied source code per band.

Every Validate scope includes

  • Agreed technical scope and rules of engagement
  • Executive and technical reporting
  • Prioritised remediation guidance
  • One retest of reported findings within 60 days
  • Closure statement
04Red teaming and purple teamingAdversarySafely test whether realistic attackers can achieve agreed objectives—and whether your team can detect and respond.
TYPICAL STARTING POINTS

Choose the level of challenge.

Choose the closest organisation profile, then refine the objectives below.

ORGANISATION PROFILE

Growing organisation

A focused exercise for a growing business that wants to understand whether a realistic initial foothold could reach sensitive information.

ORGANISATION PROFILE

Established mid-market

A broader exercise for an established organisation with Active Directory, a security team and business-critical data.

ORGANISATION PROFILE

Larger or regulated organisation

A deeper exercise spanning supply-chain and identity controls, cloud privilege, detection and incident response.

Choose objectives

Each objective carries configurable effort. Your price is calculated from the objectives selected.

Every Adversary scope includes

  • Formal rules of engagement
  • Agreed escalation and safety controls
  • Executive and technical reporting
  • Detection and control observations
  • Facilitated debrief

Common Questions

Useful answers before you request a quote.

Is this a formal quotation?

No. The calculator provides an indicative value. Pentesys checks the selected scope, assumptions and testing method before issuing a formal quotation.

What does one coverage band mean?

Each product explains its band beside the quantity field. For example, one API band covers up to 25 documented endpoints; two covers 26–50.

When should I choose Human CREST testing?

Choose Human CREST testing where expert judgement, business logic, chained attack paths or independent CREST-led assurance are important. The scoping call will confirm the proportionate method.

Is there a separate setup or onboarding charge?

No. The calculator prices the product packs and objectives you select; there is no separate standing setup charge.

Which options create an annual contract?

Standalone is a one-off engagement. Standalone plus Expose CTEM and the Annual CTEM assurance programme create a 12-month agreement, as explained in the commercial-route section.

Indicative quotation

Get a copy of your quote.

Send your selected scope to Pentesys. We’ll check it and prepare a presentable quotation within four working hours.

Pricing catalogue 2026.09.5 · Prices exclude VAT