How to Evaluate a Penetration Testing Quote
A buyer's framework for 2026. Calculate implied day rate, check for red flags, and verify your proposal covers the right deliverables.
We do not sell penetration testing services. This site is not affiliated with any pentest vendor or security firm. All prices are independently researched from publicly available quotes, industry surveys, and published rate cards.
Day Rate Calculator
Ask your vendor if not stated. Web app: 5–10 days typical.
Enter quote total and estimated days to calculate implied day rate
Below £800/day
Automated scan territory
£800–£1,200/day
Verify certifications
£1,200–£1,800/day
Fair market rate
£1,800+/day
Enterprise / Big 4
Red Flag Checklist
Check any of these that apply to your quote. Each tick warrants a follow-up question before signing.
What a Good Proposal Includes
Before engagement
During engagement
Deliverables
RFP Template
For organisations running a formal procurement process. Copy and adapt.
PENETRATION TESTING REQUEST FOR PROPOSAL Organisation: [Your organisation name] Date: [Date] Response required by: [Date] 1. SCOPE Test type: [Web application / Network / Cloud / Mobile / API / Red Team] Environment: [Brief description - production / staging / both] Assets in scope: [URLs, IP ranges, application count] 2. ENGAGEMENT MODEL Testing approach: [Black-box / Grey-box / White-box] Compliance requirement: [PCI DSS / SOC 2 / ISO 27001 / None] On-site requirement: [Yes / No / Partial] 3. COMPLIANCE AND CERTIFICATION REQUIREMENTS Required certifications: [CREST / CHECK / OSCP minimum] Report format: [Standard / PCI DSS audit-ready / SOC 2 evidence package] Regulator: [QSA name if PCI DSS / Auditor firm if SOC 2] 4. REPORTING REQUIREMENTS Executive summary: Required Technical findings with CVSS scoring: Required Remediation guidance: Required per finding Re-test window: Minimum 30 days post-report delivery 5. TIMELINE Preferred start date: [Date] Report delivery deadline: [Date] Re-test completion: [Date] 6. COMMERCIAL REQUIREMENTS Budget range: [If disclosable] Engagement model: Fixed price preferred Payment terms: [30 days / 60 days] 7. MANDATORY QUESTIONS a. What methodology does your team follow for this test type? b. What percentage of testing hours are manual vs automated? c. Who will conduct the engagement? Please provide their certifications. d. Can you provide a redacted sample report? e. What is your critical finding escalation procedure? f. What professional indemnity insurance do you carry? g. Is re-test included? What is the scope of the re-test?