By EJN Labs · 17 Jul 2026 · 9 min read
UK day rates for CREST-certified testers sit at a fair-market £1,100 to £1,400 per day in 2026. EJN Labs does not bill day rates to clients: we publish that band so you can sanity-check any quote against the wider UK CREST market, and every engagement is quoted as a scope-based fixed price agreed before work starts. Day-rate billing exposes you to scope creep and an uncertain invoice, while a fixed price gives you one agreed figure you approve up front.
The penetration testing day rate is the number most UK buyers ask for first, yet how a firm bills against it matters more than the rate itself. The same UK-based CREST-certified tester at the same published rate can leave you with a predictable invoice or an open-ended bill, depending on whether the engagement is fixed-price or charged by the day. This guide explains the day-rate band we publish for 2026, why we disclose it without billing against it, and which model protects you from a surprise final figure. For our published prices across every test type, see our penetration testing cost UK hub.
What a UK penetration testing day rate actually is
A penetration testing day rate is the price a firm charges for one tester working for one day. UK day rates for CREST-certified consultants sit at a fair-market £1,100 to £1,400 per day, and EJN Labs publishes that band for transparency on our UK penetration testing prices page.
We do not bill day rates to clients. The band is disclosed for transparency, so you can sanity-check the quotes you receive against the broader UK CREST market and confirm nobody is over-charging you or cutting corners. What you buy from us is a scope-based fixed price, agreed in writing before any testing starts.
Be cautious of rates that look unusually cheap. A quoted day rate well below the published band usually signals an automated scan dressed up as a manual test, a report with no reproduction steps, or a team based outside the UK with no UK accreditation. All EJN Labs testing is delivered by UK-based, CREST-certified testers working under our CREST company accreditation, and what you pay is set by what is in scope, not by who is assigned to it. To see what a defined scope actually costs across each service, our penetration testing cost guide sets out our published price ranges by test type.
Day-rate billing vs fixed-price billing
The same piece of testing can be billed two ways, and the difference decides how much budget certainty you get. Under day-rate billing, the firm charges for the days the engagement actually consumes, so your invoice depends on how the work runs. Under fixed-price billing, the firm agrees a written scope and commits to one figure for it, whatever the work turns out to involve. What changes between the two is who carries the risk if the testing takes longer than expected.
How day-rate billing works
Day-rate billing works by the firm giving you a rate and an estimate, then billing the days it actually uses. If scoping was tight and the environment behaves, you pay close to the estimate. If the scope grows mid-engagement, the day count climbs and so does the invoice.
The same happens if discovery takes longer than planned. Day-rate billing is honest in that you pay for work done, but it pushes the risk of an inaccurate estimate onto you, which is why it suits long-term retainers and staff-augmentation arrangements better than a one-off test.
How fixed-price billing works
Fixed-price billing works by the firm absorbing the estimation risk: a scoping call establishes the targets, testing approach and deliverables, the firm places that scope in its published price range for the service, and you receive a single price tied to a written scope. The figure you approve is the figure you pay.
The figure holds whatever happens next. If the test runs slightly long because something proved fiddly, that is the firm’s problem, not yours. The only thing that changes a fixed price is a change to the agreed scope, documented and re-quoted before any extra work begins.
Why scope creep punishes day-rate buyers
Scope creep punishes day-rate buyers because every addition to the engagement adds tester days at the going rate, and under day-rate billing every one of those days lands on your invoice. It is the silent multiplier on a day-rate engagement.
A test booked as “the main web application” turns into the application plus its admin portal, plus the API behind it, plus a forgotten staging host. Under a fixed price, the firm decides at scoping whether those targets are in or out, names them in writing, and prices them once. That discipline is why fixed pricing protects your budget: the negotiation happens before the work, not after it.
Worked example: the same test, two ways
Picture a UK SME commissioning a test of a single-role web application. That scope typically costs £5,000 to £8,000 in the UK market, and we quote one fixed figure for it before any testing starts. The difference between the two billing models is what happens around that figure once testing is under way.
| Billing model | What you are quoted | What you pay if the work runs long |
|---|---|---|
| Day rate | A rate per tester day plus an estimated number of days | The extra days are added to your invoice |
| Fixed price (EJN Labs) | One fixed figure for the written scope, typically £5,000 to £8,000 in the UK market for a single-role web application | The same figure, because we absorb the overrun |
The lesson is not that day-rate billing is dishonest, it is that it transfers estimation risk to you: if the firm under-estimated, you cover the overrun. A fixed price gives the firm every incentive to scope accurately and deliver inside that scope. For a one-off compliance or assurance test, that certainty is almost always worth more than the theoretical saving of paying for fewer days. You can see our published price range for every test type on our UK penetration testing cost hub.
What drives the size of a penetration testing quote
Scope is where the real money is decided, not the headline rate. Knowing what moves the size of an engagement helps you compare quotes that look similar on the surface but differ widely in total.
- Scope size. The number of applications, IP ranges, endpoints or user roles in scope is the single biggest driver of the price.
- Complexity. A flat brochure site is a fraction of the effort of a multi-role SaaS platform with bespoke authorisation logic.
- Test type. An external network test, a web application test, an API test and a red team engagement sit in very different published price ranges for the same organisation.
- Retesting. A firm that includes a free retest builds remediation verification into the engagement rather than charging for it later.
- Documentation and access. Good documentation, ready test accounts and a stable environment cut the discovery overhead and keep the scope tight.
How EJN Labs approaches day rate and pricing
We quote fixed, not by the day. Every engagement begins with a short scoping call where our CREST-certified testers establish the targets, the test type and the deliverables, then place that scope in our published price range for the service. All testing is carried out by UK-based, CREST-certified testers working under our CREST company accreditation. You receive one figure tied to a written scope, and that figure does not move unless you change the scope, in which case we document and re-quote the change before doing the work.
As a CREST-accredited firm that also holds Cyber Essentials, Cyber Essentials Plus, ISO 27001 and ISO 9001, we produce reports that stand up to auditor and customer scrutiny, with CVSS-scored findings, reproduction steps and a prioritised remediation plan. A free retest is included so your developers can fix the issues and have us verify them without a fresh invoice. The day-rate band is published, the scope is agreed in writing, and the final price is fixed. Explore the full range of assessments on our penetration testing services page, or see the published day-rate band and per-service price ranges on our UK penetration testing prices page.
Frequently Asked Questions
What is a typical penetration testing day rate in the UK?
£1,100 to £1,400 per day is the fair-market UK band for CREST-certified consultants, and EJN Labs publishes it as a reasonable sanity-check on day rates in 2026. At that level you are paying for hands-on manual exploitation by a UK-based tester, not an automated tool.
EJN Labs does not bill day rates to clients. We publish the band so you can compare it with what you are being quoted, and we quote scope-based fixed prices instead. Rates well below the band usually signal a scan presented as a manual test, or a team with no UK accreditation.
Is fixed-price or day-rate penetration testing better?
Fixed-price is usually better for a one-off compliance or assurance test because it gives you budget certainty: the firm agrees a written scope and commits to one figure for it. Day-rate billing suits retainers and staff augmentation, where the work is open-ended by design.
With day-rate arrangements you accept variable invoicing in exchange for flexibility.
Do you charge a day rate or a fixed price?
A fixed price, always. We agree a written scope on the scoping call and quote a single figure against our published price range for that service, so the number you approve is the number you pay.
The £1,100 to £1,400 fair-market band we publish for transparency is a sanity-check on UK day rates, not a billing basis. Once quoted, our figure is committed in writing: if the work runs long, we absorb the overrun rather than passing extra days on to you.
Why is one quote’s day rate cheaper than another?
Because the work behind the rate usually differs. A noticeably cheaper day rate often means an automated scan rather than manual testing, a report without reproduction steps, or a team with no UK accreditation. The rate reflects how the work is actually done and how thoroughly it is tested.
Two quotes can also differ in total because of what is in scope, not the rate. One firm may include the supporting API and a free retest while another prices the application alone, so compare what each quote covers rather than just the headline rate.
Can the fixed price change once the test starts?
Only if you change the agreed scope. A fixed price is tied to a written scope, so adding targets such as an extra application, API or network range changes what is being tested and is documented and re-quoted first. If the scope stays the same, the price stays the same, even if the work proves harder than expected.
Get a fixed-price penetration testing quote
Tell us what you need tested and we will return a fixed-price quote after a short scoping call, with the scope it covers laid out plainly. No open-ended day billing, no obligation, just one clear figure and a free retest included. Start with our fixed-price quote form.




Leave a Reply