VAPT BUYER'S GUIDE FOR UK BUSINESSES
What to Ask Before Hiring a Penetration Testing Firm
Produced by Securify Edge | securifyedge.com | 2026
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
INTRODUCTION
Penetration testing is one of the most commonly misunderstood purchases a business makes. Unlike buying software or hiring a contractor, the quality of a penetration test is almost impossible to judge from the outside before the engagement starts. Two firms can both claim to offer "comprehensive VAPT services" — one delivers a thorough, manually-executed assessment that finds critical vulnerabilities your team had no idea existed. The other runs an automated scanner, exports the results to a PDF, and calls it a penetration test.
This guide exists to close that gap. It covers what VAPT actually involves, what separates a credible provider from a scan-and-report shop, the five questions you should ask on every scoping call, and what a properly structured report should contain. Use it as a checklist before signing any penetration testing contract.
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
SECTION 1 — WHAT IS VAPT AND WHY DOES IT MATTER?
Vulnerability Assessment vs Penetration Testing
These two terms are often used interchangeably. They describe different activities, and understanding the difference matters when you are scoping an engagement and evaluating what you receive.
A vulnerability assessment is a systematic scan of your systems to identify known weaknesses — missing patches, default credentials, misconfigured services, outdated software. It tells you what is wrong. It does not tell you what an attacker could actually do with those weaknesses in your specific environment.
A penetration test goes further. A trained consultant actively attempts to exploit the vulnerabilities identified — chaining multiple low-severity issues together, escalating privileges, moving laterally through your network, and accessing systems or data they should not be able to reach. It tells you what an attacker would do, how far they would get, and what the real-world business impact would be.
VAPT combines both. The vulnerability assessment ensures comprehensive coverage. The penetration test provides exploitation-validated impact assessment. This combination is what most compliance frameworks — PCI DSS, ISO 27001, SOC 2, Cyber Essentials Plus — require when they mandate security testing.
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
Who Needs VAPT in the UK?
The short answer is any business that holds sensitive data, processes payments, operates a customer-facing web application, or is subject to a regulatory framework. More practically, businesses that commission VAPT in the UK typically do so for one of five reasons:
A compliance requirement — PCI DSS mandates annual pen testing for cardholder data environments. ISO 27001 requires technical security testing as part of audit evidence. SOC 2 auditors expect penetration test documentation. Cyber Essentials Plus requires a penetration test component.
An enterprise sales requirement — a larger client or prospect requires evidence of penetration testing before signing a contract or vendor agreement.
Investor due diligence — Series A and Series B investors routinely request penetration test results as part of security due diligence before closing a round.
Cyber insurance — insurers increasingly ask for penetration test evidence before underwriting or at renewal. Some policies require annual testing as a condition of cover.
Post-incident assurance — after a breach or suspected compromise, organisations commission a VAPT to understand how the attacker got in and what else may have been exposed.
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
SECTION 2 — THE FIVE QUESTIONS TO ASK EVERY PROVIDER
These are the questions that separate credible providers from scan-and-report shops. Ask all five before signing anything.
QUESTION 1: Is this a manual test or an automated scan?
This is the most important question. Automated scanning tools — Nessus, Qualys, Tenable — are useful for identifying known vulnerabilities at scale. They are not penetration tests. A credible penetration test involves a trained human consultant actively attempting to exploit vulnerabilities, chain findings together, and determine real-world impact.
Ask the firm directly: "What percentage of this engagement involves manual testing by a consultant?" If the answer is vague, or if they tell you the tool "does the testing," walk away.
RED FLAG: Any firm that cannot name the specific consultant who will conduct your test is almost certainly relying primarily on automated tools. Ask for the consultant's name and credentials before signing.
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
QUESTION 2: What methodology do you follow?
Credible firms follow established, documented methodologies. The main ones used in UK engagements are the OWASP Testing Guide (for web applications), the Penetration Testing Execution Standard (PTES) for broader engagements, NCSC CHECK methodology (for government-adjacent organisations), and NIST SP 800-115 for US-regulated clients.
If a firm cannot tell you which methodology they follow, or gives a vague answer about "industry best practices," that is a signal that their process is not documented or consistent.
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
QUESTION 3: What does the report look like?
Ask to see a sample redacted report before signing. A properly structured penetration test report has two distinct sections: an executive summary written for non-technical readers (suitable for board presentation, investor review, or insurance submission), and a detailed technical findings section with each vulnerability described, its CVSS 3.1 score assigned, proof of concept where applicable, and a specific remediation step your development or IT team can act on.
RED FLAG: If the report is a formatted export from an automated scanning tool with no consultant commentary, no exploitation evidence, and no CVSS scoring, it is not a penetration test report. It is a vulnerability scan export.
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
QUESTION 4: What is the scope and what is explicitly excluded?
Scope determines the value of the engagement. A web application test that covers only one URL when your application has 12 user roles and 40 distinct functions will miss most of the attack surface. Before signing, confirm: which URLs, IPs, or systems are in scope; which user roles will be tested; whether the API is included; whether authenticated and unauthenticated attack paths are both covered; and what is explicitly out of scope.
Get the scope in writing before the engagement starts. Any reputable firm will provide a formal scope statement as part of the engagement agreement.
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
QUESTION 5: What happens after you deliver the report?
The report is not the end of the engagement — it is the beginning of the remediation process. Ask whether the firm provides a retest to verify that critical findings have been fixed. Ask whether they are available to answer questions from your development team during remediation. Ask whether the report can be reissued with a clean bill of health after remediation — some compliance frameworks and enterprise procurement processes require this.
Firms that deliver the report and disappear are selling a document. Firms that support remediation and offer a retest are selling a security outcome.
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
SECTION 3 — PRICING: WHAT TO EXPECT IN THE UK IN 2026
Penetration testing pricing in the UK varies enormously depending on scope, methodology, and provider. Understanding the market rates helps you identify both overpricing and suspiciously low quotes that likely indicate automated scan output.
TEST TYPE | TYPICAL PRICE RANGE (GBP)
Web Application Penetration Test | £2,500 – £6,500
External Network Test | £2,500 – £5,500
Internal Infrastructure Test | £5,000 – £12,000
Mobile Application Test | £3,500 – £8,000
Cloud Security Assessment | £4,000 – £9,000
API Penetration Test | £3,000 – £7,000
Full VAPT Programme (all surfaces) | £10,000 – £25,000
These figures reflect manual engagements by experienced consultants for SME and mid-market scopes. Enterprise-scale engagements and regulatory-driven assessments (PCI DSS, FCA operational resilience) are typically quoted individually.
WARNING: Any quote below £1,500 for a web application test should be questioned carefully. At that price point, the firm is almost certainly running an automated scan, not a manual penetration test.
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
SECTION 4 — WHAT YOUR REPORT SHOULD CONTAIN
Every penetration test engagement should produce a formal written report. The structure of a well-produced report is consistent across credible providers.
EXECUTIVE SUMMARY
Written for a non-technical audience. Covers: scope of the engagement, key findings at a high level (critical, high, medium, low counts), the most significant individual finding and its business impact, overall security posture assessment, and recommended next steps. Should be readable by a CFO, board member, or investor with no security background.
TECHNICAL FINDINGS
Each finding should include: the vulnerability name and description; the CVSS 3.1 base score and severity rating; the affected system, URL, or IP; the steps taken to discover and exploit the vulnerability; evidence in the form of screenshots, HTTP request/response logs, or command output; the specific remediation step required; and estimated remediation effort and priority.
SCOPE STATEMENT
A formal record of exactly what was tested, what testing methods were used, and what was explicitly excluded. This section is what compliance auditors, insurers, and enterprise procurement teams refer to when they need to verify the engagement.
METHODOLOGY REFERENCE
A statement of which framework was followed (OWASP, PTES, NCSC, NIST) and any deviations from standard methodology.
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
SECTION 5 — COMPLIANCE FRAMEWORKS AND VAPT REQUIREMENTS
PCI DSS
Payment Card Industry Data Security Standard requires annual penetration testing for all organisations that process, store, or transmit cardholder data. Testing must cover both internal and external attack surfaces and must follow an industry-accepted methodology.
ISO 27001
ISO 27001 Annex A requires organisations to manage technical vulnerabilities. Auditors typically expect to see evidence of penetration testing as part of an organisation's technical security review process.
SOC 2
SOC 2 does not explicitly mandate penetration testing, but auditors examining the Security trust service criteria routinely ask for penetration test evidence. Most SOC 2 Type 2 assessments require a penetration test report covering the systems within the SOC 2 boundary.
UK Cyber Essentials Plus
Cyber Essentials Plus is the higher tier of the UK government's Cyber Essentials scheme. It includes an independent assessment of security controls, which involves vulnerability scanning and penetration testing elements conducted by a Cyber Essentials certifying body.
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
ABOUT SECURIFY EDGE
Securify Edge (securifyedge.com) is a specialist penetration testing and cybersecurity compliance firm serving businesses across the UK, USA, Europe, Australia, and Canada. We deliver manual VAPT engagements for web applications, mobile apps, APIs, cloud infrastructure, and corporate networks — led by named senior consultants using OWASP, PTES, and NCSC-aligned methodology.
Every Securify engagement produces a structured report suitable for board review, compliance audit evidence, enterprise vendor questionnaires, and cyber insurance submissions. Fixed-scope, fixed-price engagements with written quotes within 24 hours of a scoping call.
Book a free scoping call: https://securifyedge.com/contact/
View our penetration testing services: https://securifyedge.com/cyber-security-services/
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
© 2026 Securify Edge · securifyedge.com · All rights reserved
Top comments (0)