Choose ongoing protection, certification readiness, a penetration test or a red-team engagement. Every published “from” price includes a defined starting scope, so you know what you are buying before you commit.
01FoundationGet ready
02ExposeSee change
03ValidateProve security
04AdversaryChallenge controls
Four distinct ways in. One connected security system.
First, choose the need
What do you want to do?
Go straight to the most relevant prices. You do not need to buy Expose before choosing a penetration test or red-team engagement.
Start with managed readiness or external visibility, then add repeatable security testing when the need grows.
ONE AGREEMENT · TWO WAYS TO PAYEvery recurring plan is a 12-month commitment.
Pay monthly at the standard rate, or pay the full year in advance and receive a 5% discount. Choosing monthly payment does not create a monthly rolling contract.
Start here
Our clearest recurring entry points.
CERTIFICATION READINESS
Foundation Managed
Keep your evidence, actions and renewal preparation moving all year.
The cards above explain each plan individually. This table shows the published starting scopes side by side so you can see exactly what changes as the programme expands.
Prices exclude VAT. Foundation Managed covers Pentesys readiness support; official Cyber Essentials assessment and certification fees are separate. All plan limits shown are the included starting scope.
A clear promise on “from”
A genuine starting price—not a figure that disappears later.
01Choose the published scope
If you keep the exact starting scope shown below, the published starting price is the price.
02Shape anything larger
Use the Pentesys Portal to add targets, roles, environments, objectives or testing techniques.
03See the total before testing
Standard additions are itemised. Custom work is reviewed. Nothing starts until the scope, deliverables and fixed price are agreed.
PENTESYS FOUNDATION
Prepare for certification with a clear plan.
Use Foundation as a one-off readiness engagement or choose the managed plan above for support throughout the year.
Portal findings, executive and technical report, remediation guidance, one retest within 60 days and a closure statement.
AI-LED STARTING SCOPE
Web application test
from £1,495
One web application
One test environment
Up to 10 core user journeys
Up to two authenticated roles
Included deliverables
Portal findings, executive and technical report, remediation guidance, one retest within 60 days and a closure statement.
AI-LED STARTING SCOPE
Connected web + API
from £2,295
One web application and its documented API
One test environment
Up to 10 journeys and 25 endpoints
Up to two authenticated roles
Included deliverables
One coordinated scope, portal findings, executive and technical report, remediation guidance, one retest and a closure statement.
CONSULTANT-LED STARTING SCOPE
Human-led CREST scope
from £5,000
One agreed web application or API
One test environment
Up to two authenticated roles
Up to 20 journeys and 50 end points
Up to three consultant testing days
Included deliverables
Manual depth testing, portal findings, executive and technical report, debrief, remediation guidance and one retest within 60 days.
OPTIONAL HUMAN VERIFICATION+£995for the same AI-led scope
A qualified tester reviews the AI-led findings and manually investigates the highest-risk paths. This adds human assurance; it is not described as a fully human-led penetration test.
PENTESYS ADVERSARY
Challenge your controls against a realistic objective.
Start with a focused exercise or build a broader red-team engagement around the organisation, systems and attack paths that matter.
Rules of engagement, agreed escalation route, evidence, executive report and facilitated debrief.
FULL STARTING SCOPE
Full red-team exercise
from £22,500
Up to three agreed objectives
One agreed organisation boundary
Remote digital attack paths
Up to 10 tester days
Included deliverables
Rules of engagement, live escalation, evidence, executive and technical report, control observations and facilitated debrief.
Available through portal scoping: additional objectives, environments, business units or tester days; social engineering; physical testing; on-site work; out-of-hours activity and travel. The effect on scope and price is shown or reviewed before you commit.
Designed in the Pentesys Portal
Build the exact engagement. Approve one fixed scope.
The Pentesys Portal keeps every choice visible—from continuous exposure through to testing, findings and remediation. It is there to remove friction—not to conceal a higher eventual price.
Each product works as a genuine entry point. The next step should solve a new need—not make the first purchase feel incomplete.
FOUNDATION → EXPOSEKeep watch after readiness
Monitor the external controls and services that support certification.
EXPOSE → VALIDATEProve what matters
Test the applications that continuous visibility identifies as important.
VALIDATE → RECURRINGMake proof repeatable
Move successful one-off work into scheduled cycles, retesting and management evidence.
ADVERSARY → PROGRAMMEKeep challenging
Turn an exercise into a planned assurance programme without repeating the buying process.
Upgrade within 90 days
We will credit the net Foundation Ready fee or up to £1,495 of a qualifying one-off Validate engagement against the first year of a higher recurring plan. Eligibility and the exact credit are confirmed before the agreement is accepted.
Pricing questions
The important details, in plain English.
Does paying monthly mean I can cancel monthly?+
No. Every recurring plan has a 12-month minimum term. Monthly payment spreads the standard annual commitment across 12 invoices; annual payment receives a 5% discount.
Do I need Expose before buying a penetration test or red team?+
No. Foundation, Expose, Validate and Adversary are equal entry routes. You can go directly to the test or exercise you need.
What does “from” mean?+
It is the complete price for the published starting scope. The price changes only when you choose additional scope. Standard additions are itemised; custom requirements are reviewed before anything is agreed.
What happens after a vulnerability is fixed?+
Validate starting scopes include one retest of reported findings within 60 days and an updated closure statement. New targets or expanded functionality are treated as new scope.
Do prices include VAT and certification fees?+
Prices exclude VAT. Official Cyber Essentials and Cyber Essentials Plus assessment fees are separate from Pentesys Foundation readiness and preparation work.
Ready to begin?
Start with the security outcome you need today.
Tell us the decision, deadline and scope you are working towards. We'll recommend a proportionate starting point and keep the selected plan and billing context attached.