16 September 2026
Bottom line
Commission one grey-box penetration test of the production-like admin app and the first production-ready API before any real resident/family/staff feedback enters a pilot. Ask for unauthenticated and authenticated testing across every role, tenant isolation and business-logic abuse, with one included retest and a customer-shareable executive summary. For a compact early-stage product, budget £4,000-£10,000 + VAT as a planning range, then obtain three fixed-price quotes. Precursor, Cognisys and Cyndicate Labs are the strongest first quote set; all have current CREST directory evidence, while the shortlist spans smaller specialists through larger assurance firms.
Status key
Verified = directly supported by CREST, NCSC or the provider’s current site. Estimated = planning assumption based on published vendor rates and common engagement shapes; confirm in a written quote.
Recommended quote shortlist
Precursor Security - smaller offensive-security specialist and the clearest public pricing signal. CREST lists penetration-testing accreditation. Its site explicitly covers web apps/APIs and publishes web-app testing from £3,750 and an approximate £1,200 consultant-day benchmark. Best first call for a bounded startup scope. Verified except final Viewee price.
Cognisys Group - specialist/mid-tier option. CREST lists penetration testing; its official pages cover web applications and REST, GraphQL, SOAP and gRPC APIs, with manual OWASP API Top 10 testing. Strong fit if the API will be in scope at the same time. Verified.
Cyndicate Labs - boutique offensive-security team. CREST lists penetration testing and its site positions the firm around penetration testing, threat simulation and specialist security work. Ask specifically for recent multi-tenant SaaS and care/health data examples. Verified capabilities; SaaS-sector depth to confirm.
Closed Door Security - smaller UK option. CREST lists penetration testing; its site offers penetration testing and security assessments. Potentially better access to senior testers than a large consultancy. Confirm dedicated web/API experience, report sample and retest terms. Verified capabilities; fit details to confirm.
Pen Test Partners - established specialist with broad technical depth. CREST lists penetration testing and its site covers application/security testing across many sectors. Good comparator where unusual attack paths or deeper business logic matter, though likely less price-led than boutiques. Verified.
Blaze Information Security - specialist offensive-security firm. CREST lists penetration testing; the provider explicitly combines web application and API penetration testing and stresses manual testing beyond OWASP Top 10. Good SaaS-shaped alternative; confirm UK delivery team and data-handling location. Verified.
Bridewell - larger cyber consultancy. CREST lists penetration testing; Bridewell’s web-application service explicitly includes APIs. Useful if Viewee may later want cloud, compliance or managed-security work under one supplier. May be heavier than the first pilot needs. Verified.
NCC Group - large established provider. CREST lists penetration testing; its UK Digital Marketplace service covers web services/APIs through penetration testing, source-code review or threat modelling. Strong enterprise-recognition option, but likely higher process and cost overhead. Verified.
What to buy now
In scope:
One production-like admin application, its exact hostnames and the API used by it.
Unauthenticated attack surface plus authenticated tests for each real role: platform admin, care-provider admin/manager, staff and any read-only/reviewer role.
Cross-tenant and cross-role access control: IDOR/BOLA, privilege escalation, object ownership, direct URL/API access and tenant-boundary failures.
Authentication and session controls: login, reset/invite flows, MFA if present, token/cookie handling, logout/revocation and rate limiting.
Input/output handling: injection, XSS, CSRF where relevant, SSRF, file upload/download/export, unsafe deserialisation and sensitive error leakage.
API-specific coverage: endpoint inventory, object/function/property-level authorisation, mass assignment, schema/parameter abuse, pagination/enumeration, replay, throttling and secrets in responses.
Business logic tied to care feedback: viewing, editing, deleting, exporting and assigning feedback/actions; access to free text; audit-history integrity; aggregation/anonymisation edge cases.
Basic exposure checks around the Astro marketing site, admin and API hostnames, TLS/security headers, DNS/subdomain exposure and accidental source maps/secrets.
A technical report, severity methodology, evidence/reproduction steps, remediation advice, executive summary, debrief and one retest of fixes.
Usually separate or optional:
AWS/Azure/GCP configuration review, IAM architecture, container/Kubernetes review and CI/CD review. A web/API test sees only externally observable cloud weaknesses unless these are explicitly added.
Source-code review, secure architecture review and threat modelling.
Mobile apps, internal corporate network, employee devices, wireless, physical intrusion, denial-of-service/load testing, phishing/social engineering and red teaming.
Production data extraction. Testing should use synthetic data and agreed proof limits.
The Astro marketing site should not consume much manual time unless it has forms, authentication, previews, server functions or integrations. Ask bidders to separate a light external exposure check from the app/API effort.
Cost: planning range
Estimated for Viewee: £4,000-£10,000 + VAT for roughly 5-8 consultant days across one modest app, several roles and a compact API, including reporting and one bounded retest. A very small app with few endpoints and two roles might quote near £3,000-£5,000. A larger API, many workflows/roles, complicated tenant logic or cloud review can push the total to £8,000-£15,000+.
Evidence behind the estimate: Precursor publishes web-app testing from £3,750, overall testing from £2,500 and about £1,200 per CREST-accredited consultant day. EJN Labs publishes a £5,000 starting point for a small web app and an API heuristic of roughly 25-30 endpoints per day, with small API estimates of £2,400-£3,600. These are vendor-authored 2026 price signals, not neutral tariffs. Most CREST firms quote after scoping. Do not pick the cheapest quote unless it names manual authenticated testing, roles, endpoints, business logic, report and retest.
Optional-cost effects:
Cloud configuration review: commonly add 2-5+ days depending on accounts/services and access.
Source/code review: quote separately by repository/lines/critical components.
Social engineering: separate rules, target population, safeguards and legal approvals; unnecessary for the pilot product-assurance goal.
Urgent scheduling, weekend testing or a formal CHECK engagement can add cost. CHECK is the NCSC scheme for authorised testing of public-sector and critical-national-infrastructure systems; a private early-stage SaaS normally needs a credible CREST provider, not CHECK, unless a customer/procurement route requires it.
Timeline
Estimated practical plan:
Scoping and quotes: 2-5 working days once Viewee supplies the brief and a demo.
Lead time to a test slot: commonly 1-4 weeks; ask each bidder for the earliest named tester and dates. Specialists can sometimes move faster, but do not assume availability.
Environment/access setup: 2-5 working days in parallel, including accounts, allowlisting, synthetic data, API docs and rules of engagement.
Active test: about 4-7 working days for the initial Viewee scope; more for a large API or added cloud review.
Draft/final report: usually 2-5 working days after testing. Require critical findings to be raised immediately, not held for the report.
Fix window: typically 1-3 weeks for Viewee, driven by findings.
Retest: 1-3 days of tester effort, scheduled after evidence and fixes are ready; revised closure letter/report often follows within 1-3 working days.
Allow 4-8 elapsed weeks from first outreach to closed retest. Ask for retest validity, included days and scheduling terms in the quote; “free retest” often has limits.
When Viewee should test
Before the resident-data pilot: test after the app/API is production-like and major flows are stable, but before any real resident, family or staff feedback is loaded. Fix all critical/high findings and retest them before go-live. Do not test too early against a disposable architecture.
Before general availability: do a targeted delta test if authentication, roles, tenancy, APIs, hosting, exports or major workflows changed after the pilot test. If changes were minor and the provider confirms coverage remains representative, retain the pilot report and commission a shorter focused test rather than automatically repeating everything.
After launch: annual full external testing is a sensible baseline, plus targeted testing after material security-relevant changes. Examples: new API surface, authentication/SSO, role or tenant model, file handling, new cloud architecture, major data export/import, acquisition/integration or a serious incident. Continuous scanning and dependency/secret checks should run between tests. NCSC warns a penetration test only reflects the systems and known issues at the time of the test; it is assurance, not the primary vulnerability-management process.
Ready-to-adapt scoping brief
Subject: Request for quote - Viewee web application and API penetration test
Company and purpose
Viewee is an early-stage UK SaaS platform for adult social care providers. It collects feedback from residents, families and staff and turns it into themes, owned actions and evidence of change. We want independent security assurance before a pilot uses real feedback data.
Target timing
Preferred test window: [dates]. Target pilot date: [date]. We need the final report and retest closure by [date].
Environment
Production-like test environment: [URLs]
Astro marketing site: [URL; note forms/server functions]
Admin application: [URL and framework]
API: [base URLs; REST/GraphQL/etc.; approximate endpoint count]
Hosting/cloud/CDN/WAF: [details]
Third parties in user flows: [identity, email, storage, analytics]
Source IP allowlisting or VPN requirements: [details]
Users and workflows
Please test unauthenticated access and these roles: [platform admin], [provider admin/manager], [staff], [read-only/reviewer], [other]. Key workflows are invitations/login/reset, feedback capture/import, viewing and editing feedback, themes, actions, evidence/change history, file handling, search, reporting and export. The platform is multi-tenant; cross-tenant and cross-role access is a priority.
Requested scope
Grey-box manual web application and API penetration testing, supported by automated tools.
OWASP Web Security Testing Guide/ASVS and OWASP API Security Top 10 coverage, adapted to our architecture.
Authentication/session/token handling; authorisation and tenant isolation; injection/XSS/CSRF/SSRF; file and export handling; rate limiting; information leakage; business-logic abuse.
Light external exposure review for named public hostnames, TLS and security headers.
Test accounts and synthetic data will be provided for every role. API specification/Postman collection: [available/not yet available]. Architecture/data-flow diagram: [available].
Rules and exclusions
Authorised targets only: [exact hosts/IPs/APIs].
Testing window and emergency contacts: [details].
No denial-of-service, destructive testing, phishing/social engineering, physical testing or access to real resident data unless separately agreed in writing.
Stop/escalate conditions: service instability, access to another tenant or sensitive data, or critical compromise.
Data handling: UK GDPR-appropriate processing, least data capture, encrypted transfer/storage, named locations/subprocessors, deletion after [period], and immediate breach/escalation procedure.
Deliverables
Immediate notification of critical findings.
Technical report with scope, methodology, limitations, severity/risk basis, evidence, reproducible steps and pragmatic fixes.
Executive summary suitable for customer assurance, without exposing exploit detail.
Findings debrief with engineering.
One retest within [30/60] days and an updated report or closure letter showing verified fixes.
Please include in the quote
CREST company accreditation and proposed tester qualifications.
Named assumptions: application size, roles, workflows and API endpoints.
Consultant days, fixed price excluding/including VAT, earliest dates and report turnaround.
Exactly what is excluded, and prices for optional cloud configuration review and source-code review.
Retest allowance, deadline and cost if the allowance is exceeded.
Example redacted report and two relevant SaaS references/case studies, ideally multi-tenant and sensitive-data products.
Professional indemnity/cyber insurance, data location/retention, subcontractors and NDA terms.
Quote evaluation scorecard
25% scope fit: authenticated roles, tenant isolation, API and business logic are explicit.
20% tester quality and CREST evidence: company directory entry plus the actual tester’s experience/certifications.
15% report quality: review a redacted sample for reproducibility and practical fixes.
15% SaaS relevance: multi-tenant and sensitive-data examples.
10% timetable and continuity: named tester, dates, critical escalation, debrief.
10% total cost clarity: days, exclusions and change-control.
5% retest terms: included allowance, window and closure evidence.
Recommended next move
Send the brief to Precursor, Cognisys and Cyndicate Labs first. Add Pen Test Partners or Bridewell as a larger-firm comparator. Give each the same 30-minute product walkthrough and request fixed-price quotes against identical targets, roles and endpoint counts. Choose on scope and tester quality, not badge or price alone.
Sources
NCSC, Penetration testing: https://www.ncsc.gov.uk/guidance/penetration-testing
NCSC, CHECK penetration testing: https://www.ncsc.gov.uk/schemes/check
CREST supplier marketplace: https://www.crest-approved.org/members/
CREST, A Guide to Penetration Testing: https://www.crest-approved.org/wp-content/uploads/2023/04/A-Guide-to-Penetration-Testing-2022.pdf?ver=
CREST provider verification: Precursor https://www.crest-approved.org/member_companies/precursor-security-ltd/ ; Cognisys https://www.crest-approved.org/member_companies/cognisys-group-ltd/ ; Cyndicate Labs https://www.crest-approved.org/member_companies/cyndicate-labs/ ; Pen Test Partners https://www.crest-approved.org/member_companies/pen-test-partners/ ; Bridewell https://www.crest-approved.org/member_companies/bridewell-consulting/ ; NCC Group https://www.crest-approved.org/member_companies/ncc-group/ ; Blaze https://www.crest-approved.org/member_companies/blaze-information-security/ ; Closed Door Security https://www.crest-approved.org/member_companies/closed-door-security-ltd/
Provider service detail: Precursor web apps https://www.precursorsecurity.com/services/offensive-security/web-application-penetration-test ; Cognisys API https://cognisys.co.uk/penetration-testing/api-penetration-testing/ ; Cyndicate Labs https://cyndicatelabs.co.uk/ ; Pen Test Partners https://www.pentestpartners.com/ ; Bridewell web/API https://www.bridewell.com/web-application-testing ; NCC Group API assessment https://www.applytosupply.digitalmarketplace.service.gov.uk/g-cloud/services/246319243086096 ; Blaze web/API https://www.blazeinfosec.com/services/penetration-testing/web-app-pentest/ ; Closed Door Security https://www.cdsec.co.uk/
Price signals (vendor-authored, used only for estimates): Precursor https://www.precursorsecurity.com/services/offensive-security/penetration-testing/cost ; EJN Labs https://ejnlabs.com/pricing/ and https://ejnlabs.com/api-penetration-testing-cost/
