Solusec: Solutions for Cyber Security

Operated by Solusec Ltd
CREST accredited · IASME Certification Body

Penetration testing

Need a penetration test, urgently?

What can honestly be compressed, what cannot, and how to tell whether the test you are being sold is the one your deadline actually requires.

Accredited and recognised

CREST accredited penetration testing providerCREST AI-Enabled Penetration Testing accreditation

Real lead times

Our standard lead time from agreed scope to testing is two to three weeks. At short notice we can frequently start within a week, and occasionally within a couple of days for a contained scope such as a single web application or an external infrastructure range.

Penetration testing lead times
ScopeStandardAt short notice
Single web application, defined scope2 to 3 weeksOften within a week, occasionally 2 to 3 days
External infrastructure range2 to 3 weeksOften within a week, occasionally 2 to 3 days
Verifying a single disclosed vulnerability1 to 2 weeksFrequently within days
Internal network, single site3 to 4 weeksWithin 2 weeks, subject to site access
Large multi-application estate4 to 6 weeksRarely compressible below 3 weeks

What we will not do is agree to a date we cannot meet. If your deadline is not achievable we will say so on the first call, because discovering that two days before your submission is considerably worse than knowing immediately.

What is driving your deadline changes what you need

A client or tender requires a recent report

The most common reason people call at short notice. If the requirement names CREST, check your provider holds accreditation at company level rather than an individual certification. The wording in proposals is sometimes deliberately blurred, and a report from the wrong kind of provider may not satisfy the requirement at all.

An insurer or renewal deadline

Read the policy wording before scoping. Some insurers specify particular coverage or accreditation, and a test scoped to the wrong thing satisfies nobody.

An audit or certification deadline

These usually have some flexibility, and it is worth checking whether the auditor will accept a scheduled test rather than a completed one.

You have had an incident

Different problem, different answer. If you are dealing with an active compromise you need incident response first: containment, investigation, and establishing whether the attacker still has access. A penetration test tells you what could happen; it does not tell you what did. Test afterwards, once the environment is stable.

A vulnerability has been disclosed to you

Someone has reported a flaw and you need it verified and the surrounding area checked. Usually fast, contained, and one of the easiest engagements to turn around quickly.

Deadline already running? These two can be bought now, with no scoping call.

What compresses, and what does not

Scoping compresses to a same-day call. We do not require a forty-field form first.

Scheduling compresses depending on current commitments. Ask, and we will tell you honestly what is free.

Reporting compresses. Critical findings are reported the moment we confirm them, not held for the final document.

Testing time does not compress. A ten-day job does not become a four-day job because the deadline moved. It becomes a four-day job with six days of coverage missing, and the report will say so.

What urgency costs

Nothing extra on the rate. A short-notice engagement is priced the same as a planned one: CREST-accredited day rates run £800 to £1,200, and the day count is driven by scope rather than by how quickly you need it. What urgency costs you is choice of dates, not money.

Fixed fee or quoted, and which you actually need

Two things can be bought straight away because their scope is genuinely fixed: an external infrastructure test of up to ten public IP addresses, and a test of a standard CMS website. Those cover a large share of what tenders and insurers actually ask for, and buying one takes a few minutes rather than a few days of scoping.

Everything else needs scoping, and it needs it for a reason rather than out of process. An application with multiple user roles, a payments flow, or an API cannot be priced from a URL, and a fixed fee applied to it would either overcharge you or underdeliver. If your requirement is wider than the two tests above, the enquiry form is the faster route, not the slower one.

What we need from you to move quickly

Lead time is usually lost waiting for information rather than waiting for a tester. Having these ready when you first make contact removes most of it:

What we will not do to hit a date

We will not reduce a scope quietly so it fits the time available and hand you a report that looks complete. We will not skip the retest and leave you with a report full of open findings, which is the document your client will actually read. And we will not take the work at all if the date is not achievable: you will hear that at the first conversation, while you still have time to go elsewhere.

The commercial reality is that a test delivered late is worth less than a test not taken, because by then you have also lost the option of another provider.

Is your deadline realistic?

Tick what is already true. The more of these you can answer, the faster a test can start.

Buy a fixed-fee test now

Two tightly scoped tests you can buy without a quote, which is the fastest route when a deadline is already running. If your scope is wider than these, ask for a quote and we will price it properly rather than sell you the wrong test quickly.

Delivered by a CREST-registered tester at a CREST-accredited company. Verify us on the CREST marketplace.

Optional add-ons
Additional IP addressesIn blocks of 5, beyond the first 10 × £500

Total: £3,000 + VAT

Payment is taken by Stripe. We never see or store your card details. Rules of engagement are agreed in writing before any testing starts.

Scope wider than the two fixed-fee tests?

An application with user roles, an internal network, a cloud tenant, a mobile app. Send the scope and the deadline and we will quote it properly, or tell you the date is not achievable, on the first reply.

Your details are handled by a real person, never fed into AI.