Accredited and recognised


Real lead times
Our standard lead time from agreed scope to testing is two to three weeks. At short notice we can frequently start within a week, and occasionally within a couple of days for a contained scope such as a single web application or an external infrastructure range.
| Scope | Standard | At short notice |
|---|---|---|
| Single web application, defined scope | 2 to 3 weeks | Often within a week, occasionally 2 to 3 days |
| External infrastructure range | 2 to 3 weeks | Often within a week, occasionally 2 to 3 days |
| Verifying a single disclosed vulnerability | 1 to 2 weeks | Frequently within days |
| Internal network, single site | 3 to 4 weeks | Within 2 weeks, subject to site access |
| Large multi-application estate | 4 to 6 weeks | Rarely compressible below 3 weeks |
What we will not do is agree to a date we cannot meet. If your deadline is not achievable we will say so on the first call, because discovering that two days before your submission is considerably worse than knowing immediately.
What is driving your deadline changes what you need
A client or tender requires a recent report
The most common reason people call at short notice. If the requirement names CREST, check your provider holds accreditation at company level rather than an individual certification. The wording in proposals is sometimes deliberately blurred, and a report from the wrong kind of provider may not satisfy the requirement at all.
An insurer or renewal deadline
Read the policy wording before scoping. Some insurers specify particular coverage or accreditation, and a test scoped to the wrong thing satisfies nobody.
An audit or certification deadline
These usually have some flexibility, and it is worth checking whether the auditor will accept a scheduled test rather than a completed one.
You have had an incident
Different problem, different answer. If you are dealing with an active compromise you need incident response first: containment, investigation, and establishing whether the attacker still has access. A penetration test tells you what could happen; it does not tell you what did. Test afterwards, once the environment is stable.
A vulnerability has been disclosed to you
Someone has reported a flaw and you need it verified and the surrounding area checked. Usually fast, contained, and one of the easiest engagements to turn around quickly.
Deadline already running? These two can be bought now, with no scoping call.
What compresses, and what does not
Scoping compresses to a same-day call. We do not require a forty-field form first.
Scheduling compresses depending on current commitments. Ask, and we will tell you honestly what is free.
Reporting compresses. Critical findings are reported the moment we confirm them, not held for the final document.
Testing time does not compress. A ten-day job does not become a four-day job because the deadline moved. It becomes a four-day job with six days of coverage missing, and the report will say so.
What urgency costs
Nothing extra on the rate. A short-notice engagement is priced the same as a planned one: CREST-accredited day rates run £800 to £1,200, and the day count is driven by scope rather than by how quickly you need it. What urgency costs you is choice of dates, not money.
Fixed fee or quoted, and which you actually need
Two things can be bought straight away because their scope is genuinely fixed: an external infrastructure test of up to ten public IP addresses, and a test of a standard CMS website. Those cover a large share of what tenders and insurers actually ask for, and buying one takes a few minutes rather than a few days of scoping.
Everything else needs scoping, and it needs it for a reason rather than out of process. An application with multiple user roles, a payments flow, or an API cannot be priced from a URL, and a fixed fee applied to it would either overcharge you or underdeliver. If your requirement is wider than the two tests above, the enquiry form is the faster route, not the slower one.
What we need from you to move quickly
Lead time is usually lost waiting for information rather than waiting for a tester. Having these ready when you first make contact removes most of it:
- The exact targets: IP ranges, hostnames or URLs, and confirmation you own them or are authorised to have them tested.
- Whether testing is authenticated, and if so how many roles and who provides the credentials.
- Any system that must not be touched, and any window to avoid.
- A named technical contact who can answer a question the same day.
- The actual deadline, and what it is for. A tender submission date and an insurer's renewal are different problems.
What we will not do to hit a date
We will not reduce a scope quietly so it fits the time available and hand you a report that looks complete. We will not skip the retest and leave you with a report full of open findings, which is the document your client will actually read. And we will not take the work at all if the date is not achievable: you will hear that at the first conversation, while you still have time to go elsewhere.
The commercial reality is that a test delivered late is worth less than a test not taken, because by then you have also lost the option of another provider.
Is your deadline realistic?
Tick what is already true. The more of these you can answer, the faster a test can start.