Best Penetration Testing for PCI DSS
The best penetration testing for UK PCI DSS in 2026 comes from CREST-accredited providers that test to Requirement 11.4 (external, internal, and segmentation testing of the cardholder data environment) and can provide ASV scanning for the quarterly Requirement 11.3 vulnerability scan, with a retest included and reporting your QSA and acquiring bank will accept. Penetration testing and ASV scanning are not the QSA assessment: a Qualified Security Assessor completes the full PCI DSS assessment and Report on Compliance separately. This guide compares 7 providers: Precursor Security, NCC Group, Pen Test Partners, Redscan (Kroll), JUMPSEC, OnSecurity, and Bulletproof.
Seven penetration testing companies compared for UK PCI DSS buyers, on the criteria that actually matter: Requirement 11.4 CDE testing (external, internal, segmentation), ASV scanning for the quarterly Requirement 11.3 scan, verifiable CREST accreditation, a retest included, and reporting your QSA and acquiring bank will accept.
We are Precursor Security, and we have ranked ourselves first on this list.
Rather than pretend otherwise, we publish the selection criteria in full and describe every provider fairly, including where a rival is the better fit. The firms below are genuinely good at what they do; the differences are in CREST accreditation, ASV and QSA capability, transparency, and who each serves best against your merchant level. Confirm any CREST claim in the independent CREST member directory, and any ASV claim in the PCI Security Standards Council's list of Approved Scanning Vendors.
Seven firms, side by side
| Provider | CREST status | Pricing published | From |
|---|---|---|---|
| 1. Precursor Security | Pen Test + VA + SOC | Yes | From £2,500 |
| 2. NCC Group | Member firm | No | On application |
| 3. Pen Test Partners | Member firm | No | On application |
| 4. Redscan (Kroll) | Member firm | No | On application |
| 5. JUMPSEC | Member firm + NCSC CHECK | No | On application |
| 6. OnSecurity | Member firm | No | Instant quote via platform |
| 7. Bulletproof | Member firm | No | On application |
Verified against each provider's public website, August 2026. "No" under pricing means a rate was not published at the time of writing, not that a provider is more expensive. Redscan is part of Kroll (US-headquartered).
The 7 best for UK PCI
DSS in 2026
1. Precursor Security
Precursor holds CREST accreditation for penetration testing and delivers testing that satisfies PCI DSS Requirement 11.4: external, internal, and segmentation testing of your cardholder data environment (CDE), completed annually and after significant change. We can also provide ASV (Approved Scanning Vendor) scanning for the quarterly external vulnerability scan Requirement 11.3 demands, with guided remediation on flagged vulnerabilities rather than a scan result you are left to interpret alone. Every tester is a UK-based, DBS-checked employee. Testing starts from £2,500 at approximately £1,200 per consultant day, published on the website, with a retest included in every engagement to verify segmentation and remediation fixes, and a written quote within 24 hours of scoping. Reports are formatted to the evidence standard your QSA and acquiring bank expect.
Trade-off: Precursor provides the PCI penetration testing and ASV scanning, not the QSA assessment or Report on Compliance. A firm that needs a full QSA-led RoC pairs Precursor's testing evidence with a separate QSA engagement.
2. NCC Group
NCC Group is one of the largest security consultancies in the world, headquartered in Manchester, and holds PCI QSA, PA-QSA, P2PE QSA, PFI, and ASV credentials alongside CREST membership. For a large or systemically important merchant that wants its Requirement 11.4 penetration testing, its ASV scanning, and its QSA-led assessment delivered by a single global consultancy, NCC Group can run the whole programme.
Trade-off: Engagement model and pricing are built for enterprise procurement. Costs are on application.
3. Pen Test Partners
Pen Test Partners are the UK's best-known specialists in embedded and operational technology, and their public research on payment hardware and ATM security is widely cited. For a merchant whose CDE risk lives in payment terminals, ATMs, or specialist devices rather than a standard web and infrastructure estate, they belong on the shortlist.
Trade-off: A specialist focus; standard web and network testing for a typical e-commerce CDE is not their distinctive strength, and no PCI-specific ASV or QSA capability is published. Pricing on application.
4. Redscan (Kroll)
Redscan, now part of Kroll, pairs a large penetration testing practitioner organisation with Kroll's PCI QSA practice, incident response, and forensics business. For a merchant that wants its penetration testing, its QSA-led Report on Compliance, and its breach-response retainer under one supplier at enterprise scale, the Kroll relationship is the draw.
Trade-off: Kroll is US-headquartered, and the engagement model leans enterprise. Pricing on application.
5. JUMPSEC
JUMPSEC holds NCSC CHECK status alongside CREST membership, with a strong red teaming and adversary-simulation practice. For a merchant with PSN-connected or government-adjacent systems that mandate CHECK delivery in addition to Requirement 11.4 penetration testing, that combination is the differentiator.
Trade-off: No PCI-specific ASV or QSA capability is published. Pricing on application.
6. OnSecurity
OnSecurity runs a platform-first, pentest-as-a-service model with instant online quoting and quick scheduling. For a smaller merchant that needs its annual Requirement 11.4 test booked this week with minimal procurement friction ahead of an acquirer deadline, the platform model works well.
Trade-off: Quotes are generated through the platform rather than published as a rate card, and the model suits smaller, repeatable scopes rather than a full CDE programme.
7. Bulletproof
Bulletproof combines penetration testing with a broad compliance practice, including Cyber Essentials, ISO 27001, and PCI DSS support, which suits a smaller merchant that wants testing and wider compliance handled by a single supplier.
Trade-off: A generalist breadth play rather than a testing specialist, and PCI-specific QSA status is not published. Pricing on application.
How we ranked them for PCI DSS
Six criteria that matter specifically to a merchant buying PCI penetration testing and ASV scanning, each something you can verify without taking anyone's word for it. Weighting is ours; the facts are checkable.
Whether the provider tests the CDE from external and internal perspectives and validates segmentation controls, not just runs a network scan. Requirement 11.4 needs all three: external, internal, and segmentation testing.
Whether the provider holds or can deliver Approved Scanning Vendor status for the quarterly external vulnerability scan. Not every CREST pentest firm runs an ASV service.
Company and individual CREST accreditation, checkable in the public directory. It is the accreditation most UK QSAs and acquiring banks recognise on a penetration testing supplier.
Whether verification of your fixes, including segmentation remediation, is included or sold back as a second engagement. Your QSA and acquirer need remediation evidence, and paying twice for it is avoidable.
Whether the report maps findings to specific PCI DSS requirements and CDE components in a format your QSA or acquiring bank will accept as evidence, not raw scanner output.
Whether the provider correctly scopes your cardholder data environment before testing, including connected-to and security-impacting systems merchants commonly exclude by mistake.
Red flags for a
PCI DSS buyer
Whichever firm you choose, including us, walk away if you see these.
A "PCI pentest" that skips segmentation testing
Requirement 11.4 needs external, internal, and segmentation testing together. Ask explicitly whether segmentation testing is included, and ask to see it named in the scope, not assumed.
A vulnerability scan sold as a penetration test
PCI DSS needs both a scan (Requirement 11.3) and a penetration test (Requirement 11.4), delivered separately. Ask how many days of manual testing, by whom, with what certifications, before you accept a scan report as your 11.4 evidence.
No ASV for the quarterly scan requirement
Requirement 11.3 specifically requires an Approved Scanning Vendor. Confirm the provider holds ASV status, or is transparent about which partner runs that scan, before you commit.
POA pricing under an acquirer deadline
A firm that cannot indicate a day rate before a discovery call adds procurement drag when you are working to an acquirer or QSA-driven timeline. UK CREST day rates run £1,000 to £1,500.
No retest to evidence segmentation fixes
A test without verification of your fixes is half a service. If the retest is a separate paid engagement, your segmentation remediation evidence for the QSA costs double.
A provider that blurs QSA assessment with penetration testing
Know which you are buying. A CREST-accredited penetration testing firm is not a QSA, and a QSA-led Report on Compliance is not a substitute for Requirement 11.4 testing.
PCI penetration testing and ASV prices
CREST-accredited testing runs £1,000 to £1,500 per consultant day. At Precursor's published rate of approximately £1,200 per day: external network from £2,500, web application from £3,750, internal network (with segmentation testing) from £6,250, and full CDE assessments from £10,000. ASV scanning for the quarterly Requirement 11.3 scan is quoted alongside your annual testing. Full pricing by merchant level is on the PCI DSS compliance testing page.
Full cost guide with worked examplesMore on PCI DSS testing and the services referenced above.
Compare us against anyone on this list.
UK-based, DBS-checked testers. Fixed pricing published before you call. A written quote within 24 hours of scoping. Retest included.
Penetration testing for PCI DSS
The questions merchants ask most when comparing UK providers for PCI DSS testing.
UK PCI DSS penetration testing runs from £2,500 for a single external CDE test to £15,000 or more for a full external, internal, and segmentation testing programme, at roughly £1,000 to £1,500 per consultant day from a CREST-accredited provider. ASV scanning for the quarterly Requirement 11.3 scan is typically quoted alongside, adding a smaller recurring cost across the four scan cycles. Most firms price on application; Precursor publishes its rates, starting from £2,500. Full pricing by merchant level is set out on our PCI DSS compliance testing page.
PCI DSS Requirement 11.4 requires external and internal penetration testing of the cardholder data environment (CDE) at least annually and after any significant change, plus segmentation testing to confirm the controls separating the CDE from the rest of the network actually hold. Requirement 11.3 separately requires quarterly external vulnerability scanning by an Approved Scanning Vendor (ASV). The two are not interchangeable: a scan satisfies 11.3, a penetration test satisfies 11.4, and most merchants need both.
An ASV scan is quarterly automated vulnerability scanning of external-facing CDE systems by a PCI SSC-approved vendor, required under Requirement 11.3, checking for known vulnerabilities and misconfigurations. A PCI penetration test is annual manual testing under Requirement 11.4 that attempts to exploit vulnerabilities and bypass segmentation controls, covering both external and internal perspectives. ASV scanning is continuous compliance monitoring; penetration testing validates real-world exploitability. PCI DSS requires both, from providers holding the relevant accreditation for each.
Yes, if you need a full PCI DSS assessment and Report on Compliance. That work is done by a Qualified Security Assessor (QSA), a role distinct from penetration testing. Requirement 11.4 penetration testing and Requirement 11.3 ASV scanning are a separate, CREST-accredited capability that a firm like Precursor provides as technical testing evidence; your QSA then uses that evidence within their assessment. A Level 1 merchant needing a mandatory Report on Compliance needs both a QSA and a CREST penetration testing provider; a smaller merchant completing a Self-Assessment Questionnaire may only need the testing.
UK merchants commonly shortlist a mix of specialists and larger consultancies. This guide compares seven: Precursor Security, NCC Group, Pen Test Partners, Redscan (Kroll), JUMPSEC, OnSecurity, and Bulletproof. The right choice depends on whether the firm holds ASV or QSA credentials alongside CREST accreditation, whether pricing is published, whether a retest is included for your remediation evidence, and whether the report format satisfies your QSA and acquiring bank. Confirm any CREST accreditation in the public directory at crest-approved.org and any ASV status in the PCI Security Standards Council's approved vendor list.



