Skip to main content
Precursor Security
2026 Comparison Guide

Best Penetration Testing for PCI DSS

The best penetration testing for UK PCI DSS in 2026 comes from CREST-accredited providers that test to Requirement 11.4 (external, internal, and segmentation testing of the cardholder data environment) and can provide ASV scanning for the quarterly Requirement 11.3 vulnerability scan, with a retest included and reporting your QSA and acquiring bank will accept. Penetration testing and ASV scanning are not the QSA assessment: a Qualified Security Assessor completes the full PCI DSS assessment and Report on Compliance separately. This guide compares 7 providers: Precursor Security, NCC Group, Pen Test Partners, Redscan (Kroll), JUMPSEC, OnSecurity, and Bulletproof.

Seven penetration testing companies compared for UK PCI DSS buyers, on the criteria that actually matter: Requirement 11.4 CDE testing (external, internal, segmentation), ASV scanning for the quarterly Requirement 11.3 scan, verifiable CREST accreditation, a retest included, and reporting your QSA and acquiring bank will accept.

Updated August 2026
Every claim verifiable
QSA role explained
Scroll
3,000+ Assessments DeliveredTriple-CREST Accredited24/7 UK SOC in NewcastleReports Accepted by Insurers & RegulatorsEst. 2018
Read This First

We are Precursor Security, and we have ranked ourselves first on this list.

Rather than pretend otherwise, we publish the selection criteria in full and describe every provider fairly, including where a rival is the better fit. The firms below are genuinely good at what they do; the differences are in CREST accreditation, ASV and QSA capability, transparency, and who each serves best against your merchant level. Confirm any CREST claim in the independent CREST member directory, and any ASV claim in the PCI Security Standards Council's list of Approved Scanning Vendors.

At a Glance

Seven firms, side by side

ProviderCREST statusPricing publishedFrom
1. Precursor SecurityPen Test + VA + SOCYesFrom £2,500
2. NCC GroupMember firmNoOn application
3. Pen Test PartnersMember firmNoOn application
4. Redscan (Kroll)Member firmNoOn application
5. JUMPSECMember firm + NCSC CHECKNoOn application
6. OnSecurityMember firmNoInstant quote via platform
7. BulletproofMember firmNoOn application

Verified against each provider's public website, August 2026. "No" under pricing means a rate was not published at the time of writing, not that a provider is more expensive. Redscan is part of Kroll (US-headquartered).

The 7 best for UK PCI
DSS in 2026

1. Precursor Security

Best for: UK merchants that need CREST-accredited PCI penetration testing and ASV scanning under one supplier, at published prices

Precursor holds CREST accreditation for penetration testing and delivers testing that satisfies PCI DSS Requirement 11.4: external, internal, and segmentation testing of your cardholder data environment (CDE), completed annually and after significant change. We can also provide ASV (Approved Scanning Vendor) scanning for the quarterly external vulnerability scan Requirement 11.3 demands, with guided remediation on flagged vulnerabilities rather than a scan result you are left to interpret alone. Every tester is a UK-based, DBS-checked employee. Testing starts from £2,500 at approximately £1,200 per consultant day, published on the website, with a retest included in every engagement to verify segmentation and remediation fixes, and a written quote within 24 hours of scoping. Reports are formatted to the evidence standard your QSA and acquiring bank expect.

Trade-off: Precursor provides the PCI penetration testing and ASV scanning, not the QSA assessment or Report on Compliance. A firm that needs a full QSA-led RoC pairs Precursor's testing evidence with a separate QSA engagement.

2. NCC Group

Best for: Large or systemically important merchants wanting testing, ASV scanning, and the QSA assessment under one roof

NCC Group is one of the largest security consultancies in the world, headquartered in Manchester, and holds PCI QSA, PA-QSA, P2PE QSA, PFI, and ASV credentials alongside CREST membership. For a large or systemically important merchant that wants its Requirement 11.4 penetration testing, its ASV scanning, and its QSA-led assessment delivered by a single global consultancy, NCC Group can run the whole programme.

Trade-off: Engagement model and pricing are built for enterprise procurement. Costs are on application.

3. Pen Test Partners

Best for: Payment hardware, ATMs, and specialist embedded testing within the CDE

Pen Test Partners are the UK's best-known specialists in embedded and operational technology, and their public research on payment hardware and ATM security is widely cited. For a merchant whose CDE risk lives in payment terminals, ATMs, or specialist devices rather than a standard web and infrastructure estate, they belong on the shortlist.

Trade-off: A specialist focus; standard web and network testing for a typical e-commerce CDE is not their distinctive strength, and no PCI-specific ASV or QSA capability is published. Pricing on application.

4. Redscan (Kroll)

Best for: Merchants wanting testing, QSA assessment, and incident response under one enterprise relationship

Redscan, now part of Kroll, pairs a large penetration testing practitioner organisation with Kroll's PCI QSA practice, incident response, and forensics business. For a merchant that wants its penetration testing, its QSA-led Report on Compliance, and its breach-response retainer under one supplier at enterprise scale, the Kroll relationship is the draw.

Trade-off: Kroll is US-headquartered, and the engagement model leans enterprise. Pricing on application.

5. JUMPSEC

Best for: Merchants with public-sector-adjacent systems or an NCSC CHECK requirement alongside PCI testing

JUMPSEC holds NCSC CHECK status alongside CREST membership, with a strong red teaming and adversary-simulation practice. For a merchant with PSN-connected or government-adjacent systems that mandate CHECK delivery in addition to Requirement 11.4 penetration testing, that combination is the differentiator.

Trade-off: No PCI-specific ASV or QSA capability is published. Pricing on application.

6. OnSecurity

Best for: Smaller merchants wanting a fast, platform-led annual Requirement 11.4 test

OnSecurity runs a platform-first, pentest-as-a-service model with instant online quoting and quick scheduling. For a smaller merchant that needs its annual Requirement 11.4 test booked this week with minimal procurement friction ahead of an acquirer deadline, the platform model works well.

Trade-off: Quotes are generated through the platform rather than published as a rate card, and the model suits smaller, repeatable scopes rather than a full CDE programme.

7. Bulletproof

Best for: Smaller merchants wanting testing and wider compliance support on one contract

Bulletproof combines penetration testing with a broad compliance practice, including Cyber Essentials, ISO 27001, and PCI DSS support, which suits a smaller merchant that wants testing and wider compliance handled by a single supplier.

Trade-off: A generalist breadth play rather than a testing specialist, and PCI-specific QSA status is not published. Pricing on application.

Methodology

How we ranked them for PCI DSS

Six criteria that matter specifically to a merchant buying PCI penetration testing and ASV scanning, each something you can verify without taking anyone's word for it. Weighting is ours; the facts are checkable.

Meets PCI DSS Requirement 11.4

Whether the provider tests the CDE from external and internal perspectives and validates segmentation controls, not just runs a network scan. Requirement 11.4 needs all three: external, internal, and segmentation testing.

ASV scanning capability for Requirement 11.3

Whether the provider holds or can deliver Approved Scanning Vendor status for the quarterly external vulnerability scan. Not every CREST pentest firm runs an ASV service.

Verifiable CREST accreditation

Company and individual CREST accreditation, checkable in the public directory. It is the accreditation most UK QSAs and acquiring banks recognise on a penetration testing supplier.

Retest included

Whether verification of your fixes, including segmentation remediation, is included or sold back as a second engagement. Your QSA and acquirer need remediation evidence, and paying twice for it is avoidable.

Reporting your QSA and acquirer will accept

Whether the report maps findings to specific PCI DSS requirements and CDE components in a format your QSA or acquiring bank will accept as evidence, not raw scanner output.

Scoping that gets your CDE right

Whether the provider correctly scopes your cardholder data environment before testing, including connected-to and security-impacting systems merchants commonly exclude by mistake.

Buyer Beware

Red flags for a
PCI DSS buyer

Whichever firm you choose, including us, walk away if you see these.

A "PCI pentest" that skips segmentation testing

Requirement 11.4 needs external, internal, and segmentation testing together. Ask explicitly whether segmentation testing is included, and ask to see it named in the scope, not assumed.

A vulnerability scan sold as a penetration test

PCI DSS needs both a scan (Requirement 11.3) and a penetration test (Requirement 11.4), delivered separately. Ask how many days of manual testing, by whom, with what certifications, before you accept a scan report as your 11.4 evidence.

No ASV for the quarterly scan requirement

Requirement 11.3 specifically requires an Approved Scanning Vendor. Confirm the provider holds ASV status, or is transparent about which partner runs that scan, before you commit.

POA pricing under an acquirer deadline

A firm that cannot indicate a day rate before a discovery call adds procurement drag when you are working to an acquirer or QSA-driven timeline. UK CREST day rates run £1,000 to £1,500.

No retest to evidence segmentation fixes

A test without verification of your fixes is half a service. If the retest is a separate paid engagement, your segmentation remediation evidence for the QSA costs double.

A provider that blurs QSA assessment with penetration testing

Know which you are buying. A CREST-accredited penetration testing firm is not a QSA, and a QSA-led Report on Compliance is not a substitute for Requirement 11.4 testing.

What It Costs

PCI penetration testing and ASV prices

CREST-accredited testing runs £1,000 to £1,500 per consultant day. At Precursor's published rate of approximately £1,200 per day: external network from £2,500, web application from £3,750, internal network (with segmentation testing) from £6,250, and full CDE assessments from £10,000. ASV scanning for the quarterly Requirement 11.3 scan is quoted alongside your annual testing. Full pricing by merchant level is on the PCI DSS compliance testing page.

Full cost guide with worked examples
External networkFrom £2,500
Web applicationFrom £3,750
Internal networkFrom £6,250
Full assessmentFrom £10,000
Make It a Fair Fight

Compare us against anyone on this list.

UK-based, DBS-checked testers. Fixed pricing published before you call. A written quote within 24 hours of scoping. Retest included.

CREST Triple Accredited|Fixed Price Quotes|Free Scoping Call|UK Based Team
FAQs

Penetration testing for PCI DSS

The questions merchants ask most when comparing UK providers for PCI DSS testing.

UK PCI DSS penetration testing runs from £2,500 for a single external CDE test to £15,000 or more for a full external, internal, and segmentation testing programme, at roughly £1,000 to £1,500 per consultant day from a CREST-accredited provider. ASV scanning for the quarterly Requirement 11.3 scan is typically quoted alongside, adding a smaller recurring cost across the four scan cycles. Most firms price on application; Precursor publishes its rates, starting from £2,500. Full pricing by merchant level is set out on our PCI DSS compliance testing page.

PCI DSS Requirement 11.4 requires external and internal penetration testing of the cardholder data environment (CDE) at least annually and after any significant change, plus segmentation testing to confirm the controls separating the CDE from the rest of the network actually hold. Requirement 11.3 separately requires quarterly external vulnerability scanning by an Approved Scanning Vendor (ASV). The two are not interchangeable: a scan satisfies 11.3, a penetration test satisfies 11.4, and most merchants need both.

An ASV scan is quarterly automated vulnerability scanning of external-facing CDE systems by a PCI SSC-approved vendor, required under Requirement 11.3, checking for known vulnerabilities and misconfigurations. A PCI penetration test is annual manual testing under Requirement 11.4 that attempts to exploit vulnerabilities and bypass segmentation controls, covering both external and internal perspectives. ASV scanning is continuous compliance monitoring; penetration testing validates real-world exploitability. PCI DSS requires both, from providers holding the relevant accreditation for each.

Yes, if you need a full PCI DSS assessment and Report on Compliance. That work is done by a Qualified Security Assessor (QSA), a role distinct from penetration testing. Requirement 11.4 penetration testing and Requirement 11.3 ASV scanning are a separate, CREST-accredited capability that a firm like Precursor provides as technical testing evidence; your QSA then uses that evidence within their assessment. A Level 1 merchant needing a mandatory Report on Compliance needs both a QSA and a CREST penetration testing provider; a smaller merchant completing a Self-Assessment Questionnaire may only need the testing.

UK merchants commonly shortlist a mix of specialists and larger consultancies. This guide compares seven: Precursor Security, NCC Group, Pen Test Partners, Redscan (Kroll), JUMPSEC, OnSecurity, and Bulletproof. The right choice depends on whether the firm holds ASV or QSA credentials alongside CREST accreditation, whether pricing is published, whether a retest is included for your remediation evidence, and whether the report format satisfies your QSA and acquiring bank. Confirm any CREST accreditation in the public directory at crest-approved.org and any ASV status in the PCI Security Standards Council's approved vendor list.