Thank you
Our team of industry domain experts combined with our guaranteed SLAs, our world class technology .
Get Immediate Help
London businesses can choose from specialist boutiques, larger managed security providers and platform-based testing services. This guide compares ten CREST or CHECK-accredited penetration testing companies in London on testing depth, accreditation, reporting and retesting, so you can match a provider to your actual scope rather than picking the first name you find.
Use these five points as a filter, then read the profiles that follow for the details behind them.
This guide compares ten penetration testing companies in London based on technical expertise, service coverage, assurance credentials, reporting and retesting. Each entry reflects publicly available information current as of July 2026, gathered directly from CREST's own accreditation records, Companies House filings and each provider's service pages rather than aggregator sites.
Microminder publishes this article and appears first in the list. Every other provider was assessed using the same criteria, and we have disclosed that fact so you can weigh our recommendations accordingly. If you already know your scope, jump to the comparison table below. If you want the fundamentals first, the next two sections cover what penetration testing involves and the specific types of tests available in London.
A typical engagement moves through several stages. Scoping and rules of engagement come first, followed by reconnaissance, then active testing and validation, impact analysis, reporting, a remediation discussion and finally a retest. Every stage should happen within an agreed scope and under written authorisation. A tester who cannot explain their rules of engagement before starting work is not one you should hire.
| Company | Best For | London Presence | Main Testing Services | Key Accreditations | Retesting |
| Microminder Cyber Security | Combined IT and OT testing plus wider managed security | Stanmore, Greater London office | Web, API, infrastructure, cloud, mobile, wireless, social engineering, red team, source code, IoT/OT | CREST, ISO 27001 | Available, confirm scope |
| Redscan, A Kroll Business | Enterprise buyers wanting pentest and incident response together | London headquartered, part of the global Kroll network | Network, web app, cloud, mobile, API, social engineering, red teaming, wireless | CREST, ISO 27001, Cyber Essentials Plus | Included, confirm window |
| JUMPSEC | Threat-led testing and public sector CHECK work | Acton, West London | Network, application, cloud, threat-led testing, physical, AI system testing | CREST, NCSC CHECK, ISO 9001, ISO 27001, Cyber Essentials Plus | Available, confirm scope |
| SECFORCE | Financial services need CBEST and TIBER-aligned testing | Canary Wharf, London | Web, mobile, infrastructure, cloud, IoT, red and purple teaming, source code review | CREST, CBEST aligned, ISO 27001, ISO 9001 | Available, confirm terms |
| Precursor Security | Fixed pricing and a live findings portal | London office alongside Leeds headquarters | Web, network, cloud penetration testing, managed SOC | CREST (pentest, vulnerability assessment, SOC) | Requestable mid engagement |
| Pentest Limited | PCI DSS-driven compliance testing | Registered office in London (Shearwater Group plc) | Web, mobile, internal and external infrastructure, cloud, wifi, IoT, ICS/SCADA | CREST, ISO 27001, Cyber Essentials Plus, PCI DSS | Available, confirm scope |
| EJN Labs | AI and LLM system testing, fintech and law firm sectors | Canary Wharf, London | Web, API, mobile, external infrastructure, AI/LLM testing, bug bounty management | CREST | Free retest advertised, confirm terms |
| Teceze | Pentest bundled with global managed IT | London headquartered, with offices across multiple countries | External and managed penetration testing, broader IT and cybersecurity | CREST | Confirm scope |
| Akita | SMEs wanting a pentest with ISO 27001 and Cyber Essentials consultancy | London office | Penetration testing, vulnerability scanning, phishing simulation | CREST, ISO 9001, ISO 27001, Cyber Essentials Plus assessor | Confirm scope |
| Stripe OLT | Microsoft heavy environments want pentest plus SOC | 29 High Holborn, London office | Web, infrastructure, cloud, mobile, wireless, network | CREST, ISO 27001 | Confirm scope |
We have deliberately left star ratings out of this table. None of the review counts we found across these providers could be independently verified against the underlying review platform at the time of writing, so including them would have meant repeating marketing claims rather than checking evidence.
For London relevance, we included firms headquartered in London, firms with a genuine established London office, and firms that regularly deliver on site or remote testing to London organisations. We excluded providers that only claimed London relevance through serving UK clients remotely without any physical presence in the city.
Microminder publishes this article and appears first in the comparison. Every other provider was assessed using the same publicly available criteria, and their inclusion here is not paid placement.

Provider type: Penetration testing consultancy and wider managed cybersecurity provider.
Best for: Organisations that need testing across applications, APIs, infrastructure, cloud, mobile, IoT and OT alongside broader security services.
Microminder holds CREST accreditation for penetration testing and ISO 27001 certification, operating from an office in Stanmore, Greater London, alongside international offices in the UAE, Saudi Arabia, South Africa, India and Ireland. The service catalogue covers most of what a London buyer would need from a single provider:
What stands out is the combination of offensive testing with defensive services under one provider, including managed detection and response and compliance consulting. That breadth suits buyers who want a single point of contact rather than coordinating separately with a pentest firm and a SOC provider. However, it also means you should confirm which specific tests are delivered by Microminder's own team versus a subcontracted partner before signing.
Before engaging, confirm which tester will lead your engagement, whether retesting is included in the quoted price, and whether on-site delivery in London is required for your scope.
.webp)
Provider type: Managed security provider combining CREST-accredited penetration testing with incident response.
Best for: Enterprise and mid-market buyers seeking testing evidence and 24/7 threat monitoring from a single provider.
Redscan was founded in London in 2002 and remains headquartered there, now operating as part of Kroll following a 2021 acquisition. The firm holds CREST accreditation, ISO 27001 certification and Cyber Essentials Plus status. Testing covers network, web application, cloud, mobile, and API penetration testing, social engineering, wireless assessments, and red teaming, delivered by testers holding CREST, OSCP, and GIAC certifications.
The main draw is scale, combined with a genuine incident response bench through Kroll. If a test uncovers something serious, the same organisation can bring in forensic and breach-response capabilities without engaging a second vendor. That said, buyers wanting a boutique, senior-led engagement may find the experience feels more corporate than a smaller specialist consultancy.
Ask specifically who on the team will run your test, since Kroll's global scale means engagements can be staffed from different offices depending on demand.
.webp)
Provider type: Threat-led offensive security consultancy with CHECK approval for government work.
Best for: Organisations needing threat intelligence-driven testing, public sector CHECK engagements, or early-stage AI system testing.
JUMPSEC operates from Acton in West London and holds CREST certification for penetration testing, vulnerability assessment, intelligence-led testing and SOC services, plus NCSC CHECK approval for government and public sector work, ISO 9001, ISO 27001 and Cyber Essentials Plus. Testing covers network infrastructure, web applications, cloud environments including AWS, Azure and Microsoft 365, threat-led testing, AI penetration testing for LLM systems, and physical penetration testing.
The threat-led approach means engagements are shaped around what an actual attacker targeting your sector would realistically attempt, rather than a generic checklist. That suits organisations with a defined threat profile, such as finance or government. It suits a smaller business less well, simply looking for a straightforward compliance test, where learner engagement elsewhere may be more cost-effective.
Confirm whether your engagement actually needs CHECK accreditation, since that only applies to public sector and CNI systems.

Provider type: Boutique offensive security consultancy specialising in manual, expert-led assessments.
Best for: Financial services needing CBEST or TIBER-aligned threat-led testing with senior tester continuity.
SECFORCE is headquartered in Canary Wharf, London, and holds CREST accreditation alongside ISO 27001 and ISO 9001 certification. Services include web, mobile, infrastructure, cloud and IoT penetration testing, red and purple teaming, source code review and configuration review, with particular depth in adversary simulation aligned to the Bank of England's CBEST framework and the EU's TIBER programme.
The boutique structure means fewer, more senior consultants running each engagement rather than a large rotating bench, which typically means stronger continuity across scoping, testing and retesting. This suits complex, high-stakes environments where trusted testers matter. It suits a buyer wanting the fastest turnaround for a simple, low-complexity web app test, where this specialism may come at a premium.
Ask directly whether your engagement actually requires CBEST or TIBER alignment, since that framework applies only to institutions designated by the Bank of England.

Provider type: CREST-accredited testing and managed SOC provider with a live findings portal.
Best for: Buyers wanting transparent fixed pricing and the ability to request retests mid-engagement.
Precursor Security is headquartered in Leeds and maintains a London office, as well as locations in Newcastle and Edinburgh. The firm holds CREST accreditation across penetration testing, vulnerability assessment and SOC services, a combination held by fewer than 70 organisations globally according to CREST's own figures. Services include web, network and cloud penetration testing, alongside 24/7 managed SOC and MDR.
The standout feature is a portal that provides live updates as testers uncover findings and allows clients to request retests during the engagement, rather than only after the final report. Fixed pricing starting from £2,500 also gives smaller buyers a clearer budget than the "contact for pricing" model many larger firms use. However, London delivery runs from a regional office rather than a dedicated headquarters, so confirm on-site availability if that matters.
Ask whether your engagement needs the full triple CREST combination or just penetration testing, since bundling SOC services unnecessarily affects price.

Provider type: CREST-accredited testing firm with a strong compliance and PCI DSS focus.
Best for: Organisations needing testing evidence specifically for PCI DSS, ISO 27001 or Cyber Essentials Plus audits.
Pentest Limited is registered in London and operates as part of the publicly listed Shearwater Group plc. The firm holds CREST accreditation and delivers web, mobile, internal and external infrastructure, cloud, wifi, IoT and ICS/SCADA testing, alongside dedicated PCI DSS penetration testing and broader compliance work.
Being part of a listed group gives Pentest Limited a level of corporate transparency, including published financials and governance structures, that smaller private consultancies cannot always match. That matters if your compliance team needs to vet a supplier before procurement. The trade-off is that engagements can feel more process-heavy than at a leaner boutique, so a business running a single quick test may find onboarding slower than expected.
Confirm exactly which compliance framework your report needs to satisfy before scoping, since a PCI DSS test and a general ISO 27001 supporting test are not scoped identically.

Provider type: CREST-certified consultancy specialising in AI and LLM system testing.
Best for: Fintech firms, law firms, and businesses deploying AI products that need testing aligned with established LLM security guidance.
EJN Labs operates from Canary Wharf, London, and holds CREST certification. Services span web, API and mobile application testing, external infrastructure testing, AI and LLM penetration testing, and managed bug bounty programmes, with sector offerings for fintech firms needing FCA-aligned evidence and law firms needing SRA Cyber Standard alignment. Their AI testing work references OWASP's Top 10 for LLM Applications, the closest thing this young field has to an established standard.
As a newer, more specialised firm, EJN Labs fills a gap that larger generalist providers on this list do not cover in the same depth, namely testing for AI products and machine learning pipelines rather than only traditional web and infrastructure targets. That specialism suits any business building on LLMs today. It suits an organisation less well that wants decades of track record behind their supplier, since EJN Labs is considerably newer than firms like SECFORCE or Pentest Limited.
Ask for a sample AI-focused report and confirm exactly which vulnerability categories your engagement will cover before agreeing on the scope.

Provider type: Global managed IT provider offering CREST-certified penetration testing as one service among many.
Best for: Businesses wanting penetration testing bundled with broader managed IT support.
Teceze is headquartered in London and holds CREST certification for its testing services, delivered by consultants with CISM, GIAC, CEH, and CISA certifications. Testing covers external network penetration testing built on OSSTMM methodology, alongside managed penetration testing and a wide catalogue of broader IT services across offices in the UK, US, India and beyond.
Teceze suits organisations already using them, or considering them, for wider managed IT support who want one supplier rather than juggling a specialist testing firm alongside a separate IT provider. It suits a business less well that specifically wants a specialist offensive security firm as its sole focus, since penetration testing sits within a much larger service catalogue here.
Confirm which specific tester certifications will be assigned to your engagement, since a firm this broad in scope can vary in testing depth depending on which team picks up your project.

Provider type: Managed IT and cybersecurity provider bundling penetration testing with ISO 27001 and Cyber Essentials consultancy.
Best for: SMEs wanting a single London-based partner for testing, compliance consultancy and day-to-day IT support.
Akita operates from London, holds CREST accreditation for penetration testing, and holds ISO 9001 and ISO 27001 certifications, and works as a Cyber Essentials Plus assessor. Beyond testing itself, the firm offers vulnerability scanning, phishing simulation, ISO 27001 consultancy and core managed IT services, making it more of an MSP with a strong security division than a dedicated offensive security specialist.
This suits smaller businesses that want their pentest, Cyber Essentials certification, and day-to-day IT support handled by one relationship rather than three. It suits less well an enterprise seeking a specialist consultancy focused solely on offensive testing at scale, where a boutique like SECFORCE or an enterprise player like Redscan may be a better fit.
Ask which team member holds the CREST qualification actually running your test, and confirm whether Akita or a named subcontractor performs the assessment.

Provider type: Managed cybersecurity and IT support provider with CREST-certified testing and an in-house SOC.
Best for: Microsoft-heavy environments wanting penetration testing alongside 24/7 monitoring.
Stripe OLT holds a London office at 29 High Holborn alongside its Bristol headquarters and a Manchester office, and became part of the Littlefish Group in 2026. The firm holds CREST certification for penetration testing and ISO 27001 certification, with particular depth in Microsoft 365, Azure and hybrid cloud environments as a Microsoft security solutions partner. Testing covers web, infrastructure, cloud, mobile, wireless and network penetration testing.
The Microsoft specialism is the differentiator here. If your environment runs heavily on Microsoft's stack, Stripe OLT's testers already understand the configuration quirks that generic testers sometimes miss. That focus suits Microsoft-centric mid-market businesses well. It suits an organisation running a predominantly AWS or GCP environment, where a cloud-agnostic provider may have more relevant experience.
Confirm whether your engagement will be delivered directly from the London office or coordinated remotely from Bristol, as this affects on-site availability.
Check both the company and the individual tester's accreditations properly. CREST company status and NCSC CHECK status, where relevant, are the two most useful signals, alongside individual credentials such as OSCP, CREST CRT or CCT, and GIAC qualifications. Ask how much of the engagement involves manual testing, business logic analysis and exploit validation versus automated scanning, and avoid providers that cannot explain what happens beyond scanner output.
Review the reporting process before you sign anything. Ask for a sample report, and check that it includes an executive summary, technical evidence, a severity methodology, business impact context and clear remediation guidance. Then clarify retesting specifically: whether it is included, how many findings can be retested, the permitted retest window, and whether a revised report is issued afterwards. Finally, confirm how the provider handles data, including where evidence is stored, when it is deleted, and whether subcontractors are used on your engagement.
| Model | Best For | Main Strength | Main Limitation |
| Traditional penetration test | Formal assessment and audit evidence | Defined scope and report | Point in time |
| PTaaS | Recurring testing and remediation workflows | Faster collaboration and tracking | Quality still depends on the testers |
| Continuous penetration testing | Frequently changing environments | Ongoing assurance | Higher operational commitment |
| Bug bounty | Mature programmes seeking broad researcher coverage | Continuous external discovery | Not always a formal pentest replacement |
A traditional test usually provides a defined scope and a formal report suitable for audit evidence. PTaaS adds platform-based collaboration and recurring testing cycles, which suits businesses shipping code frequently. Bug bounty programmes provide broader researcher coverage but generally cannot replace the formal, scoped evidence that regulators and auditors expect.
Do not accept vague answers to any of these. A provider confident in their process should be able to answer all eight without hesitation.
| London provider | National or global provider |
| Easier in-person scoping | Wider specialist bench |
| Convenient on-site testing | Multi-region delivery |
| Local time zone alignment | Larger testing programmes |
| Stronger local relationships | Broader compliance coverage |
| Potentially more personalised | Greater enterprise procurement capacity |
A London-based boutique like SECFORCE or EJN Labs can offer closer scoping conversations and easier on-site access. A larger national or global provider like Kroll's Redscan brings a wider bench and broader compliance coverage for multi-region businesses. Neither is automatically the better choice. It depends on whether your priority is relationship continuity or scale.
Microminder provides CREST-accredited penetration testing services across applications, infrastructure, cloud and mobile. Speak with the team to scope the right assessment for your organisation.
Don’t Let Cyber Attacks Ruin Your Business
Call
UK: +44 (0)20 3336 7200
KSA: +966 1351 81844
UAE: +971 454 01252
Contents
To keep up with innovation in IT & OT security, subscribe to our newsletter
Recent Posts
Cyber Compliance | 21/08/2026
Penetration Testing | 21/08/2026
Cyber Threats | 21/08/2026
What are the best penetration testing companies in London?
The best choice depends on your scope, industry, required accreditation, reporting and retesting needs, not a single fixed ranking.How do I choose a penetration testing company in London?
Check relevant expertise, CREST or CHECK status, manual testing depth, sample reports and remediation support.How much does penetration testing cost in London?
Cost depends on scope, complexity, testing days, access level, reporting and retesting, so ask for a fixed quote after scoping.What penetration testing services are available in London?
Web, API, infrastructure, cloud, mobile, wireless, social engineering, red teaming, IoT and OT testing are all available.Should a penetration testing company be CREST-accredited?
CREST gives useful assurance of process and technical standards, though exact requirements depend on your engagement and sector.When is an NCSC CHECK provider required?
CHECK applies specifically to authorised testing of UK public sector and critical national infrastructure systems and networks.Is penetration testing the same as vulnerability scanning?
No. Scanning automatically finds known weaknesses, while penetration testing manually validates and exploits risks.Is retesting normally included?
Policies vary by provider, so confirm retesting terms and any time limits before you sign the engagement.Can penetration testing be performed remotely?
Web, API, external infrastructure and cloud testing are often remote, while internal, wireless and physical work may need on-site access.What should a penetration test report include?
Executive summary, scope, methodology, evidence, severity ratings, business impact, remediation guidance and retest results.