Insights · Cyber security

What is a penetration test, what does it cost in the UAE, and do you need one?

A penetration test is when you pay someone to break into your business so a criminal doesn’t do it for free. Here’s what it involves, what it costs in the UAE, and how to avoid paying for a very expensive PDF that nobody reads. See also our cyber security services.
The short answer

A penetration test is a controlled attack on your systems by a qualified tester, who reports what they could get into and how to fix it. In the UAE, published 2026 price guides put a single web application test at roughly AED 8,000 to 25,000, and a combined test for a mid-size business at roughly AED 35,000 to 90,000. You probably need one if a regulator, auditor, insurer or client has asked for it, you hold sensitive data, or you have never had one.

Key points
  • A vulnerability scan is automated. A pen test is a person thinking like an attacker.
  • Anything under about AED 5,000 is unlikely to include proper manual testing.
  • Test at least once a year and after any major change.
  • Always ask for a retest after you fix what was found.

What a pen test actually is

A qualified security tester (an “ethical hacker”, though they rarely wear the hoodie) tries to get into your systems the same way an attacker would. They look for weak passwords, unpatched software, badly configured cloud accounts, open doors in your network and gaps in your website or app.

The difference between them and a criminal is that they have your permission, they stop when they find something, and they write it all down. You get a report that says what they found, how serious it is and how to fix it.

Pen test vs vulnerability scan: not the same thing

This is where a lot of businesses get caught out.

  • A vulnerability scan is automated software that checks your systems against a list of known problems. It’s quick, cheap and useful. It’s also a bit like a smoke alarm: it tells you something might be wrong, not how bad it is.
  • A penetration test is a person thinking like an attacker. They chain small weaknesses together, test how your systems actually behave, and try things a scanner wouldn’t.

If someone quotes you a “pen test” for a few thousand dirhams and it’s done in an afternoon, you’re probably buying a scan with a nicer cover page.

The main types of penetration test

TypeWhat it testsGood for
External networkEverything visible from the internet: firewalls, remote access, email serversEvery business with an internet connection (so, every business)
Internal networkWhat an attacker could do once inside, for example through a phished laptopOffices with shared servers, file shares or sensitive data
Web applicationYour website, client portal or booking systemAnyone taking logins, payments or personal data online
CloudMicrosoft 365, Azure, AWS or Google settingsBusinesses that moved everything to the cloud and assumed it was secure by default
Social engineeringYour people: phishing emails, phone calls, tailgating at receptionEveryone, because people click things

What a pen test costs in the UAE

Prices vary with scope. Published 2026 guides from UAE providers put typical ranges at roughly:

TestTypical range (AED)
Single web application8,000 to 25,000
External network12,000 to 35,000
Internal network18,000 to 50,000
Cloud account15,000 to 40,000
Combined test, mid-size business35,000 to 90,000

What pushes the price up: the number of systems, apps and user roles in scope; compliance-specific reporting; how senior and certified the testers are; and whether a retest is included after you fix things. Always ask for the retest. Otherwise you’re trusting that the fix worked.

A rule of thumb: anything under about AED 5,000 is very unlikely to include proper manual testing.

Do you actually need one?

You almost certainly do if any of these are true:

  • A regulator, auditor or insurer has asked for one. In which case, “need” is doing a lot of work.
  • You’re working towards ISO 27001 or a similar standard.
  • A large client has sent you a security questionnaire asking when your last pen test was.
  • You store client financial, health or personal data.
  • You’ve had a major change: a new office, a move to the cloud, a new website or portal.
  • You’ve never had one. Ever.

You can probably start smaller if you’re a small team with no servers, everything in Microsoft 365 and no customer-facing systems. A configuration review of Microsoft 365 and a vulnerability scan may be the sensible first step. A good provider will tell you that, even though it’s a smaller invoice.

How often should you test?

At least once a year, and after any significant change. Attackers don’t send a calendar invite, but annual testing at least means you’re not relying on last decade’s results.

Five questions to ask before you book

  1. Is the testing manual, automated, or both?
  2. Who are the testers, and what certifications do they hold (for example OSCP or CREST)?
  3. What exactly is in scope, and what isn’t?
  4. Will the report explain fixes in plain English for management, not just in technical detail?
  5. Is a retest included?

The bit where we mention ourselves

Cre8 IT arranges independent penetration testing for businesses across the UAE, KSA and UK. We’re ISO 27001 certified, so we’ve sat on the receiving end of an audit and know what useful findings look like. We also help you fix what’s found, so the report doesn’t just sit in someone’s inbox looking worried.

Not sure which test you need, or whether you need one at all? Book a free 30-minute consultation and we’ll give you an honest answer.

Sources and further reading

Last reviewed 7 October 2026. Prices are indicative ranges from published third-party guides, not a quote. Ask us for a fixed price based on your scope.

Written by
CEO, Cre8 IT
Rob Crossley is CEO of Cre8 IT, a Dubai-born managed IT and cyber security company that has supported businesses across the UAE, Saudi Arabia and the UK since 2012. Cre8 IT is certified to ISO 27001:2022 and ISO 9001 and is a certified Microsoft Partner.
FAQ

Frequently asked questions

How long does a penetration test take?

A single web application test typically takes around 5 to 8 working days of testing plus a few days for the report. Larger, multi-part engagements can take 3 to 6 weeks.

What is VAPT?

VAPT stands for vulnerability assessment and penetration testing. It combines an automated scan of known weaknesses with manual testing by a person, and it is the term many UAE providers and regulators use.

Will a pen test disrupt our business?

It should not. A good tester agrees the scope, timing and rules in advance, avoids anything that could take systems down, and can test out of hours if needed.

Do we need a pen test for ISO 27001?

ISO 27001 does not name penetration testing as mandatory, but it does require you to manage technical vulnerabilities. Regular testing is one of the most common ways to show an auditor you are doing that.

Related guides

Keep reading

Each guide links to the regulator’s own text and shows when it was last reviewed.
Choosing a provider

How to choose an IT company in Dubai: 10 questions to ask before you sign

From SLAs and customer portals to backups and certification: the questions a good IT company will answer without flinching.
6 min read · Reviewed 7 October 2026
ISO 27001

ISO 27001 for financial firms: how it supports DFSA and FSRA expectations

What ISO 27001 certification involves and how it maps to what regulators in DIFC and ADGM expect.
4 min read · Reviewed 19 September 2026
Cyber Essentials

Cyber Essentials for UAE firms: what it is and when it is worth it

The UK baseline security certification, and when it makes sense for a business in the UAE.
4 min read · Reviewed 19 September 2026

Not sure which test you need?

Tell us what you run and who is asking for the test. We will recommend the right scope, or tell you if a scan is enough for now.