A penetration test is a controlled attack on your systems by a qualified tester, who reports what they could get into and how to fix it. In the UAE, published 2026 price guides put a single web application test at roughly AED 8,000 to 25,000, and a combined test for a mid-size business at roughly AED 35,000 to 90,000. You probably need one if a regulator, auditor, insurer or client has asked for it, you hold sensitive data, or you have never had one.
A qualified security tester (an “ethical hacker”, though they rarely wear the hoodie) tries to get into your systems the same way an attacker would. They look for weak passwords, unpatched software, badly configured cloud accounts, open doors in your network and gaps in your website or app.
The difference between them and a criminal is that they have your permission, they stop when they find something, and they write it all down. You get a report that says what they found, how serious it is and how to fix it.
This is where a lot of businesses get caught out.
If someone quotes you a “pen test” for a few thousand dirhams and it’s done in an afternoon, you’re probably buying a scan with a nicer cover page.
| Type | What it tests | Good for |
|---|---|---|
| External network | Everything visible from the internet: firewalls, remote access, email servers | Every business with an internet connection (so, every business) |
| Internal network | What an attacker could do once inside, for example through a phished laptop | Offices with shared servers, file shares or sensitive data |
| Web application | Your website, client portal or booking system | Anyone taking logins, payments or personal data online |
| Cloud | Microsoft 365, Azure, AWS or Google settings | Businesses that moved everything to the cloud and assumed it was secure by default |
| Social engineering | Your people: phishing emails, phone calls, tailgating at reception | Everyone, because people click things |
Prices vary with scope. Published 2026 guides from UAE providers put typical ranges at roughly:
| Test | Typical range (AED) |
|---|---|
| Single web application | 8,000 to 25,000 |
| External network | 12,000 to 35,000 |
| Internal network | 18,000 to 50,000 |
| Cloud account | 15,000 to 40,000 |
| Combined test, mid-size business | 35,000 to 90,000 |
What pushes the price up: the number of systems, apps and user roles in scope; compliance-specific reporting; how senior and certified the testers are; and whether a retest is included after you fix things. Always ask for the retest. Otherwise you’re trusting that the fix worked.
A rule of thumb: anything under about AED 5,000 is very unlikely to include proper manual testing.
You almost certainly do if any of these are true:
You can probably start smaller if you’re a small team with no servers, everything in Microsoft 365 and no customer-facing systems. A configuration review of Microsoft 365 and a vulnerability scan may be the sensible first step. A good provider will tell you that, even though it’s a smaller invoice.
At least once a year, and after any significant change. Attackers don’t send a calendar invite, but annual testing at least means you’re not relying on last decade’s results.
Cre8 IT arranges independent penetration testing for businesses across the UAE, KSA and UK. We’re ISO 27001 certified, so we’ve sat on the receiving end of an audit and know what useful findings look like. We also help you fix what’s found, so the report doesn’t just sit in someone’s inbox looking worried.
Not sure which test you need, or whether you need one at all? Book a free 30-minute consultation and we’ll give you an honest answer.
Last reviewed 7 October 2026. Prices are indicative ranges from published third-party guides, not a quote. Ask us for a fixed price based on your scope.
A single web application test typically takes around 5 to 8 working days of testing plus a few days for the report. Larger, multi-part engagements can take 3 to 6 weeks.
VAPT stands for vulnerability assessment and penetration testing. It combines an automated scan of known weaknesses with manual testing by a person, and it is the term many UAE providers and regulators use.
It should not. A good tester agrees the scope, timing and rules in advance, avoids anything that could take systems down, and can test out of hours if needed.
ISO 27001 does not name penetration testing as mandatory, but it does require you to manage technical vulnerabilities. Regular testing is one of the most common ways to show an auditor you are doing that.
