Published price ranges put red teaming in Poland at PLN 24,500 to over PLN 100,000, rising to hundreds of thousands of złoty for large financial institutions. A commercial engagement takes 2-3 to 16 weeks depending on the source, while in a TLPT under DORA the active attack phase alone lasts at least 12 weeks.
We collected the prices that firms in Poland, the US, the UK and the EU publish online, plus contract award notices from public tenders. Each figure comes with its source, the page date (where given) and the date we checked it: September 24, 2026. You will also find TLPT timelines under Delegated Regulation (EU) 2025/1190 and TIBER-EU, the DORA Article 27 tester requirements and questions for an apples-to-apples comparison of proposals. We do not publish our own prices, because we price every engagement around a specific objective.
TL;DR - Key takeaways
- Pentesting, red teaming and TLPT need separate budgets; the TLPT attack phase alone takes 12+ weeks
- Red teaming cost is driven by time, objectives and attack vectors
- How much does red teaming cost in Poland? Ranges start at PLN 24,500
- Abroad, red teaming starts at €10,000, £15,000 or $20,000
Pentesting, red teaming and TLPT need separate budgets; the TLPT attack phase alone takes 12+ weeks
Pentests, red teaming and TLPT are priced on a different basis, so each needs its own budget line. A penetration test is priced by scope: the number of hosts, applications or APIs, which is why pentest price lists show “starting at” prices. Red teaming price lists usually say “custom quote.” REXNET does exactly that, and Pentestica publishes a range with the same caveat.
A pentest answers one question: what vulnerabilities does this system have? An attack simulation, or red teaming, tests whether your defense team will detect and stop an attacker working toward a specific objective, such as the domain controller or a payment system. That takes weeks of team effort.
TLPT is red teaming carried out under DORA and Delegated Regulation 2025/1190 (the RTS), with a mandatory external threat intelligence provider, a control team on the institution's side, supervisory oversight and an active testing phase of at least 12 weeks. The only Polish TLPT range with both a floor and a ceiling that we found is PLN 172,000-345,000, on Pentestica's website. That is roughly seven times the bottom of its red teaming range.
Red teaming cost is driven by time, objectives and attack vectors
The price of red teaming depends above all on person-days, and those are set by the objectives and entry vectors. Breach Craft says plainly that duration and the number of objectives drive the price, not the size of the environment. Redbot Security adds stealth requirements, detection validation and enterprise scale. The factors below move a quote the most.
- Time and team. According to clev.one, expert day rates at established Polish firms in 2026 run from PLN 2,000 to over PLN 3,500 net (excluding VAT), so every 10 person-days costs PLN 20,000 to over 35,000 net. In the UK, CREST-certified testers charge £1,100-1,400 a day (EJN Labs); in Germany, certified testers charge €1,200-2,000 (Boddenberg).
- Number of objectives. Reaching one flag, such as the board's mailbox, takes less work than three flags in different network segments.
- Social engineering. Phishing, vishing and a call to the help desk are a separate vector. For scale: Pentestica adds PLN 2,000-4,000 to a pentest for social engineering and phishing, and clev.one prices a targeted spear-phishing campaign with a report from around PLN 4,000-5,000 net.
- Physical testing. Getting into the office takes people on site and separate safety rules. EJN Labs includes it in its focused exercise, and Boddenberg cites physical elements, threat intelligence and long duration as the reasons for prices of €80,000 and up.
- Assumed breach vs. full scope. An assumed breach test starts from an agreed foothold in your network, such as a compromised workstation or an employee account, so you do not pay for external reconnaissance and initial access. Full scope covers the whole attack chain from the outside.
- Threat intelligence. A scenario built on threat analysis for your industry costs more than a generic one. EJN Labs quotes up to £75,000 and more for threat-intelligence-led red teaming (STAR, TIBER-UK). We show how such a scenario is built in our article on APT emulation with MITRE ATT&CK.
- Purple teaming. Joint sessions with your SOC during or after the test. Compass IT Compliance prices them separately at $10,000-20,000 — the only source we found that does.
- Report and retest. An attack timeline with detection points takes more work than a vulnerability list. None of the sources we checked says whether red teaming includes a retest, so ask.
- Effort on your side. Boddenberg estimates 10-15 person-days on the client side for a red team campaign. They never appear on the provider's invoice, but they tie up your team.
How much does red teaming cost in Poland? Ranges start at PLN 24,500
The lowest published red teaming price in Poland is PLN 24,500, and the highest estimates run into the hundreds of thousands of złoty for large financial institutions. Most large Polish providers publish no red team pricing, so the table relies on the few sites that do.
None of these pages states whether the red teaming figure is net or gross of VAT. Pentestica notes that its ranges are indicative and do not constitute a commercial offer. Clev.one marks other figures in its article as net, but not the red teaming one.
| Source | Service | Price | Page date | Net/gross |
|---|---|---|---|---|
| Pentestica | Red teaming (multi-vector simulation without notifying IT) | PLN 24,500-54,000 | updated Sep 21, 2026 | not stated |
| Pentestica | TLPT under DORA | PLN 172,000-345,000 | updated Sep 21, 2026 | not stated |
| clev.one | Red Team operation (long stealth APT simulation) | PLN 50,000 to over 100,000 | Mar 15, 2026 | not stated for this figure |
| nFlo | Multi-week Red Team operation for a large financial institution | “hundreds of thousands of złoty” (no range) | updated Feb 5, 2026 | not stated |
| REXNET | Red Team Assessment | custom quote | no date | n/a |
Abroad, red teaming starts at €10,000, £15,000 or $20,000
In the US, the UK and EU countries, published red team ranges start at €10,000 (Netherlands, Spain), £15,000 (UK) and $20,000 (US). Upper bounds usually reach 50,000-120,000 in dollars, pounds or euros, although EJN Labs, for example, gives £35,000 for a focused exercise and CyPro £200,000.
For reference, at the National Bank of Poland (NBP) average rates from table 186/A/NBP/2026 of September 24, 2026 (USD 1 = PLN 3.8570, EUR 1 = PLN 4.3900, GBP 1 = PLN 5.1061), €10,000 is about PLN 43,900, £15,000 about PLN 76,600, and $40,000 about PLN 154,300. The conversion ignores differences in day rates between countries, so it does not tell you what the same work would cost in Poland.
Prices for regulatory tests diverge the most. Pentestica's Polish TLPT range is PLN 172,000-345,000. CyPro quotes £200,000 to over £1 million for CBEST and TIBER-UK. Precursor Security gives £40,000-60,000 or more for CBEST, STAR-FS and TIBER-EU. Boddenberg prices TLPT under DORA or TIBER-DE from €100,000, and Austria's slashsec prices a full TIBER-AT cycle from around €150,000. France's PIIRATES does not publish prices, but treats anything below €10,000 for a full red team exercise as a red flag.
| Firm (country) | Service | Price | Duration | Page date |
|---|---|---|---|---|
| Mitnick Security (US) | Red team | about $40,000 | 2-3 weeks to a month | no date |
| Schellman (US) | Red team assessment | $32,000-60,000 | not stated | no date |
| Breach Craft (US) | Red team | $20,000-100,000+ (article summary: from $40,000) | not stated | Mar 23, 2026, updated Aug 5, 2026 |
| Compass IT Compliance (US) | Basic red team / APT simulation / purple team add-on | $40,000-65,000 / $70,000-120,000+ / $10,000-20,000 | 2-4 weeks / 6-8+ weeks | Jun 3, 2025, updated Jan 13, 2026 |
| Redbot Security (US) | Red team operation | $25,000-100,000+ | not stated | April 2026 |
| Cyphere (UK) | Red team for mid-size and large companies | £15,000-50,000 | not stated | updated Sep 8, 2026 |
| EJN Labs (UK) | Focused exercise / TI-led red teaming (STAR, TIBER-UK) | £15,000-35,000 / up to £75,000+ | 2-3 weeks / not stated | updated Aug 7, 2026 |
| Precursor Security (UK) | Red team operation | £15,000-50,000+ | 2-4 weeks (standard), 4-6 weeks (extended) | August 2026 |
| CyPro (UK) | Red team exercise / CBEST, TIBER-UK | £40,000-200,000 / £200,000 to over £1 million | 6-16 weeks / 6+ months | updated Apr 28, 2026 |
| GR.IT Consultancy (UK) | Red team | £30,000-75,000+ | over 20 days | Sep 14, 2026 |
| Boddenberg (Germany) | Red team campaign / TLPT (DORA, TIBER-DE) | €30,000-80,000 / from €100,000 | 8-14 weeks / 6-12 months | Sep 9, 2026 |
| Surelock (Netherlands) | Red team | €10,000-50,000 | not stated | updated Apr 1, 2026 |
| Cibersafety (Spain) | Full red team exercise | €15,000-60,000 | not stated | Jun 24, 2026 |
| MagnoSec (Spain) | Red team | €10,000-50,000 | 2-8 weeks | no date |
| slashsec (Austria) | Full TIBER-AT cycle | from about €150,000 | 6-9 months | Jul 8, 2026 |
Public tenders show contract scale, not the price of a test
Contract award notices show what public bodies spend on red teaming, but only some of them reflect the price of a single test. Examples from the TED database: in November 2025, Spain's Red.es signed a Red Team ethical hacking contract worth €206,080.48 (the notice does not say whether VAT is excluded). In 2023, Madrid's municipal IT agency (IAM) awarded lot 2 of a contract, covering controlled Red Team attacks, for €170,100 excluding VAT after receiving 8 bids. Lithuania's Ministry of Foreign Affairs estimated a red team test of its network infrastructure at €145,233 excluding VAT, but closed the procedure without an award.
Framework agreements are a different category. Danmarks Nationalbank has a four-year TIBER-DK contract (threat intelligence reports and red team tests) worth DKK 6,000,000 excluding VAT, with two contractors. Finland's VTT research institute has an €800,000 framework agreement, excluding VAT, covering pentests, security assessments and red teaming. Each is a framework ceiling shared by two contractors, not the price of a single test.
In Poland, the closest example is the state development bank BGK (Bank Gospodarstwa Krajowego). Its 2025 tender for a security testing framework agreement, which also covered adversary emulation (Red Team, Insider Threat), required references: three contracts of at least PLN 25,000 gross each and one of at least PLN 50,000 gross. That is an experience threshold, not a price. The resulting 36-month framework agreement has a total ceiling of PLN 2,851,447, of which lot I (application and API pentests plus adversary emulation) accounts for PLN 2,298,672, shared by several contractors. In the BZP (Poland's Public Procurement Bulletin) and TED databases, we found no Polish award notice with a price for a standalone red team or TLPT.
How long red teaming and TLPT take
Published data puts a commercial red team engagement at 2-3 to 16 weeks. In TLPT, active testing alone lasts at least 12 weeks, and preparation up to 6 months. Mitnick Security gives 2-3 weeks to a month, EJN Labs 2-3 weeks for a focused exercise, Precursor Security 2-4 weeks for a standard engagement and 4-6 for an extended one, and MagnoSec 2-8 weeks. GR.IT Consultancy mentions more than 20 days. Compass IT Compliance puts an advanced APT simulation at 6-8 weeks or more, and Boddenberg a red team campaign at 8-14 weeks. CyPro splits 6-16 weeks into 1-2 weeks of reconnaissance and planning, 4-12 weeks of active testing, and 1-2 weeks of reporting and debrief.
At PWNONE, a typical red team operation takes 4-8 weeks. An assumed breach test and a ransomware simulation usually take 2-4 weeks, because they start inside your network or have a narrower objective. To see the kind of attack such a simulation reproduces, read our analysis of a ransomware attack on the Polish healthcare sector.
In TLPT, the timelines come from Delegated Regulation (EU) 2025/1190, published on June 18, 2025 and in force from the 20th day after publication, and from the 2025 TIBER-EU framework. That version, announced by the ECB on February 11, 2025, made purple teaming mandatory. We list the phases separately instead of adding them up: the RTS does not say how long the TLPT authority has to assess the reports, and the final deadlines run from that assessment.
| Phase | Timeline | Basis |
|---|---|---|
| Initiation documents | within 3 months of notification by the authority | RTS Art. 9(2); TIBER-EU ch. 6 |
| Scope specification document | within 6 months of notification | RTS Art. 9(6); TIBER-EU ch. 6 (preparation max. 6 months) |
| Threat intelligence and scenarios | usually about 4 weeks (RTS); indicatively 4-6 weeks (TIBER-EU) | RTS recital 18; TIBER-EU ch. 7.1 |
| Red team test plan | indicatively 2-3 weeks | TIBER-EU ch. 8.1 |
| Active red team testing | at least 12 weeks, with progress reports at least weekly | RTS Art. 11(5) and (7); TIBER-EU ch. 8.4 |
| Red team test report | within 4 weeks of the end of active testing | RTS Art. 12(2) |
| Blue team test report, replay and purple teaming | no later than 10 weeks after the end of active testing | RTS Art. 12(4) and (5) |
| Test summary report and remediation plan | 8 weeks each, running in parallel from the authority's notification that the reports have been assessed | RTS Art. 12(7), Art. 13(1) |
TLPT tester requirements under DORA Article 27
TLPT testers must meet all five requirements of Article 27(1) of DORA, Regulation (EU) 2022/2554, listed in the table below. The Polish text of point (d) was changed by the corrigendum of March 12, 2024 and now refers to mitigating the financial entity's business risk, where the English text says “redress”.
RTS 2025/1190 details these requirements in Article 7. An external red team must include at least a manager with 5 years of experience in penetration testing and red teaming, plus two testers with at least 2 years each. The team needs at least five previous assignments combined and at least five references. The threat intelligence provider must provide at least three references, and its team must include at least a manager with 5 years of experience and one analyst with 2 years. Professional indemnity insurance applies to both providers, but neither DORA nor the RTS sets a minimum sum insured.
The threat intelligence provider must always be external to the institution and its intra-group ICT service providers (DORA recital 61 and Article 27(2)(c), RTS Article 1(10)). TI and red teaming can come from one firm if the TI staff on a given test are separated from the red team and do not report to it (RTS Article 7(1)(e)(v) and (f)(v)). Internal testers need the authority's approval, and every third test is still run by external testers. Significant credit institutions directly supervised by the ECB may use external testers only.
In Poland, the Polish Financial Supervision Authority (KNF) designates the entities required to perform TLPT by decision (Article 18zk of the Act on Financial Market Supervision). The test is repeated at least every 3 years, and the KNF may recommend less or more frequent testing. According to CSIRT KNF, TLPT is mandatory for designated entities, while TIBER-EU remains a voluntary framework. In January 2025, the KNF Office (UKNF) announced that TIBER-PL would be published in the first half of 2025. On the ECB page listing the jurisdictions that have adopted TIBER-EU, Poland was not included on the date we checked, September 24, 2026.
| Point | Requirement |
|---|---|
| a | Highest suitability and reputability |
| b | Technical and organizational capabilities and specific expertise in threat intelligence, penetration testing and red team testing |
| c | Certification by an accreditation body in a Member State, or adherence to formal codes of conduct or ethical frameworks |
| d | Independent assurance or an audit report on the sound management of TLPT risks, including due protection of the financial entity's confidential information and redress for its business risks |
| e | Due and full professional indemnity insurance, including against risks of misconduct and negligence |
How we do it
We meet the DORA Article 27 tester requirements, carry professional indemnity insurance and have our own threat intelligence team, separated from the red team.
How to compare red teaming proposals
You can only compare red teaming proposals once each one describes the same scope, because the price alone does not tell you how much work you are buying. If a price falls well below the ranges in the tables above, ask what is missing: person-days, a vector or the report.
In your request, ask every provider for the same information:
- Number of person-days and team composition: who leads the operation and how many years of experience they have.
- Objectives (flags) and vectors included in the price: social engineering, physical testing, assumed breach or full scope.
- Whether the scenario is based on threat intelligence for your industry, and who prepares it.
- Report contents: an attack timeline with detection points, MITRE ATT&CK mapping, SIEM and EDR recommendations.
- Whether a retest after remediation and a workshop with your defense team are included.
- How much time your team must commit: control team, meetings, weekly progress reports.
- For TLPT: documents showing compliance with DORA Article 27 and RTS Article 7, i.e. CVs, certifications, references and the professional indemnity policy.
What's included in a PWNONE engagement
You get a report with an attack timeline and detection points, a MITRE ATT&CK map and SIEM/EDR recommendations, followed by a workshop with your Blue Team. One retest after remediation is included.
Summary
Published red teaming ranges in Poland are PLN 24,500-54,000 (Pentestica) and PLN 50,000 to over 100,000 (clev.one). The only Polish TLPT range with both a floor and a ceiling that we found is PLN 172,000-345,000 (Pentestica). Abroad, commercial exercises start at €10,000, £15,000 and $20,000, while sources quote £40,000 to over £1 million for regulatory tests. Commercial red teaming takes 2-3 to 16 weeks; in TLPT, the active phase alone lasts at least 12 weeks, with up to 6 months of preparation. Compare proposals on person-days, objectives, vectors, reporting and retests.
Frequently asked questions
Why do red teaming quotes vary so widely?
Because providers are pricing different amounts of work. The cost of red teaming depends on the number of person-days, the number of objectives, the entry vectors (social engineering, physical testing, assumed breach) and whether the scenario is based on threat intelligence. In Poland, published ranges are PLN 24,500-54,000 at Pentestica and PLN 50,000 to over 100,000 according to clev.one. For regulatory tests in the UK, one source quotes £40,000-60,000 or more, and another £200,000 to over £1 million.
Is red teaming more expensive than a penetration test?
Usually yes, because it takes longer and has a different goal. A pentest is priced by scope, such as the number of hosts or applications, and price lists show a “starting at” figure. Red teaming is priced by the team's time and the objectives it has to reach, such as access to the domain controller, and firms often list it as “custom quote.” The lowest published red teaming price in Poland is PLN 24,500 (Pentestica, as of September 24, 2026, with no VAT information).
How long does a TLPT under DORA take?
Delegated Regulation 2025/1190 sets deadlines for each phase. Initiation documents are due within 3 months of notification by the authority, and the scope specification document within 6 months. Threat intelligence gathering usually takes about 4 weeks, and active red team testing at least 12 weeks. The red team report follows within 4 weeks of testing, and the blue team report, replay and purple teaming within 10 weeks. The rules give no total duration, because they do not specify how long the authority takes to assess the reports.
How often must a financial institution carry out TLPT?
Entities designated by the supervisory authority carry out TLPT at least every 3 years (DORA Article 26(1)). In Poland, the Polish Financial Supervision Authority (KNF) designates them by decision under Article 18zk of the Act on Financial Market Supervision and may recommend less or more frequent testing. The obligation does not apply to microenterprises or to entities referred to in Article 16(1) of DORA. The 2025 TIBER-EU framework also treats 3 years as the normal interval between tests.
Is TIBER-PL already in effect in Poland?
In January 2025, the Office of the Polish Financial Supervision Authority (UKNF) announced that TIBER-PL would be published in the first half of 2025. On the ECB page listing the jurisdictions that have adopted TIBER-EU, Poland was not included on the date we checked, September 24, 2026. Regardless, TLPT under DORA is mandatory for entities designated by the KNF, while TIBER-EU, according to CSIRT KNF, remains a voluntary framework.
Can threat intelligence and the red team for a TLPT come from the same firm?
Yes. The threat intelligence provider must be external to the financial institution and its intra-group ICT providers, but the rules do not prohibit buying TI and red teaming from one firm. The condition, set in Article 7 of RTS 2025/1190, is that TI staff must be separated from the red team on the same test and must not report to it. The 2025 TIBER-EU guidance also allows a single provider if separate teams deliver the two services. PWNONE has its own TI team, separated from the red team.
Bibliography
Pentestica (in Polish), red teaming and TLPT ranges, updated September 21, 2026, accessed September 24, 2026
clev.one (in Polish), March 15, 2026, accessed September 24, 2026
nFlo (in Polish), updated February 5, 2026, accessed September 24, 2026
REXNET (in Polish), accessed September 24, 2026
Mitnick Security, accessed September 24, 2026
Schellman, accessed September 24, 2026
Breach Craft, March 23, 2026, accessed September 24, 2026
Compass IT Compliance, June 3, 2025, accessed September 24, 2026
Redbot Security, April 2026, accessed September 24, 2026
Cyphere, updated September 8, 2026, accessed September 24, 2026
EJN Labs, updated August 7, 2026, accessed September 24, 2026
Precursor Security, August 2026, accessed September 24, 2026
Precursor Security, August 2026, accessed September 24, 2026
CyPro, updated April 28, 2026, accessed September 24, 2026
GR.IT Consultancy, September 14, 2026, accessed September 24, 2026
Boddenberg (in German), September 9, 2026, accessed September 24, 2026
Surelock (in Dutch), updated April 1, 2026, accessed September 24, 2026
Cibersafety (in Spanish), June 24, 2026, accessed September 24, 2026
MagnoSec (in Spanish), accessed September 24, 2026
PIIRATES (in French), accessed September 24, 2026
slashsec, July 8, 2026, accessed September 24, 2026
National Bank of Poland (NBP), table A of September 24, 2026 (USD, EUR, GBP), accessed September 24, 2026
Tenders Electronic Daily, Publications Office of the European Union, accessed September 24, 2026
Tenders Electronic Daily, Publications Office of the European Union, accessed September 24, 2026
Tenders Electronic Daily, Publications Office of the European Union, accessed September 24, 2026
Tenders Electronic Daily, Publications Office of the European Union, accessed September 24, 2026
Tenders Electronic Daily, Publications Office of the European Union, accessed September 24, 2026
Tenders Electronic Daily, Publications Office of the European Union, accessed September 24, 2026
Tenders Electronic Daily, Publications Office of the European Union, accessed September 24, 2026
EUR-Lex, Official Journal of the EU L 333, December 27, 2022, accessed September 24, 2026
EUR-Lex, corrigendum of March 12, 2024, accessed September 24, 2026
EUR-Lex, Official Journal of the EU, June 18, 2025, accessed September 24, 2026
European Central Bank, January 2025, accessed September 24, 2026
European Central Bank, February 11, 2025, accessed September 24, 2026
European Central Bank, January 2025, accessed September 24, 2026
European Central Bank, list of jurisdictions, accessed September 24, 2026
Polish Financial Supervision Authority (KNF), in Polish, updated January 27, 2025, accessed September 24, 2026
Polish Financial Supervision Authority (KNF), in Polish, updated July 14, 2025, accessed September 24, 2026
Journal of Laws of the Republic of Poland (Dziennik Ustaw), in Polish, August 6, 2025, accessed September 24, 2026

