The verdict in three sentences
A grey-box penetration test of a B2B web application costs EUR 6,000 to 18,000 excl. VAT in 2026, for 5 to 12 days of audit against the OWASP ASVS standard. Add EUR 3,000 to 10,000 in fixes and insist on an included retest, otherwise the report you hand to the enterprise client will show open vulnerabilities. A PASSI-qualified provider (the French ANSSI label) is only useful if your client explicitly requires it (public sector, critical operators, some banks).
Defining the scope: what drives the price
Pentest pricing is based on auditor-days, billed at EUR 1,000 to 1,500 excl. VAT in France (similar to USD 1,200 to 2,000 in the US). The number of days depends on scope, not on company size.
| Scope item | Effect on duration | Indicative days |
|---|---|---|
| Web application with 2 roles (user, admin) | Baseline | 4 to 5 days |
| Each extra role (manager, support, partner) | Segregation and privilege escalation tests | + 0.5 to 1 day |
| REST or GraphQL API exposed to clients | Authentication, rate limits, injections | + 1 to 3 days |
| Multi-tenant (data from several clients) | Tenant isolation testing, critical for an enterprise client | + 1 to 2 days |
| Companion mobile app | Local storage, certificates, API | + 2 to 4 days |
| Cloud infrastructure (AWS, Azure, GCP configuration) | IAM, buckets, network review | + 1 to 3 days |
| Report writing and debrief | Executive summary and technical detail | 1 day |
A typical B2B SaaS platform (3 roles, public API, multi-tenant) usually needs 8 to 9 days, i.e. EUR 9,000 to 13,000 excl. VAT.
Comparing offers: black, grey, white box and PASSI
| Service type (2026 order of magnitude) | Price excl. VAT | Days | When to choose it |
|---|---|---|---|
| Automated scan with manual verification | EUR 1,500 to 3,500 | 1 to 2 | Continuous checks, not for an enterprise client |
| Black-box pentest (no account) | EUR 4,000 to 9,000 | 4 to 7 | Simulate an external attacker |
| Grey-box pentest (test accounts provided) | EUR 6,000 to 18,000 | 5 to 12 | Standard expected by enterprise clients |
| White-box pentest (code access) | EUR 10,000 to 25,000 | 8 to 18 | Sensitive apps, health, finance |
| Pentest by a PASSI-qualified provider | + 20 to 40% | Same | Explicit contractual requirement |
| Retest of fixed vulnerabilities | Often included, else EUR 1,000 to 2,500 | 1 to 2 | Always, before sending the report |
The deliverable an enterprise security team expects: a report with CVSS scoring, explicit coverage of OWASP ASVS level 2 controls and a retest attestation less than 12 months old.
Fix budget and timeline
A first campaign on a never-tested application finds on average 1 to 3 critical or high vulnerabilities and 8 to 15 medium or low ones. Fixes cost EUR 3,000 to 10,000 depending on their nature: broken access control between tenants (the most expensive), security headers and configuration (the cheapest). Typical timeline: 1 week of scoping and test account setup, 2 weeks of audit, 2 to 3 weeks of fixes, 1 week of retest, so 6 to 7 weeks before handing the final report to the client.
Mini case study
Julien, CTO of a B2B expense management platform in Nantes, must provide a pentest report to sign an industrial group worth EUR 140,000 in annual recurring revenue. His scope: 3 roles, public API, multi-tenant, so 9 days at EUR 1,200, EUR 10,800 excl. VAT, retest included. The pentest reveals a critical tenant isolation flaw and 11 medium issues, fixed for EUR 6,500. Total cost: EUR 17,300, or 12% of the contract's first year. The report is reused for two more tenders during the year.
Need a professional website?
Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.
FAQ
How much does a web app pentest cost in 2026?
A grey-box test costs EUR 6,000 to 18,000 excl. VAT for 5 to 12 audit days, at EUR 1,000 to 1,500 per auditor-day. Add EUR 3,000 to 10,000 in fixes depending on findings.
Is a PASSI-qualified provider mandatory?
No, unless your client requires it contractually or falls under specific regulation (critical operators, public administration). A PASSI provider costs 20 to 40% more for the same scope.
How long before we can hand the report to the client?
Plan 6 to 7 weeks from scoping to the final retested report. Reputable providers often have a 3 to 6 week start lead time, so book early.
What does the report given to the enterprise client contain?
An executive summary, the list of vulnerabilities ranked by CVSS score, OWASP ASVS coverage and the retest attestation. Most security teams treat the report as valid for about 12 months.
Do we need a new pentest for every release?
One full pentest a year is usually enough, plus a targeted 2 to 4 day test after a major change (new module, new API). In between, a monthly automated scan costs a few hundred euros.
Let's scope your project. Tell us your roles, APIs and your client's requirement, and we will scope the pentest, budget fixes between EUR 3,000 and 10,000 and deliver a retested report in 6 to 7 weeks. Detailed quote within 48 h. WhatsApp +221 77 596 93 33.
Mohamed Bah
Fondateur, Kolonell
Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.
