Websites11 min read

Web App Penetration Test Before Launch: Cost and Scope (2026)

Mohamed Bah·Fondateur, Kolonell
October 10, 2026
Share:
Web App Penetration Test Before Launch: Cost and Scope (2026)

Web App Penetration Test Before Launch: Cost and Scope (2026)

Websites

The verdict in three sentences

A grey-box penetration test of a B2B web application costs EUR 6,000 to 18,000 excl. VAT in 2026, for 5 to 12 days of audit against the OWASP ASVS standard. Add EUR 3,000 to 10,000 in fixes and insist on an included retest, otherwise the report you hand to the enterprise client will show open vulnerabilities. A PASSI-qualified provider (the French ANSSI label) is only useful if your client explicitly requires it (public sector, critical operators, some banks).

Defining the scope: what drives the price

Pentest pricing is based on auditor-days, billed at EUR 1,000 to 1,500 excl. VAT in France (similar to USD 1,200 to 2,000 in the US). The number of days depends on scope, not on company size.

Scope itemEffect on durationIndicative days
Web application with 2 roles (user, admin)Baseline4 to 5 days
Each extra role (manager, support, partner)Segregation and privilege escalation tests+ 0.5 to 1 day
REST or GraphQL API exposed to clientsAuthentication, rate limits, injections+ 1 to 3 days
Multi-tenant (data from several clients)Tenant isolation testing, critical for an enterprise client+ 1 to 2 days
Companion mobile appLocal storage, certificates, API+ 2 to 4 days
Cloud infrastructure (AWS, Azure, GCP configuration)IAM, buckets, network review+ 1 to 3 days
Report writing and debriefExecutive summary and technical detail1 day

A typical B2B SaaS platform (3 roles, public API, multi-tenant) usually needs 8 to 9 days, i.e. EUR 9,000 to 13,000 excl. VAT.

Comparing offers: black, grey, white box and PASSI

Service type (2026 order of magnitude)Price excl. VATDaysWhen to choose it
Automated scan with manual verificationEUR 1,500 to 3,5001 to 2Continuous checks, not for an enterprise client
Black-box pentest (no account)EUR 4,000 to 9,0004 to 7Simulate an external attacker
Grey-box pentest (test accounts provided)EUR 6,000 to 18,0005 to 12Standard expected by enterprise clients
White-box pentest (code access)EUR 10,000 to 25,0008 to 18Sensitive apps, health, finance
Pentest by a PASSI-qualified provider+ 20 to 40%SameExplicit contractual requirement
Retest of fixed vulnerabilitiesOften included, else EUR 1,000 to 2,5001 to 2Always, before sending the report

The deliverable an enterprise security team expects: a report with CVSS scoring, explicit coverage of OWASP ASVS level 2 controls and a retest attestation less than 12 months old.

Fix budget and timeline

A first campaign on a never-tested application finds on average 1 to 3 critical or high vulnerabilities and 8 to 15 medium or low ones. Fixes cost EUR 3,000 to 10,000 depending on their nature: broken access control between tenants (the most expensive), security headers and configuration (the cheapest). Typical timeline: 1 week of scoping and test account setup, 2 weeks of audit, 2 to 3 weeks of fixes, 1 week of retest, so 6 to 7 weeks before handing the final report to the client.

Mini case study

Julien, CTO of a B2B expense management platform in Nantes, must provide a pentest report to sign an industrial group worth EUR 140,000 in annual recurring revenue. His scope: 3 roles, public API, multi-tenant, so 9 days at EUR 1,200, EUR 10,800 excl. VAT, retest included. The pentest reveals a critical tenant isolation flaw and 11 medium issues, fixed for EUR 6,500. Total cost: EUR 17,300, or 12% of the contract's first year. The report is reused for two more tenders during the year.

Need a professional website?

Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.

Prefer a call back?

Leave your WhatsApp number and a Kolonell expert will get back to you within 1 business day. Free, no strings attached.

You are :

FAQ

How much does a web app pentest cost in 2026?

A grey-box test costs EUR 6,000 to 18,000 excl. VAT for 5 to 12 audit days, at EUR 1,000 to 1,500 per auditor-day. Add EUR 3,000 to 10,000 in fixes depending on findings.

Is a PASSI-qualified provider mandatory?

No, unless your client requires it contractually or falls under specific regulation (critical operators, public administration). A PASSI provider costs 20 to 40% more for the same scope.

How long before we can hand the report to the client?

Plan 6 to 7 weeks from scoping to the final retested report. Reputable providers often have a 3 to 6 week start lead time, so book early.

What does the report given to the enterprise client contain?

An executive summary, the list of vulnerabilities ranked by CVSS score, OWASP ASVS coverage and the retest attestation. Most security teams treat the report as valid for about 12 months.

Do we need a new pentest for every release?

One full pentest a year is usually enough, plus a targeted 2 to 4 day test after a major change (new module, new API). In between, a monthly automated scan costs a few hundred euros.

Let's scope your project. Tell us your roles, APIs and your client's requirement, and we will scope the pentest, budget fixes between EUR 3,000 and 10,000 and deliver a retested report in 6 to 7 weeks. Detailed quote within 48 h. WhatsApp +221 77 596 93 33.

Tags:#web app pentest#penetration testing#OWASP#SaaS security#PASSI#security audit cost
Share:

Mohamed Bah

Fondateur, Kolonell

Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.