The verdict in three sentences
A banking portal pentest in London budgets at EUR 8,000 to 25,000 in 2026, depending on attack surface and the level of intrusion requested. Expect 2 to 4 weeks for the audit, then EUR 5,000 to 15,000 of remediation before a validation re-test, usually included. The real cost is never the audit: it is the incident avoided, whose average cost runs into hundreds of thousands of euros plus PSD2 / GDPR penalties.
What a banking pentest actually covers
A serious penetration test is more than an automated scan. It combines reconnaissance, manual exploitation of OWASP Top 10 flaws, strong-authentication testing (SCA/PSD2), and API flow review. The core deliverable is a criticality report that ranks each vulnerability (critical, high, medium, low) with proof of exploitation and a remediation plan.
| 2026 service | Perimeter | Price EUR | Timeline |
|---|---|---|---|
| Black box pentest | Public portal, no access | 8,000 – 12,000 | 2 weeks |
| Grey box pentest | Portal + test accounts | 12,000 – 18,000 | 2 – 3 weeks |
| White box pentest | Code + infra + API | 18,000 – 25,000 | 3 – 4 weeks |
| Remediation | Priority fixes | 5,000 – 15,000 | 2 – 5 weeks |
| Validation re-test | Fix verification | Included | 3 – 5 days |
Criticality, compliance and prioritization
Not all flaws are equal. An injection that exposes client accounts blocks go-live; a missing security header is a one-hour fix. Prioritizing by criticality avoids paying for uniform remediation when 20% of fixes neutralize 80% of the risk.
| Criticality | Example | Fix window | Blocks prod? |
|---|---|---|---|
| Critical | SQL injection, auth bypass | 24 – 72 h | Yes |
| High | IDOR, non-expiring session | 1 week | Yes |
| Medium | Partial CSRF, verbose errors | 2 – 3 weeks | No |
| Low | Missing headers | 1 – 2 days | No |
| Informational | Exposed server version | Optional | No |
Mini case study
Need a professional website?
Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.
Thomas, CISO of a credit institution in London, must sign off a new client portal before launch. He orders a grey box pentest at EUR 15,000. The audit finds 2 critical and 4 high flaws. Remediation costs EUR 9,000 and the re-test is included. Total: EUR 24,000 over 6 weeks. Against an average banking incident cost estimated above EUR 300,000 (client notification, penalty, emergency remediation), the ROI turns on a single avoided incident.
FAQ
Is a pentest mandatory for a banking portal? PSD2 requires strong authentication and documented risk management; regular penetration testing is the evidence regulators and auditors expect. In practice it is unavoidable before go-live.
Black box, grey box or white box? Grey box (EUR 12,000-18,000) offers the best coverage-to-cost ratio for a portal: testers have test accounts but probe like a real attacker. White box is justified for sensitive code.
Is the re-test really included? With a serious provider, a validation re-test of critical and high fixes is included within 3 months. Check the contract: without a re-test you cannot prove the flaw is closed.
How often should it be renewed? An annual pentest at minimum, plus a test on every major change (new payment flow, new API). Budget a recurring EUR 10,000-20,000 per year.
Can the same provider do audit and remediation? Yes, and it is faster, but demand a clear separation of deliverables. Ideal: independent external audit, remediation by your teams or us, re-test by the auditor.
Let's scope your project. Tell us about your portal (tech stack, payment flows, user count) and your go-live deadline. Detailed quote within 48 h. WhatsApp +221 77 596 93 33.
Mohamed Bah
Fondateur, Kolonell
Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.

