The verdict in three sentences
A grey-box pentest on a client portal costs 5,000 to 15,000 EUR in Toronto in 2026 for 3 to 8 days of testing, and finds on average 8 to 15 vulnerabilities including 1 to 3 critical. Scope covers authentication, IDOR access, injections, file upload and business logic, with a re-test of fixes included. Testing it before go-live turns a potential 30,000 EUR incident into a planned fix worth a few thousand.
Scope and price of a portal pentest
The pentest simulates an attacker holding a user account (grey-box), which reflects the real risk of a client portal: a legitimate user trying to reach other people's data. Here are the 2026 packages.
| Package | Approach | Duration | Price 2026 (EUR) |
|---|---|---|---|
| Targeted pentest | Black-box, public surface | 2-3 days | 5,000 - 7,000 |
| Portal pentest | Grey-box, 2-3 roles | 4-6 days | 8,000 - 12,000 |
| Deep pentest | Grey-box + API + business logic | 7-8 days | 13,000 - 15,000 |
| Fix re-test | Post-fix verification | 1 day | Included |
| Recurring pentest | 1 campaign / year | Yearly | 8,000 - 12,000 |
A client portal concentrates several high-impact risks: horizontal access to neighbouring accounts (IDOR), privilege escalation, data leakage through poorly filtered APIs. This is exactly what a grey-box pentest exposes before your real clients do.
What a pentest typically finds
Here is the distribution observed on B2B portals before launch, with associated severity.
| Vulnerability type | Frequency | Typical severity | Fix effort |
|---|---|---|---|
| IDOR (access to others' data) | Very common | Critical / High | 1-3 days |
| Broken role-based access control | Common | High | 2-4 days |
| Injection (SQL, NoSQL, command) | Medium | Critical | 1-2 days |
| Unfiltered file upload | Common | High | 1-2 days |
| Weak session management | Medium | Medium | 1 day |
| Internal API exposure | Common | High | 2-3 days |
The final report ranks each flaw by CVSS score and provides concrete remediation. The re-test confirms fixes are effective, which is essential before opening the portal to the public.
Need a professional website?
Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.
Mini case study
Daniel, COO of a B2B services firm in Toronto, is about to launch a portal where 400 clients will view their contracts. He commissions a portal pentest at 10,000 EUR (5 days) two weeks before the launch date. The test surfaces 2 critical flaws (an IDOR letting one client read another's contracts, an injection on the search module) and 11 secondary issues. Fixing takes 5 person-days (about 3,000 EUR), followed by the included re-test. Total cost: 13,000 EUR. In contrast, a single B2B contract lost after a data leak would have cost far more, let alone the regulatory notification.
FAQ
Why test before production rather than after? Before go-live, a flaw is fixed calmly, with no exposed clients and no notification duty. After, the same flaw becomes an incident: forensics, crisis comms, lost trust, often 20,000 to 50,000 EUR total.
Black-box or grey-box for a client portal? Grey-box is recommended: it simulates an authenticated user and reveals horizontal access (IDOR) and role problems, the number-one portal risks. Black-box alone misses the essentials.
Is the re-test really included? With serious providers, yes: after your fixes, the auditor verifies each flaw is closed and updates the report. Demand it in the quote; it's what distinguishes a pentest from a mere scan.
How much time between test and launch? Plan 2 to 4 weeks: a few days of testing, then time to fix and re-test. Launching without this margin means going live with known critical flaws.
Isn't an automated scanner enough? No: a scanner detects known technical flaws but misses business logic, contextual IDOR and exploitation chains. A pentest combines tools and human expertise, which explains the gap in price and value.
Let's scope your project. Tell us the number of roles, whether there are APIs, and your launch date: we'll frame a pentest between 5,000 and 15,000 EUR, re-test included. Detailed quote within 48 h. WhatsApp +221 77 596 93 33.
Mohamed Bah
Fondateur, Kolonell
Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.

