The verdict in three sentences
For a business web application exposed to customers, the right benchmark is OWASP ASVS Level 2, which typically adds 10 to 15% to the development budget. That cost belongs in the quote, together with a grey-box penetration test of EUR 6,000 to 15,000 excl. VAT before go-live. A mid-sized company in Amsterdam that skips it is exposed to an average incident of EUR 50,000 or more, before counting downtime and the data breach notification to the Dutch DPA.
ASVS in plain terms: three levels, three budgets
The Application Security Verification Standard (ASVS 4.0.3, with version 5.0 released in 2025) lists around 280 verifiable requirements split into three levels. Level 1 covers the minimum that can be tested from the outside. Level 2 targets applications handling personal or commercial data: it is the normal target for a customer portal, a supplier extranet or a B2B ordering tool. Level 3 is for critical applications (healthcare, payments, defence).
| ASVS level | Typical use | Share of development budget | Example on a EUR 120,000 project |
|---|---|---|---|
| Level 1 | Internal site, low exposure | 5 to 8% | EUR 6,000 to 9,600 |
| Level 2 | Customer portal, extranet, personal data | 10 to 15% | EUR 12,000 to 18,000 |
| Level 3 | Payments, healthcare, sensitive data | 20 to 30% | EUR 24,000 to 36,000 |
| Grey-box penetration test | Before go-live | Fixed fee | EUR 6,000 to 15,000 |
| Security code review | Critical modules (authentication, permissions) | EUR 800 to 1,200/day | EUR 4,000 to 8,400 (5 to 7 days) |
| WAF and monitoring | Operations | EUR 150 to 600/month | EUR 1,800 to 7,200/year |
These 2026 orders of magnitude (excl. VAT) reflect rates charged by qualified security firms in Western Europe and by agencies that build security in from the design stage.
The requirements that actually cost money
The budget is not spread evenly. A few ASVS chapters concentrate most of the effort, and they are the ones you should see line by line in a serious quote.
| ASVS chapter | Typical Level 2 requirement | Estimated effort | Indicative 2026 cost |
|---|---|---|---|
| V2 Authentication | MFA, password policy, credential stuffing protection | 4 to 6 days | EUR 2,400 to 4,200 |
| V3 Sessions | Expiry, revocation, secure cookies | 1 to 2 days | EUR 600 to 1,400 |
| V4 Access control | Role and object-level permissions, IDOR tests | 5 to 8 days | EUR 3,000 to 5,600 |
| V5 Input validation | Parameterised queries, output encoding | 3 to 5 days | EUR 1,800 to 3,500 |
| V7 Logging | Timestamped audit log, alerts | 2 to 4 days | EUR 1,200 to 2,800 |
| V9 and V14 Configuration | TLS, CSP and HSTS headers, secrets out of the code | 2 to 3 days | EUR 1,200 to 2,100 |
| V12 Files | Upload controls, antivirus | 1 to 3 days | EUR 600 to 2,100 |
Access control is the most underestimated line. In penetration tests of business applications, authorisation flaws (a customer viewing another customer's order by changing an ID) remain the leading cause of critical findings. Automated tests for each role avoid paying twice.
How to put it in the quote
Ask the vendor for an ASVS compliance matrix: each selected requirement, its status (planned, out of scope, compensated) and the evidence expected at acceptance. Add a line for an independent penetration test, ideally by a different firm than the development team, and a line for fixing findings (allow 3 to 5 days). On the operations side, budget the WAF, log monitoring and dependency updates, around EUR 150 to 600 per month depending on volume.
GDPR Article 32 and, for in-scope entities, the NIS2 directive require 'appropriate' security measures: the ASVS matrix then becomes useful evidence for an auditor or a cyber insurer.
Mini case study
Need a professional website?
Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.
Thomas, CIO of a 180-employee wine trading company in Amsterdam, is launching an ordering portal for 1,400 wine shops and restaurants. Development budget: EUR 140,000. He chooses ASVS Level 2 at 12%, i.e. EUR 16,800, a grey-box penetration test at EUR 9,500, two days of fixes at EUR 2,000 and a monitored WAF at EUR 350 per month, i.e. EUR 4,200 in year one. Total security spend in year 1: EUR 32,500, or 23% of the project. Against an incident estimated at EUR 50,000 minimum plus two to three days of blocked orders (around EUR 45,000 in revenue), the budget pays for itself with the first incident avoided.
FAQ
Is ASVS Level 1 enough for a customer portal?
Rarely. As soon as the application handles personal data or negotiated prices, Level 2 is the reference; the cost difference is about 5 to 7 points of the development budget.
How long does a grey-box penetration test take?
Allow 5 to 12 audit days depending on the number of roles and screens, i.e. EUR 6,000 to 15,000 excl. VAT. The report usually arrives within 1 to 2 weeks.
Do we need a new test for every release?
One full test per year is enough in most cases, backed by weekly automated scans. A major change (new payment module, new API) justifies a targeted 2 to 4 day test.
What does an incident cost a European SME?
2026 estimates put the average above EUR 50,000, adding remediation, forensics, downtime and communication. Ransomware or a customer data leak quickly pushes the bill past EUR 200,000.
Does a WAF replace secure development?
No. It filters known attacks but fixes neither access control flaws nor business logic. It costs EUR 150 to 600 per month and complements ASVS without replacing it.
Let's scope your project. Send us your application scope and target ASVS level: we will price development, the compliance matrix and the penetration test, with a realistic delivery timeline. Detailed quote within 48 h. WhatsApp +221 77 596 93 33.
Mohamed Bah
Fondateur, Kolonell
Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.