Websites10 min read

OWASP ASVS Web App Security Budget: 2026 Costs in Amsterdam

Mohamed Bah·Fondateur, Kolonell
October 8, 2026
Share:
OWASP ASVS Web App Security Budget: 2026 Costs in Amsterdam

OWASP ASVS Web App Security Budget: 2026 Costs in Amsterdam

Websites

The verdict in three sentences

For a business web application exposed to customers, the right benchmark is OWASP ASVS Level 2, which typically adds 10 to 15% to the development budget. That cost belongs in the quote, together with a grey-box penetration test of EUR 6,000 to 15,000 excl. VAT before go-live. A mid-sized company in Amsterdam that skips it is exposed to an average incident of EUR 50,000 or more, before counting downtime and the data breach notification to the Dutch DPA.

ASVS in plain terms: three levels, three budgets

The Application Security Verification Standard (ASVS 4.0.3, with version 5.0 released in 2025) lists around 280 verifiable requirements split into three levels. Level 1 covers the minimum that can be tested from the outside. Level 2 targets applications handling personal or commercial data: it is the normal target for a customer portal, a supplier extranet or a B2B ordering tool. Level 3 is for critical applications (healthcare, payments, defence).

ASVS levelTypical useShare of development budgetExample on a EUR 120,000 project
Level 1Internal site, low exposure5 to 8%EUR 6,000 to 9,600
Level 2Customer portal, extranet, personal data10 to 15%EUR 12,000 to 18,000
Level 3Payments, healthcare, sensitive data20 to 30%EUR 24,000 to 36,000
Grey-box penetration testBefore go-liveFixed feeEUR 6,000 to 15,000
Security code reviewCritical modules (authentication, permissions)EUR 800 to 1,200/dayEUR 4,000 to 8,400 (5 to 7 days)
WAF and monitoringOperationsEUR 150 to 600/monthEUR 1,800 to 7,200/year

These 2026 orders of magnitude (excl. VAT) reflect rates charged by qualified security firms in Western Europe and by agencies that build security in from the design stage.

The requirements that actually cost money

The budget is not spread evenly. A few ASVS chapters concentrate most of the effort, and they are the ones you should see line by line in a serious quote.

ASVS chapterTypical Level 2 requirementEstimated effortIndicative 2026 cost
V2 AuthenticationMFA, password policy, credential stuffing protection4 to 6 daysEUR 2,400 to 4,200
V3 SessionsExpiry, revocation, secure cookies1 to 2 daysEUR 600 to 1,400
V4 Access controlRole and object-level permissions, IDOR tests5 to 8 daysEUR 3,000 to 5,600
V5 Input validationParameterised queries, output encoding3 to 5 daysEUR 1,800 to 3,500
V7 LoggingTimestamped audit log, alerts2 to 4 daysEUR 1,200 to 2,800
V9 and V14 ConfigurationTLS, CSP and HSTS headers, secrets out of the code2 to 3 daysEUR 1,200 to 2,100
V12 FilesUpload controls, antivirus1 to 3 daysEUR 600 to 2,100

Access control is the most underestimated line. In penetration tests of business applications, authorisation flaws (a customer viewing another customer's order by changing an ID) remain the leading cause of critical findings. Automated tests for each role avoid paying twice.

How to put it in the quote

Ask the vendor for an ASVS compliance matrix: each selected requirement, its status (planned, out of scope, compensated) and the evidence expected at acceptance. Add a line for an independent penetration test, ideally by a different firm than the development team, and a line for fixing findings (allow 3 to 5 days). On the operations side, budget the WAF, log monitoring and dependency updates, around EUR 150 to 600 per month depending on volume.

GDPR Article 32 and, for in-scope entities, the NIS2 directive require 'appropriate' security measures: the ASVS matrix then becomes useful evidence for an auditor or a cyber insurer.

Mini case study

Need a professional website?

Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.

Prefer a call back?

Leave your WhatsApp number and a Kolonell expert will get back to you within 1 business day. Free, no strings attached.

Thomas, CIO of a 180-employee wine trading company in Amsterdam, is launching an ordering portal for 1,400 wine shops and restaurants. Development budget: EUR 140,000. He chooses ASVS Level 2 at 12%, i.e. EUR 16,800, a grey-box penetration test at EUR 9,500, two days of fixes at EUR 2,000 and a monitored WAF at EUR 350 per month, i.e. EUR 4,200 in year one. Total security spend in year 1: EUR 32,500, or 23% of the project. Against an incident estimated at EUR 50,000 minimum plus two to three days of blocked orders (around EUR 45,000 in revenue), the budget pays for itself with the first incident avoided.

FAQ

Is ASVS Level 1 enough for a customer portal?

Rarely. As soon as the application handles personal data or negotiated prices, Level 2 is the reference; the cost difference is about 5 to 7 points of the development budget.

How long does a grey-box penetration test take?

Allow 5 to 12 audit days depending on the number of roles and screens, i.e. EUR 6,000 to 15,000 excl. VAT. The report usually arrives within 1 to 2 weeks.

Do we need a new test for every release?

One full test per year is enough in most cases, backed by weekly automated scans. A major change (new payment module, new API) justifies a targeted 2 to 4 day test.

What does an incident cost a European SME?

2026 estimates put the average above EUR 50,000, adding remediation, forensics, downtime and communication. Ransomware or a customer data leak quickly pushes the bill past EUR 200,000.

Does a WAF replace secure development?

No. It filters known attacks but fixes neither access control flaws nor business logic. It costs EUR 150 to 600 per month and complements ASVS without replacing it.

Let's scope your project. Send us your application scope and target ASVS level: we will price development, the compliance matrix and the penetration test, with a realistic delivery timeline. Detailed quote within 48 h. WhatsApp +221 77 596 93 33.

Tags:#OWASP ASVS#web application security#penetration testing#security budget#Amsterdam#CIO#business application#SME cybersecurity
Share:

Mohamed Bah

Fondateur, Kolonell

Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.