The verdict in three sentences
A web app penetration test costs between 7 000 and 30 000 USD in 2026, depending on scope and how much information the tester is given. Pricing is built in person-days (700 to 1 300 USD/day), plus a retest to validate fixes. For a CIO, a pen test is not optional before a critical deployment or an ISO 27001 certification: it is the tangible proof of robustness demanded by clients and auditors.
Pen-test types and pricing
Cost depends first on the approach. In black box, the tester simulates an external attacker with no information; in white box, they have the code and access, maximising coverage. 2026 orders of magnitude.
| Pen-test type | Information provided | Cost 2026 (USD) |
|---|---|---|
| Black box | None (external attacker) | 7 000 - 12 000 |
| Grey box | Standard user accounts | 11 000 - 19 000 |
| White box | Code + access + architecture | 16 000 - 30 000 |
| Dedicated API pen test | Endpoints + documentation | 7 000 - 15 000 |
| Validation retest | Fix verification | 2 000 - 5 500 |
Cost per person-day
Most providers bill by the day. Estimating the days needed by app size lets you budget precisely. 2026 orders of magnitude.
| App size | Estimated person-days | Budget 2026 (USD) |
|---|---|---|
| Small app / API | 5 - 8 days | 7 000 - 11 000 |
| Standard business app | 8 - 14 days | 11 000 - 19 000 |
| Multi-role platform | 14 - 22 days | 19 000 - 30 000 |
| Average daily rate | — | 700 - 1 300 |
| Retest (1-3 days) | 1 - 3 days | 2 000 - 5 500 |
Mini case study
Thomas, CIO of a logistics group in Rennes, is preparing an ISO 27001 certification requiring an annual penetration test. He commissions a grey-box pen test of his carrier portal at 15 000 USD (12 person-days). Two critical flaws are found, fixed internally, then a retest at 3 300 USD confirms closure. Total: 18 300 USD, a budget line that unlocks the certification and secures the renewal of a 1.3 M USD framework contract conditioned on this security proof.
FAQ
Need a professional website?
Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.
What's the difference between a pen test and a security audit?
The pen test simulates a real, targeted attack to prove exploitability. The audit is broader (code review, configuration, compliance). They complement each other; many projects run an audit then a validation pen test.
Black box or white box: which to choose?
Grey box offers the best coverage-to-cost ratio in 2026 for most applications. White box is reserved for critical systems where maximum coverage justifies the premium.
Is the retest really necessary?
Yes, it is often required by ISO 27001 auditors. Without a retest, you fix without proof. Budget 2 000 to 5 500 USD for this short but decisive step.
How often should we run a pen test?
At least once a year and after any major architecture change. Frameworks like ISO 27001 or PCI DSS require a documented annual cadence.
Can a pen test disrupt production?
A professional tester prefers a pre-production environment, or production within defined windows and safeguards. Scope and precautions are contracted before work begins.
Let's scope your project. Tell us your application scope, preferred approach (black/grey/white box) and certification deadline: we price a pen test with retest included. Detailed quote within 48 h. WhatsApp +221 77 596 93 33.
Mohamed Bah
Fondateur, Kolonell
Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.
