The verdict in three sentences
Securing and making a custom web app GDPR-compliant costs, in 2026, between 6,000 and 20,000 EUR for audit and pentest, plus encryption, logging and EU hosting. The timeline is short: 3 to 6 weeks before go-live. Against a CNIL fine that can reach 20M EUR or 4% of global turnover, this investment is insurance, not needless cost.
How much does securing a business app cost?
The budget depends on data sensitivity, user volume and the required audit level (internal vs certified external pentest).
| Service | Content | 2026 cost (EUR) | Timeline |
|---|---|---|---|
| Security audit | Code + config + architecture review | 4,000 - 9,000 | 1-2 wks |
| Pentest (intrusion test) | Simulated grey-box attack | 6,000 - 15,000 | 1-2 wks |
| GDPR compliance | Register, notices, DPA, consent | 5,000 - 12,000 | 2-3 wks |
| Encryption & logging | At rest + in transit + logs | 3,000 - 7,000 | 1-2 wks |
| Certified France/EU hosting | HDS/SecNumCloud if health | 250 - 900/mo | ongoing |
A reasonable baseline for an SME (audit + pentest + GDPR compliance) sits around 15,000 EUR in 2026.
Costed security / GDPR checklist
| Item | Mandatory? | Indicative cost (EUR) |
|---|---|---|
| Data encryption at rest and in transit | Yes | 3,000 - 7,000 |
| Strong authentication (2FA) | Recommended | 2,000 - 4,000 |
| Logging & audit trail | Yes | included / 3,000 - 6,000 |
| Records-of-processing register | Yes | included in compliance |
| Retention & purge policy | Yes | 1,500 - 3,000 |
| DPA with sub-processors | Yes | 1,000 - 2,500 |
| Encrypted backups + recovery plan | Yes | 2,000 - 5,000 |
| Annual renewal pentest | Recommended | 6,000 - 15,000/yr |
Logging and the records-of-processing register are often neglected, yet they are the first items requested during a CNIL inspection.
Mini case study
Nadia, DPO of a healthcare SME in Bordeaux (45 employees), must go live with a patient-tracking app handling health data. She budgets 17,000 EUR: audit, pentest, GDPR compliance, encryption, plus HDS hosting at 700 EUR/month.
The risk avoided is major: a health-data breach exposes her to a CNIL fine and a loss of trust worth hundreds of thousands of euros. Against turnover (3.2M EUR), a fine capped at 4% would reach 128,000 EUR. The 17,000 EUR of compliance represents 13% of that maximum risk: the trade-off is obvious, before counting the legal HDS requirement for health.
Need a professional website?
Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.
FAQ
Is an internal audit enough or do we need an external pentest?
An internal audit catches configuration mistakes; an external pentest simulates a real attack and reveals flaws the team no longer sees. For an app handling sensitive data, both are recommended.
Is France hosting mandatory?
Not for all data, but the EU is in practice for GDPR. For health data in France, certified HDS hosting is mandatory (250-900 EUR/month depending on volume).
How much does GDPR non-compliance cost in 2026?
Fines can reach 20M EUR or 4% of annual global turnover, whichever is higher. Beyond the fine, reputation and contract loss often weigh more.
How often should we redo a pentest?
At least once a year and after any major app change. Budget 6,000 to 15,000 EUR per campaign, to include in the annual maintenance budget.
Does GDPR slow down go-live?
Well anticipated, no: 3 to 6 weeks suffice in parallel with development. It is handling it after the fact, in a rush, that costs money and delays launch.
Let's scope your project. Tell us your data sensitivity (health, financial...), user volume and go-live date, and we'll price audit, pentest and compliance. Detailed quote within 48h. WhatsApp +221 77 596 93 33.
Mohamed Bah
Fondateur, Kolonell
Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.
