The verdict in three sentences
A grey-box penetration test on a SaaS web application costs between EUR 5,000 and 15,000 excluding VAT in 2026, for 5 to 10 audit days. For a scale-up in Berlin that wants to sign enterprise accounts, this report, ideally produced by a certified provider (BSI-listed in Germany, PASSI in France, CREST internationally), is now required by buyers' security questionnaires. The real cost is not the pentest but the remediation, to be budgeted upfront at 30 to 80% of the audit price.
How much a pentest costs by scope
Price depends on three variables: the number of user roles, the API surface and how much information the auditor receives. Grey box (test accounts provided, partial API documentation) gives the best coverage-to-price ratio for a B2B SaaS.
| Scope | Approach | Audit days | 2026 price excl. VAT (order of magnitude) |
|---|---|---|---|
| Marketing site + form | Black box | 2 to 3 | EUR 2,000 to 4,000 |
| Web app, 2 roles | Grey box | 5 | EUR 5,000 to 7,000 |
| B2B SaaS, 4 roles + REST API | Grey box | 7 to 8 | EUR 8,000 to 11,000 |
| Multi-tenant SaaS + public API | Grey box | 10 | EUR 12,000 to 15,000 |
| Web + mobile + API | Grey box | 12 to 15 | EUR 16,000 to 22,000 |
| Retest after fixes | Targeted | 1 to 2 | EUR 1,200 to 2,500 |
A certified provider charges on average 10 to 20% more than an uncertified firm, with day rates of EUR 1,000 to 1,400. Certification is rarely mandatory for a private SaaS, but it reassures public buyers, banks and critical infrastructure operators.
The method: what a serious audit covers
The baseline remains the OWASP Top 10 (2021 edition, updated 2025), complemented by the OWASP API Security Top 10 for platforms exposing APIs. A serious audit runs in five steps.
| Step | Content | Share of time |
|---|---|---|
| Scoping | Scope, test accounts, testing window, written authorization | 5% |
| Reconnaissance | Mapping routes, subdomains and APIs | 15% |
| Authentication and authorization tests | IDOR, privilege escalation, cross-tenant leaks | 35% |
| Injection and business logic tests | SQL, XSS, SSRF, payment bypass | 30% |
| Report and debrief | CVSS score, evidence, prioritized fixes | 15% |
On a multi-tenant SaaS, the critical point is tenant isolation: in the audits we see, more than one pentest in three reveals at least one IDOR-type authorization flaw that lets a user read another customer's data. That is exactly the flaw that kills a due diligence.
Data breach versus pentest: the math
The average cost of a data breach reaches USD 4.4 million worldwide according to the IBM 2025 study. For a 40-person scale-up the risk looks different: a lost enterprise contract, a GDPR notification within 72 hours, fines up to 4% of global revenue, and churn among existing customers.
| Item | Without pentest (incident) | With annual pentest |
|---|---|---|
| Direct cost | EUR 150,000 to 500,000 (SME) | EUR 8,000 to 15,000 |
| Enterprise sales cycle | Blocked at the security questionnaire | Report shared within 48 h |
| Remediation | Emergency, premium day rates | Planned in a sprint |
| Cyber insurance | Higher premium or refusal | Standard premium |
| Reputation | Crisis communication | Sales argument |
The remediation plan
A report without an action plan is useless. We recommend fixing critical and high findings within 15 days, medium ones within 60 days, then ordering a targeted retest to get a clean attestation for prospects. At Kolonell, remediation on an application we built usually takes 3 to 8 development days.
Need a professional website?
Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.
Mini case study
Lena, CISO of a 45-person HR tech scale-up in Berlin, must answer the security questionnaire of a DAX group for a contract worth EUR 180,000 per year. She orders an 8-day grey-box pentest at EUR 9,600. Result: 2 critical flaws (IDOR on employee record export), 4 high, 7 medium. Remediation: 6 development days at EUR 650, i.e. EUR 3,900, then a retest at EUR 1,800. Total: EUR 15,300, or 8.5% of the first year of the contract signed three months later.
FAQ
Is a certified pentest mandatory to sell to an enterprise account?
No, except for some public or critical infrastructure buyers. In practice about 1 enterprise buyer in 2 values it, and certification costs 10 to 20% more.
When should the pentest happen: before or after launch?
Before sensitive features go live, ideally 3 to 4 weeks before launch to leave 15 days for fixes. Then one audit per year or at each major rebuild.
What is the difference between an automated scan and a penetration test?
A scanner at EUR 100 to 500 per month detects known flaws but misses business logic and authorization. A manual pentest finds on average 3 to 5 times more exploitable flaws.
How long does a 5 to 10 day pentest take on the calendar?
Allow 2 to 3 weeks from signature to final report, including 1 to 2 weeks of testing and 3 to 5 days of writing.
Should you test in production?
Preferably on a staging environment identical to production, with anonymized data. That avoids any risk of downtime for your customers.
Let's scope your project. We prepare your application for the pentest, fix the findings and coordinate the audit with a certified provider, indicative budget EUR 8,000 to 20,000 including remediation, over 4 to 6 weeks. Detailed quote within 48 h. WhatsApp +221 77 596 93 33.
Mohamed Bah
Fondateur, Kolonell
Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.