Websites11 min read

Web Application Penetration Test Cost in Dublin: Pricing and OWASP Remediation

Mohamed Bah·Fondateur, Kolonell
October 6, 2026
Share:
Web Application Penetration Test Cost in Dublin: Pricing and OWASP Remediation

Web Application Penetration Test Cost in Dublin: Pricing and OWASP Remediation

Websites

The verdict in three sentences

For a business application with 2,000 customer accounts, a 5 to 6 day grey-box pentest (about EUR 6,000 to 8,000 excl. VAT) is usually enough to produce a report an enterprise procurement team will accept. The real budget line is often OWASP remediation, which can double the bill if the application has never been tested. Plan an annual test with a retest included, especially if your client or your sector falls under NIS2.

What a web application pentest costs in 2026

Price depends mostly on tester days, which depend on scope: number of user roles, exposed APIs and sensitive flows (payment, data export, administration). In Dublin and across Western Europe, a qualified tester's day rate sits between EUR 1,000 and 1,500 excl. VAT.

Test typeDuration2026 price (excl. VAT)Best for
Automated scan + light manual review1 to 2 daysEUR 1,500 to 3,000Brochure site, first look
Black-box pentest (no account)3 to 4 daysEUR 3,500 to 6,000Public surface only
Grey-box pentest (test accounts provided)4 to 8 daysEUR 4,000 to 12,000Business app, client portal
Grey-box pentest + REST API6 to 10 daysEUR 8,000 to 15,000SaaS with public API
Targeted source code review3 to 6 daysEUR 4,000 to 9,000Critical modules (auth, payment)
CREST-accredited provider5 to 10 daysEUR 9,000 to 20,000Regulated sectors, public bodies
Retest after fixes1 to 2 daysEUR 1,000 to 2,500Required to close the report

Grey-box testing is the best value for an SME: the tester gets an account for each role and checks what a malicious customer or a compromised account could do. That is exactly what enterprise security questionnaires ask about.

What OWASP Top 10 fixes cost

The report ranks vulnerabilities by severity (critical, high, medium, low). Remediation cost varies widely with the application's architecture and technical debt.

OWASP 2021 categoryCommon exampleFix effortIndicative cost (excl. VAT)
A01 Broken access controlA customer reads another customer's invoices via the URL ID3 to 8 daysEUR 2,000 to 6,000
A02 Cryptographic failuresSHA-1 passwords, cookies without Secure flag1 to 3 daysEUR 800 to 2,500
A03 InjectionConcatenated SQL query in an export1 to 4 daysEUR 800 to 3,000
A05 Security misconfigurationMissing CSP headers, debug mode on0.5 to 2 daysEUR 400 to 1,500
A06 Vulnerable componentsFramework not updated for 3 years3 to 15 daysEUR 2,500 to 10,000
A07 Authentication failuresNo rate limiting, no admin MFA2 to 4 daysEUR 1,500 to 3,000
A09 Logging failuresNo trace of admin logins2 to 3 daysEUR 1,500 to 2,500

2026 ballpark: an application that has never been tested often shows 1 to 3 high and 5 to 10 medium findings, meaning EUR 3,000 to 15,000 in fixes. Upgrading an outdated framework (A06) is the least predictable line.

NIS2, enterprise clients and testing frequency

The NIS2 directive, transposed into Irish and other EU national laws, requires essential and important entities (transport, health, energy, digital, manufacturing above 50 staff or EUR 10M turnover) to manage risk in a documented way, including across their supply chain. In practice, even if your company is not directly in scope, your clients are, and they ask for evidence: a pentest report under 12 months old, a dated remediation plan, a password policy and a 24-hour incident notification procedure.

Common procurement questionnaire requirementEvidence to provideTime to produce it
Recent penetration testExecutive summary under 12 months old3 to 6 weeks
Critical findings fixedRetest certificate2 to 4 weeks after fixes
Data encryptionTLS 1.2+ and encryption at rest description1 week
Tested backupsProcedure and date of last restore test1 to 2 weeks
Access managementAdmin MFA, quarterly account review2 to 3 weeks

Ask the tester for a two-part report: a 3 to 5 page executive summary you can share with the client, and a detailed technical report kept for your team.

Need a professional website?

Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.

Prefer a call back?

Leave your WhatsApp number and a Kolonell expert will get back to you within 1 business day. Free, no strings attached.

Mini case study

Ciarán, CIO of a Dublin logistics software SME, runs a portal with 2,000 customer accounts. A retail group requires a pentest report before signing a EUR 180,000 per year contract. Budget: 6-day grey-box pentest at EUR 1,250, i.e. EUR 7,500 excl. VAT, fixes for 2 high findings (access control and outdated framework) and 6 medium ones for EUR 9,000, retest at EUR 1,500. Total: EUR 18,000 excl. VAT, 10% of the contract's first year. Time from order to final certificate: 9 weeks.

FAQ

Do I need an accredited provider for a web app pentest?

Not unless you are a public body or critical operator, or your client requires it contractually. Accredited providers often charge 30 to 60% more for a similar methodology.

How often should we run a security test?

At least once a year, and after any major change (new payment module, new API). Enterprise clients rarely accept a report older than 12 months.

How long does a pentest take end to end?

Allow 1 to 2 weeks of scoping, 4 to 8 days of testing, then 5 to 10 working days for the report. With fixes and retest, plan 6 to 10 weeks.

Can testing happen in production?

It is possible in grey-box mode with dedicated accounts, but an identical staging environment is better. It removes any risk to the 2,000 real accounts and rarely costs more than EUR 200 per month in hosting.

Is an automated scan enough for a security questionnaire?

Rarely. A EUR 1,500 scan catches misconfigurations but not access control flaws, which are OWASP's top category.

Let's scope your project. We scope your test, price the OWASP fixes and deliver a report your clients will accept within 6 to 10 weeks, for EUR 8,000 to 25,000 excl. VAT depending on the application. Detailed quote within 48 h. WhatsApp +221 77 596 93 33.

Tags:#security audit#pentest#OWASP#web application#NIS2#Dublin
Share:

Mohamed Bah

Fondateur, Kolonell

Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.