The verdict in three sentences
For a business application with 2,000 customer accounts, a 5 to 6 day grey-box pentest (about EUR 6,000 to 8,000 excl. VAT) is usually enough to produce a report an enterprise procurement team will accept. The real budget line is often OWASP remediation, which can double the bill if the application has never been tested. Plan an annual test with a retest included, especially if your client or your sector falls under NIS2.
What a web application pentest costs in 2026
Price depends mostly on tester days, which depend on scope: number of user roles, exposed APIs and sensitive flows (payment, data export, administration). In Dublin and across Western Europe, a qualified tester's day rate sits between EUR 1,000 and 1,500 excl. VAT.
| Test type | Duration | 2026 price (excl. VAT) | Best for |
|---|---|---|---|
| Automated scan + light manual review | 1 to 2 days | EUR 1,500 to 3,000 | Brochure site, first look |
| Black-box pentest (no account) | 3 to 4 days | EUR 3,500 to 6,000 | Public surface only |
| Grey-box pentest (test accounts provided) | 4 to 8 days | EUR 4,000 to 12,000 | Business app, client portal |
| Grey-box pentest + REST API | 6 to 10 days | EUR 8,000 to 15,000 | SaaS with public API |
| Targeted source code review | 3 to 6 days | EUR 4,000 to 9,000 | Critical modules (auth, payment) |
| CREST-accredited provider | 5 to 10 days | EUR 9,000 to 20,000 | Regulated sectors, public bodies |
| Retest after fixes | 1 to 2 days | EUR 1,000 to 2,500 | Required to close the report |
Grey-box testing is the best value for an SME: the tester gets an account for each role and checks what a malicious customer or a compromised account could do. That is exactly what enterprise security questionnaires ask about.
What OWASP Top 10 fixes cost
The report ranks vulnerabilities by severity (critical, high, medium, low). Remediation cost varies widely with the application's architecture and technical debt.
| OWASP 2021 category | Common example | Fix effort | Indicative cost (excl. VAT) |
|---|---|---|---|
| A01 Broken access control | A customer reads another customer's invoices via the URL ID | 3 to 8 days | EUR 2,000 to 6,000 |
| A02 Cryptographic failures | SHA-1 passwords, cookies without Secure flag | 1 to 3 days | EUR 800 to 2,500 |
| A03 Injection | Concatenated SQL query in an export | 1 to 4 days | EUR 800 to 3,000 |
| A05 Security misconfiguration | Missing CSP headers, debug mode on | 0.5 to 2 days | EUR 400 to 1,500 |
| A06 Vulnerable components | Framework not updated for 3 years | 3 to 15 days | EUR 2,500 to 10,000 |
| A07 Authentication failures | No rate limiting, no admin MFA | 2 to 4 days | EUR 1,500 to 3,000 |
| A09 Logging failures | No trace of admin logins | 2 to 3 days | EUR 1,500 to 2,500 |
2026 ballpark: an application that has never been tested often shows 1 to 3 high and 5 to 10 medium findings, meaning EUR 3,000 to 15,000 in fixes. Upgrading an outdated framework (A06) is the least predictable line.
NIS2, enterprise clients and testing frequency
The NIS2 directive, transposed into Irish and other EU national laws, requires essential and important entities (transport, health, energy, digital, manufacturing above 50 staff or EUR 10M turnover) to manage risk in a documented way, including across their supply chain. In practice, even if your company is not directly in scope, your clients are, and they ask for evidence: a pentest report under 12 months old, a dated remediation plan, a password policy and a 24-hour incident notification procedure.
| Common procurement questionnaire requirement | Evidence to provide | Time to produce it |
|---|---|---|
| Recent penetration test | Executive summary under 12 months old | 3 to 6 weeks |
| Critical findings fixed | Retest certificate | 2 to 4 weeks after fixes |
| Data encryption | TLS 1.2+ and encryption at rest description | 1 week |
| Tested backups | Procedure and date of last restore test | 1 to 2 weeks |
| Access management | Admin MFA, quarterly account review | 2 to 3 weeks |
Ask the tester for a two-part report: a 3 to 5 page executive summary you can share with the client, and a detailed technical report kept for your team.
Need a professional website?
Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.
Mini case study
Ciarán, CIO of a Dublin logistics software SME, runs a portal with 2,000 customer accounts. A retail group requires a pentest report before signing a EUR 180,000 per year contract. Budget: 6-day grey-box pentest at EUR 1,250, i.e. EUR 7,500 excl. VAT, fixes for 2 high findings (access control and outdated framework) and 6 medium ones for EUR 9,000, retest at EUR 1,500. Total: EUR 18,000 excl. VAT, 10% of the contract's first year. Time from order to final certificate: 9 weeks.
FAQ
Do I need an accredited provider for a web app pentest?
Not unless you are a public body or critical operator, or your client requires it contractually. Accredited providers often charge 30 to 60% more for a similar methodology.
How often should we run a security test?
At least once a year, and after any major change (new payment module, new API). Enterprise clients rarely accept a report older than 12 months.
How long does a pentest take end to end?
Allow 1 to 2 weeks of scoping, 4 to 8 days of testing, then 5 to 10 working days for the report. With fixes and retest, plan 6 to 10 weeks.
Can testing happen in production?
It is possible in grey-box mode with dedicated accounts, but an identical staging environment is better. It removes any risk to the 2,000 real accounts and rarely costs more than EUR 200 per month in hosting.
Is an automated scan enough for a security questionnaire?
Rarely. A EUR 1,500 scan catches misconfigurations but not access control flaws, which are OWASP's top category.
Let's scope your project. We scope your test, price the OWASP fixes and deliver a report your clients will accept within 6 to 10 weeks, for EUR 8,000 to 25,000 excl. VAT depending on the application. Detailed quote within 48 h. WhatsApp +221 77 596 93 33.
Mohamed Bah
Fondateur, Kolonell
Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.