The verdict in three sentences
Once a business application is exposed to external customers, an enterprise client will sooner or later ask for a recent pentest report and a remediation plan. In London in 2026, a grey-box penetration test costs 8,000 to 25,000 GBP excluding VAT, with 3,000 to 18,000 GBP of fixes depending on the age of the code. Good governance means setting aside 8 to 15% of the application's cost for security every year, rather than reacting to a supplier audit questionnaire.
What a pentest costs in 2026
Price depends on scope (number of roles, APIs, screens), test type and the provider's accreditation. CREST-accredited testers are often required by enterprise and public sector buyers in the UK.
| Test type | Typical scope | Duration | Budget excl. VAT |
|---|---|---|---|
| Automated scan + review (non-accredited) | Simple application | 1 to 2 days | 1,500 to 3,500 GBP |
| Black-box pentest | External surface, no account | 3 to 5 days | 4,500 to 8,500 GBP |
| Grey-box pentest | 2 to 4 user roles, APIs | 5 to 10 days | 8,000 to 16,000 GBP |
| Grey-box pentest, CREST provider | Same, report accepted by enterprise buyers | 6 to 14 days | 10,000 to 25,000 GBP |
| Targeted source code review | Authentication, permissions, payments | 4 to 8 days | 5,500 to 12,000 GBP |
| Retest after fixes | Verify vulnerabilities are closed | 1 to 2 days | 1,200 to 3,000 GBP |
A pentester day typically costs 1,100 to 1,800 GBP in London.
OWASP Top 10: what testers actually find
The OWASP Top 10 remains the standard reference. On SME business applications, some vulnerability families come up almost every time.
| OWASP category | Concrete example in a business app | Observed frequency | Fix cost excl. VAT |
|---|---|---|---|
| A01 Broken access control | A customer sees another's invoices by changing the ID in the URL | Very common | 2,000 to 7,500 GBP |
| A02 Cryptographic failures | Weakly hashed passwords, poor TLS configuration | Common | 500 to 2,800 GBP |
| A03 Injection | Search field vulnerable to SQL injection | Less common with ORMs | 1,000 to 4,500 GBP |
| A05 Security misconfiguration | Missing security headers, debug mode on | Very common | 300 to 1,400 GBP |
| A06 Vulnerable components | Libraries 3 years out of date | Common | 1,500 to 9,000 GBP |
| A07 Authentication failures | No rate limiting, no admin 2FA | Common | 1,000 to 3,800 GBP |
| A09 Logging failures | No trace of access to sensitive data | Common | 1,500 to 4,500 GBP |
Building the annual security budget
For an application that cost 120,000 GBP, an annual budget of 10,000 to 18,000 GBP generally covers:
- an annual grey-box pentest and its retest;
- quarterly dependency updates and patches;
- vulnerability monitoring (scanner, alerts) and log review;
- one backup restore exercise per year.
Cyber Essentials and enterprise requirements
In the UK, Cyber Essentials Plus certification (around 1,500 to 4,000 GBP for an SME) is increasingly a baseline in supplier questionnaires, and EU clients subject to the NIS 2 directive pass their obligations down contractually: proof of testing, fix deadlines, incident notification within 24 hours.
Need a professional website?
Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.
Mini case study
James, CTO of a 120-staff aviation services SME in London, opens a business portal to 2,000 customers. An enterprise client requires a pentest report less than 12 months old before renewing a contract worth 400,000 GBP a year.
The grey-box pentest by a CREST provider costs 15,000 GBP and uncovers 2 critical access control flaws and 6 medium issues. Fixes cost 9,000 GBP and the retest 2,000 GBP, 26,000 GBP in total. Against the secured contract, the investment equals 6.5% of a single year of that client's revenue, not counting the avoided cost of a data breach, estimated at several hundred thousand pounds for an SME.
FAQ
How often should we run a pentest?
At least once a year, and after every major change (new module, new API, authentication change). Enterprise clients often ask for a report under 12 months old.
Is an automated scan enough?
No. It mostly catches misconfigurations and outdated components but misses access control flaws, which make up most critical issues in business applications.
Do we need a CREST-accredited provider?
It is only mandatory in some contexts (public sector, regulated firms), but a CREST report is more readily accepted by enterprise buyers. The premium is around 20 to 30%.
Can the app's developer run the pentest?
No, the test must be independent. The development team does handle the fixes, ideally within 30 days for critical issues.
Let's scope your project. Describe your application, its roles and APIs: we will price the audit, the fixes and an annual security budget, ballpark 10,000 to 35,000 GBP in year one. Detailed quote within 48 h. WhatsApp +221 77 596 93 33.
Mohamed Bah
Fondateur, Kolonell
Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.