Websites11 min read

Web Application Pentest (OWASP) for an SME in London: 2026 Cost

Mohamed Bah·Fondateur, Kolonell
October 8, 2026
Share:
Web Application Pentest (OWASP) for an SME in London: 2026 Cost

Web Application Pentest (OWASP) for an SME in London: 2026 Cost

Websites

The verdict in three sentences

An SME opening a customer portal to enterprise clients should budget a grey-box pentest at EUR 4,000 to 12,000 (about GBP 3,400 to 10,200), i.e. 5 to 10 days of testing against the OWASP Top 10. The real budget also includes EUR 2,000 to 8,000 of fixes and a retest, included or billed around EUR 1,000. The report is requested in close to 60% of supplier security questionnaires, so it directly gates your contracts.

Black, grey or white box: what to pay for in 2026

The test type sets audit depth and day rate. For a business application with login, grey box (the tester gets test accounts for each role) gives the best coverage for the money.

Test typeWhat the tester getsTypical duration2026 budgetUse
Black boxURL only3 to 5 daysEUR 3,000 to 6,000External attacker view, limited coverage
Grey boxAccounts per role, API docs5 to 10 daysEUR 4,000 to 12,000Standard for a customer portal
White boxSource code + architecture8 to 15 daysEUR 9,000 to 20,000Sensitive apps, health or banking data
Automated scan onlyURL access1 dayEUR 500 to 1,500Hygiene, does not replace a pentest
Retest of fixesInitial report1 to 2 daysIncluded or about EUR 1,000Proof of remediation for the client
API-only pentest (REST, GraphQL)OpenAPI spec3 to 6 daysEUR 3,500 to 8,000Partner integrations

A qualified tester's day rate sits between EUR 800 and 1,300 (roughly GBP 700 to 1,100 in London). A CREST-accredited provider costs 10 to 25% more, but some public-sector and banking clients require it.

What an OWASP pentest reveals on an SME application

On business apps built quickly, the same flaws keep coming back. The table gives a 2026 order of magnitude for frequent findings and fix costs.

OWASP Top 10 categoryConcrete exampleObserved frequencyIndicative fix cost
A01 Broken access controlA customer sees another's invoice by changing the IDVery frequentEUR 1,000 to 4,000
A02 Cryptographic failuresWeak password hashing, weak TLSFrequentEUR 500 to 2,000
A03 InjectionHand-built SQL queryMediumEUR 800 to 3,000
A05 Security misconfigurationMissing CSP headers, debug mode onVery frequentEUR 300 to 1,500
A07 Authentication failuresNo attempt limit, no MFAFrequentEUR 1,000 to 3,000
A06 Vulnerable componentsOutdated librariesFrequentEUR 500 to 2,500

Access control is the critical point of a customer portal: it is what loses a contract when a client discovers it can read a competitor's data.

How to scope the engagement and avoid overpaying

Ask for three things in writing: the exact scope (URLs, roles, APIs included), the number of tester-days and the retest policy. Prepare a staging environment with dummy data: without it, the audit is often reduced or postponed. Finally, plan the fixes at order time, since the report only has commercial value with a retest showing critical flaws closed.

Mini case study

Thomas, CIO of a 85-person logistics services SME in London, is opening a shipment-tracking portal. His largest client, worth EUR 1.2m in annual revenue, requires a pentest report before renewal.

Need a professional website?

Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.

Prefer a call back?

Leave your WhatsApp number and a Kolonell expert will get back to you within 1 business day. Free, no strings attached.

  • Grey-box pentest, 7 days: EUR 7,700
  • Fixes (2 critical access control flaws, 5 medium): EUR 4,500
  • Retest: included
  • Total: EUR 12,200

Against the secured contract, the audit represents 1% of the client's annual revenue. The same report is then reused to answer three other supplier questionnaires that year.

FAQ

Is a pentest mandatory for an SME?

There is no general legal obligation, but UK GDPR requires appropriate security measures and about 60% of enterprise questionnaires ask for a report under 12 months old.

How often should it be repeated?

Once a year, and after each major change (new module, new API). Allow 60 to 80% of the initial price for a follow-up audit.

Is an automated scan enough?

No: a EUR 500 to 1,500 scanner catches misconfigurations but misses most access control flaws, the top OWASP category.

How long does remediation take?

Usually 2 to 6 weeks for critical and medium flaws, depending on technical debt. Critical flaws should be fixed first, ideally within 15 days.

Do I need a CREST-accredited provider?

Only if your client requires it, which is common in the public sector and banking. The premium is 10 to 25%.

Let's scope your project. Tell us about your application, its user roles and your client's requirement: we will scope the pentest, fixes and retest with an indicative budget and timeline. Detailed quote within 48 h. WhatsApp +221 77 596 93 33.

Tags:#penetration testing#pentest#OWASP#web application security#SME#security audit
Share:

Mohamed Bah

Fondateur, Kolonell

Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.