The verdict in three sentences
An SME opening a customer portal to enterprise clients should budget a grey-box pentest at EUR 4,000 to 12,000 (about GBP 3,400 to 10,200), i.e. 5 to 10 days of testing against the OWASP Top 10. The real budget also includes EUR 2,000 to 8,000 of fixes and a retest, included or billed around EUR 1,000. The report is requested in close to 60% of supplier security questionnaires, so it directly gates your contracts.
Black, grey or white box: what to pay for in 2026
The test type sets audit depth and day rate. For a business application with login, grey box (the tester gets test accounts for each role) gives the best coverage for the money.
| Test type | What the tester gets | Typical duration | 2026 budget | Use |
|---|---|---|---|---|
| Black box | URL only | 3 to 5 days | EUR 3,000 to 6,000 | External attacker view, limited coverage |
| Grey box | Accounts per role, API docs | 5 to 10 days | EUR 4,000 to 12,000 | Standard for a customer portal |
| White box | Source code + architecture | 8 to 15 days | EUR 9,000 to 20,000 | Sensitive apps, health or banking data |
| Automated scan only | URL access | 1 day | EUR 500 to 1,500 | Hygiene, does not replace a pentest |
| Retest of fixes | Initial report | 1 to 2 days | Included or about EUR 1,000 | Proof of remediation for the client |
| API-only pentest (REST, GraphQL) | OpenAPI spec | 3 to 6 days | EUR 3,500 to 8,000 | Partner integrations |
A qualified tester's day rate sits between EUR 800 and 1,300 (roughly GBP 700 to 1,100 in London). A CREST-accredited provider costs 10 to 25% more, but some public-sector and banking clients require it.
What an OWASP pentest reveals on an SME application
On business apps built quickly, the same flaws keep coming back. The table gives a 2026 order of magnitude for frequent findings and fix costs.
| OWASP Top 10 category | Concrete example | Observed frequency | Indicative fix cost |
|---|---|---|---|
| A01 Broken access control | A customer sees another's invoice by changing the ID | Very frequent | EUR 1,000 to 4,000 |
| A02 Cryptographic failures | Weak password hashing, weak TLS | Frequent | EUR 500 to 2,000 |
| A03 Injection | Hand-built SQL query | Medium | EUR 800 to 3,000 |
| A05 Security misconfiguration | Missing CSP headers, debug mode on | Very frequent | EUR 300 to 1,500 |
| A07 Authentication failures | No attempt limit, no MFA | Frequent | EUR 1,000 to 3,000 |
| A06 Vulnerable components | Outdated libraries | Frequent | EUR 500 to 2,500 |
Access control is the critical point of a customer portal: it is what loses a contract when a client discovers it can read a competitor's data.
How to scope the engagement and avoid overpaying
Ask for three things in writing: the exact scope (URLs, roles, APIs included), the number of tester-days and the retest policy. Prepare a staging environment with dummy data: without it, the audit is often reduced or postponed. Finally, plan the fixes at order time, since the report only has commercial value with a retest showing critical flaws closed.
Mini case study
Thomas, CIO of a 85-person logistics services SME in London, is opening a shipment-tracking portal. His largest client, worth EUR 1.2m in annual revenue, requires a pentest report before renewal.
Need a professional website?
Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.
- Grey-box pentest, 7 days: EUR 7,700
- Fixes (2 critical access control flaws, 5 medium): EUR 4,500
- Retest: included
- Total: EUR 12,200
Against the secured contract, the audit represents 1% of the client's annual revenue. The same report is then reused to answer three other supplier questionnaires that year.
FAQ
Is a pentest mandatory for an SME?
There is no general legal obligation, but UK GDPR requires appropriate security measures and about 60% of enterprise questionnaires ask for a report under 12 months old.
How often should it be repeated?
Once a year, and after each major change (new module, new API). Allow 60 to 80% of the initial price for a follow-up audit.
Is an automated scan enough?
No: a EUR 500 to 1,500 scanner catches misconfigurations but misses most access control flaws, the top OWASP category.
How long does remediation take?
Usually 2 to 6 weeks for critical and medium flaws, depending on technical debt. Critical flaws should be fixed first, ideally within 15 days.
Do I need a CREST-accredited provider?
Only if your client requires it, which is common in the public sector and banking. The premium is 10 to 25%.
Let's scope your project. Tell us about your application, its user roles and your client's requirement: we will scope the pentest, fixes and retest with an indicative budget and timeline. Detailed quote within 48 h. WhatsApp +221 77 596 93 33.
Mohamed Bah
Fondateur, Kolonell
Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.