The verdict in three sentences
A security audit of a B2B web app costs between 6 000 and 18 000 EUR in Amsterdam in 2026, depending on scope and pentest depth. An audit without a retest after remediation proves nothing: fixing and re-verification must be budgeted in the quote from the start. Budget 2 to 4 weeks and expect a remediation cost often equal to 40-80 % of the audit cost.
Scope and its cost
The price of an audit depends directly on what you test. Here are the 2026 ballpark figures for an SME in Amsterdam.
| Scope | Content | Time | Cost (EUR) |
|---|---|---|---|
| OWASP Top 10 (web) | Injections, XSS, CSRF, config | 4-6 d | 3 500 - 7 000 |
| Authentication / sessions | MFA, JWT, role management | 2-4 d | 2 000 - 4 500 |
| REST/GraphQL API | Auth, quotas, data exposure | 3-5 d | 2 500 - 6 000 |
| Infrastructure / config | Headers, TLS, secrets, CI/CD | 2-3 d | 1 500 - 4 000 |
| Authenticated pentest | Privilege escalation | 3-5 d | 3 000 - 7 000 |
| Targeted code review | Critical points | 2-4 d | 2 000 - 5 000 |
A full go-live audit combines OWASP, auth and API, typically 6 000-12 000 EUR; adding the authenticated test and code review pushes towards 18 000 EUR.
Severity levels and remediation cost
A good report classifies each vulnerability by severity with a costed fix effort. That is what enables trade-offs.
| Severity | Typical example | Fix deadline | Remediation cost (EUR) |
|---|---|---|---|
| Critical | SQL injection, auth bypass | Immediate | 1 500 - 4 000 |
| High | Privilege escalation, IDOR | < 1 week | 1 000 - 3 000 |
| Medium | Stored XSS, CSRF | 2-4 weeks | 600 - 2 000 |
| Low | Missing headers, verbose | Best effort | 300 - 1 000 |
| Informational | Best practices | Optional | 0 - 500 |
The retest after remediation typically costs 1 000 to 3 000 EUR and must always be included: without it, you have no proof the flaws are closed.
GDPR compliance and continuous security
Need a professional website?
Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.
A one-off audit is not enough if the app changes every month. Security is managed over time, especially with B2B personal data.
| Measure | Goal | Cost (EUR) |
|---|---|---|
| GDPR register + analysis | Data mapping | 1 500 - 4 000 |
| Monthly automated scan | Continuous detection | 200 - 600 /mo |
| Annual audit | Deep verification | 5 000 - 12 000 /yr |
| Incident response plan | Procedure + contacts | 1 500 - 3 500 |
| Dev team training | Secure coding | 1 200 - 3 000 |
Mini case study
Sophie, CISO of a 60-person SaaS SME in Amsterdam, must secure an app before go-live handling sensitive customer data. She orders an OWASP + auth + API audit for 9 500 EUR. The report reveals 2 critical flaws, 3 high and 6 medium; remediation costs 5 200 EUR and the retest 1 800 EUR, a total of 16 500 EUR. A single critical flaw (an IDOR exposing other customers' invoices) could have triggered a data breach; with the average cost of a GDPR notification and incident handling often above 50 000 EUR, the audit pays for itself on the first flaw avoided.
FAQ
Black-box or white-box pentest? Black-box simulates an external attacker with no access; white-box provides the code and accounts. White-box finds more flaws at a similar cost: it is usually the best choice before go-live.
Is an audit needed at every release? No, but a monthly automated scan plus a full annual audit is enough for most SMEs. A major rebuild or adding payments justifies a dedicated audit.
Is the retest really essential? Yes. Without a retest you do not know whether fixes are effective or whether they introduced new flaws. An audit without a retest is incomplete.
Does the audit cover GDPR compliance? Partly: it covers the technical security of data. Legal compliance (register, notices, processors) is a complementary strand at 1 500-4 000 EUR.
How long is an audit valid? Technically, until the next significant code change. In practice, an audit older than 12 months on an active app is considered stale.
Let's scope your project. Tell us the scope to audit (web, API, authentication), the technology and the go-live date for a quote between 6 000 and 18 000 EUR, retest included. Detailed quote within 48 h. WhatsApp +221 77 596 93 33.
Mohamed Bah
Fondateur, Kolonell
Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.
