The verdict in three sentences
A security audit / pentest of a web application is budgeted at 6,000 to 20,000 EUR in Dublin in 2026, depending on scope and test depth. A code review (3,500-8,000 EUR) complements the pentest by catching flaws at the source, and the re-test after fixes costs about 30 % of the initial audit. Plan 2 to 4 weeks, coverage of the OWASP Top 10, and an attestation you can use to reassure an enterprise client or answer a tender.
Audit types and their 2026 prices
The price depends mainly on how much information the auditor is given: the less they know, the more the test simulates a real attacker, but the longer it takes.
| Audit type | Approach | 2026 price (EUR) |
|---|---|---|
| Black box | No access, like an external attacker | 6,000 - 10,000 |
| Grey box | User accounts provided | 9,000 - 15,000 |
| White box | Code + architecture access | 12,000 - 20,000 |
| Dedicated code review | Static + manual analysis | 3,500 - 8,000 |
| Re-test after fixes | Verifying the fixes | ~30 % of audit |
| Continuous audit (subscription) | Periodic scans + pentest | 800 - 2,500 EUR/month |
Grey box is the best value for a business app with authentication: the auditor tests access rights and application flaws without starting from scratch.
What the audit covers and the expected deliverables
A good audit is not just an automated scan. Here is what should be in scope and in the deliverables in 2026.
| Element | Content | Expected |
|---|---|---|
| OWASP Top 10 | Injection, XSS, broken auth, etc. | Mandatory |
| Prioritised report | Flaws by severity (CVSS) | Mandatory |
| Exploitation proof | Screenshots, reproduction steps | Recommended |
| Remediation guidance | Concrete fix per flaw | Mandatory |
| Post-fix re-test | Validating the corrections | Recommended |
| Security attestation | Document for clients/tenders | As needed |
Without a prioritised report and concrete recommendations, an audit is useless: your developers must know what to fix first and how.
Need a professional website?
Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.
Mini case study
Declan, IT director of a services SME in Dublin, must secure an application that handles customer data before signing a contract with a large group that requires an attestation. He opts for a grey-box audit at 12,500 EUR over 3 weeks, including OWASP Top 10 and a partial code review. The audit reveals 3 critical and 7 medium flaws. Fixes are done in-house, then a re-test at 3,800 EUR validates the corrections and delivers the attestation. Total cost: 16,300 EUR to secure a contract estimated at 180,000 EUR/year, less than 10 % of the contract's first-year revenue.
FAQ
Black, grey or white box? Grey box (accounts provided) is the best compromise for an app with authentication at 9,000-15,000 EUR. White box, pricier, is justified for a critical app or a review before a major release.
Do I need a code review on top of the pentest? The pentest tests the running app; the code review catches flaws at the source. The two are complementary; add the review (3,500-8,000 EUR) for sensitive applications.
How much does the re-test after fixes cost? About 30 % of the initial audit cost. It confirms your fixes work and lets you deliver a credible attestation for your clients or tenders.
Does an audit guarantee full security? No: it photographs the security state at a given moment. For an evolving app, a continuous subscription audit (800-2,500 EUR/month) maintains the level over time.
How long does an audit take? Plan 2 to 4 weeks depending on scope, between kick-off, testing, report writing and debrief. The re-test adds about a week.
Let's scope your project. Tell us the scope to audit, the sensitivity of the data and the deadline (contract, tender), and we will price the audit and the re-test. Detailed quote within 48 h. WhatsApp +221 77 596 93 33.
Mohamed Bah
Fondateur, Kolonell
Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.
