The verdict in three sentences
A security audit with penetration testing of a web application costs between €4,000 and €15,000 in 2026, with remediation adding €3,000 to €20,000 depending on severity. The audit covers at minimum the OWASP Top 10: injection, broken authentication, access control, sensitive data exposure. The cost/benefit is overwhelming: the average global data breach cost exceeds €4 million, before reputational damage.
What a serious audit covers
A pentest is not a mere automated scan. It combines tooling and manual analysis by an expert who thinks like an attacker. Scope is negotiated based on data criticality.
| Scope | Range | Typical duration |
|---|---|---|
| Automated scan + report | €1,500 – 3,500 | 2 – 4 days |
| Black box pentest (web app) | €4,000 – 8,000 | 5 – 8 days |
| Grey box pentest (with accounts) | €6,000 – 12,000 | 8 – 12 days |
| Code + infra + API audit | €10,000 – 15,000 | 12 – 18 days |
| Compliance audit (ISO/GDPR) | €12,000 – 20,000 | 15 – 25 days |
The grey box test, where the auditor has user accounts, reveals far more access-control flaws (privilege escalation, horizontal access) than a purely external test. It's the best coverage/price ratio for a business application.
Remediation line items
Finding flaws isn't enough: you must fix and re-verify. Here are the most common fixes and their 2026 orders of magnitude.
| Fix | Range | Priority |
|---|---|---|
| Fix injections / input validation | €1,500 – 5,000 | Critical |
| Access control rework (RBAC) | €3,000 – 8,000 | Critical |
| MFA + password policy | €1,500 – 4,000 | High |
| Encryption at rest and in transit | €2,000 – 6,000 | High |
| Logging and anomaly detection | €2,000 – 5,000 | Medium |
| Verification re-audit | €1,500 – 3,500 | Recommended |
The re-audit is essential: it confirms fixes actually close the flaws without opening new ones. Many organizations skip it and stay vulnerable despite a first report.
Need a professional website?
Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.
Mini case study
Sophie, CISO of a 60-person fintech in Amsterdam, must secure an application handling IBANs and ID documents before launch. She orders a grey box pentest at €9,500. Result: three critical flaws (horizontal access to client files, no MFA, insufficient logging). Remediation costs €12,000, plus a re-audit at €2,500, i.e. €24,000 total. Compare it to a single breach: across 40,000 clients, mandatory notification, GDPR fines (up to 4% of turnover) and lost trust would easily exceed €500,000. The investment is under 5% of that risk.
FAQ
How often should a pentest be run? At least once a year, and systematically before any major release or architecture change. Applications handling sensitive data benefit from a semi-annual test, complemented by continuous automated scans.
Black box, grey box or white box: what's the price difference? Black box (no access) costs €4,000–8,000, grey box (with accounts) €6,000–12,000, white box (with source code) up to €15,000. Grey box usually offers the best coverage/cost ratio.
Is a pentest enough for GDPR compliance? No: GDPR also requires data governance, processing records and organizational measures. The pentest documents technical security, a necessary but insufficient brick of overall compliance.
How long between audit and report? Expect 2 to 4 weeks total: 1 to 3 weeks of testing depending on scope, then 3 to 5 days writing the report with risk classification and a prioritized remediation plan.
Can you test in production safely? Yes, with precautions: scheduled window, a staging environment for destructive tests, and written agreement on scope. A serious auditor avoids any action that could alter real data.
Let's scope your project. Tell us your application type, the volume of sensitive data and your go-live deadline: we'll frame an audit scope, an indicative budget of €4,000 to €20,000 including remediation, and a timeline. Detailed quote within 48 h. WhatsApp +221 77 596 93 33.
Mohamed Bah
Fondateur, Kolonell
Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.


