The verdict in three sentences
A security audit + pentest of a web application costs between €4,000 and €14,000 in Amsterdam in 2026, depending on whether you run an automated review or a deep manual intrusion test. The real deliverable isn't the raw vulnerability list but a CVSS-scored report with a prioritised, re-testable remediation roadmap. Recommended cadence: every major release and at minimum once a year for an app handling personal data.
What an audit covers, and at what price
Not all "audits" are equal. An automated scan catches known flaws; a manual pentest hunts the logic flaws tools miss. Here are 2026 tiers on the Amsterdam market.
| Audit level | Scope | Price (€) | Duration |
|---|---|---|---|
| Automated scan | OWASP Top 10, dependencies | 4,000 - 6,000 | 3-5 days |
| Black-box pentest | External attack, no access | 6,000 - 9,000 | 5-8 days |
| Grey-box pentest | With user accounts | 8,000 - 11,000 | 8-12 days |
| Full audit + code review | White-box, GDPR included | 11,000 - 14,000 | 12-18 days |
| Post-remediation re-test | Fix verification | 1,500 - 3,000 | 2-3 days |
The re-test is essential: fixing without re-checking risks an incomplete patch. A serious audit always includes a re-test of critical flaws.
What a pentest hunts: OWASP Top 10 and beyond
A good intrusion test follows a framework (OWASP) but goes further on business logic. Here are the most frequently found flaw categories and their typical severity.
| Flaw category | 2026 frequency | Typical CVSS severity |
|---|---|---|
| Broken access control | Very common | 7.0 - 9.0 (high/critical) |
| Injection (SQL, XSS) | Common | 6.5 - 9.0 |
| Security misconfiguration | Very common | 5.0 - 7.5 |
| Weak authentication | Common | 6.0 - 8.5 |
| Sensitive data exposure | Medium | 6.0 - 8.0 |
| Outdated components | Very common | 5.0 - 9.0 |
The CVSS score (0 to 10) drives prioritisation: fix remotely exploitable flaws ≥ 7.0 first, before cosmetic alerts. A pro report ranks each flaw by score, fix effort and business impact.
Mini case study
Lars, IT director of a healthcare SME in Amsterdam, had to ship an app managing patient records — sensitive data under GDPR. He commissioned a grey-box pentest at €9,800. The report revealed 3 critical flaws (including a broken access control letting one account read other accounts' records, CVSS 8.6). Remediation cost: 4 dev days, roughly €3,000. Compare that to a GDPR breach: a possible fine up to 4 % of turnover plus lost patient trust. The audit turned a six-figure risk into a controlled €12,800 spend.
Need a professional website?
Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.
FAQ
How often should we pentest?
Every major release and at minimum once a year. An app handling sensitive data or processing payments should be tested at every significant change to its scope.
Pentest or just an automated scan?
The scan (€4,000-€6,000) catches known flaws and outdated dependencies. The manual pentest (€6,000+) finds business-logic flaws — access control, privilege escalation — that tools can't see.
What is the CVSS score?
A 0-to-10 scale rating a flaw's severity by exploitability and impact. It drives remediation priority: fix critical flaws (≥ 9.0) first, then high (7.0-8.9).
Does the audit cover GDPR?
A full audit reviews personal-data processing: encryption, retention periods, consent, logging. It's essential before shipping an app subject to GDPR.
Do we re-test after fixing?
Yes. The re-test (€1,500-€3,000) confirms fixes actually close the flaws without introducing new ones. Fixing without re-checking leaves an uncontrolled risk.
Let's scope your project. Tell us your application (stack, data processed, go-live deadline) and we'll frame the audit scope to your risk level. Detailed quote within 48 h. WhatsApp +221 77 596 93 33.
Mohamed Bah
Fondateur, Kolonell
Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.
