The verdict in three sentences
An application pentest for a mid-market firm in Amsterdam costs between 6,000 and 20,000 EUR in 2026 depending on the surface tested, with report, remediation plan and re-test included. The baseline reference remains the OWASP Top 10 (injection, authentication, access control, data exposure). Budget 2 to 3 weeks: a modest investment against the cost of an incident (outage, data exfiltration, regulatory fine).
Pentest pricing grid in 2026
Price depends on scope, depth (black, grey, white box) and the number of roles to test.
| Audit type | Typical scope | 2026 order of magnitude (EUR) | Timeline |
|---|---|---|---|
| Standard app pentest | 1 web app, 2-3 roles | 6,000 - 12,000 | 2 weeks |
| Deep pentest | App + API + back office | 12,000 - 20,000 | 3 weeks |
| Code audit (review) | Source code security review | 8,000 - 18,000 | 2-3 weeks |
| Architecture audit | Cloud, network, segmentation | 7,000 - 15,000 | 2 weeks |
| External intrusion test | Internet-facing perimeter | 5,000 - 12,000 | 1-2 weeks |
| Post-fix re-test | Verify remediations | often included | 2-4 days |
A mid-market firm shipping a new application usually picks the deep app pentest (app + API), since the back office is often where access-control flaws hide.
What the OWASP Top 10 covers
The report ranks vulnerabilities by severity with an action plan. Here are the most commonly found categories and their impact.
| OWASP category | Concrete example | Potential impact |
|---|---|---|
| Broken access control | Access to another account's data | Customer data leak |
| Injection (SQL, etc.) | Unfiltered query | Database theft/tampering |
| Cryptographic failures | Sensitive data in clear text | GDPR exposure |
| Security misconfiguration | Missing header, exposed service | Takeover |
| Weak authentication | No attempt limit | Compromised accounts |
| Vulnerable components | Outdated library | Known exploit |
Each vulnerability is rated (critical / high / medium / low) with an actionable recommendation, so you can prioritize fixes.
Need a professional website?
Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.
Mini case study
Nadia, CISO of a 400-employee industrial mid-market firm in Amsterdam. Before shipping a client portal handling 15,000 accounts, she orders a deep pentest (chosen budget: 15,000 EUR). The audit reveals 2 critical flaws (access control and injection) and 5 medium ones. Fix, then re-test included. By contrast, exfiltration of the 15,000 accounts would trigger a regulator notification, incident-response costs and a potential fine: in crisis management and lost trust alone, the order of magnitude exceeds 150,000 - 300,000 EUR. The audit cost / risk avoided ratio is around 1 to 10 or 1 to 20.
FAQ
Black, grey or white box: how does price differ? In white box (with code and account access), the tester goes faster and deeper, so better value. Black box simulates an external attacker but covers less surface at equal budget.
Is the re-test really included? With a serious provider, yes: after your fixes, a verification confirms the flaws are closed. Require it in the quote; it is what truly validates the fix.
How often should we redo a pentest? At least once a year and systematically before every major release or architecture change. Budget 6,000 to 20,000 EUR per campaign depending on scope.
Does an audit guarantee zero flaws? No: it strongly reduces risk by finding known, exploitable vulnerabilities at test time. Security is a continuous process, not a permanent certificate.
Should we warn the host before testing? Yes, written authorization and a test window are essential, especially on cloud infrastructure, to avoid automatic blocking during the engagement.
Let's scope your project. Share the scope to test (app, API, back office), the number of roles and your go-live date. Detailed quote within 48 h. WhatsApp +221 77 596 93 33.
Mohamed Bah
Fondateur, Kolonell
Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.
