The verdict in three sentences
A serious grey-box pentest costs between EUR 6,000 and 18,000 in 2026 depending on scope, plus remediation (EUR 3,000-15,000) and a retest (30-40 % of the initial cost). The deliverable that matters is not the number of findings but the CVSS-prioritised action plan with actionable fixes. Expect 2 to 4 weeks, and note that some enterprise contracts now require an annual contractual pentest.
What a pentest costs in 2026
Price depends mostly on the tested scope and the approach. Here are the 2026 ranges for a B2B web application.
| Service | 2026 range (EUR) | Timeline |
|---|---|---|
| Black-box pentest (external) | 4,000 - 9,000 | 1 - 2 weeks |
| Grey-box pentest (with accounts) | 6,000 - 18,000 | 2 - 4 weeks |
| White-box pentest (+ source) | 12,000 - 30,000 | 3 - 5 weeks |
| Post-remediation retest | 30 - 40 % of initial | 3 - 5 days |
| Remediation (fixes) | 3,000 - 15,000 | 1 - 3 weeks |
Grey-box is the best coverage/price ratio: the tester has user accounts, reflecting the real risk of an attacker with legitimate access.
What a serious report contains
A credible audit is more than a vulnerability list. Here are the expected deliverables and their use.
| Deliverable | Content | Purpose |
|---|---|---|
| Executive summary | Overall risk level | Go/no-go decision |
| OWASP mapping | Findings by Top 10 | Prioritise workstreams |
| CVSS score per finding | Criticality 0-10 | Sort critical/major/minor |
| Exploitation evidence | Screenshots, requests | Convince the teams |
| Prioritised action plan | Fixes + effort | Cost the remediation |
A critical finding (CVSS ≥ 9) on an exposed application must be fixed before any go-live: it is often the condition set by an enterprise client.
Mini case study
David, CTO of a fintech in New York, must audit his application before an integration required by a banking client. He orders a grey-box pentest at EUR 12,000. The report surfaces 2 critical and 5 major findings; remediation is costed at EUR 8,000, the retest at EUR 4,000. Total budget: EUR 24,000 over 6 weeks. The target banking contract is worth EUR 320,000/year and conditions its signature on this pentest: the audit is under 8 % of the first year and directly unlocks the sale.
Need a professional website?
Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.
FAQ
Black-box, grey-box or white-box: which to choose?
Grey-box (EUR 6,000-18,000) offers the best balance: the tester has user accounts and covers the most common risk. White-box (with source access) is more thorough but twice as expensive; reserve it for highly sensitive applications.
Is remediation included in the pentest price?
No. The pentest identifies and prioritises; remediation fixes. Expect EUR 3,000 to 15,000 depending on the number and severity of findings, then a retest at 30-40 % of the initial cost to validate the fixes.
How long does an audit take?
From 2 to 4 weeks for a standard grey-box pentest, more for a wide scope or white-box. Add 1 to 3 weeks of remediation then a few days of retest.
How often should a pentest be repeated?
An annual pentest is the norm for sensitive applications, and more enterprise tenders now mandate it contractually. A retest is also recommended after any major architecture change.
What does the CVSS score mean?
It is a criticality score from 0 to 10 assigned to each finding. Above 9 (critical), the vulnerability must be fixed before go-live; between 7 and 9 (major), quickly; below that, per the action plan.
Let's scope your project. Tell us your application's scope, your client requirements and your go-live deadline: we cost a credible pentest and its remediation plan. Detailed quote within 48 h. WhatsApp +221 77 596 93 33.
Mohamed Bah
Fondateur, Kolonell
Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.
