The verdict in three sentences
A black-box pentest of a web application ranges from EUR 4,000 to 9,000 in 2026, grey-box (with test accounts) from EUR 8,000 to 18,000, over a 2-to-4-week timeline. The key deliverable is not the price but the OWASP report ranked by severity, paired with a free retest after fixes. Against an average breach cost above EUR 100,000 for an SMB, an audit is one of the best-ratio security investments you can make.
What a pentest really costs in 2026
Price depends mainly on the level of information given to the tester and the app's attack surface (endpoints, roles, integrations). A short audit of a brochure site with a form is nothing like a multi-tenant SaaS with dozens of APIs.
| Pentest type | Scope | Price 2026 | Timeline |
|---|---|---|---|
| Black box | No access, external attacker view | EUR 4,000 - 9,000 | 2 - 3 weeks |
| Grey box | User accounts + partial docs | EUR 8,000 - 18,000 | 3 - 4 weeks |
| White box | Source code + architecture | EUR 15,000 - 30,000 | 4 - 6 weeks |
| Dedicated API pentest | REST/GraphQL, tokens, quotas | EUR 5,000 - 12,000 | 2 - 3 weeks |
| Verification retest | Revalidation after fixes | Included (EUR 0) | 3 - 5 days |
| Continuous bug bounty | 12-month program | EUR 12,000 - 40,000/yr | Ongoing |
Grey box offers the best coverage-to-price ratio for a SaaS: the tester probes privilege escalation and cross-tenant leaks an external scan will never see.
What a serious report covers
A good report is not just a list of flaws. It rates each vulnerability using CVSS and maps it to the OWASP Top 10 (injections, broken access control, misconfiguration, etc.).
| Deliverable | Expected content | Impact for you |
|---|---|---|
| Executive summary | 1-2 non-technical pages | To show investors / clients |
| Per-vulnerability detail | Proof, CVSS, reproduction | Fix prioritization |
| Remediation plan | Actions + estimated effort | Dev budget sizing |
| Retest | Revalidation after fixes | Proof it's closed |
| Attestation | Signed, dated document | Required by enterprise buyers |
Without a signed attestation, your report won't reassure an enterprise buyer or a fund in due diligence.
Need a professional website?
Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.
Mini case study
Thomas, CTO of a B2B SaaS startup in Nantes, is preparing a Series A. The fund requires a security audit in due diligence. He picks a grey-box pentest at EUR 12,000, 3-week timeline. The report reveals 2 critical flaws (access control) and 5 medium ones; remediation costs 9 dev-days, roughly EUR 4,500. Total: EUR 16,500. A breach exploiting those flaws would have triggered a data-authority notification, the loss of 3 pilot customers, and an estimated cost above EUR 100,000 - not counting the jeopardized round. The audit paid off the moment the first flaw was fixed.
FAQ
Pentest or plain automated scan, what's the difference? A scan (EUR 150-600/month of tooling) finds known vulnerabilities but misses business logic and privilege escalation. A human pentest chains attacks no scanner finds - which is exactly what funds and enterprises require.
How often should you re-run a pentest? At least once a year and after any major change (new API, auth rework). An annual program at EUR 12,000-40,000/yr covers continuous evolution.
Is the retest really free? With serious providers, a verification retest is included within 30-60 days of the initial report, as long as it covers already-identified flaws. A brand-new full audit is billed separately.
How long until results? Expect 2 to 4 weeks between kickoff and final report, retest included. Plan that lead time before a funding deadline or client launch.
Does a pentest make you GDPR-compliant? No: it covers technical security, not data governance (records, legal bases, DPAs). Combine it with an application-level GDPR audit for full compliance.
Let's scope your project. Describe your application (stack, number of APIs, roles, funding or deal deadline) and we'll define the pentest type matching your budget. Detailed quote within 48 h. WhatsApp +221 77 596 93 33.
Mohamed Bah
Fondateur, Kolonell
Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.