The verdict in three sentences
A pentest (penetration test) of a web application costs between EUR 4,000 and EUR 15,000 excl. VAT in 2026, depending on the tested scope, number of user roles and whether a retest is included. It's the cheapest insurance in the project against the cost of a breach: GDPR violation (up to 4% of global revenue), service interruption and loss of customer trust. For an ongoing need, bug bounty complements the one-off audit, and an optional ISO 27001 certification opens the doors to large accounts.
What a pentest covers and its price
A serious pentest isn't just an automated scan: a consultant manually exploits vulnerabilities, as a real attacker would. Scope directly determines price.
| Audit type | Scope | Duration | Cost excl. VAT 2026 |
|---|---|---|---|
| Automated scan | Public surface | 1-2 days | EUR 1,500-3,000 |
| Black-box pentest | App, no access | 3-5 days | EUR 4,000-7,000 |
| Grey-box pentest | App + test accounts | 5-8 days | EUR 7,000-11,000 |
| White-box pentest | App + source code | 8-12 days | EUR 11,000-15,000 |
| Fix retest | Verify the fixes | 1-2 days | EUR 1,500-3,000 |
The grey-box pentest is the best value for most SaaS: the tester has accounts and covers authorization flaws, often the most severe.
The cost of a breach vs the cost of the audit
The math is brutal. A EUR 9,000 audit looks expensive until you quantify the incident it prevents.
| Incident item | Estimated impact 2026 |
|---|---|
| GDPR fine (regulator) | EUR 20,000 to 4% of global revenue |
| Emergency notification & remediation | EUR 15,000-60,000 |
| Service interruption (per day) | EUR 5,000-40,000 |
| Customer loss (churn) | 5-20% of the base |
| Reputational damage | Hard to quantify |
Against these figures, an annual pentest at EUR 9,000 is a fraction of the covered risk. Large-account contracts require it contractually anyway.
Need a professional website?
Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.
Mini case study
A CIO of a London scale-up (HR SaaS, 12,000 users) must prove its security before signing a EUR 180,000/year contract with a bank. He orders a grey-box pentest at EUR 9,500 excl. VAT plus a retest at EUR 2,000. The audit reveals 2 critical authorization flaws allowing access to other companies' payroll records. Fixed in 3 weeks, they could have triggered a massive GDPR breach. The EUR 11,500 investment secures a EUR 180,000 contract: immediate ROI, not counting other large accounts unlocked.
FAQ
Black, grey or white box: which to choose? Grey box (EUR 7,000-11,000) is the best compromise: the tester has accounts and finds authorization flaws. White box, with source code, is reserved for highly sensitive applications.
Is the retest mandatory? Strongly recommended: it verifies your fixes actually work and don't introduce new flaws. Expect EUR 1,500-3,000, often required by large-account clients.
One-off audit or bug bounty? A pentest gives a snapshot at a point in time; bug bounty offers continuous monitoring (from EUR 500-2,000/month in rewards). The two are complementary.
Do I need ISO 27001 certification? Not always, but it becomes a strong sales argument for large accounts and the public sector. Expect EUR 15,000-40,000 for the first certification, beyond a simple pentest.
How often should I audit? At least once a year and after every major change (new sensitive feature, migration). Cyber threats evolve continuously.
Let's scope your project. Describe your application, the number of user roles and the deadline (contract, certification): we'll frame the pentest type and budget. Detailed quote within 48 h. WhatsApp +221 77 596 93 33.
Mohamed Bah
Fondateur, Kolonell
Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.
