The verdict in three sentences
A web app security audit (pentest) costs between 3,500 and 15,000 EUR in 2026, depending on scope and depth (black, grey or white box). Vulnerability remediation usually adds 20 to 40% of the audit cost. Set against the risk of a GDPR fine reaching up to 4% of revenue and the business shutdown a breach causes, it is one of the most cost-effective security investments available.
How much an audit costs by type and scope
Price is driven by three factors: the attack surface (endpoints, roles, integrations), the level of information given to testers, and the compliance requirement (OWASP, ISO 27001, PCI-DSS).
| Audit type | Information provided | Typical duration | 2026 price (EUR) |
|---|---|---|---|
| Automated scan + review | None (tool) | 2 - 3 days | 1,500 - 3,500 |
| Black box pentest | None | 4 - 6 days | 3,500 - 7,000 |
| Grey box pentest | Test accounts | 6 - 10 days | 6,000 - 11,000 |
| White box pentest | Code + architecture | 10 - 15 days | 9,000 - 15,000 |
| Compliance audit (GDPR/ISO) | Docs + code | 8 - 12 days | 7,000 - 14,000 |
A grey box pentest is the best coverage-to-cost ratio for most business applications.
Vulnerability severity and remediation budget
An audit report ranks vulnerabilities by severity (CVSS). What matters to the decision maker is the cost and time to fix, often higher than the audit itself for critical flaws.
| Severity | Examples (OWASP) | Fix window | Remediation cost (EUR) |
|---|---|---|---|
| Critical | SQL injection, RCE, broken auth | Immediate (48-72 h) | 3,000 - 8,000 |
| High | Stored XSS, IDOR, exposed secrets | 1 - 2 weeks | 1,500 - 4,000 |
| Medium | CSRF, weak config, CORS | 2 - 4 weeks | 800 - 2,500 |
| Low | Missing headers, verbosity | Next sprint | 300 - 1,000 |
Budget a retest after remediation (1,000 to 2,500 EUR) to prove critical flaws are closed, often required by enterprise customers.
Need a professional website?
Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.
Mini case study
Me Diop runs a consulting firm in Dakar whose client app hosts sensitive data. A major account demands a security audit before signing a 180,000 EUR/year contract. The firm invests 8,500 EUR in a grey box pentest that reveals a critical IDOR flaw (access to other clients' files). Remediation costs 3,200 EUR and the retest 1,400 EUR. Total: 13,100 EUR to secure a 180,000 EUR/year contract and avoid a breach that could have triggered a regulator notification and the loss of the client. Immediate, obvious ROI.
FAQ
How often should you audit an application? At least once a year, and always before a major release or on a client's request. A quarterly automated scan (1,500-3,500 EUR) usefully complements the annual pentest.
Black, grey or white box: which to choose? Grey box (with test accounts) offers the best balance: testers see what an authenticated user can exploit. White box is reserved for critical or regulated applications.
What do you actually risk without an audit? A data breach exposes you to a GDPR fine of up to 4% of global revenue, plus emergency remediation cost, customer loss and reputational damage. An incident costs far more than an audit.
Does the audit cover GDPR compliance? A pentest tests technical security; GDPR compliance adds a review of processing, consent and retention periods. Budget 7,000 to 14,000 EUR for a combined audit.
How long from order to report? Usually 2 to 4 weeks: 1 week of planning, 4 to 15 days of testing depending on type, then the report with a prioritized remediation plan.
Let's scope your project. Share the application type, number of endpoints and compliance requirement (GDPR, ISO, enterprise client) for an audit sized to the right scope. Detailed quote within 48 h. WhatsApp +221 77 596 93 33.
Mohamed Bah
Fondateur, Kolonell
Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.