The verdict in three sentences
A web app security audit in Dublin costs 3,000,000 to 8,000,000 FCFA (about 4,600-12,200 EUR) in 2026, depending on the surface (endpoints, roles, integrations). It combines an OWASP Top 10 pentest, code review and a retest after fixes, delivered in 3 to 5 weeks. The trap is not finding flaws but prioritizing them: one uncorrected critical flaw before scaling can cost far more than a full audit.
What an audit contains and its price in 2026
A serious audit is not just an automated scan. It combines manual tests, code analysis and configuration review. Here are the 2026 orders of magnitude.
| Service | Contents | Timeline | Price (FCFA) |
|---|---|---|---|
| Express audit | Scan + OWASP Top 10 | 1-2 wks | 3,000,000 - 4,000,000 |
| Standard audit | Pentest + code review | 3-4 wks | 4,500,000 - 6,000,000 |
| Full audit | + retest + fixes | 4-5 wks | 6,500,000 - 8,000,000 |
| Retest only | verify fixes | 3-5 d | 500,000 - 900,000 |
| Security maintenance | monthly monitoring | recurring | 150,000 - 350,000/mo |
Fixes (development) are sometimes billed separately: expect 5 to 15 person-days depending on the number of critical vulnerabilities.
Vulnerability prioritization: the real deliverable
The report ranks each flaw by criticality (CVSS) and by remediation effort. This table drives the IT lead's decisions.
| Criticality | Example | Target fix time | Business impact |
|---|---|---|---|
| Critical | SQL injection, RCE | Immediate (48 h) | Full data breach |
| High | Broken auth, IDOR | 1 week | Unauthorized access |
| Medium | Stored XSS, CSRF | 2-4 weeks | Targeted compromise |
| Low | Missing headers | Next release | Hardening |
| Info | Exposed version | Optional | Reconnaissance |
A good provider also delivers a costed remediation plan and an included retest to confirm each fix works.
Mini case study
Mr. Okemba, IT lead at a 25-person fintech in Dublin, is preparing to launch an app targeting 10,000 users. He orders a standard audit at 5,500,000 FCFA (about 8,400 EUR). The audit reveals 2 critical flaws (account IDOR, injection on a filter) and 6 medium flaws.
Fixes: 9 person-days, about 2,700,000 FCFA. Total security: 8,200,000 FCFA. Compare that to the cost of a breach: compromising 10,000 customer accounts would trigger loss of trust, mandatory notification and estimated lost revenue above 30,000,000 FCFA. The return is obvious from the first critical flaw avoided.
Need a professional website?
Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.
FAQ
How long does a security audit take?
3 to 5 weeks for a standard-to-full audit, retest included. An express audit finishes in 1 to 2 weeks.
Is the retest included in the price?
In a full audit, yes. Otherwise a standalone retest costs 500,000 to 900,000 FCFA and confirms the fixes close the flaws.
What does the pentest actually test?
The OWASP Top 10: injections, broken auth, data exposure, IDOR, XSS, misconfigurations. Tests are manual, not just automated.
Is monitoring needed after the audit?
Yes, security maintenance at 150,000 to 350,000 FCFA/month watches for new vulnerabilities and outdated dependencies.
Does an audit guarantee zero risk?
No, but it sharply reduces the attack surface. Fixing critical and high flaws removes over 90 % of the short-term exploitable risk.
Let's scope your project. Tell us your app scope (endpoints, roles, integrations) and your scaling deadline: we'll price the audit, fixes and retest. Detailed quote within 48 h. WhatsApp +221 77 596 93 33.
Mohamed Bah
Fondateur, Kolonell
Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.
