The verdict in three sentences
A full penetration test of a business web application runs between GBP 6,000 and GBP 20,000 in 2026 in London, and a code audit between GBP 4,000 and GBP 12,000, depending on the number of roles and endpoints. Bringing the app in line with the OWASP Top 10 typically adds GBP 3,000 to GBP 15,000 of remediation, for an overall timeline of 3 to 6 weeks. Against an average data breach cost estimated above GBP 100,000 for an SME (notification, lost business, emergency remediation), the audit remains the most profitable line item on your security roadmap.
Audit scope and 2026 budget
Price depends mostly on scope: number of user roles, API endpoints, third-party integrations and exposure. Here are the 2026 orders of magnitude seen on the London market.
| Service | Scope | 2026 budget (GBP) | Timeline |
|---|---|---|---|
| Black-box pentest | Exposed app, 1-2 roles | 6,000 - 9,000 | 1-2 wk |
| Grey-box pentest | Accounts provided, 3-5 roles | 9,000 - 14,000 | 2-3 wk |
| Full pentest + API | Web + API + mobile | 14,000 - 20,000 | 3-4 wk |
| Code audit | 20,000-80,000 lines | 4,000 - 12,000 | 1-3 wk |
| OWASP remediation | Priority fixes | 3,000 - 15,000 | 1-3 wk |
| Bug bounty (option) | Private annual programme | 8,000 - 30,000/yr | ongoing |
A CISO rarely picks a single line: the common combo is grey-box pentest + remediation + re-test, i.e. GBP 15,000 to 25,000 for an end-to-end secured cycle.
What the OWASP Top 10 covers
The OWASP Top 10 reference structures almost every audit. Here are the vulnerability families tested and the typical remediation cost per family.
| OWASP category | Concrete example | Severity | Remediation (GBP) |
|---|---|---|---|
| Broken access control | Access to another account | Critical | 2,000 - 6,000 |
| Injection (SQL, XSS) | Unfiltered form | Critical | 1,500 - 5,000 |
| Security misconfiguration | Missing header, open port | High | 800 - 3,000 |
| Weak authentication | No MFA | High | 1,500 - 4,000 |
| Vulnerable components | Outdated dependency | Medium | 1,000 - 3,500 |
| Sensitive data exposure | Unencrypted logs | High | 1,200 - 4,000 |
The report must deliver a CVSS matrix prioritising each flaw, a dated remediation plan, and a re-test after fixes included in the engagement.
Need a professional website?
Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.
Mini case study
Thomas, CISO of a financial services SME in London (85 staff), must secure a portfolio-management app exposed to 400 clients. He orders a grey-box pentest at GBP 12,000, remediation at GBP 8,000 and an included re-test, i.e. GBP 20,000 total. The audit reveals broken access control letting one client view another's data. Left unfixed, exploitation would have triggered an ICO notification, loss of trust and a cost estimated at GBP 120,000 (emergency audit, legal, churn). The ROI is immediate: GBP 20,000 invested against GBP 120,000 of avoided risk, a factor of 6x.
FAQ
What is the difference between a pentest and a code audit? The pentest attacks the app from the outside like a hacker would (GBP 6,000-20,000); the code audit reads the source to find flaws at the root (GBP 4,000-12,000). They are complementary and a full cycle often combines both.
How often should a pentest be repeated? At least once a year and after every major change. A bug bounty programme (GBP 8,000-30,000/yr) usefully complements point-in-time tests on an ongoing basis.
Does a pentest guarantee zero flaws? No: it sharply reduces the attack surface and documents residual risks via a CVSS matrix. No serious provider guarantees zero risk.
How much does a data breach really cost? For an SME, the 2026 order of magnitude often exceeds GBP 100,000: notification, emergency remediation, legal, lost business and possible ICO fines up to 4% of turnover.
Can the security budget be phased? Yes: start with the pentest (week 1-3), fix the critical items, then plan the remaining remediation across a quarter. Sequencing limits cash-flow impact.
Let's scope your project. Describe your application (roles, API, hosting) and your indicative budget: we will scope a pentest and remediation matched to your exposure. Detailed quote within 48 h. WhatsApp +221 77 596 93 33.
Mohamed Bah
Fondateur, Kolonell
Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.