The verdict in three sentences
For an SMB whose business web application must pass an enterprise client's security audit, the realistic 2026 budget is EUR 8,000 to 30,000 (about USD 8,700 to 32,500) all in: grey-box pentest, fixes and retest. The full timeline is 3 to 6 weeks, provided you book the tester before the buyer sets its deadline. Compared with the average cost of a cyberattack on a small business, estimated at around EUR 50,000, the spend is modest and becomes a sales argument.
What the enterprise client really expects
Procurement teams at manufacturers, banks and large groups rarely require a heavy certification. They want a penetration test report less than 12 months old, performed by a third party, with proof that critical and high vulnerabilities were fixed. The expected baseline is almost always the OWASP Top 10, sometimes extended with OWASP ASVS level 2 for apps handling sensitive data. In Quebec, Law 25 on personal information adds weight to that request.
| Common requirement | What it covers | Indicative 2026 cost (excl. tax) |
|---|---|---|
| Grey-box application pentest | 5 to 10 days of testing with user accounts provided | EUR 4,000 to 12,000 |
| Retest after fixes | Verification of critical and high findings | EUR 800 to 2,500 |
| Development fixes | Code, dependencies, configuration rework | EUR 2,000 to 15,000 |
| WAF (web application firewall) | Injection filtering, bots, rate limiting | EUR 20 to 200/month |
| Automated vulnerability scanning | Monthly dependency and exposure scan | EUR 50 to 300/month |
| Vendor security questionnaire | Documented answers, backup policy, privacy | EUR 1,000 to 3,000 |
| Ballpark first-year total | Audit, fixes, tooling | EUR 8,000 to 30,000 |
Grey box is the right compromise for an SMB: the tester receives accounts for several roles (user, manager, admin) and can check access controls, where most serious flaws live. Black box costs less but finds less; white box with full code review often exceeds EUR 15,000.
The OWASP Top 10 applied to a business app
On a management application built a few years ago, the findings come back with striking regularity. Here is what we see most often and the related fix effort.
| OWASP 2021 category | Typical SMB finding | Fix effort | Usual severity |
|---|---|---|---|
| A01 Broken access control | A user reads another client's record by changing the ID in the URL | 3 to 8 days | Critical |
| A02 Cryptographic failures | Passwords hashed with MD5, cookies without the Secure flag | 1 to 3 days | High |
| A03 Injection | Concatenated SQL query in an export module | 1 to 4 days | Critical |
| A05 Security misconfiguration | Missing CSP headers, debug mode on in production | 0.5 to 2 days | Medium |
| A06 Vulnerable components | Framework not updated for 3 years | 3 to 15 days | High |
| A07 Authentication failures | No login throttling, no 2FA for admins | 2 to 4 days | High |
| A09 Logging failures | No trace of logins and exports | 2 to 5 days | Medium |
The line that blows the budget is almost always A06: a major upgrade of an abandoned framework can alone cost EUR 10,000. If your app runs on an unsupported version, get that upgrade quoted before the pentest, because the report will list it anyway.
Realistic 3 to 6 week schedule
| Step | Duration | Deliverable |
|---|---|---|
| Scoping | 2 to 5 days | Test agreement, accounts, authorized windows |
| Internal pre-audit and obvious updates | 1 to 2 weeks | Updated dependencies, security headers, WAF on |
| Penetration test | 1 to 2 weeks | Report with a CVSS score per vulnerability |
| Fixes | 1 to 3 weeks | Patched code, regression tests |
| Retest and attestation | 3 to 5 days | Final report handed to the client |
Qualified testers are often booked 3 to 4 weeks ahead in spring and at year end. The internal pre-audit sharply reduces the fix bill, because the tester spends time on business logic flaws rather than on obvious issues.
Mini case study
Thomas, IT director of a 60-person industrial maintenance SMB in Montreal, must provide a pentest report to a car maker to renew a contract worth EUR 420,000 a year. His client portal, built in 2019, has never been tested.
Need a professional website?
Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.
- Pre-audit and framework upgrade: EUR 6,500
- 7-day grey-box pentest: EUR 8,400
- Fixes (access control, logging): EUR 5,200
- Retest: EUR 1,500
- WAF: EUR 90/month, i.e. EUR 1,080 over a year
First-year total: EUR 22,680, or 5.4% of the contract preserved. The report is then reused for two other tenders, which amortizes the spend further.
FAQ
Is a pentest mandatory for an SMB?
No law imposes it on every SMB, but privacy laws such as GDPR or Quebec's Law 25 require appropriate security measures, and large buyers increasingly demand proof from suppliers. In practice, more than half of the vendor questionnaires received in 2026 ask for a test under 12 months old.
Should a pentest be repeated every year?
Yes, to keep a valid report for buyers, or after any major change. The second test often costs 20 to 30% less because the scope is already documented.
Can a WAF replace the fixes?
No: a EUR 20 to 200 per month WAF blocks part of the injections and bots, but does not fix broken access control. It acts as a safety net during the 1 to 3 weeks of fixes.
How long does fixing critical flaws take?
Count 1 to 3 weeks for a mid-sized application. An isolated SQL injection is fixed in 1 day; reworking access rights can take 8 days.
What if the report reveals critical flaws?
That is normal and the enterprise client knows it: what it checks is proof of remediation through the retest. A final report with zero open critical findings is enough in 9 cases out of 10.
Let's scope your project. Send us your application scope and your client's deadline: we quote pre-audit, fixes and pentest coordination, with an indicative budget of EUR 8,000 to 30,000 over 3 to 6 weeks. Detailed quote within 48 h. WhatsApp +221 77 596 93 33.
Mohamed Bah
Fondateur, Kolonell
Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.
