The verdict in three sentences
Before opening a business application to clients, a mid-size company should plan a grey-box penetration test of EUR 6,000 to 15,000 excl. tax (about USD 6,500 to 16,500) for 5 to 10 days of testing. Fixes then cost EUR 2,000 to 10,000 depending on technical debt, and a retest must be included in the offer to prove remediation. For public contracts or demanding insurers, an accredited provider (PASSI in France, CREST in Canada and the UK) often becomes the entry condition.
Black, grey or white box: which test to choose
The test type drives price and depth. In black box, the tester starts from zero like an external attacker. In grey box, they get user accounts for several roles, which allows testing access controls, the leading cause of data leaks in business apps. In white box, they also read the source code.
| Test type | Information provided | Testing days | 2026 cost (excl. tax) |
|---|---|---|---|
| Black box | URL only | 3 to 5 days | EUR 4,000 to 8,000 |
| Grey box | Accounts for 2 to 4 roles | 5 to 10 days | EUR 6,000 to 15,000 |
| White box | Accounts and source code | 8 to 15 days | EUR 10,000 to 22,000 |
| Accredited grey box | Accounts, CREST or PASSI framework | 6 to 10 days | EUR 9,000 to 18,000 |
| API-only test | OpenAPI spec, keys | 3 to 6 days | EUR 4,000 to 9,000 |
| Retest | Fix verification | 1 to 2 days | Included or EUR 1,000 to 2,500 |
A senior tester's day rate sits between EUR 1,000 and 1,600 in 2026. Grey box gives the best coverage for the price on an application handling clients, roles and documents.
What the audit checks and what fixes cost
The OWASP Top 10 is the baseline: broken access control, injection, misconfiguration, vulnerable components, authentication failures. The report ranks each vulnerability by severity (CVSS score) with a remediation recommendation.
| Common vulnerability | Concrete example | Typical severity | Fix cost |
|---|---|---|---|
| Broken access control | A client views another client's invoice by changing the ID | Critical | EUR 1,500 to 5,000 |
| SQL or NoSQL injection | Unfiltered search field | Critical | EUR 800 to 3,000 |
| Weak authentication | No lockout after 10 attempts, no MFA | High | EUR 1,000 to 3,500 |
| Vulnerable components | JavaScript library with a known CVE | Medium to high | EUR 500 to 2,500 |
| Missing security headers | No CSP, cookies without Secure flag | Medium | EUR 300 to 1,000 |
| Information leakage | Detailed stack traces in production | Low to medium | EUR 300 to 800 |
On an application built without security review, expect 8 to 20 vulnerabilities including 1 to 3 critical ones. On an application built on a secure foundation from day one, total fixes often stay under EUR 3,000.
Cyber insurance, public contracts and timeline
Cyber insurers increasingly ask for proof of a recent test (under 12 months) for exposed applications, with a higher deductible or premium otherwise. For public contracts and sensitive operators, specifications often require an accredited provider. Schedule the test 4 to 6 weeks before go-live: 1 week of scoping, 1 to 2 weeks of testing, 2 weeks of fixes, then the retest.
Mini case study
Isabelle, CIO of a 180-employee industrial maintenance company in Toronto, is opening a client portal to track interventions and download reports. Her insurer makes renewal conditional on a pentest.
Need a professional website?
Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.
Budget: 7-day grey box at EUR 1,300 per day, i.e. EUR 9,100, retest included. The report finds 11 vulnerabilities including 2 critical access control issues. Fixes: EUR 4,500. Total: EUR 13,600 (about USD 14,900). In return, the insurer keeps the premium at EUR 9,000 per year instead of an announced 25% increase, saving EUR 2,250 every year, and the portal opens without risk of cross-client leaks.
FAQ
Is an automated scan enough instead of a pentest?
No, a scanner at EUR 100 to 300 per month mostly detects known and configuration flaws. It misses business logic flaws, such as accessing another client's data, which account for nearly 40% of critical findings.
Is an accredited provider mandatory?
Only for some public contracts, critical infrastructure operators and a few specifications. For a private mid-size company, an OSCP-certified tester or equivalent is enough and costs 15 to 25% less.
How often should the test be repeated?
Once a year, and after every major change affecting authentication or permissions. A yearly follow-up test often costs 30% less than the first one.
Is the application down during the audit?
No, testing usually runs on a staging environment identical to production. Allow 1 to 2 days to prepare it with synthetic data.
Who pays for fixes if a vendor built the application?
It depends on the contract: critical vulnerabilities often fall under the conformity warranty for 3 to 12 months. Check that clause before signing.
Let's scope your project. We prepare your application for the penetration test, fix the vulnerabilities and coordinate the retest, with an indicative budget and a 4 to 6 week timeline. Detailed quote within 48 h. WhatsApp +221 77 596 93 33.
Mohamed Bah
Fondateur, Kolonell
Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.

