The verdict in three sentences
For a software SME selling a business application, a grey-box penetration test costs EUR 5,000 to 15,000 excl. VAT in 2026 for 5 to 12 days of testing. The real budget sits elsewhere: fixing the findings (EUR 3,000 to 20,000) and the retest (EUR 1,000 to 3,000) often double the initial invoice. A well-split scope and code hardened before the audit are the two levers that bring the total down.
What a web app pentest costs in Amsterdam in 2026
Price depends on three variables: the number of user roles to test, the exposed API surface and the requirements of the end customer. A large bank, a public body or a regulated customer will often require a provider with a recognised quality mark (CREST, or a government-qualified provider such as PASSI in France), which adds 20 to 40% to the quote.
| Audit scope | Test days | Standard provider | Certified top-tier provider |
|---|---|---|---|
| Simple app, 2 roles, 20 screens | 5 days | EUR 5,000 to 6,500 | EUR 6,500 to 9,000 |
| Business app, 4 roles, REST API | 7 to 8 days | EUR 7,500 to 10,000 | EUR 9,500 to 13,500 |
| Multi-tenant SaaS, public API | 10 days | EUR 10,000 to 13,000 | EUR 13,000 to 18,000 |
| SaaS + mobile app | 12 days | EUR 12,000 to 15,000 | EUR 15,000 to 21,000 |
| Retest after remediation | 1 to 2 days | EUR 1,000 to 3,000 | EUR 1,300 to 4,000 |
| Report in a second language | flat fee | EUR 500 to 1,000 | EUR 700 to 1,400 |
Grey box (the tester receives test accounts for each role) is the most cost-effective format for a business application: it covers authorisation flaws, the most severe ones, without losing two days on reconnaissance as in black box. White box, with source code access, adds 2 to 4 days but finds more logic flaws.
The most frequent OWASP flaws and what they cost to fix
In business applications built by small teams, the same OWASP Top 10 categories show up report after report. The table below gives a 2026 order of magnitude for observed frequency and average remediation cost.
| Flaw (OWASP 2021) | Estimated frequency | Typical severity | Average remediation cost |
|---|---|---|---|
| A01 Broken access control (IDOR) | 6 audits in 10 | Critical | EUR 2,000 to 8,000 |
| A07 Weak authentication (no MFA, long sessions) | 5 in 10 | High | EUR 1,500 to 5,000 |
| A05 Misconfiguration (headers, CORS) | 7 in 10 | Medium | EUR 500 to 2,000 |
| A03 Injection (SQL, stored XSS) | 3 in 10 | Critical | EUR 1,000 to 6,000 |
| A06 Vulnerable components (dependencies) | 6 in 10 | Variable | EUR 800 to 4,000 |
| A09 Insufficient logging | 5 in 10 | Medium | EUR 1,500 to 4,000 |
| A10 SSRF on URL import or webhook | 1 in 10 | High | EUR 1,000 to 3,000 |
Access control is the most expensive item because it is rarely fixed in a single place: the authorisation layer of the whole API often has to be reviewed. Security headers (CSP, HSTS) and CORS configuration, by contrast, take half a day.
Preparing the audit to pay less and fix faster
A pentest on an unprepared application produces a 40-finding report, half of which an automated scanner could have caught. Three upstream actions cut the total cost:
- Run a dependency scan (npm audit, Dependabot) and a free DAST scanner such as OWASP ZAP two weeks before the audit.
- Give the tester a role and permission matrix: it saves a day of discovery, i.e. EUR 800 to 1,200.
- At signature, set aside a remediation envelope of 1 to 1.5 times the pentest price, and book a retest slot at D+30.
On timing, expect a 2 to 4 week wait with a certified provider in the busy season (September to December), then 5 to 12 days of testing, one week of report writing and 2 to 6 weeks of remediation.
Need a professional website?
Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.
Mini case study
Sanne, CISO of a 45-person Amsterdam SME that publishes construction site management software, must hand a pentest report to a construction group before signing a EUR 180,000 per year contract. The certified provider quotes 8 grey-box days, i.e. EUR 11,200 excl. VAT. The report lists 2 critical flaws (IDOR on quotes, no admin MFA) and 9 medium findings. Remediation: EUR 6,500, retest: EUR 1,800. Total budget: EUR 19,500 excl. VAT, or 10.8% of the contract's first year. Without preparation, the team estimates it would have paid about EUR 4,000 more in test days and avoidable fixes.
FAQ
Do I need a government-qualified provider?
Not always: qualification is mainly required by critical infrastructure operators, public bodies and some large accounts. For a standard private customer, a provider with certified testers (OSCP, CREST) is usually enough and costs 20 to 40% less.
How often should the pentest be repeated?
Once a year is the norm most enterprise customers ask for, plus a targeted test after each major release. A 7-day annual pentest represents about EUR 9,000 per year for a typical business app.
Can the pentest report be shared with the customer?
Yes, providers deliver a 3 to 5 page executive summary meant for customers, separate from the technical report. Budget EUR 500 to 1,000 if it must be translated.
Is an automated scanner enough?
No, a scanner finds roughly 30 to 40% of flaws, mostly configuration and dependency issues. Authorisation and business logic flaws, the most severe, need a human tester.
How long does it take to fix critical flaws?
15 to 30 days is the reference customers expect for critical findings. A team of 2 developers usually fixes 2 critical and 8 medium findings in 2 to 4 weeks.
Let's scope your project. We prepare your application for the pentest, fix the findings and organise the retest, with a remediation budget set from day one. Detailed quote within 48 h. WhatsApp +221 77 596 93 33.
Mohamed Bah
Fondateur, Kolonell
Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.