Websites11 min read

Web Application Penetration Test Cost in Amsterdam (2026): Scope, Pricing and Remediation

Mohamed Bah·Fondateur, Kolonell
October 7, 2026
Share:
Web Application Penetration Test Cost in Amsterdam (2026): Scope, Pricing and Remediation

Web Application Penetration Test Cost in Amsterdam (2026): Scope, Pricing and Remediation

Websites

The verdict in three sentences

For a software SME selling a business application, a grey-box penetration test costs EUR 5,000 to 15,000 excl. VAT in 2026 for 5 to 12 days of testing. The real budget sits elsewhere: fixing the findings (EUR 3,000 to 20,000) and the retest (EUR 1,000 to 3,000) often double the initial invoice. A well-split scope and code hardened before the audit are the two levers that bring the total down.

What a web app pentest costs in Amsterdam in 2026

Price depends on three variables: the number of user roles to test, the exposed API surface and the requirements of the end customer. A large bank, a public body or a regulated customer will often require a provider with a recognised quality mark (CREST, or a government-qualified provider such as PASSI in France), which adds 20 to 40% to the quote.

Audit scopeTest daysStandard providerCertified top-tier provider
Simple app, 2 roles, 20 screens5 daysEUR 5,000 to 6,500EUR 6,500 to 9,000
Business app, 4 roles, REST API7 to 8 daysEUR 7,500 to 10,000EUR 9,500 to 13,500
Multi-tenant SaaS, public API10 daysEUR 10,000 to 13,000EUR 13,000 to 18,000
SaaS + mobile app12 daysEUR 12,000 to 15,000EUR 15,000 to 21,000
Retest after remediation1 to 2 daysEUR 1,000 to 3,000EUR 1,300 to 4,000
Report in a second languageflat feeEUR 500 to 1,000EUR 700 to 1,400

Grey box (the tester receives test accounts for each role) is the most cost-effective format for a business application: it covers authorisation flaws, the most severe ones, without losing two days on reconnaissance as in black box. White box, with source code access, adds 2 to 4 days but finds more logic flaws.

The most frequent OWASP flaws and what they cost to fix

In business applications built by small teams, the same OWASP Top 10 categories show up report after report. The table below gives a 2026 order of magnitude for observed frequency and average remediation cost.

Flaw (OWASP 2021)Estimated frequencyTypical severityAverage remediation cost
A01 Broken access control (IDOR)6 audits in 10CriticalEUR 2,000 to 8,000
A07 Weak authentication (no MFA, long sessions)5 in 10HighEUR 1,500 to 5,000
A05 Misconfiguration (headers, CORS)7 in 10MediumEUR 500 to 2,000
A03 Injection (SQL, stored XSS)3 in 10CriticalEUR 1,000 to 6,000
A06 Vulnerable components (dependencies)6 in 10VariableEUR 800 to 4,000
A09 Insufficient logging5 in 10MediumEUR 1,500 to 4,000
A10 SSRF on URL import or webhook1 in 10HighEUR 1,000 to 3,000

Access control is the most expensive item because it is rarely fixed in a single place: the authorisation layer of the whole API often has to be reviewed. Security headers (CSP, HSTS) and CORS configuration, by contrast, take half a day.

Preparing the audit to pay less and fix faster

A pentest on an unprepared application produces a 40-finding report, half of which an automated scanner could have caught. Three upstream actions cut the total cost:

  • Run a dependency scan (npm audit, Dependabot) and a free DAST scanner such as OWASP ZAP two weeks before the audit.
  • Give the tester a role and permission matrix: it saves a day of discovery, i.e. EUR 800 to 1,200.
  • At signature, set aside a remediation envelope of 1 to 1.5 times the pentest price, and book a retest slot at D+30.

On timing, expect a 2 to 4 week wait with a certified provider in the busy season (September to December), then 5 to 12 days of testing, one week of report writing and 2 to 6 weeks of remediation.

Need a professional website?

Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.

Prefer a call back?

Leave your WhatsApp number and a Kolonell expert will get back to you within 1 business day. Free, no strings attached.

Mini case study

Sanne, CISO of a 45-person Amsterdam SME that publishes construction site management software, must hand a pentest report to a construction group before signing a EUR 180,000 per year contract. The certified provider quotes 8 grey-box days, i.e. EUR 11,200 excl. VAT. The report lists 2 critical flaws (IDOR on quotes, no admin MFA) and 9 medium findings. Remediation: EUR 6,500, retest: EUR 1,800. Total budget: EUR 19,500 excl. VAT, or 10.8% of the contract's first year. Without preparation, the team estimates it would have paid about EUR 4,000 more in test days and avoidable fixes.

FAQ

Do I need a government-qualified provider?

Not always: qualification is mainly required by critical infrastructure operators, public bodies and some large accounts. For a standard private customer, a provider with certified testers (OSCP, CREST) is usually enough and costs 20 to 40% less.

How often should the pentest be repeated?

Once a year is the norm most enterprise customers ask for, plus a targeted test after each major release. A 7-day annual pentest represents about EUR 9,000 per year for a typical business app.

Can the pentest report be shared with the customer?

Yes, providers deliver a 3 to 5 page executive summary meant for customers, separate from the technical report. Budget EUR 500 to 1,000 if it must be translated.

Is an automated scanner enough?

No, a scanner finds roughly 30 to 40% of flaws, mostly configuration and dependency issues. Authorisation and business logic flaws, the most severe, need a human tester.

How long does it take to fix critical flaws?

15 to 30 days is the reference customers expect for critical findings. A team of 2 developers usually fixes 2 critical and 8 medium findings in 2 to 4 weeks.

Let's scope your project. We prepare your application for the pentest, fix the findings and organise the retest, with a remediation budget set from day one. Detailed quote within 48 h. WhatsApp +221 77 596 93 33.

Tags:#penetration test#web app pentest#OWASP#application security#CREST#security audit Amsterdam
Share:

Mohamed Bah

Fondateur, Kolonell

Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.