The verdict in three sentences
An automated scan (0 to 2,000 EUR) catches obvious flaws but never replaces a grey-box pentest run by a human tester. For a business application or SaaS handling personal data, budget 6,000 to 20,000 EUR (about 6,500 to 22,000 USD) and 5 to 15 days of testing, plus a retest after fixes. A bug bounty comes later, once the application is stable, not before go-live.
Three approaches, three levels of assurance
The real question is not which tool to buy but what level of evidence you must provide. Around 60 % of enterprise buyers (banks, insurers, industrial groups) now require a penetration test report less than 12 months old in their vendor security questionnaire, and SOC 2 auditors in London or New York expect one as well. A raw scanner export almost never passes that step.
| Approach | 2026 price (excl. VAT) | Duration | What it covers | Main limit |
|---|---|---|---|---|
| Automated scan (OWASP ZAP, Burp, scanning SaaS) | 0 to 2,000 EUR | 1 to 2 days | Known flaws, headers, vulnerable versions | No business logic, many false positives |
| Black-box pentest | 4,000 to 10,000 EUR | 4 to 8 days | Exposed surface without an account | Does not test cross-user permissions |
| Grey-box pentest, accredited firm (CREST, PASSI) | 6,000 to 20,000 EUR | 5 to 15 days | OWASP Top 10, permissions, APIs, business logic | Snapshot at a point in time |
| Retest after fixes | 1,500 to 4,000 EUR | 1 to 3 days | Verification of fixes | Does not look for new flaws |
| Private bug bounty | 5,000 to 30,000 EUR per year | Continuous | Many researchers, new flaws | Requires a team able to triage and fix fast |
| Pentest + targeted code review | 12,000 to 30,000 EUR | 10 to 20 days | Authentication, encryption, multi-tenancy | Higher budget |
CREST accreditation in the UK and the French PASSI qualification reassure procurement teams. An accredited tester typically bills 900 to 1,400 EUR per day (London rates often 1,000 to 1,500 GBP), versus 600 to 1,000 EUR for an unaccredited freelancer.
What drives the price
The number of days depends mainly on the attack surface, not on the number of pages. A client portal with three roles and a REST API takes 5 to 7 days. A multi-tenant SaaS with a back office, public API and mobile app needs 12 to 15 days.
| Factor | Impact on days | Example |
|---|---|---|
| Number of user roles | +1 day per role beyond 2 | Client, manager, admin, support |
| Exposed API | +2 to 4 days | 40 to 80 REST or GraphQL endpoints |
| Multi-tenant | +2 days | Data isolation between customers |
| Companion mobile app | +3 to 5 days | iOS and Android |
| Integrated online payment | +1 to 2 days | Stripe, Wave, Orange Money |
| Stable staging environment provided | -1 to 2 days | Test accounts ready on day 1 |
| Unclear scope at kickoff | +20 to 30 % | Days lost scoping during the test |
The report should include an executive summary, vulnerabilities ranked by severity (CVSS score), mapping to the OWASP Top 10, reproducible evidence and a prioritised remediation plan. Without that plan, developers often lose 2 to 3 days interpreting findings.
The right timeline before go-live
Schedule the pentest 4 to 6 weeks before launch: 1 to 2 weeks of testing, 2 weeks of fixes, then the retest. A pentest run in launch week produces either a delay or a go-live with known flaws, which is worse legally under GDPR (article 32, security obligation). On the development side, remediation costs on average 15 to 25 % of the pentest budget itself.
Mini case study
Need a professional website?
Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.
Claire, CIO of an HR software vendor in Lyon, is launching an employee portal for 40 client companies. A 3,000-employee enterprise makes its signature (85,000 EUR per year) conditional on a pentest report. Chosen budget: 8-day accredited grey-box pentest at 1,100 EUR per day, so 8,800 EUR, a 2-day retest at 2,200 EUR, and 4 days of internal fixes valued at 2,400 EUR. Total: 13,400 EUR, or 16 % of the first annual contract. The test uncovers two critical access-control flaws between client companies, fixed before go-live.
FAQ
Is an automated scan enough for a small SaaS?
For an MVP without sensitive data, a scan under 2,000 EUR is a good starting point. As soon as you handle health, financial or HR data, or sell to enterprises, a grey-box pentest of at least 5 days becomes necessary.
How often should a penetration test be repeated?
Common practice is one pentest per year, plus a targeted test after each major change (new API, new payment module). Budget 4,000 to 8,000 EUR for a targeted 3 to 5 day test.
Should testing happen in production or staging?
In staging, on an environment identical to production, to avoid corrupting real data. The tester then checks the production configuration in 1 day (headers, TLS, exposed services).
Can a bug bounty replace a pentest?
No, it complements it. A private programme costs 5,000 to 30,000 EUR per year in bounties and platform fees, and only makes sense once major flaws have been fixed by a first pentest.
Does Kolonell perform pentests?
We build applications designed to pass a pentest (OWASP Top 10, multi-tenant isolation, logging) and coordinate the test with an accredited firm, then the remediation. Fixes are often included in the acceptance-phase budget.
Let's scope your project. Send us your application scope (roles, APIs, data processed) and launch date: we will price secure development, pentest coordination and remediation. Detailed quote within 48 h. WhatsApp +221 77 596 93 33.
Mohamed Bah
Fondateur, Kolonell
Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.
