Websites10 min read

Web Application Penetration Test Cost Before Go-Live (2026)

Mohamed Bah·Fondateur, Kolonell
October 5, 2026
Share:
Web Application Penetration Test Cost Before Go-Live (2026)

Web Application Penetration Test Cost Before Go-Live (2026)

Websites

The verdict in three sentences

An automated scan (0 to 2,000 EUR) catches obvious flaws but never replaces a grey-box pentest run by a human tester. For a business application or SaaS handling personal data, budget 6,000 to 20,000 EUR (about 6,500 to 22,000 USD) and 5 to 15 days of testing, plus a retest after fixes. A bug bounty comes later, once the application is stable, not before go-live.

Three approaches, three levels of assurance

The real question is not which tool to buy but what level of evidence you must provide. Around 60 % of enterprise buyers (banks, insurers, industrial groups) now require a penetration test report less than 12 months old in their vendor security questionnaire, and SOC 2 auditors in London or New York expect one as well. A raw scanner export almost never passes that step.

Approach2026 price (excl. VAT)DurationWhat it coversMain limit
Automated scan (OWASP ZAP, Burp, scanning SaaS)0 to 2,000 EUR1 to 2 daysKnown flaws, headers, vulnerable versionsNo business logic, many false positives
Black-box pentest4,000 to 10,000 EUR4 to 8 daysExposed surface without an accountDoes not test cross-user permissions
Grey-box pentest, accredited firm (CREST, PASSI)6,000 to 20,000 EUR5 to 15 daysOWASP Top 10, permissions, APIs, business logicSnapshot at a point in time
Retest after fixes1,500 to 4,000 EUR1 to 3 daysVerification of fixesDoes not look for new flaws
Private bug bounty5,000 to 30,000 EUR per yearContinuousMany researchers, new flawsRequires a team able to triage and fix fast
Pentest + targeted code review12,000 to 30,000 EUR10 to 20 daysAuthentication, encryption, multi-tenancyHigher budget

CREST accreditation in the UK and the French PASSI qualification reassure procurement teams. An accredited tester typically bills 900 to 1,400 EUR per day (London rates often 1,000 to 1,500 GBP), versus 600 to 1,000 EUR for an unaccredited freelancer.

What drives the price

The number of days depends mainly on the attack surface, not on the number of pages. A client portal with three roles and a REST API takes 5 to 7 days. A multi-tenant SaaS with a back office, public API and mobile app needs 12 to 15 days.

FactorImpact on daysExample
Number of user roles+1 day per role beyond 2Client, manager, admin, support
Exposed API+2 to 4 days40 to 80 REST or GraphQL endpoints
Multi-tenant+2 daysData isolation between customers
Companion mobile app+3 to 5 daysiOS and Android
Integrated online payment+1 to 2 daysStripe, Wave, Orange Money
Stable staging environment provided-1 to 2 daysTest accounts ready on day 1
Unclear scope at kickoff+20 to 30 %Days lost scoping during the test

The report should include an executive summary, vulnerabilities ranked by severity (CVSS score), mapping to the OWASP Top 10, reproducible evidence and a prioritised remediation plan. Without that plan, developers often lose 2 to 3 days interpreting findings.

The right timeline before go-live

Schedule the pentest 4 to 6 weeks before launch: 1 to 2 weeks of testing, 2 weeks of fixes, then the retest. A pentest run in launch week produces either a delay or a go-live with known flaws, which is worse legally under GDPR (article 32, security obligation). On the development side, remediation costs on average 15 to 25 % of the pentest budget itself.

Mini case study

Need a professional website?

Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.

Prefer a call back?

Leave your WhatsApp number and a Kolonell expert will get back to you within 1 business day. Free, no strings attached.

Claire, CIO of an HR software vendor in Lyon, is launching an employee portal for 40 client companies. A 3,000-employee enterprise makes its signature (85,000 EUR per year) conditional on a pentest report. Chosen budget: 8-day accredited grey-box pentest at 1,100 EUR per day, so 8,800 EUR, a 2-day retest at 2,200 EUR, and 4 days of internal fixes valued at 2,400 EUR. Total: 13,400 EUR, or 16 % of the first annual contract. The test uncovers two critical access-control flaws between client companies, fixed before go-live.

FAQ

Is an automated scan enough for a small SaaS?

For an MVP without sensitive data, a scan under 2,000 EUR is a good starting point. As soon as you handle health, financial or HR data, or sell to enterprises, a grey-box pentest of at least 5 days becomes necessary.

How often should a penetration test be repeated?

Common practice is one pentest per year, plus a targeted test after each major change (new API, new payment module). Budget 4,000 to 8,000 EUR for a targeted 3 to 5 day test.

Should testing happen in production or staging?

In staging, on an environment identical to production, to avoid corrupting real data. The tester then checks the production configuration in 1 day (headers, TLS, exposed services).

Can a bug bounty replace a pentest?

No, it complements it. A private programme costs 5,000 to 30,000 EUR per year in bounties and platform fees, and only makes sense once major flaws have been fixed by a first pentest.

Does Kolonell perform pentests?

We build applications designed to pass a pentest (OWASP Top 10, multi-tenant isolation, logging) and coordinate the test with an accredited firm, then the remediation. Fixes are often included in the acceptance-phase budget.

Let's scope your project. Send us your application scope (roles, APIs, data processed) and launch date: we will price secure development, pentest coordination and remediation. Detailed quote within 48 h. WhatsApp +221 77 596 93 33.

Tags:#penetration test#web application pentest#application security#OWASP#CREST#go-live#security audit cost
Share:

Mohamed Bah

Fondateur, Kolonell

Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.