The verdict in three sentences
For an SME selling SaaS, a serious grey-box penetration test costs EUR 6,000 to 18,000 excl. VAT in 2026 (roughly GBP 5,200 to 15,500 in London) and takes 5 to 10 auditor days. The real budget then lies in remediation (EUR 3,000 to 20,000) and the re-test (about EUR 1,500), which alone produces the attestation the enterprise buyer expects. Scoping before requesting quotes stops you paying audit days on low-risk screens and missing the signing date.
What a web app pentest costs in 2026
Price depends on three variables: the number of user roles to test, the exposed API surface and the end customer's requirements. Banking or public sector buyers often require an accredited provider (PASSI in France, CREST or CHECK in the UK), which raises day rates by 15 to 30%.
| Tested scope | Audit days | Price excl. VAT 2026 (estimate) | Deliverable |
|---|---|---|---|
| Simple app, 2 roles, no public API | 4 to 5 days | EUR 6,000 to 7,500 | Report + executive summary |
| B2B SaaS, 3 to 4 roles, REST API | 6 to 8 days | EUR 8,500 to 12,000 | OWASP Top 10 report + remediation plan |
| Multi-tenant SaaS, SSO, public API | 8 to 10 days | EUR 12,000 to 18,000 | ASVS level 2 report + exploitation evidence |
| Same scope, accredited provider | 8 to 10 days | EUR 15,000 to 22,000 | Report meeting public sector requirements |
| Re-test of fixed vulnerabilities | 1 day | EUR 1,200 to 1,800 | Remediation attestation |
| Companion mobile app test | 3 to 5 days | EUR 4,500 to 8,000 | OWASP MASVS report |
A senior tester's day rate sits around EUR 1,100 to 1,500 excl. VAT in Paris and London. Be wary of offers under EUR 4,000: they are often a repackaged automated scan, which most enterprise security teams reject.
Black, grey or white box: which scope reassures the buyer
In black box, the tester starts from nothing, with no account: useful to simulate an external attacker, but half the time goes into discovering the application. In grey box, they get one account per role: this is the format expected by 80% of enterprise security questionnaires, because it tests authorization flaws between customers, the main risk of a multi-tenant SaaS. White box adds source code review and suits applications handling health or payment data.
Standards to require in the quote: OWASP Top 10 for minimum coverage, OWASP ASVS level 2 for a SaaS storing personal data of business customers.
Common vulnerabilities and cost to fix
On the SME SaaS products we see, the same families of flaws keep coming back. Here is the average fix cost with a developer at EUR 550 to 700 per day.
| Vulnerability (OWASP) | Observed frequency | Typical severity | Fix cost excl. VAT |
|---|---|---|---|
| Broken access control (IDOR between tenants) | Very common | Critical | EUR 2,000 to 8,000 |
| Weak session handling (non-expiring tokens) | Common | High | EUR 800 to 2,500 |
| SQL or NoSQL injection | Less common | Critical | EUR 1,000 to 4,000 |
| Stored XSS in rich text fields | Common | Medium to high | EUR 700 to 2,000 |
| Outdated dependencies with known CVEs | Very common | Variable | EUR 1,500 to 6,000 |
| Missing security headers (CSP, HSTS) | Very common | Low | EUR 300 to 800 |
| No rate limiting on login | Common | Medium | EUR 500 to 1,500 |
A well-designed application gets by with EUR 3,000 to 5,000 of fixes. A product built fast, without an authorization review, can exceed EUR 20,000 if the permission model has to be redesigned.
Mini case study
Need a professional website?
Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.
Thomas, CIO of a 25-person HR software company in Paris, must provide a pentest report to a retail group before signing a EUR 180,000 per year contract. He picks a 7-day grey-box audit at EUR 1,300 per day, so EUR 9,100 excl. VAT. The audit finds 2 critical IDOR flaws and 6 medium issues: 9 days of fixes at EUR 650, so EUR 5,850, then a re-test at EUR 1,500. Total: EUR 16,450 excl. VAT, or 9.1% of the contract's first year. The report is then reused for the next three tenders.
FAQ
How long between ordering and receiving the report?
Expect a 2 to 4 week wait at an established firm, then 5 to 10 audit days and 5 days of report writing. Plan 6 to 8 weeks before the target signing date.
Is an accredited provider mandatory?
Not for most private customers. It is required by some public operators, critical infrastructure and healthcare players, with a 15 to 30% day rate premium.
Do we need a new pentest every year?
Most enterprise buyers ask for a report under 12 months old. An annual pentest at EUR 8,000 to 12,000 excl. VAT, focused on new features, is the usual order of magnitude.
Is an automated scan enough?
A scanner at EUR 100 to 300 per month catches outdated dependencies and missing headers. It almost never finds cross-tenant authorization flaws, which make up most critical vulnerabilities.
Can we test in production?
It is possible with an agreed window, but a staging environment with anonymized data cuts incident risk to near zero for about EUR 500 of setup.
Let's scope your project. We scope the pentest, handle the fixes on your application and prepare the re-test, with an indicative budget of EUR 10,000 to 30,000 excl. VAT depending on surface and a 6 to 8 week timeline. Detailed quote within 48 h. WhatsApp +221 77 596 93 33.
Mohamed Bah
Fondateur, Kolonell
Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.

