Websites10 min read

Web Application Penetration Test Cost in London (2026)

Mohamed Bah·Fondateur, Kolonell
October 10, 2026
Share:
Web Application Penetration Test Cost in London (2026)

Web Application Penetration Test Cost in London (2026)

Websites

The verdict in three sentences

For an SME selling SaaS, a serious grey-box penetration test costs EUR 6,000 to 18,000 excl. VAT in 2026 (roughly GBP 5,200 to 15,500 in London) and takes 5 to 10 auditor days. The real budget then lies in remediation (EUR 3,000 to 20,000) and the re-test (about EUR 1,500), which alone produces the attestation the enterprise buyer expects. Scoping before requesting quotes stops you paying audit days on low-risk screens and missing the signing date.

What a web app pentest costs in 2026

Price depends on three variables: the number of user roles to test, the exposed API surface and the end customer's requirements. Banking or public sector buyers often require an accredited provider (PASSI in France, CREST or CHECK in the UK), which raises day rates by 15 to 30%.

Tested scopeAudit daysPrice excl. VAT 2026 (estimate)Deliverable
Simple app, 2 roles, no public API4 to 5 daysEUR 6,000 to 7,500Report + executive summary
B2B SaaS, 3 to 4 roles, REST API6 to 8 daysEUR 8,500 to 12,000OWASP Top 10 report + remediation plan
Multi-tenant SaaS, SSO, public API8 to 10 daysEUR 12,000 to 18,000ASVS level 2 report + exploitation evidence
Same scope, accredited provider8 to 10 daysEUR 15,000 to 22,000Report meeting public sector requirements
Re-test of fixed vulnerabilities1 dayEUR 1,200 to 1,800Remediation attestation
Companion mobile app test3 to 5 daysEUR 4,500 to 8,000OWASP MASVS report

A senior tester's day rate sits around EUR 1,100 to 1,500 excl. VAT in Paris and London. Be wary of offers under EUR 4,000: they are often a repackaged automated scan, which most enterprise security teams reject.

Black, grey or white box: which scope reassures the buyer

In black box, the tester starts from nothing, with no account: useful to simulate an external attacker, but half the time goes into discovering the application. In grey box, they get one account per role: this is the format expected by 80% of enterprise security questionnaires, because it tests authorization flaws between customers, the main risk of a multi-tenant SaaS. White box adds source code review and suits applications handling health or payment data.

Standards to require in the quote: OWASP Top 10 for minimum coverage, OWASP ASVS level 2 for a SaaS storing personal data of business customers.

Common vulnerabilities and cost to fix

On the SME SaaS products we see, the same families of flaws keep coming back. Here is the average fix cost with a developer at EUR 550 to 700 per day.

Vulnerability (OWASP)Observed frequencyTypical severityFix cost excl. VAT
Broken access control (IDOR between tenants)Very commonCriticalEUR 2,000 to 8,000
Weak session handling (non-expiring tokens)CommonHighEUR 800 to 2,500
SQL or NoSQL injectionLess commonCriticalEUR 1,000 to 4,000
Stored XSS in rich text fieldsCommonMedium to highEUR 700 to 2,000
Outdated dependencies with known CVEsVery commonVariableEUR 1,500 to 6,000
Missing security headers (CSP, HSTS)Very commonLowEUR 300 to 800
No rate limiting on loginCommonMediumEUR 500 to 1,500

A well-designed application gets by with EUR 3,000 to 5,000 of fixes. A product built fast, without an authorization review, can exceed EUR 20,000 if the permission model has to be redesigned.

Mini case study

Need a professional website?

Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.

Prefer a call back?

Leave your WhatsApp number and a Kolonell expert will get back to you within 1 business day. Free, no strings attached.

You are :

Thomas, CIO of a 25-person HR software company in Paris, must provide a pentest report to a retail group before signing a EUR 180,000 per year contract. He picks a 7-day grey-box audit at EUR 1,300 per day, so EUR 9,100 excl. VAT. The audit finds 2 critical IDOR flaws and 6 medium issues: 9 days of fixes at EUR 650, so EUR 5,850, then a re-test at EUR 1,500. Total: EUR 16,450 excl. VAT, or 9.1% of the contract's first year. The report is then reused for the next three tenders.

FAQ

How long between ordering and receiving the report?

Expect a 2 to 4 week wait at an established firm, then 5 to 10 audit days and 5 days of report writing. Plan 6 to 8 weeks before the target signing date.

Is an accredited provider mandatory?

Not for most private customers. It is required by some public operators, critical infrastructure and healthcare players, with a 15 to 30% day rate premium.

Do we need a new pentest every year?

Most enterprise buyers ask for a report under 12 months old. An annual pentest at EUR 8,000 to 12,000 excl. VAT, focused on new features, is the usual order of magnitude.

Is an automated scan enough?

A scanner at EUR 100 to 300 per month catches outdated dependencies and missing headers. It almost never finds cross-tenant authorization flaws, which make up most critical vulnerabilities.

Can we test in production?

It is possible with an agreed window, but a staging environment with anonymized data cuts incident risk to near zero for about EUR 500 of setup.

Let's scope your project. We scope the pentest, handle the fixes on your application and prepare the re-test, with an indicative budget of EUR 10,000 to 30,000 excl. VAT depending on surface and a 6 to 8 week timeline. Detailed quote within 48 h. WhatsApp +221 77 596 93 33.

Tags:#pentest#web application security#OWASP#SME#London#accredited provider
Share:

Mohamed Bah

Fondateur, Kolonell

Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.