Websites10 min read

Penetration test for a health web platform in Berlin: 2026 pricing

Mohamed Bah·Fondateur, Kolonell
October 7, 2026
Share:
Penetration test for a health web platform in Berlin: 2026 pricing

Penetration test for a health web platform in Berlin: 2026 pricing

Websites

The verdict in three sentences

A grey-box penetration test on a health platform costs between EUR 6,000 and 15,000 excl. VAT (about USD 6,500 to 16,200) in 2026, for 5 to 10 days of testing billed at EUR 1,000 to 1,400 per day. You must also budget EUR 3,000 to 12,000 for fixes and a retest, either included or billed at around EUR 1,500. To reassure a hospital group, a certified provider (PASSI in France, BSI-listed IS penetration testers or CREST in Germany and the UK) and a report aligned with OWASP ASVS matter more than price.

What hospitals actually expect

Certified health data hosting (HDS in France, C5-attested cloud in Germany) covers infrastructure, not your application code. Hospital IT departments therefore ask, before connecting your flows to their systems, for proof that the application itself holds up: access control between patients and professionals, isolation between facilities, strong authentication and API robustness. A security questionnaire of 80 to 200 questions often comes with the tender, and a pentest report less than 12 months old is its centrepiece.

Test typeTypical scopeDays2026 price (EUR excl. VAT)
External black boxInternet surface, no account3 to 53,500 to 7,000
Grey-box web applicationPatient, clinician, admin accounts5 to 86,000 to 11,000
Grey-box web + mobile APIWeb app, REST API, iOS and Android app8 to 1010,000 to 15,000
Targeted code reviewAuthentication, permissions, encryption3 to 54,000 to 7,000
Cloud configuration auditHosting accounts, IAM, backups, logs2 to 42,500 to 5,500
RetestFix verification1 to 1.50 (included) to 1,500

For a platform with 40,000 patients, a web app, an API and a mobile app, the realistic scenario is around 9 to 10 days, i.e. EUR 11,000 to 14,000 excl. VAT.

Certified or not: the budget impact

A government-recognised certification guarantees a method, assessed auditors and secure handling of your test data. It is not mandatory for a private company, but it becomes decisive when facing a university hospital or a public tender.

CriterionCertified providerNon-certified providerBug bounty platform
Day rateEUR 1,200 to 1,400EUR 800 to 1,100Bounties of EUR 100 to 5,000 per flaw
Recognition by hospitalsVery strongMediumWeak as sole evidence
Formal report and action planYesVariableNo, individual reports
Health data confidentialityFramedMust be contractedTricky
Lead time3 to 8 weeks1 to 4 weeksImmediate
Cost for 8 daysEUR 9,600 to 11,200EUR 6,400 to 8,800Unpredictable

Fixes, the forgotten line item

A first pentest on a never-audited platform usually uncovers 2 to 5 critical or high vulnerabilities and 8 to 15 medium ones. The most frequent in healthcare: access to another patient's record by changing an identifier (IDOR), overly long session tokens, no multi-factor authentication for clinicians, unlogged CSV exports. Fixing costs range from EUR 3,000 (settings and headers) to EUR 12,000 when the permission model must be redesigned. The retest then confirms each flaw is closed, and that report is what you send to facilities.

Plan an annual renewal and a targeted test after each major change (new API, new teleconsultation module).

Mini case study

Julien is CTO of a care coordination platform (40,000 patients, 600 professionals) bidding for a hospital group contract worth EUR 180,000 per year in licences. The tender requires a pentest less than 12 months old.

Need a professional website?

Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.

Prefer a call back?

Leave your WhatsApp number and a Kolonell expert will get back to you within 1 business day. Free, no strings attached.

  • Grey-box web + API pentest by a certified provider: 9 days at EUR 1,250 = EUR 11,250
  • Fixes (3 high, 9 medium flaws): 6 days of in-house work, i.e. EUR 5,400
  • Retest: EUR 1,500
  • Total budget: EUR 18,150, about 10% of the contract's first year

Without this report, the bid would have been rejected at the eligibility check. The same report is then reused for two other prospected facilities.

FAQ

How long does it take to get the report?

Allow 3 to 8 weeks of lead time for a certified provider, 1 to 2 weeks of testing, then 5 to 10 working days for the final report.

Should we test in production?

Preferably on an identical staging environment loaded with dummy data. Testing in production with real health data requires strict contractual framing and a low-activity window.

Does a pentest replace certified health hosting?

No. Hosting certification covers the provider; the pentest assesses your application. Both are complementary and often requested together.

What frequency is reasonable?

One full test per year and a targeted 2 to 3 day test, i.e. EUR 2,500 to 4,000, after each major change.

What does OWASP ASVS add?

It is a standard of about 280 requirements across 3 levels. Targeting level 2 gives hospitals a clear grid that is comparable between suppliers.

Let's scope your project. Describe your platform, APIs and tender deadlines: we will scope the pentest, fixes and retest, from EUR 6,000 to 15,000 excl. VAT for the audit. Detailed quote within 48 h. WhatsApp +221 77 596 93 33.

Tags:#penetration test#pentest#web application security#Berlin#health data#certified auditor
Share:

Mohamed Bah

Fondateur, Kolonell

Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.