Websites11 min read

Web Application Penetration Test Price in Amsterdam (2026)

Mohamed Bah·Fondateur, Kolonell
October 9, 2026
Share:
Web Application Penetration Test Price in Amsterdam (2026)

Web Application Penetration Test Price in Amsterdam (2026)

Websites

The verdict in three sentences

For a mid-sized company's client extranet, the right format is a grey-box pentest of 5 to 10 person-days, priced at EUR 6,000 to 15,000 excluding VAT in 2026. The full budget must include remediation, worth 20 to 60% of the audit price, and a retest after fixes. A recognised certification for the testing provider (CREST, or a national qualification such as PASSI in France) is only mandatory in some regulatory contexts, but it carries real weight when a large client demands it in its security questionnaire.

Audit levels and their price

« Security audit » covers very different services. Before comparing quotes, compare scopes.

Service typeScopeDurationIndicative 2026 price
Automated scanVulnerability tools, raw report1 dayEUR 800 to 2,000
Black-box pentestAttack with no account or prior information3 to 6 person-daysEUR 4,000 to 9,000
Grey-box pentestAttack with test accounts per role5 to 10 person-daysEUR 6,000 to 15,000
White-box pentest with code reviewAccess to source code and architecture10 to 20 person-daysEUR 12,000 to 30,000
Infrastructure configuration auditServers, cloud, WAF, TLS2 to 5 person-daysEUR 2,500 to 7,000
Retest after fixesVerification of fixed flaws1 to 2 person-daysEUR 1,000 to 2,500

The day rate of an experienced tester is between EUR 1,000 and 1,500, and EUR 1,300 to 1,800 for a CREST-accredited provider.

What a serious OWASP pentest covers

The OWASP Top 10 is the baseline. A serious report does not stop at a list: it ranks each flaw by severity, shows proof of exploitation and proposes a fix.

OWASP categoryConcrete example on an extranetObserved frequency
Broken access controlA client sees another client's invoices by changing an ID in the URLVery common
Cryptographic failuresPasswords stored with weak hashingCommon
InjectionSearch field vulnerable to SQL injectionLess common on modern frameworks
Security misconfigurationMissing security headers, verbose error pagesVery common
Vulnerable componentsJavaScript library not updated for 3 yearsCommon
Authentication failuresNo rate limiting on login attemptsCommon
Insufficient loggingNo trace of document downloadsVery common

Certified provider or not: how to choose

Certification guarantees an assessed methodology and testers. It is often required for critical infrastructure operators and recommended for entities in scope of NIS 2. For a mid-sized company answering a large industrial client's questionnaire, the question is simple: does the client require a certified provider? If yes, the 15 to 25% premium is unavoidable. If not, an experienced non-certified provider with a report following OWASP methodology is often enough.

Mini case study

Need a professional website?

Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.

Prefer a call back?

Leave your WhatsApp number and a Kolonell expert will get back to you within 1 business day. Free, no strings attached.

Pieter, CIO of a 450-employee aerospace subcontractor in Amsterdam, must provide a pentest certificate for his supplier extranet before renewing a EUR 4 million contract. He orders a 7 person-day grey-box pentest at EUR 1,250, or EUR 8,750. The report reveals 2 critical and 6 medium flaws. Fixes take 12 development days at EUR 600, EUR 7,200, then a retest at EUR 1,500. Total budget: EUR 17,450, or 0.4% of the contract secured.

FAQ

How long from order to report?

Providers usually have a 2 to 4 week lead time. Testing takes 1 to 2 weeks and the report is delivered 5 to 10 working days later.

Should we test in production or staging?

Staging is preferable if it mirrors production. Otherwise, testing in production is possible with an agreed window and dedicated accounts, with no noticeable user impact in 95% of cases.

How often should we repeat a pentest?

At least once a year, and after every major change to the application. Many large clients require a report less than 12 months old.

Who fixes the flaws found?

The team that maintains the application. If you have no in-house team, a development agency can handle remediation, usually 20 to 60% of the audit price depending on severity.

Let's scope your project. Send us your application URL, the number of user roles and your client's requirement, and we will price the audit, fixes and retest within a 4 to 6 week schedule. Detailed quote within 48 h. WhatsApp +221 77 596 93 33.

Tags:#web application pentest#security audit#OWASP#Amsterdam#pentest price#custom development#development agency 2026
Share:

Mohamed Bah

Fondateur, Kolonell

Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.