The verdict in three sentences
For a mid-sized company's client extranet, the right format is a grey-box pentest of 5 to 10 person-days, priced at EUR 6,000 to 15,000 excluding VAT in 2026. The full budget must include remediation, worth 20 to 60% of the audit price, and a retest after fixes. A recognised certification for the testing provider (CREST, or a national qualification such as PASSI in France) is only mandatory in some regulatory contexts, but it carries real weight when a large client demands it in its security questionnaire.
Audit levels and their price
« Security audit » covers very different services. Before comparing quotes, compare scopes.
| Service type | Scope | Duration | Indicative 2026 price |
|---|---|---|---|
| Automated scan | Vulnerability tools, raw report | 1 day | EUR 800 to 2,000 |
| Black-box pentest | Attack with no account or prior information | 3 to 6 person-days | EUR 4,000 to 9,000 |
| Grey-box pentest | Attack with test accounts per role | 5 to 10 person-days | EUR 6,000 to 15,000 |
| White-box pentest with code review | Access to source code and architecture | 10 to 20 person-days | EUR 12,000 to 30,000 |
| Infrastructure configuration audit | Servers, cloud, WAF, TLS | 2 to 5 person-days | EUR 2,500 to 7,000 |
| Retest after fixes | Verification of fixed flaws | 1 to 2 person-days | EUR 1,000 to 2,500 |
The day rate of an experienced tester is between EUR 1,000 and 1,500, and EUR 1,300 to 1,800 for a CREST-accredited provider.
What a serious OWASP pentest covers
The OWASP Top 10 is the baseline. A serious report does not stop at a list: it ranks each flaw by severity, shows proof of exploitation and proposes a fix.
| OWASP category | Concrete example on an extranet | Observed frequency |
|---|---|---|
| Broken access control | A client sees another client's invoices by changing an ID in the URL | Very common |
| Cryptographic failures | Passwords stored with weak hashing | Common |
| Injection | Search field vulnerable to SQL injection | Less common on modern frameworks |
| Security misconfiguration | Missing security headers, verbose error pages | Very common |
| Vulnerable components | JavaScript library not updated for 3 years | Common |
| Authentication failures | No rate limiting on login attempts | Common |
| Insufficient logging | No trace of document downloads | Very common |
Certified provider or not: how to choose
Certification guarantees an assessed methodology and testers. It is often required for critical infrastructure operators and recommended for entities in scope of NIS 2. For a mid-sized company answering a large industrial client's questionnaire, the question is simple: does the client require a certified provider? If yes, the 15 to 25% premium is unavoidable. If not, an experienced non-certified provider with a report following OWASP methodology is often enough.
Mini case study
Need a professional website?
Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.
Pieter, CIO of a 450-employee aerospace subcontractor in Amsterdam, must provide a pentest certificate for his supplier extranet before renewing a EUR 4 million contract. He orders a 7 person-day grey-box pentest at EUR 1,250, or EUR 8,750. The report reveals 2 critical and 6 medium flaws. Fixes take 12 development days at EUR 600, EUR 7,200, then a retest at EUR 1,500. Total budget: EUR 17,450, or 0.4% of the contract secured.
FAQ
How long from order to report?
Providers usually have a 2 to 4 week lead time. Testing takes 1 to 2 weeks and the report is delivered 5 to 10 working days later.
Should we test in production or staging?
Staging is preferable if it mirrors production. Otherwise, testing in production is possible with an agreed window and dedicated accounts, with no noticeable user impact in 95% of cases.
How often should we repeat a pentest?
At least once a year, and after every major change to the application. Many large clients require a report less than 12 months old.
Who fixes the flaws found?
The team that maintains the application. If you have no in-house team, a development agency can handle remediation, usually 20 to 60% of the audit price depending on severity.
Let's scope your project. Send us your application URL, the number of user roles and your client's requirement, and we will price the audit, fixes and retest within a 4 to 6 week schedule. Detailed quote within 48 h. WhatsApp +221 77 596 93 33.
Mohamed Bah
Fondateur, Kolonell
Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.