The verdict in three sentences
In 2026, a grey-box penetration test of an SMB web application takes 5 to 10 auditor days billed at EUR 1,000 to 1,400 per day ex. VAT in Dublin or Paris, so EUR 5,000 to 14,000 before fixes. The real budget also covers 8 to 20 days of development to fix vulnerabilities and a retest, often billed separately. When a banking client demands the report, choosing a certified provider (CREST in Ireland and the UK, PASSI in France) avoids redoing the audit six months later.
What a pentest costs depending on scope
The number of days depends on user roles, screens, API endpoints and whether a mobile app is in scope. Grey box (the auditor gets test accounts) is the format financial buyers ask for most, because it covers access-control flaws that black-box testing misses.
| Scope | Audit days | 2026 budget (ex. VAT) | Typical use |
|---|---|---|---|
| Brochure site or simple app, 1 role | 3 to 4 | EUR 3,000 to 5,500 | Pre-launch check |
| SaaS app, 2 to 3 roles | 5 to 7 | EUR 5,000 to 9,800 | B2B client requirement |
| Fintech app + REST API | 7 to 10 | EUR 7,000 to 14,000 | Bank due diligence |
| Web + iOS/Android app | 10 to 15 | EUR 10,000 to 21,000 | Payments, health |
| Retest of fixed vulnerabilities | 1 to 2 | EUR 1,000 to 2,800 | Proof of remediation |
| Targeted code review (optional) | 3 to 5 | EUR 3,000 to 7,000 | Critical functions |
Capital-city day rates in Dublin and Paris sit roughly 10 to 15% above regional rates, based on 2026 quotes we have reviewed.
Certified firm or freelancer: what you are really buying
Certification (CREST, or PASSI issued by France's ANSSI) is not mandatory for an SMB, but many banks, insurers and regulated operators require it in supplier questionnaires, especially since the EU DORA regulation started applying in January 2025 to their ICT supply chain.
| Criterion | Certified provider | Non-certified firm | Experienced freelancer |
|---|---|---|---|
| Indicative 2026 day rate | EUR 1,200 to 1,400 | EUR 1,000 to 1,250 | EUR 650 to 950 |
| Recognition by a bank | Very strong | Variable | Weak without references |
| Documented methodology | Externally audited | In-house | Variable |
| Start lead time | 4 to 8 weeks | 2 to 4 weeks | 1 to 2 weeks |
| Professional indemnity insurance | Always | Usually | Check |
| Retest included | Rarely, 1 to 2 extra days | Sometimes | Often negotiable |
A freelancer works well for an internal audit before going live. For a report aimed at a banking client, first ask that client for its written requirements: many accept a non-certified firm if it covers the OWASP Top 10 and OWASP ASVS level 2.
The real budget: audit, fixes, retest
The OWASP Top 10 (broken access control, cryptographic failures, injection, insecure design, security misconfiguration...) structures most reports. On a fintech app never audited before, a first pentest typically surfaces 2 to 5 critical or high vulnerabilities and 8 to 15 medium or low ones. Fixes take 8 to 20 days of development, or EUR 4,800 to 13,000 at a senior developer day rate of EUR 600 to 650.
To avoid surprises:
- require a report with CVSS scores and proof of exploitation for each flaw;
- state in the purchase order whether the retest is included and within what window (often 3 months);
- prepare a staging environment identical to production, with dummy data;
- schedule fixes in the sprint after the audit, not the next quarter.
Mini case study
Need a professional website?
Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.
Niamh, CISO of a 40-person fintech in Dublin, must hand a pentest report to a partner bank before signing a contract worth EUR 380,000 a year.
- Certified grey-box audit, web app + API: 8 days × EUR 1,300 = EUR 10,400.
- Fixes: 3 high and 9 medium flaws, 14 days × EUR 620 = EUR 8,680.
- Retest: 1.5 days × EUR 1,300 = EUR 1,950.
- Total: EUR 21,030 ex. VAT, or 5.5% of the first year of the contract it unlocks.
The bank treats the report as valid for 12 months, which also serves the next two prospects.
FAQ
How much does a penetration test cost for an SMB?
Between EUR 5,000 and 14,000 ex. VAT for a grey-box web application test over 5 to 10 days. Add the retest (EUR 1,000 to 2,800) and the cost of fixes.
Is certification mandatory?
Not for a typical SMB. It is, however, often required by banks, insurers and critical infrastructure operators in tenders and supplier questionnaires.
Black, grey or white box: which to choose?
Grey box gives the best coverage-to-price ratio, because the auditor tests every user role. White box (code access) adds 3 to 5 days but finds more logic flaws.
How often should I repeat a pentest?
Once a year and after every major change (new payment module, authentication rebuild). Banking clients usually ask for a report less than 12 months old.
How long does remediation take?
As a 2026 order of magnitude, 8 to 20 development days for a first campaign. Critical flaws should be fixed within 15 days, medium ones within the quarter.
Let's scope your project. Describe your application, your user roles and your client's requirement: we scope the audit, the remediation budget and the retest with a realistic schedule. Detailed quote within 48 h. WhatsApp +221 77 596 93 33.
Mohamed Bah
Fondateur, Kolonell
Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.
