Websites11 min read

Web Application Penetration Test Price for SMBs in Dublin in 2026

Mohamed Bah·Fondateur, Kolonell
October 5, 2026
Share:
Web Application Penetration Test Price for SMBs in Dublin in 2026

Web Application Penetration Test Price for SMBs in Dublin in 2026

Websites

The verdict in three sentences

In 2026, a grey-box penetration test of an SMB web application takes 5 to 10 auditor days billed at EUR 1,000 to 1,400 per day ex. VAT in Dublin or Paris, so EUR 5,000 to 14,000 before fixes. The real budget also covers 8 to 20 days of development to fix vulnerabilities and a retest, often billed separately. When a banking client demands the report, choosing a certified provider (CREST in Ireland and the UK, PASSI in France) avoids redoing the audit six months later.

What a pentest costs depending on scope

The number of days depends on user roles, screens, API endpoints and whether a mobile app is in scope. Grey box (the auditor gets test accounts) is the format financial buyers ask for most, because it covers access-control flaws that black-box testing misses.

ScopeAudit days2026 budget (ex. VAT)Typical use
Brochure site or simple app, 1 role3 to 4EUR 3,000 to 5,500Pre-launch check
SaaS app, 2 to 3 roles5 to 7EUR 5,000 to 9,800B2B client requirement
Fintech app + REST API7 to 10EUR 7,000 to 14,000Bank due diligence
Web + iOS/Android app10 to 15EUR 10,000 to 21,000Payments, health
Retest of fixed vulnerabilities1 to 2EUR 1,000 to 2,800Proof of remediation
Targeted code review (optional)3 to 5EUR 3,000 to 7,000Critical functions

Capital-city day rates in Dublin and Paris sit roughly 10 to 15% above regional rates, based on 2026 quotes we have reviewed.

Certified firm or freelancer: what you are really buying

Certification (CREST, or PASSI issued by France's ANSSI) is not mandatory for an SMB, but many banks, insurers and regulated operators require it in supplier questionnaires, especially since the EU DORA regulation started applying in January 2025 to their ICT supply chain.

CriterionCertified providerNon-certified firmExperienced freelancer
Indicative 2026 day rateEUR 1,200 to 1,400EUR 1,000 to 1,250EUR 650 to 950
Recognition by a bankVery strongVariableWeak without references
Documented methodologyExternally auditedIn-houseVariable
Start lead time4 to 8 weeks2 to 4 weeks1 to 2 weeks
Professional indemnity insuranceAlwaysUsuallyCheck
Retest includedRarely, 1 to 2 extra daysSometimesOften negotiable

A freelancer works well for an internal audit before going live. For a report aimed at a banking client, first ask that client for its written requirements: many accept a non-certified firm if it covers the OWASP Top 10 and OWASP ASVS level 2.

The real budget: audit, fixes, retest

The OWASP Top 10 (broken access control, cryptographic failures, injection, insecure design, security misconfiguration...) structures most reports. On a fintech app never audited before, a first pentest typically surfaces 2 to 5 critical or high vulnerabilities and 8 to 15 medium or low ones. Fixes take 8 to 20 days of development, or EUR 4,800 to 13,000 at a senior developer day rate of EUR 600 to 650.

To avoid surprises:

  • require a report with CVSS scores and proof of exploitation for each flaw;
  • state in the purchase order whether the retest is included and within what window (often 3 months);
  • prepare a staging environment identical to production, with dummy data;
  • schedule fixes in the sprint after the audit, not the next quarter.

Mini case study

Need a professional website?

Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.

Prefer a call back?

Leave your WhatsApp number and a Kolonell expert will get back to you within 1 business day. Free, no strings attached.

Niamh, CISO of a 40-person fintech in Dublin, must hand a pentest report to a partner bank before signing a contract worth EUR 380,000 a year.

  • Certified grey-box audit, web app + API: 8 days × EUR 1,300 = EUR 10,400.
  • Fixes: 3 high and 9 medium flaws, 14 days × EUR 620 = EUR 8,680.
  • Retest: 1.5 days × EUR 1,300 = EUR 1,950.
  • Total: EUR 21,030 ex. VAT, or 5.5% of the first year of the contract it unlocks.

The bank treats the report as valid for 12 months, which also serves the next two prospects.

FAQ

How much does a penetration test cost for an SMB?

Between EUR 5,000 and 14,000 ex. VAT for a grey-box web application test over 5 to 10 days. Add the retest (EUR 1,000 to 2,800) and the cost of fixes.

Is certification mandatory?

Not for a typical SMB. It is, however, often required by banks, insurers and critical infrastructure operators in tenders and supplier questionnaires.

Black, grey or white box: which to choose?

Grey box gives the best coverage-to-price ratio, because the auditor tests every user role. White box (code access) adds 3 to 5 days but finds more logic flaws.

How often should I repeat a pentest?

Once a year and after every major change (new payment module, authentication rebuild). Banking clients usually ask for a report less than 12 months old.

How long does remediation take?

As a 2026 order of magnitude, 8 to 20 development days for a first campaign. Critical flaws should be fixed within 15 days, medium ones within the quarter.

Let's scope your project. Describe your application, your user roles and your client's requirement: we scope the audit, the remediation budget and the retest with a realistic schedule. Detailed quote within 48 h. WhatsApp +221 77 596 93 33.

Tags:#penetration test#pentest price#web application security#OWASP#CREST#security audit Dublin
Share:

Mohamed Bah

Fondateur, Kolonell

Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.