Websites10 min read

Web application penetration test for an SME: price, scope and report in 2026

Mohamed Bah·Fondateur, Kolonell
October 6, 2026
Share:
Web application penetration test for an SME: price, scope and report in 2026

Web application penetration test for an SME: price, scope and report in 2026

Websites

The verdict in three sentences

When an enterprise client demands a penetration test, an SME should budget EUR 4,000 to 15,000 excl. VAT for the audit, then EUR 2,000 to 8,000 of fixes and a 1 to 2 day retest. The key decision is the mode (grey box in 80% of cases) and a provider able to deliver a report structured around the OWASP Top 10, ideally PASSI-qualified if your client is public or regulated. Well scoped, this pentest becomes a sales argument and lowers your cyber insurance premium.

What a web app pentest costs in 2026

Price depends on auditor days, billed at EUR 900 to 1,500 excl. VAT per day in France depending on seniority and firm qualification.

ScopeRecommended modeAudit daysIndicative price excl. VAT
Brochure site with formsBlack box2 to 3 daysEUR 2,500 to 4,000
Simple business app (1 role, 20 screens)Grey box3 to 4 daysEUR 4,000 to 6,000
Multi-role B2B SaaS + REST APIGrey box5 to 6 daysEUR 6,500 to 9,500
SaaS + API + mobile appGrey box7 to 8 daysEUR 9,500 to 12,500
Full audit with code reviewWhite box8 to 10 daysEUR 11,000 to 15,000
Retest after fixesSame mode1 to 2 daysEUR 1,200 to 2,500

These are 2026 orders of magnitude. A provider qualified PASSI by ANSSI (the French cybersecurity agency) usually charges 15 to 25% more than a non-qualified firm, but its report is accepted without debate by banks, insurers and public bodies.

Black, grey or white box: which scope to choose

ModeWhat the auditor receivesWhat they findWhen to choose it
Black boxOnly the URLPublicly exposed flawsSurface test, tight budget
Grey boxTest accounts per rolePrivilege escalation, access to other clients' data (IDOR)Standard client requirement, B2B SaaS
White boxAccounts + source code + architectureLogic flaws, secrets in code, subtle injectionCritical app, sensitive data

For a B2B SaaS, grey box offers the best cost-to-coverage ratio: the most frequent flaw in 2026 is still broken access control (category A01 of the OWASP Top 10), which lets one client read another client's data. It is only found with authenticated accounts.

Reading the report and budgeting fixes

A good report includes an executive summary, a list of vulnerabilities scored with CVSS, reproduction evidence and concrete recommendations. Here are typical findings on an SME application and their fix cost.

SeverityCommon exampleAverage count per auditFix cost excl. VAT
Critical (CVSS 9 to 10)Access to another client's data (IDOR)0 to 1EUR 800 to 2,500
High (7 to 8.9)SQL injection, authentication bypass1 to 2EUR 600 to 2,000
Medium (4 to 6.9)No login attempt rate limiting3 to 5EUR 300 to 800
Low (0.1 to 3.9)Missing security headers (CSP, HSTS)4 to 8EUR 100 to 300
Typical total fixesEUR 2,000 to 8,000

On the contract side, your enterprise client will often ask for a certificate that critical and high flaws are fixed within 30 to 90 days, plus an annual pentest. Negotiate so the full report stays confidential and only the summary is shared.

Mini case study

Need a professional website?

Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.

Prefer a call back?

Leave your WhatsApp number and a Kolonell expert will get back to you within 1 business day. Free, no strings attached.

Julien, CEO of a 25-person Lyon SME publishing fleet management software, must sign a EUR 180,000 per year contract with a transport group. The security clause requires a pentest. He orders a 5-day grey box audit at EUR 7,500 excl. VAT; the auditor finds 1 critical, 2 high and 6 medium flaws. Fixes cost EUR 4,200 and the retest EUR 1,500. Total: EUR 13,200 excl. VAT, or 7.3% of the contract's first year. Bonus: his cyber insurer cuts the premium by 12%, saving EUR 540 a year.

FAQ

How often should a pentest be repeated?

At least once a year, and after every major change (new payment module, new API). Many enterprise contracts impose an annual cycle, i.e. EUR 4,000 to 10,000 excl. VAT per year for an SME.

Is an automated scanner enough?

No: a scanner at EUR 50 to 300 per month detects known flaws and missing headers, but it misses logic flaws such as access to another client's data. Use it between pentests, not instead of them.

Do we need a PASSI provider?

It is mandatory for operators of vital importance and strongly expected by banks and the public sector. For a standard private client, a serious firm with OSCP or equivalent certifications is enough and costs 15 to 25% less.

Can the pentest break the production app?

The risk exists but is low if the audit targets a staging environment with anonymized data. Allow 1 to 2 days to set up that environment if you do not have one.

How long between order and report?

Expect 2 to 4 weeks of scheduling lead time with a good firm, then 3 to 8 audit days and 5 business days for the report. Plan 5 to 7 weeks ahead of the contractual deadline.

Let's scope your project. Tell us about your application and your client's requirement: we prepare the test environment, fix the reported flaws (EUR 2,000 to 8,000 on average) and manage the retest. Detailed quote within 48 h. WhatsApp +221 77 596 93 33.

Tags:#penetration test#pentest#web application security#OWASP#PASSI#pentest price 2026
Share:

Mohamed Bah

Fondateur, Kolonell

Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.