The verdict in three sentences
When an enterprise client demands a penetration test, an SME should budget EUR 4,000 to 15,000 excl. VAT for the audit, then EUR 2,000 to 8,000 of fixes and a 1 to 2 day retest. The key decision is the mode (grey box in 80% of cases) and a provider able to deliver a report structured around the OWASP Top 10, ideally PASSI-qualified if your client is public or regulated. Well scoped, this pentest becomes a sales argument and lowers your cyber insurance premium.
What a web app pentest costs in 2026
Price depends on auditor days, billed at EUR 900 to 1,500 excl. VAT per day in France depending on seniority and firm qualification.
| Scope | Recommended mode | Audit days | Indicative price excl. VAT |
|---|---|---|---|
| Brochure site with forms | Black box | 2 to 3 days | EUR 2,500 to 4,000 |
| Simple business app (1 role, 20 screens) | Grey box | 3 to 4 days | EUR 4,000 to 6,000 |
| Multi-role B2B SaaS + REST API | Grey box | 5 to 6 days | EUR 6,500 to 9,500 |
| SaaS + API + mobile app | Grey box | 7 to 8 days | EUR 9,500 to 12,500 |
| Full audit with code review | White box | 8 to 10 days | EUR 11,000 to 15,000 |
| Retest after fixes | Same mode | 1 to 2 days | EUR 1,200 to 2,500 |
These are 2026 orders of magnitude. A provider qualified PASSI by ANSSI (the French cybersecurity agency) usually charges 15 to 25% more than a non-qualified firm, but its report is accepted without debate by banks, insurers and public bodies.
Black, grey or white box: which scope to choose
| Mode | What the auditor receives | What they find | When to choose it |
|---|---|---|---|
| Black box | Only the URL | Publicly exposed flaws | Surface test, tight budget |
| Grey box | Test accounts per role | Privilege escalation, access to other clients' data (IDOR) | Standard client requirement, B2B SaaS |
| White box | Accounts + source code + architecture | Logic flaws, secrets in code, subtle injection | Critical app, sensitive data |
For a B2B SaaS, grey box offers the best cost-to-coverage ratio: the most frequent flaw in 2026 is still broken access control (category A01 of the OWASP Top 10), which lets one client read another client's data. It is only found with authenticated accounts.
Reading the report and budgeting fixes
A good report includes an executive summary, a list of vulnerabilities scored with CVSS, reproduction evidence and concrete recommendations. Here are typical findings on an SME application and their fix cost.
| Severity | Common example | Average count per audit | Fix cost excl. VAT |
|---|---|---|---|
| Critical (CVSS 9 to 10) | Access to another client's data (IDOR) | 0 to 1 | EUR 800 to 2,500 |
| High (7 to 8.9) | SQL injection, authentication bypass | 1 to 2 | EUR 600 to 2,000 |
| Medium (4 to 6.9) | No login attempt rate limiting | 3 to 5 | EUR 300 to 800 |
| Low (0.1 to 3.9) | Missing security headers (CSP, HSTS) | 4 to 8 | EUR 100 to 300 |
| Typical total fixes | EUR 2,000 to 8,000 |
On the contract side, your enterprise client will often ask for a certificate that critical and high flaws are fixed within 30 to 90 days, plus an annual pentest. Negotiate so the full report stays confidential and only the summary is shared.
Mini case study
Need a professional website?
Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.
Julien, CEO of a 25-person Lyon SME publishing fleet management software, must sign a EUR 180,000 per year contract with a transport group. The security clause requires a pentest. He orders a 5-day grey box audit at EUR 7,500 excl. VAT; the auditor finds 1 critical, 2 high and 6 medium flaws. Fixes cost EUR 4,200 and the retest EUR 1,500. Total: EUR 13,200 excl. VAT, or 7.3% of the contract's first year. Bonus: his cyber insurer cuts the premium by 12%, saving EUR 540 a year.
FAQ
How often should a pentest be repeated?
At least once a year, and after every major change (new payment module, new API). Many enterprise contracts impose an annual cycle, i.e. EUR 4,000 to 10,000 excl. VAT per year for an SME.
Is an automated scanner enough?
No: a scanner at EUR 50 to 300 per month detects known flaws and missing headers, but it misses logic flaws such as access to another client's data. Use it between pentests, not instead of them.
Do we need a PASSI provider?
It is mandatory for operators of vital importance and strongly expected by banks and the public sector. For a standard private client, a serious firm with OSCP or equivalent certifications is enough and costs 15 to 25% less.
Can the pentest break the production app?
The risk exists but is low if the audit targets a staging environment with anonymized data. Allow 1 to 2 days to set up that environment if you do not have one.
How long between order and report?
Expect 2 to 4 weeks of scheduling lead time with a good firm, then 3 to 8 audit days and 5 business days for the report. Plan 5 to 7 weeks ahead of the contractual deadline.
Let's scope your project. Tell us about your application and your client's requirement: we prepare the test environment, fix the reported flaws (EUR 2,000 to 8,000 on average) and manage the retest. Detailed quote within 48 h. WhatsApp +221 77 596 93 33.
Mohamed Bah
Fondateur, Kolonell
Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.