The verdict in three sentences
Before opening a business application to customers, a grey-box penetration test is the reasonable minimum: budget USD 4,300 to 13,000 excl. tax (40,000 to 120,000 MAD on the Moroccan market) for 5 to 25 days, delivered in 3 weeks with a retest included. In Singapore, local firms typically charge 1.5 to 2.5 times these rates. The real cost often lies in fixing OWASP Top 10 vulnerabilities, so plan it from the quote, then set an annual security budget of 8 to 12% of the application cost and meet your PDPA obligations.
What a penetration test costs in 2026
Price depends on three variables: the surface to test (number of screens, roles and APIs), the mode (black, grey or white box) and report depth. For a B2B business application, grey box, where the tester receives test accounts for each role, gives the best coverage-to-cost ratio.
| Scope | Test days | Indicative price excl. tax | Example |
|---|---|---|---|
| Small app, 1 to 2 roles | 5 days | USD 4,300 to 5,400 | Order tracking portal |
| Mid-sized app, 3 roles, REST API | 8 to 10 days | USD 6,000 to 8,100 | Client area with documents and payments |
| Full application, API and mobile | 12 to 15 days | USD 8,100 to 10,300 | Service platform with mobile app |
| Multi-application system | 18 to 25 days | USD 10,300 to 13,000 | Extranet, back office and partner APIs |
| Retest after fixes | 1 to 3 days | Included or USD 870 to 1,600 | Verification of critical findings |
| Targeted code review add-on | 3 to 5 days | USD 2,700 to 4,300 | Authentication and access control |
A senior tester's day rate in Casablanca runs USD 540 to 870 in 2026, against roughly SGD 1,200 to 2,000 in Singapore. These are market orders of magnitude, used here to benchmark nearshore delivery.
What the test finds, and what fixes cost
Findings on business applications closely track the OWASP Top 10. Here is the distribution and average remediation cost observed in our audits.
| OWASP category | Observed frequency | Typical severity | Indicative fix cost |
|---|---|---|---|
| Broken access control (A01) | 60% of applications | Critical | USD 1,600 to 4,300 |
| Security misconfiguration (A05) | 55% | Medium to high | USD 540 to 1,600 |
| Vulnerable or outdated components (A06) | 45% | Variable | USD 870 to 2,700 |
| Authentication failures (A07) | 35% | High | USD 1,100 to 3,300 |
| Injection, including SQL (A03) | 20% | Critical | USD 870 to 2,200 |
| Insufficient logging (A09) | 70% | Medium | USD 650 to 1,600 |
A remediation budget equal to 50 to 100% of the test price is a sensible rule for an application that has never been audited.
Data protection law and timeline
As soon as the application processes customer personal data, Singapore's PDPA requires reasonable security arrangements, and Morocco's Law 09-08 requires a CNDP declaration plus adequate security measures. A dated penetration test report with a remediation plan is the simplest evidence of those measures. Typical timeline: 1 week of scoping and test account setup, 1 to 2 weeks of testing, 3 to 5 days for the report, then a retest after your fixes. About 3 weeks in total, excluding fix time.
Mini case study
Mr Bennani, CIO of a 120-person services company, opens a case-tracking application built for USD 97,000 (900,000 MAD) to 800 customers.
Need a professional website?
Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.
- Grey-box penetration test, 10 days: USD 7,600 excl. tax, retest included
- Fixes: 2 critical access control flaws and 5 medium findings, USD 5,200
- Annual security budget set at 10% of the application: USD 9,700, covering a yearly test, component monitoring and alerting
Total first-year cost: USD 12,800, or 13% of the application cost. A single customer data leak would have exposed the company to regulator penalties and lost contracts worth far more.
FAQ
Black, grey or white box: which to choose?
Grey box is the most cost-effective for a B2B application: it tests every user role, with 30 to 40% more coverage than black box for the same number of days. White box, with code access, costs 30 to 50% more.
Isn't an automated scanner enough?
A scanner catches outdated components and misconfigurations well, for USD 200 to 1,100 a year. It almost always misses access control flaws, which make up 60% of critical findings.
How often should we repeat a penetration test?
At least once a year, and at every major change (new module, new API, new user type). Enterprise customers often require a report less than 12 months old.
Can the report be used for regulators and tenders?
Yes, it comes with an executive summary in English or French, technical detail and a prioritised remediation plan. A retest certificate is issued once critical findings are fixed.
Can you also fix the vulnerabilities found?
Yes, our development team fixes them under a separate quote, with a different tester for the retest to keep the assessment independent.
Let's scope your project. Describe your application, its roles and APIs: we will price a penetration test between USD 4,300 and 13,000 excl. tax, delivered in 3 weeks with retest included. Detailed quote within 48 h. WhatsApp +221 77 596 93 33.
Mohamed Bah
Fondateur, Kolonell
Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.
