The verdict in three sentences
For an SME hosting a customer portal with personal data, a grey-box pentest of 5 to 10 days, billed at EUR 5,000 to 12,000 (about USD 5,400 to 13,000), is the format that satisfies enterprise security questionnaires. The real budget also includes OWASP Top 10 fixes (5 to 15 development days) and a re-test at around EUR 1,500, without which the report proves nothing. A certified provider (PASSI in France, CREST or equivalent elsewhere) costs 20 to 30 % more and is only justified when a customer or a regulation requires it.
Black, grey or white box: which scope to buy
The test mode drives the price as much as the value of the report. In black box, the tester starts from nothing and spends part of the time discovering what you could simply hand over. In grey box, they get user accounts for every role, which lets them test access rights, the number one source of leaks on a customer portal.
| Test mode | What the tester receives | Typical SME duration | Price (2026 order of magnitude) | Recommended use |
|---|---|---|---|---|
| Black box | URL only | 4 to 6 days | EUR 4,000 to 7,500 | External attacker simulation |
| Grey box | Accounts for each role, API documentation | 5 to 10 days | EUR 5,000 to 12,000 | Customer portal, enterprise requirement |
| White box | Source code + accounts | 8 to 15 days | EUR 9,000 to 19,000 | Critical app, before fundraising |
| Automated scan only | Nothing, SaaS tool | A few hours | EUR 100 to 400 a month | Continuous monitoring, not a pentest |
| Certified provider (grey box) | Same as grey box | 6 to 10 days | EUR 6,500 to 15,500 | Healthcare, finance, regulated operators |
An experienced tester's day rate sits between EUR 900 and 1,300. Be wary of offers at EUR 2,500 for "a full pentest": it is almost always an automated scan dressed up as a report.
The full cost: testing, fixes, re-test
A pentest report lists vulnerabilities ranked by severity. The real budget depends on what you do next.
| Item | 2026 range | Who carries it | Comment |
|---|---|---|---|
| Scoping and rules of engagement | 0 to 1 day | Provider | Written authorisation required, IP and URL scope |
| Penetration testing | EUR 5,000 to 12,000 | Provider | 5 to 10 days depending on roles and APIs |
| Critical and high fixes | 3 to 8 dev days | Your team or agency | Access control, injection, sessions |
| Medium fixes | 2 to 7 dev days | Your team or agency | Headers, password policy, logging |
| Re-test | about EUR 1,500 | Provider | 1 to 1.5 days, remediation certificate |
| Next annual pentest | 70 to 80 % of the first | Provider | Scope already known |
At a development cost of EUR 550 to 700 a day, fixes amount to EUR 2,750 to 10,500. On a recent, well-structured application you stay at the low end. On old code with no framework, access control fixes may require a partial rebuild.
What insurers and enterprise customers look for
Cyber insurers increasingly ask for a report less than 12 months old and proof that critical vulnerabilities are fixed. Enterprise customers send questionnaires of 80 to 200 questions in which the pentest carries a lot of weight. A report with a clear executive summary, a risk matrix and a re-test certificate saves several weeks in vendor onboarding. Data protection rules (GDPR article 32 in Europe, state privacy laws in the US) also require regular testing of security measures.
Mini case study
Julian, IT director of a logistics services SME in New York (60 staff), must answer the security questionnaire of an enterprise customer worth EUR 900,000 in annual revenue. His customer portal holds addresses, contacts and delivery histories.
Need a professional website?
Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.
- Grey-box pentest, 7 days at EUR 1,100: EUR 7,700.
- Fixes: 2 high vulnerabilities (access control, IDOR) and 6 medium ones, i.e. 9 days at EUR 600: EUR 5,400.
- Re-test: EUR 1,500.
- Total: EUR 14,600, i.e. 1.6 % of the protected contract.
- Bonus: the cyber insurance premium drops 8 %, about EUR 600 a year on a EUR 7,500 premium.
FAQ
What does a web application penetration test cost in 2026?
A grey-box pentest costs EUR 5,000 to 12,000 for 5 to 10 days. The price depends on the number of user roles, APIs and sensitive features such as payments.
Do we need a certified provider?
Only if a customer, a regulator or a public tender requires it. It costs 20 to 30 % more for a methodology framed by a recognised body.
Can the test break production?
The risk is low but real. Testing ideally happens on an identical staging environment, or in production during an agreed window with a backup verified the day before.
How often should we repeat a pentest?
Once a year, and after any major change (new payment module, new API). The follow-up pentest often costs 70 to 80 % of the first one.
How long do fixes take?
Budget 5 to 15 development days depending on code quality. Critical vulnerabilities should be fixed within 2 to 4 weeks to stay credible with an enterprise customer.
Let's scope your project. Send us the pentest report or your customer's questionnaire: we will price the OWASP fixes, the re-test and a 2 to 6 week plan. Detailed quote within 48 h. WhatsApp +221 77 596 93 33.
Mohamed Bah
Fondateur, Kolonell
Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.