Websites11 min read

Web Application Penetration Testing Cost in Dublin

Mohamed Bah·Fondateur, Kolonell
October 1, 2026
Share:
Web Application Penetration Testing Cost in Dublin

Web Application Penetration Testing Cost in Dublin

Websites

The verdict in three sentences

A grey-box penetration test of a business web application costs EUR 8,000 to 25,000 in Dublin in 2026, against EUR 6,000 to 18,000 in a French regional hub such as Rennes, where testers bill EUR 1,000 to 1,300 per day for 5 to 15 days. Price depends mainly on scope (number of roles, APIs and critical flows), far more than on codebase size. Plan an annual test, a test after each major release and a retest of EUR 1,500 to 3,000 to prove to your enterprise client that findings are fixed.

What the enterprise client actually expects

The scenario is familiar for a software vendor: a bank, an insurer or a critical infrastructure operator sends a security questionnaire of 150 to 300 questions and asks for "your latest pentest report, less than 12 months old". Without it, vendor onboarding stalls, sometimes for a full quarter.

What the buyer reads in the report, in this order: the date of the test, the scope (is the product you sell the one that was tested?), the methodology (OWASP, grey box, test accounts per role), the number of critical and high findings still open, and the tester's accreditation. Since NIS2 transposition across the EU (Ireland included), essential and important entities push their obligations down the supply chain: they want evidence, not promises.

Common client requirementWhat satisfies itIndicative 2026 cost
Pentest report under 12 months oldGrey-box pentest of the product soldEUR 6,000 to 18,000 (France) / 8,000 to 25,000 (Dublin)
No critical or high finding openRemediation plan + retestEUR 1,500 to 3,000 retest
Accredited testerPASSI (France), CREST (Ireland/UK)+15 to 30 % vs non-accredited
Public API testedAPI scope extension+2 to 5 days, EUR 2,000 to 6,500
Evidence of ongoing practice (ISO 27001, NIS2)Annual pentest + after major releaseEUR 12,000 to 30,000 per year
Shareable summary letter2 to 4 page non-technical summaryOften included, otherwise EUR 500 to 1,000

Scope and price: the 2026 grid

Pentests are quoted in person-days. An experienced tester bills EUR 1,000 to 1,300 per day in Rennes, EUR 1,200 to 1,500 in Paris and EUR 1,300 to 1,700 in Dublin, which explains the EUR 8,000 to 25,000 range there. The number of days depends on four variables: the number of user roles (admin, manager, standard user, external customer), the number of sensitive features (payment, data export, permission management), whether an API is exposed, and whether there is a mobile app.

Application scopeAudit daysRennes budget (EUR 1,000 to 1,300/day)
Simple app, 2 roles, no public API5 daysEUR 6,000 to 6,500
Business app, 3 to 4 roles, back office7 to 8 daysEUR 7,500 to 10,400
Multi-client B2B SaaS, documented REST API10 daysEUR 10,000 to 13,000
SaaS + iOS/Android app12 to 13 daysEUR 12,500 to 17,000
SaaS + API + mobile + cloud infrastructure14 to 15 daysEUR 14,000 to 18,000
Retest of fixed findings1.5 to 2.5 daysEUR 1,500 to 3,000

Grey box (the tester gets test accounts for each role) is the right trade-off for a vendor: it tests what scares clients most, privilege escalation and access to another client's data. Black box costs less but finds less; white box (with source code access) adds 30 to 50 % and is mainly justified for financial applications.

Accredited or not? A PASSI-qualified tester in France, or CREST-accredited in Dublin, costs 15 to 30 % more, but regulated operators accept the report without debate. For an SME client, a serious non-accredited firm (OSCP certifications, verifiable references) is often enough. Ask your client what they require before choosing: the gap can reach EUR 3,000 to 4,000.

Frequency, fixes and the real annual cost

The pentest is only half the budget. Typical findings on a business application in 2026 are always the same: broken access control (IDOR), missing security headers, weak session handling, outdated dependencies, injection in a search field. Fixing them consumes your development team.

Typical findingUsual severityFix effortEstimated cost
Access to another client's data (IDOR)Critical3 to 8 daysEUR 1,800 to 5,000
Privilege escalation between rolesHigh2 to 5 daysEUR 1,200 to 3,000
Dependencies with known CVEsMedium to high1 to 3 daysEUR 600 to 1,800
Missing CSP, HSTS headersLow to medium0.5 to 1 dayEUR 300 to 600
Password policy, no MFAMedium2 to 4 daysEUR 1,200 to 2,400
Information leak in error messagesLow0.5 dayEUR 300

Rule of thumb: budget a remediation envelope equal to 50 to 100 % of the pentest price in year one, then 25 to 40 % in later years if you add automated dependency scanning to your deployment pipeline. For ISO 27001 (control 8.29 on security testing) and NIS2 alike, what matters is regularity: a documented annual test plus a test after each major change (new authentication, new API, move to multi-tenancy).

Mini case study

Need a professional website?

Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.

Prefer a call back?

Leave your WhatsApp number and a Kolonell expert will get back to you within 1 business day. Free, no strings attached.

Gaëlle, CISO of an HR software vendor in Rennes (45 staff), must hand a report to a national mutual insurer before signing a EUR 180,000 per year contract. Her application has 4 roles, a REST API and no mobile app.

  • PASSI grey-box pentest: 10 days x EUR 1,250 = EUR 12,500
  • Fixing 1 critical (IDOR) and 3 high findings: 9 dev days at EUR 600 = EUR 5,400
  • Retest: 2 days x EUR 1,250 = EUR 2,500
  • Total: EUR 20,400, i.e. 11.3 % of the contract's first year

The same scope tested in Dublin would land around EUR 15,000 to 17,000 for the pentest alone. Without a report, the contract does not get signed. With it, the vendor reuses the same document for two other tenders that year.

FAQ

How much does a web application pentest cost in Dublin in 2026?

Budget EUR 8,000 to 25,000 for a grey-box test, against EUR 6,000 to 18,000 in Rennes, for 5 to 15 audit days. An accredited tester adds 15 to 30 %.

How often should we repeat a pentest?

At least once a year, and after every major release (new authentication, new API, redesign). Most enterprise buyers reject a report older than 12 months.

Is a retest mandatory?

It is not mandatory, but it is what proves critical findings are closed. It costs EUR 1,500 to 3,000 and turns a worrying report into evidence of control.

Is a pentest enough for NIS2 or ISO 27001?

No, it is one control among many. It covers the requirement for regular security testing, alongside vulnerability management, logging and an incident response plan.

How long until we have the report?

Allow 2 to 4 weeks of scheduling lead time, 1 to 3 weeks of testing, then 5 to 10 days for the final report. Start 6 to 8 weeks before your client's deadline.

Let's scope your project. We prepare your application for the pentest and fix what it uncovers: defined scope, costed remediation budget, retest scheduled within 4 to 8 weeks. Detailed quote within 48 h. WhatsApp +221 77 596 93 33.

Tags:#penetration testing#pentest#web application security#Dublin#NIS2#CREST#2026 pricing
Share:

Mohamed Bah

Fondateur, Kolonell

Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.