The verdict in three sentences
A grey-box penetration test of a business web application costs EUR 8,000 to 25,000 in Dublin in 2026, against EUR 6,000 to 18,000 in a French regional hub such as Rennes, where testers bill EUR 1,000 to 1,300 per day for 5 to 15 days. Price depends mainly on scope (number of roles, APIs and critical flows), far more than on codebase size. Plan an annual test, a test after each major release and a retest of EUR 1,500 to 3,000 to prove to your enterprise client that findings are fixed.
What the enterprise client actually expects
The scenario is familiar for a software vendor: a bank, an insurer or a critical infrastructure operator sends a security questionnaire of 150 to 300 questions and asks for "your latest pentest report, less than 12 months old". Without it, vendor onboarding stalls, sometimes for a full quarter.
What the buyer reads in the report, in this order: the date of the test, the scope (is the product you sell the one that was tested?), the methodology (OWASP, grey box, test accounts per role), the number of critical and high findings still open, and the tester's accreditation. Since NIS2 transposition across the EU (Ireland included), essential and important entities push their obligations down the supply chain: they want evidence, not promises.
| Common client requirement | What satisfies it | Indicative 2026 cost |
|---|---|---|
| Pentest report under 12 months old | Grey-box pentest of the product sold | EUR 6,000 to 18,000 (France) / 8,000 to 25,000 (Dublin) |
| No critical or high finding open | Remediation plan + retest | EUR 1,500 to 3,000 retest |
| Accredited tester | PASSI (France), CREST (Ireland/UK) | +15 to 30 % vs non-accredited |
| Public API tested | API scope extension | +2 to 5 days, EUR 2,000 to 6,500 |
| Evidence of ongoing practice (ISO 27001, NIS2) | Annual pentest + after major release | EUR 12,000 to 30,000 per year |
| Shareable summary letter | 2 to 4 page non-technical summary | Often included, otherwise EUR 500 to 1,000 |
Scope and price: the 2026 grid
Pentests are quoted in person-days. An experienced tester bills EUR 1,000 to 1,300 per day in Rennes, EUR 1,200 to 1,500 in Paris and EUR 1,300 to 1,700 in Dublin, which explains the EUR 8,000 to 25,000 range there. The number of days depends on four variables: the number of user roles (admin, manager, standard user, external customer), the number of sensitive features (payment, data export, permission management), whether an API is exposed, and whether there is a mobile app.
| Application scope | Audit days | Rennes budget (EUR 1,000 to 1,300/day) |
|---|---|---|
| Simple app, 2 roles, no public API | 5 days | EUR 6,000 to 6,500 |
| Business app, 3 to 4 roles, back office | 7 to 8 days | EUR 7,500 to 10,400 |
| Multi-client B2B SaaS, documented REST API | 10 days | EUR 10,000 to 13,000 |
| SaaS + iOS/Android app | 12 to 13 days | EUR 12,500 to 17,000 |
| SaaS + API + mobile + cloud infrastructure | 14 to 15 days | EUR 14,000 to 18,000 |
| Retest of fixed findings | 1.5 to 2.5 days | EUR 1,500 to 3,000 |
Grey box (the tester gets test accounts for each role) is the right trade-off for a vendor: it tests what scares clients most, privilege escalation and access to another client's data. Black box costs less but finds less; white box (with source code access) adds 30 to 50 % and is mainly justified for financial applications.
Accredited or not? A PASSI-qualified tester in France, or CREST-accredited in Dublin, costs 15 to 30 % more, but regulated operators accept the report without debate. For an SME client, a serious non-accredited firm (OSCP certifications, verifiable references) is often enough. Ask your client what they require before choosing: the gap can reach EUR 3,000 to 4,000.
Frequency, fixes and the real annual cost
The pentest is only half the budget. Typical findings on a business application in 2026 are always the same: broken access control (IDOR), missing security headers, weak session handling, outdated dependencies, injection in a search field. Fixing them consumes your development team.
| Typical finding | Usual severity | Fix effort | Estimated cost |
|---|---|---|---|
| Access to another client's data (IDOR) | Critical | 3 to 8 days | EUR 1,800 to 5,000 |
| Privilege escalation between roles | High | 2 to 5 days | EUR 1,200 to 3,000 |
| Dependencies with known CVEs | Medium to high | 1 to 3 days | EUR 600 to 1,800 |
| Missing CSP, HSTS headers | Low to medium | 0.5 to 1 day | EUR 300 to 600 |
| Password policy, no MFA | Medium | 2 to 4 days | EUR 1,200 to 2,400 |
| Information leak in error messages | Low | 0.5 day | EUR 300 |
Rule of thumb: budget a remediation envelope equal to 50 to 100 % of the pentest price in year one, then 25 to 40 % in later years if you add automated dependency scanning to your deployment pipeline. For ISO 27001 (control 8.29 on security testing) and NIS2 alike, what matters is regularity: a documented annual test plus a test after each major change (new authentication, new API, move to multi-tenancy).
Mini case study
Need a professional website?
Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.
Gaëlle, CISO of an HR software vendor in Rennes (45 staff), must hand a report to a national mutual insurer before signing a EUR 180,000 per year contract. Her application has 4 roles, a REST API and no mobile app.
- PASSI grey-box pentest: 10 days x EUR 1,250 = EUR 12,500
- Fixing 1 critical (IDOR) and 3 high findings: 9 dev days at EUR 600 = EUR 5,400
- Retest: 2 days x EUR 1,250 = EUR 2,500
- Total: EUR 20,400, i.e. 11.3 % of the contract's first year
The same scope tested in Dublin would land around EUR 15,000 to 17,000 for the pentest alone. Without a report, the contract does not get signed. With it, the vendor reuses the same document for two other tenders that year.
FAQ
How much does a web application pentest cost in Dublin in 2026?
Budget EUR 8,000 to 25,000 for a grey-box test, against EUR 6,000 to 18,000 in Rennes, for 5 to 15 audit days. An accredited tester adds 15 to 30 %.
How often should we repeat a pentest?
At least once a year, and after every major release (new authentication, new API, redesign). Most enterprise buyers reject a report older than 12 months.
Is a retest mandatory?
It is not mandatory, but it is what proves critical findings are closed. It costs EUR 1,500 to 3,000 and turns a worrying report into evidence of control.
Is a pentest enough for NIS2 or ISO 27001?
No, it is one control among many. It covers the requirement for regular security testing, alongside vulnerability management, logging and an incident response plan.
How long until we have the report?
Allow 2 to 4 weeks of scheduling lead time, 1 to 3 weeks of testing, then 5 to 10 days for the final report. Start 6 to 8 weeks before your client's deadline.
Let's scope your project. We prepare your application for the pentest and fix what it uncovers: defined scope, costed remediation budget, retest scheduled within 4 to 8 weeks. Detailed quote within 48 h. WhatsApp +221 77 596 93 33.
Mohamed Bah
Fondateur, Kolonell
Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.
