Websites10 min read

Web Application Penetration Test Cost in Dublin in 2026

Mohamed Bah·Fondateur, Kolonell
October 8, 2026
Share:
Web Application Penetration Test Cost in Dublin in 2026

Web Application Penetration Test Cost in Dublin in 2026

Websites

The verdict in three sentences

A grey-box penetration test on a mid-sized web application costs 6,000 to 20,000 EUR in Dublin in 2026, and 4,000 to 12,000 EUR excl. VAT in a French city like Nantes, for 5 to 15 person-days of testing. A CREST-accredited firm in Ireland (or PASSI-qualified in France) is only mandatory in regulated sectors, but it reassures enterprise buyers and costs 20 to 40% more. The real budget also covers fixes, 2,000 to 15,000 EUR, plus a retest before you hand the report to the client.

The typical scenario: an enterprise client demands a pentest

You are the CTO or founder of a SaaS company. A bank, an insurer or an industrial group is ready to sign, but their CISO sends a 150-line security questionnaire and asks for a pentest report less than 12 months old. Without it, the contract stalls. The question becomes: which audit type, which scope, which provider, at what price.

Audit typeWhat is testedDurationIndicative 2026 price (Nantes / Dublin)
Automated vulnerability scanKnown flaws, configuration1 to 2 days800 to 2,500 EUR / 1,200 to 3,500 EUR
Black-box pentestApp seen by an external attacker4 to 8 person-days3,500 to 8,000 EUR / 5,000 to 12,000 EUR
Grey-box pentestWith user accounts, roles, API5 to 15 person-days4,000 to 12,000 EUR / 6,000 to 20,000 EUR
White-box pentest + code reviewSource code, business logic10 to 25 person-days9,000 to 25,000 EUR / 14,000 to 35,000 EUR
Cloud architecture reviewAWS, Azure, IAM, network3 to 8 person-days3,000 to 9,000 EUR / 4,500 to 12,000 EUR
Accredited provider (PASSI or CREST)Formal methodology, recognized report+20 to 40%6,000 to 16,000 EUR / 8,000 to 24,000 EUR for grey box

A tester's day rate sits around 750 to 1,100 EUR in France in 2026 and 1,000 to 1,400 EUR in Dublin.

What drives the price

FactorEffect on budget
Number of user roles (admin, customer, partner)+1 to 2 person-days per role
Public or mobile API to test+2 to 5 person-days
Multi-tenant (isolation between customers)+1 to 3 person-days, top priority for SaaS
Online payment and sensitive personal data+1 to 3 person-days
Retest after fixes1 to 2 person-days, 800 to 2,000 EUR
Urgency (start within 2 weeks)+10 to 25%

For a B2B SaaS, the absolute priority is tenant isolation: a user from customer A must never read customer B's data by changing an ID in a request. Broken access control tops the OWASP Top 10, and it is the first thing a CISO checks.

After the report: fixes and continuous security

Item2026 budgetFrequency
Critical and high fixes2,000 to 15,000 EURAfter each pentest
Retest800 to 2,000 EUROnce
Annual follow-up pentest4,000 to 10,000 EUREvery 12 months
Bug bounty program500 to 5,000 EUR per valid findingContinuous
Dependency monitoring (SCA)0 to 300 EUR per monthContinuous

A typical report contains 10 to 30 findings. In practice, 2 to 5 are critical or high and must be fixed before the report goes to the client.

Mini case study

Thomas, founder of a construction site management SaaS in Nantes (12 people, 900,000 EUR ARR), must deliver a pentest to sign a construction group worth 180,000 EUR per year. Scope: web app, mobile API, three roles, multi-tenant. Chosen quote: 9 grey-box person-days at 950 EUR, or 8,550 EUR excl. VAT, plus a 1,500 EUR retest.

Need a professional website?

Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.

Prefer a call back?

Leave your WhatsApp number and a Kolonell expert will get back to you within 1 business day. Free, no strings attached.

The report shows 18 findings, 3 of them high (access to another customer's documents, no login rate limiting, missing security headers). Fixes: 6 development days, about 4,800 EUR. Total cost: 14,850 EUR, 8% of the contract's first year. The same report then unlocks two other enterprise prospects. In Dublin, the same scope would have landed around 12,000 to 13,000 EUR for testing alone.

FAQ

How much does a web app pentest cost in Dublin in 2026?

Between 6,000 and 20,000 EUR for a grey-box test on a mid-sized application. In France, the same scope costs 4,000 to 12,000 EUR excl. VAT.

Do we need an accredited provider?

Only for critical infrastructure, some public contracts and health data hosting. For a private client, an experienced tester with a documented OWASP methodology is enough in about 80% of cases.

How long from order to report?

Plan 2 to 4 weeks lead time, 1 to 3 weeks of testing, then 3 to 5 days for the report. With fixes and retest, budget 6 to 10 weeks in total.

Isn't an automated scan enough?

Not for an enterprise buyer: a 800 to 2,500 EUR scan misses business logic flaws and tenant isolation issues. It remains useful as a monthly complement.

Can bug bounty replace a pentest?

No, it complements one once the obvious flaws are fixed. Bounties of 500 to 5,000 EUR per finding make a program expensive if the app has never been audited.

Let's scope your project. Send us your application scope (roles, API, hosting) and your client's requirement, and we will plan the audit, fixes and retest, with an indicative 4,000 to 12,000 EUR budget for the pentest. Detailed quote within 48 h. WhatsApp +221 77 596 93 33.

Tags:#web application pentest#security audit#penetration testing Dublin#CREST#OWASP Top 10#SaaS security
Share:

Mohamed Bah

Fondateur, Kolonell

Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.