The verdict in three sentences
A grey-box penetration test on a mid-sized web application costs 6,000 to 20,000 EUR in Dublin in 2026, and 4,000 to 12,000 EUR excl. VAT in a French city like Nantes, for 5 to 15 person-days of testing. A CREST-accredited firm in Ireland (or PASSI-qualified in France) is only mandatory in regulated sectors, but it reassures enterprise buyers and costs 20 to 40% more. The real budget also covers fixes, 2,000 to 15,000 EUR, plus a retest before you hand the report to the client.
The typical scenario: an enterprise client demands a pentest
You are the CTO or founder of a SaaS company. A bank, an insurer or an industrial group is ready to sign, but their CISO sends a 150-line security questionnaire and asks for a pentest report less than 12 months old. Without it, the contract stalls. The question becomes: which audit type, which scope, which provider, at what price.
| Audit type | What is tested | Duration | Indicative 2026 price (Nantes / Dublin) |
|---|---|---|---|
| Automated vulnerability scan | Known flaws, configuration | 1 to 2 days | 800 to 2,500 EUR / 1,200 to 3,500 EUR |
| Black-box pentest | App seen by an external attacker | 4 to 8 person-days | 3,500 to 8,000 EUR / 5,000 to 12,000 EUR |
| Grey-box pentest | With user accounts, roles, API | 5 to 15 person-days | 4,000 to 12,000 EUR / 6,000 to 20,000 EUR |
| White-box pentest + code review | Source code, business logic | 10 to 25 person-days | 9,000 to 25,000 EUR / 14,000 to 35,000 EUR |
| Cloud architecture review | AWS, Azure, IAM, network | 3 to 8 person-days | 3,000 to 9,000 EUR / 4,500 to 12,000 EUR |
| Accredited provider (PASSI or CREST) | Formal methodology, recognized report | +20 to 40% | 6,000 to 16,000 EUR / 8,000 to 24,000 EUR for grey box |
A tester's day rate sits around 750 to 1,100 EUR in France in 2026 and 1,000 to 1,400 EUR in Dublin.
What drives the price
| Factor | Effect on budget |
|---|---|
| Number of user roles (admin, customer, partner) | +1 to 2 person-days per role |
| Public or mobile API to test | +2 to 5 person-days |
| Multi-tenant (isolation between customers) | +1 to 3 person-days, top priority for SaaS |
| Online payment and sensitive personal data | +1 to 3 person-days |
| Retest after fixes | 1 to 2 person-days, 800 to 2,000 EUR |
| Urgency (start within 2 weeks) | +10 to 25% |
For a B2B SaaS, the absolute priority is tenant isolation: a user from customer A must never read customer B's data by changing an ID in a request. Broken access control tops the OWASP Top 10, and it is the first thing a CISO checks.
After the report: fixes and continuous security
| Item | 2026 budget | Frequency |
|---|---|---|
| Critical and high fixes | 2,000 to 15,000 EUR | After each pentest |
| Retest | 800 to 2,000 EUR | Once |
| Annual follow-up pentest | 4,000 to 10,000 EUR | Every 12 months |
| Bug bounty program | 500 to 5,000 EUR per valid finding | Continuous |
| Dependency monitoring (SCA) | 0 to 300 EUR per month | Continuous |
A typical report contains 10 to 30 findings. In practice, 2 to 5 are critical or high and must be fixed before the report goes to the client.
Mini case study
Thomas, founder of a construction site management SaaS in Nantes (12 people, 900,000 EUR ARR), must deliver a pentest to sign a construction group worth 180,000 EUR per year. Scope: web app, mobile API, three roles, multi-tenant. Chosen quote: 9 grey-box person-days at 950 EUR, or 8,550 EUR excl. VAT, plus a 1,500 EUR retest.
Need a professional website?
Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.
The report shows 18 findings, 3 of them high (access to another customer's documents, no login rate limiting, missing security headers). Fixes: 6 development days, about 4,800 EUR. Total cost: 14,850 EUR, 8% of the contract's first year. The same report then unlocks two other enterprise prospects. In Dublin, the same scope would have landed around 12,000 to 13,000 EUR for testing alone.
FAQ
How much does a web app pentest cost in Dublin in 2026?
Between 6,000 and 20,000 EUR for a grey-box test on a mid-sized application. In France, the same scope costs 4,000 to 12,000 EUR excl. VAT.
Do we need an accredited provider?
Only for critical infrastructure, some public contracts and health data hosting. For a private client, an experienced tester with a documented OWASP methodology is enough in about 80% of cases.
How long from order to report?
Plan 2 to 4 weeks lead time, 1 to 3 weeks of testing, then 3 to 5 days for the report. With fixes and retest, budget 6 to 10 weeks in total.
Isn't an automated scan enough?
Not for an enterprise buyer: a 800 to 2,500 EUR scan misses business logic flaws and tenant isolation issues. It remains useful as a monthly complement.
Can bug bounty replace a pentest?
No, it complements one once the obvious flaws are fixed. Bounties of 500 to 5,000 EUR per finding make a program expensive if the app has never been audited.
Let's scope your project. Send us your application scope (roles, API, hosting) and your client's requirement, and we will plan the audit, fixes and retest, with an indicative 4,000 to 12,000 EUR budget for the pentest. Detailed quote within 48 h. WhatsApp +221 77 596 93 33.
Mohamed Bah
Fondateur, Kolonell
Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.