The verdict in three sentences
For a business or fintech web application in Singapore, the right format is almost always a grey-box pentest of 5 to 15 days, priced at SGD 8,000 to 30,000 depending on the number of roles, APIs and sensitive flows. The deliverable that matters to a regulator or an enterprise client is a report aligned with OWASP ASVS with a score per vulnerability and a re-test attestation after remediation. Plan 2 to 6 weeks of fixes between the two campaigns, and budget the re-test from day one (20 to 30% of the price).
Black, grey or white box: which format for which need
The CTO of a payments fintech in Singapore receives two requests in the same week: a security questionnaire from a partner bank and a demand for penetration testing evidence under the MAS Technology Risk Management (TRM) Guidelines. The format choice drives both price and report value.
| Format | What the tester receives | Typical duration | Price 2026 (SGD) | Recommended use |
|---|---|---|---|---|
| Black box | URL only | 4 to 8 days | 6,000 to 15,000 | Simulate an external attacker |
| Grey box | Test accounts per role + API docs | 5 to 15 days | 8,000 to 30,000 | Business apps, fintech, B2B SaaS |
| White box | Source code + architecture | 10 to 25 days | 20,000 to 55,000 | Critical apps, code review |
| API-only pentest | Postman collection or OpenAPI | 3 to 8 days | 5,000 to 15,000 | Mobile back end, open banking |
| Mobile app pentest | APK or IPA + API | 5 to 12 days | 9,000 to 27,000 | Wallets, banking apps |
| Post-fix re-test | Vulnerability list | 1 to 3 days | 20 to 30% of initial price | Closure and attestation |
Grey box offers the best cost-to-coverage ratio: the tester spends time on business logic flaws (privilege escalation, access to another customer's data) rather than guessing how the application works.
What the report must cover in Singapore in 2026
A useful pentest maps to recognized frameworks and to the local legal context. The PDPA requires reasonable security arrangements to protect personal data, and the PDPC has fined organizations for weak application security. Financial institutions supervised by the MAS must follow the TRM Guidelines, which expect regular penetration testing, and their vendors are pulled into that scope.
| Requirement or framework | What the pentest must show | Expected evidence |
|---|---|---|
| OWASP Top 10 (2021, revision in progress) | No injection, broken access control or misconfiguration | Coverage table per category |
| OWASP ASVS level 2 | Check of about 280 requirements for a sensitive app | Compliance matrix |
| PDPA and PDPC | Confidentiality of personal data | Documented cross-account access tests |
| MAS TRM Guidelines and partner banks | Periodic penetration tests, at least annual | Dated report + re-test attestation |
| PCI DSS v4.0 (if cards) | Annual internal and external pentest | Report meeting requirement 11.4 |
| CVSS v3.1 or v4.0 score | Objective prioritization of flaws | Score per vulnerability |
A serious report contains an executive summary, the technical detail of each flaw with proof of concept, a risk level and a precise remediation recommendation. Singapore buyers often favor testers holding CREST accreditation.
How to avoid paying for a useless pentest
Three mistakes come up often. First: running the pentest on an environment that does not mirror production, which makes results disputable. Second: not providing test accounts for each role (customer, agent, admin), which turns a paid grey box into a black box. Third: not planning remediation, while critical flaws take 2 to 6 weeks of development on average depending on technical debt.
An automated scan (OWASP ZAP, Burp Suite scanner) at SGD 1,000 to 3,500 is not a pentest. It detects known issues but misses business logic flaws, which are often the most severe vulnerabilities in a fintech.
Mini case study
Need a professional website?
Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.
Wei Ling, CTO of a merchant payments fintech in Singapore (web app, API and back office, 4 roles), orders a 10-day grey-box pentest at SGD 20,000, plus a re-test at 25%, i.e. SGD 5,000. Total: SGD 25,000. The report reveals 2 critical flaws (access to another merchant's transactions through a predictable ID) and 6 medium ones. Fixes keep 2 developers busy for 3 weeks, about SGD 18,000 of internal cost. The report unlocks a bank contract worth SGD 300,000 in annual revenue: the full security cost weighs about 14% of the contract's first year.
FAQ
How much does a web application pentest cost in Singapore in 2026?
A grey-box pentest costs between SGD 8,000 and 30,000 for 5 to 15 days. Price depends on the number of roles, APIs and sensitive flows to test.
Is the re-test mandatory?
It is not a legal requirement, but a bank or the MAS will ask for proof that critical flaws are fixed. Budget 20 to 30% of the initial price for 1 to 3 days of verification.
How often should a pentest be repeated?
At least once a year, and after every major change (new payment module, new API). PCI DSS requires an annual rhythm for card environments.
Is an automated scan enough for PDPA compliance?
No, a SGD 1,000 to 3,500 scan finds known issues but not business logic flaws. The PDPA requires reasonable security arrangements, and a manual pentest is the strongest evidence.
How long between the audit and the final attestation?
In practice 4 to 10 weeks: 1 to 3 weeks of testing and reporting, 2 to 6 weeks of fixes, then 1 to 3 days of re-test.
Let's scope your project. Describe your application, its roles and its APIs: we will define the pentest scope, its budget and the remediation schedule. Detailed quote within 48 h. WhatsApp +221 77 596 93 33.
Mohamed Bah
Fondateur, Kolonell
Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.
