The verdict in three sentences
For a B2B software vendor in Amsterdam, a grey-box pentest of the web application costs EUR 5,000 to 15,000 excl. VAT for 5 to 10 audit days, and it is the format enterprise procurement teams expect. A certified provider (CREST, or PASSI for French public-sector clients) is only mandatory for some customers (critical infrastructure, government, healthcare, defence) and costs 20 to 40% more. Always budget the retest (EUR 1,500 to 3,000): it is what proves to the customer that the flaws were fixed.
What a web application pentest costs in 2026
Price is calculated in auditor days, at a day rate of EUR 1,000 to 1,500 for an experienced pentester in Paris or Amsterdam. The number of days depends on the attack surface: user roles, screens, APIs and sensitive functions (payments, exports, admin).
| Audit type | Typical scope | Days | Price excl. VAT |
|---|---|---|---|
| Automated scan + quick review | Brochure site, form, 1 role | 1 to 2 | EUR 1,500 to 3,000 |
| Black-box pentest | SaaS application, no account provided | 3 to 5 | EUR 4,000 to 7,500 |
| Grey-box pentest | B2B SaaS, 2 to 4 roles, REST API | 5 to 10 | EUR 5,000 to 15,000 |
| Grey-box pentest + public API | SaaS + documented API for integrators | 8 to 12 | EUR 10,000 to 18,000 |
| Source code review (white box) | Targeted review of critical modules | 5 to 10 | EUR 6,000 to 15,000 |
| Retest | Verification of fixes | 1 to 2 | EUR 1,500 to 3,000 |
| Certified provider (CREST or PASSI) | Same scope, accredited methodology | +20 to 40% | EUR 7,000 to 21,000 |
Grey box (the auditor gets one account per role) gives the best value: it tests what a malicious customer or a stolen account could do, which is the scenario that actually worries a buyer. Black box spends a lot of time looking for a way in and finds fewer business logic flaws.
What the audit must cover: OWASP Top 10 and beyond
A credible report follows the OWASP Top 10 (2021 edition, revised in 2025) and OWASP ASVS level 2 for B2B applications. These are the areas that produce the most findings in the SaaS products we see.
| OWASP category | What the auditor tests | Observed frequency of flaws |
|---|---|---|
| Broken access control | Reading another customer's data by changing an ID | Very high (1 SaaS in 2) |
| Cryptographic failures | Passwords, tokens, sensitive data in clear text | Medium |
| Injection | SQL, NoSQL, commands, templates | Low to medium |
| Insecure design | Bypassable business logic (discount, quota, workflow) | High |
| Security misconfiguration | CSP and CORS headers, public buckets, error pages | Very high |
| Vulnerable components | Outdated libraries | High |
| Authentication | No MFA, brute force, password reset | Medium |
The deliverable an enterprise buyer expects: a 2-page executive summary, the list of vulnerabilities scored with CVSS, proof of exploitation, a prioritised remediation plan and, after the fixes, a retest attestation.
Recommended frequency and annual budget
| Situation | Frequency | Annual budget excl. VAT |
|---|---|---|
| Standard B2B SaaS | 1 pentest a year + retest | EUR 7,000 to 18,000 |
| Major release (redesign, new payment module) | Targeted pentest before go-live | + EUR 3,000 to 8,000 |
| Healthcare, finance or public-sector client | 1 certified pentest a year | EUR 10,000 to 24,000 |
| Continuous monitoring | Monthly automated scan | EUR 1,200 to 4,800 |
| Private bug bounty programme | Per-finding rewards | EUR 5,000 to 20,000 |
The simple rule: one pentest a year, plus a targeted pentest whenever the attack surface changes significantly. In between, an automated scanner limits drift.
Mini case study
Need a professional website?
Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.
Emma, CEO of a 22-person HR software vendor in Amsterdam, must provide a pentest report less than 12 months old to sign a EUR 180,000 a year contract with an industrial group. Her application has 3 roles and a REST API.
Selected quote: a 7-day grey-box pentest at EUR 1,200, or EUR 8,400, then a 1.5-day retest, EUR 1,800. The audit finds 2 critical flaws (access to another customer's records, a predictable password reset) and 6 medium ones. Fixing them takes 8 days of in-house development, valued at EUR 4,800. Total cost: EUR 15,000, or 8.3% of the contract's first year, and the report then supports the next 3 tenders.
FAQ
Is a certified provider mandatory?
Not for most private customers. It is required by government bodies, critical infrastructure operators and some healthcare players; it adds 20 to 40% to the price and often pushes the start date out by 4 to 8 weeks.
How long until we get the report?
Plan 2 to 4 weeks before the start, 5 to 10 audit days, then 5 working days for the report. In total, 5 to 8 weeks from signature to final report.
Should we test in production or staging?
In staging, with realistic but anonymised data. Production testing is possible for black box, with an agreed window and a degradation risk accepted in writing.
Is an automated scanner enough?
No: it detects roughly 30 to 40% of vulnerabilities, mostly configuration issues. Access control and business logic flaws, the most serious for a SaaS, need a human auditor.
What if the audit finds critical flaws?
Fix them within 15 to 30 days, run the retest and send the customer the attestation. A report showing fixed critical flaws reassures a buyer more than an empty one.
Let's scope your project. Tell us your application's scope (roles, APIs, sensitive data) and your customer's requirement: we will frame the audit, the remediation work and the retest, with a firm budget and timeline. Detailed quote within 48 h. WhatsApp +221 77 596 93 33.
Mohamed Bah
Fondateur, Kolonell
Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.
