Websites11 min read

Web Application Pentest Cost for an SMB in Amsterdam (2026)

Mohamed Bah·Fondateur, Kolonell
October 6, 2026
Share:
Web Application Pentest Cost for an SMB in Amsterdam (2026)

Web Application Pentest Cost for an SMB in Amsterdam (2026)

Websites

The verdict in three sentences

For a B2B software vendor in Amsterdam, a grey-box pentest of the web application costs EUR 5,000 to 15,000 excl. VAT for 5 to 10 audit days, and it is the format enterprise procurement teams expect. A certified provider (CREST, or PASSI for French public-sector clients) is only mandatory for some customers (critical infrastructure, government, healthcare, defence) and costs 20 to 40% more. Always budget the retest (EUR 1,500 to 3,000): it is what proves to the customer that the flaws were fixed.

What a web application pentest costs in 2026

Price is calculated in auditor days, at a day rate of EUR 1,000 to 1,500 for an experienced pentester in Paris or Amsterdam. The number of days depends on the attack surface: user roles, screens, APIs and sensitive functions (payments, exports, admin).

Audit typeTypical scopeDaysPrice excl. VAT
Automated scan + quick reviewBrochure site, form, 1 role1 to 2EUR 1,500 to 3,000
Black-box pentestSaaS application, no account provided3 to 5EUR 4,000 to 7,500
Grey-box pentestB2B SaaS, 2 to 4 roles, REST API5 to 10EUR 5,000 to 15,000
Grey-box pentest + public APISaaS + documented API for integrators8 to 12EUR 10,000 to 18,000
Source code review (white box)Targeted review of critical modules5 to 10EUR 6,000 to 15,000
RetestVerification of fixes1 to 2EUR 1,500 to 3,000
Certified provider (CREST or PASSI)Same scope, accredited methodology+20 to 40%EUR 7,000 to 21,000

Grey box (the auditor gets one account per role) gives the best value: it tests what a malicious customer or a stolen account could do, which is the scenario that actually worries a buyer. Black box spends a lot of time looking for a way in and finds fewer business logic flaws.

What the audit must cover: OWASP Top 10 and beyond

A credible report follows the OWASP Top 10 (2021 edition, revised in 2025) and OWASP ASVS level 2 for B2B applications. These are the areas that produce the most findings in the SaaS products we see.

OWASP categoryWhat the auditor testsObserved frequency of flaws
Broken access controlReading another customer's data by changing an IDVery high (1 SaaS in 2)
Cryptographic failuresPasswords, tokens, sensitive data in clear textMedium
InjectionSQL, NoSQL, commands, templatesLow to medium
Insecure designBypassable business logic (discount, quota, workflow)High
Security misconfigurationCSP and CORS headers, public buckets, error pagesVery high
Vulnerable componentsOutdated librariesHigh
AuthenticationNo MFA, brute force, password resetMedium

The deliverable an enterprise buyer expects: a 2-page executive summary, the list of vulnerabilities scored with CVSS, proof of exploitation, a prioritised remediation plan and, after the fixes, a retest attestation.

SituationFrequencyAnnual budget excl. VAT
Standard B2B SaaS1 pentest a year + retestEUR 7,000 to 18,000
Major release (redesign, new payment module)Targeted pentest before go-live+ EUR 3,000 to 8,000
Healthcare, finance or public-sector client1 certified pentest a yearEUR 10,000 to 24,000
Continuous monitoringMonthly automated scanEUR 1,200 to 4,800
Private bug bounty programmePer-finding rewardsEUR 5,000 to 20,000

The simple rule: one pentest a year, plus a targeted pentest whenever the attack surface changes significantly. In between, an automated scanner limits drift.

Mini case study

Need a professional website?

Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.

Prefer a call back?

Leave your WhatsApp number and a Kolonell expert will get back to you within 1 business day. Free, no strings attached.

Emma, CEO of a 22-person HR software vendor in Amsterdam, must provide a pentest report less than 12 months old to sign a EUR 180,000 a year contract with an industrial group. Her application has 3 roles and a REST API.

Selected quote: a 7-day grey-box pentest at EUR 1,200, or EUR 8,400, then a 1.5-day retest, EUR 1,800. The audit finds 2 critical flaws (access to another customer's records, a predictable password reset) and 6 medium ones. Fixing them takes 8 days of in-house development, valued at EUR 4,800. Total cost: EUR 15,000, or 8.3% of the contract's first year, and the report then supports the next 3 tenders.

FAQ

Is a certified provider mandatory?

Not for most private customers. It is required by government bodies, critical infrastructure operators and some healthcare players; it adds 20 to 40% to the price and often pushes the start date out by 4 to 8 weeks.

How long until we get the report?

Plan 2 to 4 weeks before the start, 5 to 10 audit days, then 5 working days for the report. In total, 5 to 8 weeks from signature to final report.

Should we test in production or staging?

In staging, with realistic but anonymised data. Production testing is possible for black box, with an agreed window and a degradation risk accepted in writing.

Is an automated scanner enough?

No: it detects roughly 30 to 40% of vulnerabilities, mostly configuration issues. Access control and business logic flaws, the most serious for a SaaS, need a human auditor.

What if the audit finds critical flaws?

Fix them within 15 to 30 days, run the retest and send the customer the attestation. A report showing fixed critical flaws reassures a buyer more than an empty one.

Let's scope your project. Tell us your application's scope (roles, APIs, sensitive data) and your customer's requirement: we will frame the audit, the remediation work and the retest, with a firm budget and timeline. Detailed quote within 48 h. WhatsApp +221 77 596 93 33.

Tags:#pentest#web application security#Amsterdam#OWASP#web agency#2026 quote#Kolonell
Share:

Mohamed Bah

Fondateur, Kolonell

Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.