The verdict in three sentences
For a London SME that must hand a pentest report to a large customer, a realistic budget is between 4,000 and 15,000 EUR excl. VAT (roughly 3,400 to 12,800 GBP) for 3 to 10 days of testing. Add 20 to 40% of that amount for fixes, then a short retest to prove the vulnerabilities are closed. An accredited tester (CREST or CHECK in the UK, PASSI in France) is not always mandatory, but it reassures demanding buyers and cyber insurers.
What a pentest costs by scope
Pentest pricing is based on tester-days, billed in 2026 between 900 and 1,500 EUR excl. VAT depending on expertise. Scope sets the number of days.
| Scope tested | Testing days | Indicative price excl. VAT | Typical case |
|---|---|---|---|
| Brochure site with a form | 2 to 3 days | 2,500 to 4,000 EUR | Minimum customer requirement |
| Simple web app, 1 user role | 3 to 4 days | 4,000 to 6,000 EUR | Customer extranet, booking tool |
| Business app, 2 to 3 roles | 5 to 7 days | 6,000 to 10,000 EUR | B2B portal, management tool |
| App + exposed REST API | 6 to 8 days | 8,000 to 12,000 EUR | SaaS, partner integrations |
| App + API + cloud infrastructure | 8 to 10 days | 11,000 to 15,000 EUR | Sensitive data, health, finance |
| Retest after fixes | 1 to 2 days | 1,000 to 2,500 EUR | Proof of remediation |
Testing mode also affects price. In black box, the tester starts from nothing, which costs more days for less coverage. In grey box, with test accounts provided, coverage is better for the same budget: it is the format most large customers recommend.
Accredited firm, independent tester or bug bounty
Accreditation (CREST or CHECK in the UK, PASSI from ANSSI in France) guarantees a controlled methodology and vetted testers. It is required for critical infrastructure and increasingly in public tenders.
| Criterion | Accredited firm | Non-accredited firm | Bug bounty |
|---|---|---|---|
| Day rate excl. VAT | 1,200 to 1,500 EUR | 900 to 1,200 EUR | Per finding (100 to 5,000 EUR) |
| Report accepted by large customers | Yes, consistently | Often | Rarely |
| Lead time | 3 to 8 weeks | 1 to 4 weeks | Immediate |
| Methodical coverage | Full, OWASP framework | Variable | Random |
| Fit for NIS 2 and public tenders | Yes | Partial | No |
| Realistic minimum budget | 5,000 EUR | 3,500 EUR | 3,000 EUR in rewards |
To satisfy a customer request, an experienced non-accredited firm is enough in most cases, provided the report follows OWASP and ranks findings by CVSS severity. Check your customer's exact requirement before signing: some explicitly demand accreditation.
Budgeting fixes and available support
A pentest typically reveals 5 to 15 vulnerabilities on a business application, 1 to 3 of them critical or high: broken access control, injection, weak session handling. Fixing them takes the development team 20 to 40% of the audit budget, or 1,500 to 5,000 EUR excl. VAT for an 8,000 EUR audit.
On funding, French SMEs can use France Num and regional grants covering 30 to 50% of an audit, and Cybermalveillance.gouv.fr lists labelled providers. In the UK, the Cyber Essentials scheme and the National Cyber Security Centre offer free guidance, and some local growth hubs co-fund security assessments. Check with your local business support body before going to tender.
Mini case study
Need a professional website?
Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.
Natalie, part-time CISO of an 80-employee logistics SME in London, must provide a pentest report to a major retail customer to keep a contract worth 600,000 EUR a year. Agreed scope: shipment tracking portal and the order transmission API.
Selected quote: 7 grey-box days at 1,150 EUR, i.e. 8,050 EUR excl. VAT. Fixes estimated at 30%: 2,415 EUR. One-day retest: 1,150 EUR. Total: 11,615 EUR excl. VAT, with 40% covered by a regional grant, leaving 6,969 EUR to pay. Set against the protected contract and the average cost of a cyberattack for an SME, estimated at 59,000 EUR, the decision is quick.
FAQ
What is the average price of a web application pentest for an SME?
In 2026, most SME audits fall between 5,000 and 10,000 EUR excl. VAT for 4 to 7 days. The spread comes from the number of user roles and whether an API is in scope.
How long until we get the report?
Allow 1 to 2 weeks after testing ends, so 3 to 6 weeks in total with lead time. Accredited firms may ask for up to 8 weeks' notice.
Do we need a pentest every year?
Yes, that is the common recommendation and often a contractual requirement from large customers. An annual 4 to 5-day pentest at 5,000 to 7,000 EUR excl. VAT is enough if the architecture has not changed.
Can an automated scanner replace a pentest?
No. A scanner finds known flaws for 50 to 300 EUR a month, but it misses business logic flaws, such as accessing another customer's data, which often make up half of critical findings.
Who fixes the vulnerabilities found?
The team or agency maintaining the application. Plan 20 to 40% of the audit budget and require a retest to get a clean final report to send to your customer.
Let's scope your project. Tell us about your application and your customer's requirement, and we will scope the pentest, the remediation budget and the retest. Detailed quote within 48 h. WhatsApp +221 77 596 93 33.
Mohamed Bah
Fondateur, Kolonell
Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.
