Websites11 min read

Web Application Penetration Test Cost for an SME in London

Mohamed Bah·Fondateur, Kolonell
October 1, 2026
Share:
Web Application Penetration Test Cost for an SME in London

Web Application Penetration Test Cost for an SME in London

Websites

The verdict in three sentences

For a London SME that must hand a pentest report to a large customer, a realistic budget is between 4,000 and 15,000 EUR excl. VAT (roughly 3,400 to 12,800 GBP) for 3 to 10 days of testing. Add 20 to 40% of that amount for fixes, then a short retest to prove the vulnerabilities are closed. An accredited tester (CREST or CHECK in the UK, PASSI in France) is not always mandatory, but it reassures demanding buyers and cyber insurers.

What a pentest costs by scope

Pentest pricing is based on tester-days, billed in 2026 between 900 and 1,500 EUR excl. VAT depending on expertise. Scope sets the number of days.

Scope testedTesting daysIndicative price excl. VATTypical case
Brochure site with a form2 to 3 days2,500 to 4,000 EURMinimum customer requirement
Simple web app, 1 user role3 to 4 days4,000 to 6,000 EURCustomer extranet, booking tool
Business app, 2 to 3 roles5 to 7 days6,000 to 10,000 EURB2B portal, management tool
App + exposed REST API6 to 8 days8,000 to 12,000 EURSaaS, partner integrations
App + API + cloud infrastructure8 to 10 days11,000 to 15,000 EURSensitive data, health, finance
Retest after fixes1 to 2 days1,000 to 2,500 EURProof of remediation

Testing mode also affects price. In black box, the tester starts from nothing, which costs more days for less coverage. In grey box, with test accounts provided, coverage is better for the same budget: it is the format most large customers recommend.

Accredited firm, independent tester or bug bounty

Accreditation (CREST or CHECK in the UK, PASSI from ANSSI in France) guarantees a controlled methodology and vetted testers. It is required for critical infrastructure and increasingly in public tenders.

CriterionAccredited firmNon-accredited firmBug bounty
Day rate excl. VAT1,200 to 1,500 EUR900 to 1,200 EURPer finding (100 to 5,000 EUR)
Report accepted by large customersYes, consistentlyOftenRarely
Lead time3 to 8 weeks1 to 4 weeksImmediate
Methodical coverageFull, OWASP frameworkVariableRandom
Fit for NIS 2 and public tendersYesPartialNo
Realistic minimum budget5,000 EUR3,500 EUR3,000 EUR in rewards

To satisfy a customer request, an experienced non-accredited firm is enough in most cases, provided the report follows OWASP and ranks findings by CVSS severity. Check your customer's exact requirement before signing: some explicitly demand accreditation.

Budgeting fixes and available support

A pentest typically reveals 5 to 15 vulnerabilities on a business application, 1 to 3 of them critical or high: broken access control, injection, weak session handling. Fixing them takes the development team 20 to 40% of the audit budget, or 1,500 to 5,000 EUR excl. VAT for an 8,000 EUR audit.

On funding, French SMEs can use France Num and regional grants covering 30 to 50% of an audit, and Cybermalveillance.gouv.fr lists labelled providers. In the UK, the Cyber Essentials scheme and the National Cyber Security Centre offer free guidance, and some local growth hubs co-fund security assessments. Check with your local business support body before going to tender.

Mini case study

Need a professional website?

Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.

Prefer a call back?

Leave your WhatsApp number and a Kolonell expert will get back to you within 1 business day. Free, no strings attached.

Natalie, part-time CISO of an 80-employee logistics SME in London, must provide a pentest report to a major retail customer to keep a contract worth 600,000 EUR a year. Agreed scope: shipment tracking portal and the order transmission API.

Selected quote: 7 grey-box days at 1,150 EUR, i.e. 8,050 EUR excl. VAT. Fixes estimated at 30%: 2,415 EUR. One-day retest: 1,150 EUR. Total: 11,615 EUR excl. VAT, with 40% covered by a regional grant, leaving 6,969 EUR to pay. Set against the protected contract and the average cost of a cyberattack for an SME, estimated at 59,000 EUR, the decision is quick.

FAQ

What is the average price of a web application pentest for an SME?

In 2026, most SME audits fall between 5,000 and 10,000 EUR excl. VAT for 4 to 7 days. The spread comes from the number of user roles and whether an API is in scope.

How long until we get the report?

Allow 1 to 2 weeks after testing ends, so 3 to 6 weeks in total with lead time. Accredited firms may ask for up to 8 weeks' notice.

Do we need a pentest every year?

Yes, that is the common recommendation and often a contractual requirement from large customers. An annual 4 to 5-day pentest at 5,000 to 7,000 EUR excl. VAT is enough if the architecture has not changed.

Can an automated scanner replace a pentest?

No. A scanner finds known flaws for 50 to 300 EUR a month, but it misses business logic flaws, such as accessing another customer's data, which often make up half of critical findings.

Who fixes the vulnerabilities found?

The team or agency maintaining the application. Plan 20 to 40% of the audit budget and require a retest to get a clean final report to send to your customer.

Let's scope your project. Tell us about your application and your customer's requirement, and we will scope the pentest, the remediation budget and the retest. Detailed quote within 48 h. WhatsApp +221 77 596 93 33.

Tags:#pentest#penetration testing#application security#SME#CREST#cybersecurity
Share:

Mohamed Bah

Fondateur, Kolonell

Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.