The verdict in three sentences
A serious application pentest in London costs between 5,000 and 18,000 EUR depending on scope, and a code audit between 3,000 and 9,000 EUR. An exploited breach typically costs 20,000 to 200,000 EUR in emergency remediation, lost business and crisis management, on top of the mandatory regulator notification within 72 hours. The one-off audit before go-live remains the best cost/risk ratio, with continuous auditing justified beyond a certain volume of sensitive data.
How much a security audit costs in 2026
The price depends on scope: number of endpoints, user roles, presence of APIs, payments, personal data. A grey-box pentest (partial access to code and accounts) is the 2026 standard for a business web application.
| Service | Scope | 2026 price (EUR) | Timeline |
|---|---|---|---|
| Express pentest | Marketing app, 1 role | 5,000 - 7,000 | 1 week |
| Standard pentest | Business app, API, 3 roles | 9,000 - 14,000 | 2-3 weeks |
| Extended pentest | Multi-tenant SaaS, payments | 15,000 - 18,000 | 3-4 weeks |
| Code audit (SAST) | Manual + tooled review | 3,000 - 9,000 | 1-2 weeks |
| Remediation retest | Fix verification | 1,500 - 3,000 | 3-5 days |
Remediation itself (fixing the vulnerabilities found) often represents 30 to 60% of the audit budget in developer time, depending on severity.
What an undetected breach costs
| Item | 2026 estimate (EUR) | Comment |
|---|---|---|
| Emergency remediation | 8,000 - 40,000 | Developers in crisis mode |
| Service interruption | 5,000 - 60,000 | Depends on duration and revenue |
| Regulator + client notice | 3,000 - 15,000 | Within 72 h, legal obligation |
| Regulatory fine (severe) | Up to 4% of global turnover | GDPR order of magnitude |
| Reputation damage | 10,000 - 100,000+ | Lost deals, churn |
GDPR requires notifying the regulator within 72 hours of discovering a personal data breach that presents a risk. The maths are simple: a 12,000 EUR audit is a modest investment against a six-figure incident.
What drives audit price variation
Need a professional website?
Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.
Four factors explain the gap between a 5,000 EUR pentest and an 18,000 EUR one. First, the number of user roles: each profile (client, admin, manager) multiplies the privilege-escalation scenarios to test. Second, the API surface: an exposed REST API with 40 endpoints demands far more work than a contact form. Third, the presence of payments or sensitive data forces deep business-logic testing (double spending, amount tampering). Finally, the level of proof expected: a simple report differs from a full dossier with exploitable proofs of concept, required by some enterprise clients or cyber insurers. Precise upfront scoping avoids paying for an oversized perimeter or, conversely, leaving an untested blind spot.
Mini case study
Thomas, CISO of a 40-person SaaS SME in London, must sign off a new B2B platform before production. He orders a standard pentest at 11,000 EUR and a code audit at 5,000 EUR, totalling 16,000 EUR. The audit reveals an injection allowing access to other customers' data (a multi-tenant flaw). Remediation costs 6,000 EUR in developer time. Total: 22,000 EUR. A year earlier, a competitor suffered the same flaw exploited: regulator notification, two lost enterprise accounts, an estimated 140,000 EUR bill. The audit ROI here is around 6 to 1.
FAQ
How long does an application security audit take? Between 1 and 4 weeks depending on scope: expect 2-3 weeks for a standard business application with API and several user roles.
One-off pentest or continuous auditing, which to choose? A one-off audit (5,000-18,000 EUR) suffices for most go-lives. Continuous auditing (often 800-2,500 EUR/month) is justified beyond a high volume of sensitive data or weekly releases.
Is remediation retesting mandatory? No, but strongly recommended: for 1,500-3,000 EUR it confirms fixes are effective and serves as proof of due diligence in a regulator review.
Does an audit guarantee zero flaws? No. It sharply reduces risk by covering the OWASP Top 10 and business logic, but no absolute guarantee exists. The value is probabilistic: dividing incident risk by 5 to 10.
Should you audit before every major release? For an application handling personal data or payments, yes: a targeted 5,000-7,000 EUR pentest on new features is a reasonable standard.
Let's scope your project. Tell us about your application (scope, APIs, sensitive data), your indicative budget and your go-live date. Detailed quote within 48 h. WhatsApp +221 77 596 93 33.
Mohamed Bah
Fondateur, Kolonell
Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.

