The verdict in three sentences
A security audit of a site and app costs, in 2026, between 4,000 and 15,000 EUR depending on scope (penetration test, OWASP Top 10 review, header analysis, configuration), delivered in 2 to 4 weeks. It produces a prioritized remediation plan ranking vulnerabilities by criticality. The stake exceeds the audit price: an exploited flaw can trigger ransomware or a GDPR breach fined up to 4 % of global revenue.
What an audit covers by scope
Price varies with test depth. A "black box" audit (no access) is cheaper than a "white box" audit with code review and authenticated access.
| Audit type | Content | 2026 order of magnitude |
|---|---|---|
| Automated scan | Known vulnerabilities, headers | 1,000-3,000 EUR |
| Black-box pentest | External intrusion, no access | 4,000-8,000 EUR |
| Grey-box pentest | User access, business logic | 6,000-12,000 EUR |
| White-box audit | Code review + configuration | 10,000-15,000 EUR |
| Post-fix re-audit | Verification of fixes | 1,500-4,000 EUR |
A serious audit covers the OWASP Top 10 (injections, XSS, access control, authentication, misconfiguration) and delivers a report with evidence and recommendations.
The cost of an untreated flaw
Not auditing is betting that nothing will happen. The risk calculation shows the opposite: an incident costs far more than an audit.
| Incident type | Impact | 2026 order of magnitude |
|---|---|---|
| Ransomware | Lockout, ransom, remediation | 20,000-200,000 EUR |
| GDPR data breach | CNIL fine | Up to 4 % of global revenue |
| Defacement / downtime | Reputation, lost sales | 5,000-50,000 EUR |
| Loss of customer trust | Churn, lost tenders | Variable, often major |
| Legal + notification costs | Lawyers, crisis comms | 10,000-50,000 EUR |
For a company at 10M EUR revenue, a maximum 4 % fine is 400,000 EUR: a 10,000 EUR audit is 2.5 % of that risk.
Mini case study
Elodie, CISO in Strasbourg, must secure a corporate site and a client app before a tender requiring proof of security. She orders a grey-box pentest at 9,000 EUR delivered in 3 weeks, which reveals 2 critical and 5 medium vulnerabilities. Remediation costs an extra 4,000 EUR, plus a re-audit at 2,000 EUR. Total: 15,000 EUR. In contrast, ransomware exploiting one of the flaws would have cost between 20,000 and 200,000 EUR, without counting the lost tender. The audit secures both the infrastructure and the target commercial contract.
Need a professional website?
Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.
FAQ
What is the difference between an automated scan and a pentest?
The scan automatically detects known vulnerabilities (1,000-3,000 EUR); the pentest adds human expertise to exploit business logic and complex flaws (4,000-15,000 EUR).
How often should a site be audited?
At least once a year and after any major change (redesign, new feature, migration). Sensitive sites audit every 6 months.
What does the remediation plan contain?
The list of vulnerabilities ranked by criticality (critical, high, medium, low), with impact, fix difficulty and prioritization. It is the audit's most useful deliverable.
Is a re-audit necessary?
Yes, to confirm fixes are effective and have not introduced new flaws. Plan 1,500 to 4,000 EUR, often required in tenders.
Does an audit protect against GDPR fines?
It strongly reduces risk by fixing flaws before exploitation. A breach can cost up to 4 % of global revenue; documenting regular audits also demonstrates your diligence.
Let's scope your project. Tell us the scope (site, app, page count, authenticated access) and the deadline; we will propose an audit with a prioritized remediation plan, from 4,000 EUR. Detailed quote within 48 h. WhatsApp +221 77 596 93 33.
Mohamed Bah
Fondateur, Kolonell
Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.
