The verdict in three sentences
A security audit of an institutional website costs in 2026 between 3,000 and 9,000 EUR, and a full pentest between 5,000 and 15,000 EUR depending on depth. The average cost of a defacement or incident (data breach, ransomware) sits between 8,000 and 40,000 EUR, before the reputational damage to a public institution. Investing in audit and hardening (CSP headers, WAF, advanced TLS) pays off on the very first incident avoided.
Audit types and their prices
| Audit type | 2026 price | Recommended frequency | What it covers |
|---|---|---|---|
| Static analysis (SAST) | 1,500 - 4,000 EUR | Twice a year | Code, dependencies, config |
| Configuration audit | 2,000 - 5,000 EUR | Yearly | Server, headers, TLS, WAF |
| Pentest (intrusion test) | 5,000 - 15,000 EUR | Yearly | Simulated real attack |
| GDPR + data security audit | 3,000 - 7,000 EUR | Yearly | Encryption, access, logs |
| Continuous monitoring (SOC) | 400 - 2,000 EUR/month | Continuous | Real-time detection |
For an institutional brochure site, a yearly configuration audit (3,500 EUR) plus a pentest every 2 years covers the core risk, a 2026 ballpark of 4,000 to 8,000 EUR/year.
Hardening: what actually protects
| Measure | Setup cost | Effect | Target standard |
|---|---|---|---|
| CSP + HSTS headers | 800 - 2,500 EUR | Blocks XSS, injections | OWASP |
| WAF (app firewall) | 25 - 200 EUR/month | Filters bots, attacks | — |
| TLS 1.3 + advanced cert | 300 - 1,200 EUR/year | Strong encryption | ISO 27001 |
| Encrypted 3-2-1 backups | 20 - 80 EUR/month | Disaster recovery | — |
| Access management (MFA, RBAC) | 1,000 - 4,000 EUR | Shrinks attack surface | GDPR |
Most incidents stem from known unpatched flaws and weak passwords: basic hardening (CSP, WAF, MFA) removes 80% of the risk for under 5,000 EUR.
Mini case study
Nadia, CISO of a 180-staff metropolitan authority in Grenoble, must secure the citizen portal before a national audit court review. She orders a configuration audit (4,000 EUR) then a pentest (8,500 EUR), revealing 3 critical vulnerabilities. Hardening (CSP, WAF, MFA, TLS) costs 6,200 EUR. Total: 18,700 EUR. Against the average cost of a public-service incident (up to 40,000 EUR + service freeze + local press), the investment secures 60,000 users and passes the external audit with no major reservation.
Need a professional website?
Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.
FAQ
Are a security audit and an accessibility audit the same thing?
No. Accessibility (WCAG) concerns disability; security concerns protection against attacks. Both are often required together for public sites, but they are distinct skills and budgets.
How often should an institutional site be audited?
A yearly configuration audit and a pentest every 12 to 24 months is a good standard. After every major site change, a targeted check is also warranted.
Can a pentest break my live site?
A professional pentest runs on a staging environment or in a planned window, with the client's written consent. Disruption risk is controlled and contractual.
Which standard should an institution target?
ISO 27001 for security management, complemented by GDPR compliance and national cybersecurity agency guidance. For sensitive data, sovereign certified hosting reinforces compliance.
Let's scope your project. Give us the institution type, site scope and audit deadline: we'll price audit + pentest + hardening in a prioritized plan. Detailed quote within 48 h. WhatsApp +221 77 596 93 33.
Mohamed Bah
Fondateur, Kolonell
Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.