Critical flaws wp2shell + xss2shellTest my site
PentestAuditBudget

How much does a security audit cost in 2026? A real pricing grid

What a pentest, a vulnerability scan and a full audit actually cost in 2026: market ranges, what moves a quote, and how to read one without getting burned.

by Thibaud Robin10 min read
How much does a security audit cost in 2026? A real pricing grid

Introduction

"How much does a security audit cost?" is a question nobody wants to answer online, and it is easy to see why: the honest answer starts with "it depends". Except the executive asking it needs an order of magnitude to make a budget decision, not a sales call.

So here are the ranges actually seen on the French and wider European market in 2026, what makes one quote six times another, and above all how to compare two proposals that carry the same title while containing very different work. We sell a product in this market, so let us say it upfront: you will also read what we think of the one-off pentest model. Judge for yourself.

First, what are we actually buying?

The word "audit" covers at least five different services, sold at prices that have nothing in common. That is where the first bad surprise lives, not in the rate card.

  • The vulnerability scan. A tool runs across your perimeter and reports what it detects. Automated, repeatable, but it produces false positives and never tests business logic.
  • The penetration test. Humans try to break in, with scenarios. It is the most expensive service because it is expert time.
  • The configuration or code audit. You hand over access, the auditor reads. Excellent findings-per-hour ratio, but it says nothing about what an attacker sees from outside.
  • The organisational audit. Gaps against a framework (ISO 27001, NIS2, a sector standard). Little to no technical work.
  • Bug bounty. You pay for results. An interesting model, but it assumes real maturity, otherwise you pay a premium for findings you could have caught yourself.

We covered the technical differences between these approaches in our article on which vulnerability scan to use. This one is about money.

The 2026 grid

Here are the ranges we observe, based on published rate cards and on the quotes our customers show us. Excluding tax.

ServiceCommon rangeTypical duration
Automated vulnerability scan (as a service)€1,900 to €4,000A few days
External pentest, limited scope€3,300 to €8,0003 to 8 days
Web application pentest (one application)€5,000 to €15,0005 to 15 days
Full audit, single-site SME€3,500 to €18,0001 to 4 weeks
Internal / Active Directory pentest€8,000 to €25,0008 to 20 days
Red team€25,000 to €80,0001 to 3 months
ISO 27001 readiness audit€5,000 to €20,000Variable
Continuous monitoring (annual subscription)from €5,000All year round

Underneath all of it, most of the market runs on a daily rate between €900 and €1,500 depending on consultant seniority and the firm's reputation. Multiply that by the number of days quoted and you will know whether the proposal is internally consistent.

The five factors that move the price

1. Scope, obviously

Number of IPs, number of applications, number of user roles to test. A pentest on an application with three profiles (visitor, customer, admin) costs roughly three times a single-profile test, because the authorisation testing has to be redone at every level.

2. Depth: black, grey or white box

  • Black box: the auditor gets nothing. Realistic, but part of the budget burns on discovering what you could have handed over.
  • Grey box: they get test accounts. Best findings-per-euro ratio in the vast majority of cases.
  • White box: they get the code and the architecture. The most thorough, the most expensive in analysis time.

Paying for an expensive black box to feel reassured about realism is a common mistake. The attacker has time. Your provider does not.

3. Who actually does the work

This is where quotes look most alike and delivery differs most. Ask explicitly who will run the tests and what their experience is. A firm selling at senior rates and delivering with a supervised junior is common, and it is not illegitimate as long as it is stated.

4. Is the retest included?

The retest after remediation changes everything, and it is sometimes billed separately. Without it you have a list of problems and no evidence they were solved. That evidence is exactly what an ISO 27001 auditor, or tomorrow a NIS2 inspection, will ask for.

5. The deliverable and the debrief

A tool-generated report and a written report with a technical debrief meeting are not the same amount of work. Ask for an anonymised sample report before signing. It is a normal request and any serious firm has one ready.

What each budget tier actually buys

This is the table we wish we had read when we were on the other side of it.

BudgetWhat it honestly buysWho it fits
~€2,000An automated scan on a limited scope, with a readable report. No manual validation.First snapshot, very small companies
~€5,000A short external pentest, or a tightly scoped application test. Obvious findings, not chained ones. At the same price, a full year of continuous monitoring.SMEs, a customer contract requirement
~€15,000A real application pentest across several roles, or a full external test, retest included.Mid-market, revenue-critical app
~€30,000+A deep audit or the start of a red team. Scenarios get tested, not isolated points.Critical scope, existing maturity

A piece of advice we give often, and that occasionally annoys people: if your total budget is €5,000, do not put all of it into a pentest. Keep enough to fix things. An uncorrected report costs the price of the report and reduces no risk.

The cost nobody quotes: the time between two audits

Here is our main disagreement with the dominant model, and it is less about the price than about the unit of measure.

An annual €15,000 pentest gives you a photograph. The day after the debrief, a developer ships a new API route, a contractor publishes a subdomain, a critical CVE drops on your reverse proxy. None of that is covered by the report you just paid for, and you will not know until the next audit.

Do the maths differently. Take the annual cost, divide it by the number of days on which you hold current information about your exposure. On an annual pentest, that information is reliable for a handful of days a year. For the remaining eleven months you are paying for a document, not for knowledge.

This is not an argument against pentesting. A human penetration test finds things no tool will ever find: crooked business logic, chained abuses, misuse of legitimate features. It is an argument against pentesting alone, and for splitting the budget between continuous coverage and occasional depth.

Seven questions to ask before signing

Copy them into your next conversation with a provider. They take ten minutes and they rule out most bad surprises.

  1. How many person-days, and for which named profiles?
  2. Is this manual testing, tooled scanning, or a mix? In what proportion?
  3. Is the post-remediation retest included, and for how long?
  4. Can I see an anonymised sample report?
  5. What happens if you find a critical vulnerability mid-engagement? How fast am I told?
  6. Does the scope include subdomains you discover, or only the list I provide?
  7. What is explicitly not covered?

Question 6 is the one that costs the most when forgotten. Many engagements only test the list the client provided, and that list is nearly always incomplete. We wrote a free method to build it properly before requesting quotes: inventory your external attack surface.

So what does Flawfence cost?

Let us be specific, since that is the whole point of this article: our annual subscription starts at €5,000, and scales from there with the size of your perimeter.

We sit on the continuous coverage segment, not the day-rate pentest one. So what those €5,000 buy is not a five-day engagement: it is a map of your external surface rebuilt continuously, detection and validation of exploitable vulnerabilities as they appear, and dated reports usable as evidence for ISO 27001 and NIS2 alike.

Against the table above, that sits at the level of a short external pentest. The difference is not the amount, it is the unit: a pentest covers you for a few days, a subscription covers you for three hundred and sixty-five. On the other hand it will never find a business logic flaw, which is exactly why we recommend keeping budget for a targeted pentest rather than spending all of it with us.

The right way to find out whether it is worth it for you is to start by looking at what you expose. If your surface is three well-maintained assets, a one-off pentest will probably do, and we will tell you so.

FAQ

Is a security audit mandatory?

Not as such under general law. But several regimes require it indirectly: ISO 27001 requires demonstrable management of technical vulnerabilities, NIS2 mandates risk management measures, and some regulated sectors have their own requirements. In practice, your enterprise customers will be the first to ask.

Why do two quotes for the same service vary threefold?

Nine times out of ten, because they do not describe the same service. Compare the number of days, the share of manual testing and whether the retest is included, before comparing prices. If a gap remains after that, it comes down to seniority or to the firm's margin.

Can an automated scan replace a pentest?

No, and not the other way round either. The scan continuously covers the known (vulnerable versions, misconfigurations, exposure). The pentest finds the unknown and the contextual. Together they cost less than a quarterly pentest and cover more.

How much does fixing the findings cost?

That is the line item budgets systematically forget. Plan for at least as much as the audit itself, sometimes more when remediation implies application version upgrades. An audit with no remediation budget attached reduces no risk.

Should we insist on a certified provider?

If you are under an obligation that requires it, yes. Otherwise, certification is one signal of seriousness among others, with a matching price tag. Plenty of excellent firms are not certified, and certification does not guarantee the quality of a given consultant on a given engagement.

Conclusion

For the large majority of small and mid-sized company needs, a security audit in 2026 lands between €3,000 and €20,000. But the number to watch is not the one on the quote: it is the cost per day of actual coverage, and the remediation budget you kept aside.

Before requesting three quotes, do one thing: list what you expose. A provider prices the perimeter you hand them, and if that perimeter is wrong, so is the quote. Start there, it is free and it takes a minute.

Let’s discuss your external exposure

Request a personalized Flawfence demo and discover your real exposure level.