Skip to main content
Fleuret raises €3.5M pre-seed

What does a pentest cost in Europe in 2026?

Yanis Grigy, CEO3 min read

The honest range

Penetration testing in Europe in 2026 spans two orders of magnitude:

TypePrice rangeTurnaround
Automated AI pentest (POC)€3,000 per webapp72 hours
Continuous AI pentest (annual)€10,000 to €25,000/yrWeekly cadence
Mid-tier consultancy€8,000 to €20,0002 to 4 weeks
Boutique offensive firm€15,000 to €40,0003 to 6 weeks
Big 4 / Tier-1 advisory€30,000 to €100,000+6 to 12 weeks

Same word, "pentest", on every line item. Not the same product.

What drives the price

Five factors, in decreasing order of impact.

  1. Headcount on the engagement. A senior pentester at €1,200 a day for ten days is €12,000 before margin. That is the baseline.
  2. Scope. A 50-endpoint web app costs more than a single login form. APIs, mobile, internal AD each multiply hours.
  3. Methodology. Black box (URL only) is cheaper than grey box (with credentials), which is cheaper than white box (with source).
  4. Reporting depth. A 5-page summary is cheaper than a 60-page DORA-mapped, CVSS-scored, PoC-reproducible deliverable.
  5. Brand and certification. PASSI in France, CREST in the UK, third-party signatures. Each adds 20% to 50%.

Margins above the senior cost floor are mostly brand, sales overhead, and project management.

The same web app, tested by the same person, ships to the buyer at €8,000 from a freelancer and €25,000 from a tier-1 consultancy. The findings list is often identical.

What automation actually changes

An autonomous AI pentester does not have a daily rate. The marginal cost of one engagement is dominated by GPU inference and LLM time. Roughly €20 to €25 of compute per pentest at our infrastructure cost basis.

That changes the economics in two ways:

  • The floor drops from €8,000 (one human-week) to €3,000 per webapp (compute plus margin).
  • The ceiling becomes a function of scope, not consultant availability.

For a CISO at a 300-employee SaaS with 12 web apps and 4 APIs, the choice is no longer "annual €25,000 boutique pentest." It becomes "continuous coverage on all 16 surfaces for the same yearly budget."

Where humans still win

Three categories still demand a senior offensive expert:

  1. Business-logic abuse on bespoke workflows (lateral movement in a custom CRM, multi-actor fraud chains).
  2. Active Directory and complex internal network red team. Public AI pentest products are weak here today.
  3. Regulatory red team. TIBER-EU style threat-led testing under DORA TLPT. Mandatory third-party signature. Multi-week scope.

A serious 2026 pentest program pairs continuous AI coverage on the bulk of the attack surface with one or two human red team engagements per year for the high-stakes scenarios.

How Fleuret prices

We list a one-time POC at €3,000 per webapp, with annual subscriptions starting at €10,000 (Starter, 1-3 apps) and €25,000 (Growth, 4-10 apps, weekly automated rescans, Jira ticket creation per finding, and DORA-mapped audit PDFs). Large deployments (Scale, 10+ apps, dedicated CSM) are scoped per case.

If you are evaluating offers and want a reference number that is not a salesperson's quote, request a demo.


Share this postShare on LinkedIn

The Fleuret newsletter

One email a month. Cyber analysis, DORA, NIS2, and what we learn pentesting our customers' apps.

Privacy Settings

This site uses third-party website tracking technologies to provide and continually improve our services, and to display information according to users' interests. I agree and may revoke or change my consent at any time with effect for the future.