What does a security audit cost for a small web app?

Updated 15 August 2026 · Real published 2026 prices, with sources · Broid
Short answer: between $0 and $200,000, and the reason every guide gives you a useless range is that they're all answering for a different buyer than you. Concretely, for 2026: free tools cover configuration, known CVEs and dependencies for $0. Automated scanners with real published pricing start at $699/year. A genuine human penetration test with a published rate card starts around $1,500–$5,000 for a small single application. The $18,300 average everyone quotes is for a mid-size company with an enterprise procurement process. And under $4,000, you are almost certainly buying an automated scan being sold as a pentest — which is fine if you know that's what it is.
One thing that shapes this whole page: almost nobody publishes prices. A June 2026 survey of the best-known vendors — Cobalt, HackerOne, Bishop Fox, NCC Group, Trail of Bits, Synack, Bugcrowd, IOActive — found essentially all of them are contact-sales only. We went looking and found a handful more who do publish. Every figure below is either a published price, or real transaction data, and it says which.

The whole market on one page

TierWhat you getReal 2026 price
0 · FreeOpen-source scanners, dependency alerts, header and TLS graders$0
1 · Self-serve scannerAutomated authenticated scanning, subscription$699–$5,000/yr
2 · Automated "pentest"Autonomous or AI-assisted test, one re-scan$2,999–$3,500
3 · Small human pentest3–8 tester-days, single app, under ~20 pages$1,500–$6,000
4 · Standard SaaS pentest5–12 tester-days, grey box, API and roles, retest$6,000–$24,000
5 · Enterprise / multi-appMultiple roles and APIs, source code review$15,000–$60,000+
6 · Red team / continuousAdversary simulation, ongoing programme$20,000–$150,000+
7 · Bug bounty programmePlatform + triage + bounty pool, first year$40,000–$120,000
8 · SOC 2 Type II auditAttestation only — pentest is a separate line item$15,000–$200,000

Tier 0 — what $0 actually buys you in 2026

More than most people assume, and this is where a solo builder should start.

ToolCoversDoesn't cover
OWASP ZAPSQL injection, XSS, SSRF, path traversal, command injection, header misconfiguration. Authenticated scanning and AJAX-heavy pages. Broadest free coverage available.Full scans take 1–8 hours; misses some single-page-app routes; false positives.
NucleiKnown CVEs, misconfigurations, exposed panels, default credentials — 11,000+ community templates, new CVEs covered within days. Good in CI.Doesn't crawl or discover endpoints. Won't fuzz for unknown bugs.
NiktoOutdated server software, dangerous default files, server misconfiguration — 7,000+ checks.No application logic, no crawling, high false-positive rate.
GitHub code + secret scanningFree on public repos: CodeQL static analysis, leaked credential detection, push protection.Private repos are paid, billed per active committer.
Dependabot / npm auditKnown-vulnerable dependencies. Free on GitHub's free plan.Nothing about your own code or logic.
Snyk FreeDependencies, static analysis, infrastructure-as-code, containers, IDE and CLI.Five-project limit.
Mozilla HTTP ObservatoryHTTP headers, CSP, HSTS, key security config. Has run 47 million scans.Configuration only.
SSL Labs · securityheaders.comTLS configuration and certificate chain; response header grading.One narrow layer each.
Free tiers: Intruder, Probely, BeagleIntruder: 5 web apps, weekly external scans. Probely: 5 scan hours/month. Beagle: 1 test/month.Not continuous.

The honest framing: stack ZAP + Nuclei + Dependabot + Snyk Free + Observatory + SSL Labs and you have covered configuration, known CVEs, vulnerable dependencies and the classic injection and XSS classes — for nothing.

What $0 cannot buy is business logic flaws, broken access control between tenants or roles, and authentication bypass. That is precisely what human testers are paid to find, and precisely what breaks small SaaS apps. It's also, not coincidentally, what the research keeps finding in AI-generated code — one study of five agentic coding tools found them "very prone to business logic vulnerabilities" while encountering not a single exploitable SQL injection or XSS.

Tier 1–2 — automated scanners with published prices

VendorPublished price
AstraScanner Lite $69/mo · $699/yr (1 target) · Scanner $199/mo · $1,999/yr (unlimited scans) · Scanner Agency $499/mo · $4,999/yr (5 targets, compliance views). Pentest Auto $2,999/yr, Pentest Expert $5,999/yr. $7 one-week trial. The most price-transparent vendor in the market.
Beagle SecurityFree (1 test/mo) · Essential $99/mo · Advanced $299/mo (15 tests/mo, API and GraphQL). Usage-based, no per-target fee.
IntruderFree tier · Cloud $299/mo · Pro $499/mo. AI-powered web app pentests from $3,500/test. 20% off annual.
Pentest-ToolsFrom $95/mo (NetSec) to $190/mo (Pentest Suite) at 5 assets. Annual = pay for 10 months.
DetectifyStarter €0 · Standard from €2,500/yr · Professional from €5,000/yr · Enterprise from €15,000/yr. Watch out: per-domain and per-target charges sit on top, so the headline is a floor.
SnykFree · Team from $25/developer/mo · Ignite from $1,260/developer/yr.
TenableWeb App Scanning $7,434/yr for 5 domains · Vulnerability Management $6,112/yr for 100 assets.
Acunetix · Invicti · QualysNot published. Acunetix is around $7,000/yr entry per a cloud marketplace listing; Qualys web app scanning is quoted by resellers near $1,995/yr for 25 apps. Treat both as third-party estimates, not vendor prices.

Start at the free end. Before you price anything above, see what your live app currently exposes — A–F grade, free, no signup.

Scan my app free →

Tier 3–4 — human penetration testing

The vendors who publish a rate card

This short list is the useful part of this page, because it's what the rest of the internet doesn't give you.

VendorPublished prices
Sherlock ForensicsQuick Audit $1,500 CAD, 3–5 days — auth and session, access control, injection, secrets across code and git history, API enumeration, OWASP mapping, retest included. Standard $5,000 CAD (10–15 days). Comprehensive $12,000 CAD. The only genuinely solo-founder-priced published card we found.
Software SecuredWeb & API pentest from $10,800 with 3 retest rounds over 12 months · mobile from $5,400 · secure code review from $9,300 · external network from $5,400 · PTaaS subscription from $21,400/yr with unlimited retesting.
AstraPentest Expert $5,999/yr — manual testing by certified experts, 2 re-scans, one target.
Budget Security€849/day (~$985), OSCP-certified manual testing, full report plus one free retest.
Secure IdeasPublishes its hourly rate: $340/hr, and states the industry band is $200–$500/hr.

What the opaque vendors actually charge

For two of the biggest names, aggregated real signed-contract data exists — stronger evidence than any published guide:

VendorMedian contractRangeSample
Cobalt.io$30,000/yr$8,937 – $87,840194 purchases
HackerOne$40,000/yr$18,609 – $125,834305 purchases

Note Cobalt's floor: $8,937 is a real price a small buyer has actually achieved, well below the five-figure minimums usually implied. Buyers routinely negotiate 15–30% off list.

Market ranges, and where the guides disagree

The disagreement is almost entirely about the floor. For a small, simple web app under about 20 pages with no API, published guides range from $2,500–$6,000 at the low end to $5,000–$30,000 at the high end. For a medium SaaS with a REST API and multiple roles, the consensus is roughly $6,000–$15,000; complex enterprise work runs $15,000–$40,000+, and full-stack with source code review reaches $20,000–$60,000+.

The 2026 average across the market is put at around $18,300, with most organisations spending $10,000–$30,000 per test.

The rule that resolves the disagreement: multiple independent sources converge on the same line — anything under about $4,000 is an automated scan, not a penetration test. The red flags are specific and easy to check: 24–48 hour turnaround promised, no stated tester-day allocation, scanner output with minimal narrative, no authenticated testing, no reproduction steps, no retest. None of that makes a cheap scan worthless. It makes it a different product, and you should know which one you're buying.

What drives the price

Tester-days is the real unit; everything else is a proxy for it. A grey-box test of a medium SaaS application takes a minimum of 5–10 business days of active testing. At mid-market day rates of $1,500–$3,500 that arithmetic alone produces $7,500–$35,000.

Day rates themselves span roughly seven times across the market — from about $985/day published at the budget end to $4,000–$7,000/day at boutique and Big Four firms, with the Big Four typically charging 2–3× a boutique for identical scope.

Compliance — the part most guides get wrong

FrameworkPentest required?Cost
PCI DSSYes — requirements 11.4.1 and 11.4.4, at least annually plus after significant change. But only for SAQ C and SAQ D. Not required for SAQ A, B, B-IP, C-VT or P2PE.$12,000–$25,000, or a 15–30% premium on a base test
SOC 2No. SOC 2 does not explicitly require penetration testing. CC4.1 lists it as one example of a separate evaluation; CC7.1 references vulnerability scanning. Auditors recommend it and it's strong Type II evidence — but it is not mandatory.Audit fee: Type I $5,000–$25,000 · Type II $15,000–$200,000 depending on firm tier. Pentest is a separate $8,000–$30,000 line item. Total programme typically $30,000–$150,000; startups $20,000–$60,000; maintenance ~40% of initial spend annually.
ISO 27001Not named as a mandatory control. No accredited certification body publishes a rate card.Audit fees quote-only. Compliance tooling for a 25-person org runs $7,500–$32,500/yr depending on vendor.
HIPAA · FedRAMPEffectively yes in practiceHIPAA $10,000–$50,000 · FedRAMP $15,000–$75,000+
The single most useful line on this page for a small SaaS: if you take payments through Stripe or another hosted checkout, you almost certainly fall under PCI SAQ A — which requires no penetration test at all. A lot of vendors are vague about this. Check which SAQ applies to you before you buy anything on PCI grounds.

Bug bounty is not the budget option

A common assumption, and it's backwards. Real contract data puts HackerOne's median at $40,000/year. A vulnerability disclosure programme with no bounties still runs $20,000–$50,000/year in platform fees. First-year totals for a small or mid-market company land at $40,000–$120,000 — the platform floor alone exceeds a full mid-tier human pentest before a single bounty is paid.

The genuinely free version is a self-run disclosure programme: publish a security.txt, a clear disclosure policy and an email address. You pay nothing but triage time, and researchers do find things.

What small companies actually spend

We looked for a survey of solo-founder or small-SaaS application security spend and couldn't find one. That absence is itself part of why this question is answered so badly online. The closest available data is general small-business security spend:

Put those together and the real answer emerges: a typical small business's entire annual security budget is one mid-tier penetration test. That's why the honest recommendation for most small apps is not "save up for a $15,000 pentest." It's: exhaust the free tier properly, add an automated scanner for the price of a lunch, and buy human testing when you have something specific that needs it — money, regulated data, or an enterprise customer asking.

So what should you actually buy?

You are…Buy thisCost
Launching a side project or MVPFree stack + your platform's built-in scan + an external scan of the live URL$0 – ~$5
Early SaaS with paying users, no regulated dataThe above, plus an automated scanner subscription, run continuously$699 – $2,000/yr
Taking payments via hosted checkout (Stripe etc.)Same as above. Check your SAQ — you likely need no pentest for PCI$699 – $2,000/yr
First enterprise customer asking security questionsA small human pentest with a letter of attestation — that's the document they want$1,500 – $6,000
Handling health, financial or regulated dataFull human pentest, scoped to compliance. Nothing automated substitutes$6,000 – $25,000
Pursuing SOC 2 Type IIAudit + readiness + tooling + a pentest as separate line items$20,000 – $60,000 (startup range)

Common questions

How much does a security audit cost for a small web app?

For a genuinely small application, published rate cards start around $1,500–$5,000 for a human penetration test of 3–8 tester-days. Market guides put the band at $2,500–$6,000. Below roughly $4,000 you are usually buying an automated scan presented as a pentest. Automated scanning subscriptions with published prices start at $699/year, and a capable free stack costs nothing.

Why do security audit prices vary so much?

Because the unit is tester-days, and day rates span about seven times across the market — from roughly $985/day at the budget end to $4,000–$7,000/day at boutique and Big Four firms, who typically charge 2–3× a boutique for identical scope. On top of that, scope (endpoints, roles, APIs, multi-tenancy), methodology, whether retesting is included, and whether you need a letter of attestation all move the number substantially.

Is a $500 security audit worth it?

It's worth it if you understand you're buying an automated scan, and automated scans genuinely catch the most common failures in small apps — exposed databases, leaked keys, unprotected endpoints, missing headers. It is not worth it if it's sold as equivalent to a manual test. The tells: 24–48 hour turnaround, no stated tester-days, scanner output with little narrative, no authenticated testing, no retest.

Do I need a penetration test for SOC 2?

No. SOC 2 does not explicitly require one — CC4.1 lists penetration testing as one example of the separate evaluations management may use, and CC7.1 references vulnerability scanning. Auditors commonly recommend it and it makes strong Type II evidence, but it is not mandatory. Budget it as a separate $8,000–$30,000 line item if you choose to do it, not as part of the audit fee.

Do I need a penetration test for PCI compliance?

Only for SAQ C and SAQ D. Requirements 11.4.1 and 11.4.4 mandate annual testing plus testing after significant change — but SAQ A, B, B-IP, C-VT and P2PE do not require it. If you take payments through a hosted checkout like Stripe, you're most likely SAQ A and need no penetration test for PCI purposes.

What's the cheapest way to check my app is secure?

Free, in this order: run your platform's built-in scan if it has one; verify Row Level Security on every database table; check your JavaScript bundle for secret keys; confirm your API endpoints require authentication; then run a free external scan for headers, TLS and exposed files. That sequence catches the failures that actually take down small apps. The 10-minute pre-launch check walks through it step by step.

Is a bug bounty cheaper than a pentest?

No — it's typically several times more expensive. Real contract data puts HackerOne's median at $40,000/year, and even a bounty-free disclosure programme runs $20,000–$50,000/year in platform fees. The free version is running your own: publish a security.txt, a disclosure policy and a contact address, and pay only in triage time.

Start at the free end — scan your app now

An A–F security grade in seconds, no signup, including a live database-exposure test. A full report with fixes costs about a dollar.

Scan my app free

We'll also tell you what a scan can't find — that's what the human tiers above are for.

Prices verified August 2026 from vendors' own pricing pages (Astra, Software Secured, Sherlock Forensics, Beagle Security, Intruder, Detectify, Pentest-Tools, Snyk, Tenable, Budget Security, Secure Ideas, Cobalt), from aggregated signed-contract data for Cobalt and HackerOne, from a directory analysis of 173 SOC 2 attestation firms, and from published PCI DSS and SOC 2 requirement documentation. Ranges attributed to "guides" come from vendor-published cost guides, which have a commercial interest in the numbers — we've said so where it matters.
Related: Is my AI-built app safe to launch? · Lovable vs Bolt vs v0 security · Broid vs the platform's own checker
← All Broid guides
Broid Business Solutions · Terms & Privacy
Vendor names and prices are trademarks and pricing of their respective owners. Prices shown were published by each vendor as at 15 August 2026, are indicative only, exclude taxes, and change frequently — always confirm directly with the vendor before budgeting or purchasing. Figures attributed to cost guides come from vendors that also sell these services. Broid is an independent service and is not affiliated with, endorsed by, sponsored by or connected to any company named on this page. All product and company names, logos and brands are the property of their respective owners and are used here for identification and factual comparison only. Comparisons reflect each vendor's publicly available documentation as at 15 August 2026 and may be out of date; verify current behaviour with the vendor. Nothing on this page is legal, compliance or professional security advice, and no automated scan — including ours — guarantees that an application is secure. Corrections: broid@broid.net.