MagnoSec
Complete 2026 Guide

Web Pentesting Guide: Methodology, Tools and Prices

Everything you need to know about web application pentesting: what it is, how it's done, which methodologies are used, which tools professionals use, how much it costs in Spain and how to choose the best pentesting company.

1. What is web pentesting?

Web pentesting (web application penetration testing) is an offensive security audit that simulates a real attack against a web application to identify, exploit and document vulnerabilities before real attackers can take advantage of them.

Unlike a simple vulnerability scan — which only produces a list of possible problems — a professional web pentest involves the controlled manual exploitation of each vulnerability found to demonstrate its real impact on the business. It is not enough to say "you have SQL Injection": you have to prove that, through that injection, an attacker could access the entire customer database.

The end goal is not just to find flaws, but to deliver a prioritized remediation plan that allows the organization to fix vulnerabilities in order of criticality. A good pentest does not end with the report: it ends when all critical vulnerabilities have been fixed and validated.

Web pentesting is mandatory to comply with regulations such as ISO 27001, ENS, DORA, PCI-DSS and NIS2. It is also an increasingly common requirement in cyber insurance policies and in contracts with large clients that want to verify the security of their suppliers.

2. Web pentesting methodologies

A professional web pentest follows internationally standardized methodologies. The three most recognized are:

OWASP WSTG

Web Security Testing Guide. The de facto standard for web pentesting. Covers 12 testing categories including authentication, authorization, sessions, input validation and cryptography.

PTES

Penetration Testing Execution Standard. A complete framework covering everything from the pre-engagement phase to the final report. Widely used in enterprise pentesting.

OSSTMM

Open Source Security Testing Methodology Manual. A scientific approach that measures the real security state through quantifiable metrics (RAVs).

At MagnoSec we use a combination of these three methodologies, adapting them to each client's specific context: a startup that needs to validate its MVP does not require the same approach as a bank subject to DORA that needs a TLPT (Threat-Led Penetration Testing).

3. The 5 phases of a professional web pentest

01

Reconnaissance and planning

Definition of scope (URLs, APIs, features), rules of engagement, test credentials. Information gathering about the technologies used, subdomains, endpoints and application architecture. Tools: Nmap, Sublist3r, Amass, Burp Suite.

02

Vulnerability analysis

Combination of automated scanning (Burp Scanner, Nuclei, Nikto) with expert manual analysis. Mapping of the attack surface: forms, APIs, parameters, headers, cookies, WebSockets. Manual analysis is critical because many vulnerabilities are not detected by automated tools.

03

Controlled exploitation

Manual exploitation of each vulnerability found to confirm it exists and demonstrate its real impact. Common techniques: SQL Injection, XSS, CSRF, SSRF, IDOR, path traversal, insecure deserialization, authentication and authorization bypass. Every exploitation is documented with screenshots and reproduction steps.

04

Post-exploitation

Assessment of the compromise's scope: pivoting to other systems, privilege escalation, persistence, access to sensitive data. The goal is to answer: how far could a real attacker get from this vulnerability? This phase is what separates a real pentest from an automated scan.

05

Report and recommendations

Executive document for management + detailed technical report. Every finding includes: description, CVSS score, evidence (screenshots, payloads), reproduction steps, business impact and prioritized remediation recommendations. Includes a results presentation session with the client's technical team.

4. Professional web pentesting tools

ToolTypeMain usePrice
Burp Suite ProfessionalProxy + ScannerManual and automated analysis of HTTP/S traffic: interception, modification and replay of requests€449/year
OWASP ZAPProxy + ScannerFree alternative to Burp Suite. Automated scanning based on the OWASP Top 10Free
NucleiScannerVulnerability scanning based on YAML templates. Fast and extensibleFree
SQLMapExploitationAutomatic detection and exploitation of SQL Injection vulnerabilitiesFree
FFuF / DirbFuzzingDiscovery of hidden directories, files and endpoints through brute forceFree
CaidoProxyModern Burp Suite alternative with better UX. HTTP and WebSocket traffic analysisFree/Premium
NmapReconnaissancePort scanning, service detection and operating system fingerprintingFree

5. Black box, grey box and white box

Black Box

The pentester receives no prior information about the application. Simulates an external attacker who only knows the URL. More realistic, but may miss vulnerabilities in undiscovered areas. Ideal for evaluating real exposure from the internet.

Grey Box

The pentester receives standard user credentials and basic documentation. The most common and recommended approach. It evaluates what a legitimate user could do with malicious intent, or an attacker who has stolen basic credentials.

White Box

The pentester has full access to the source code, architecture and configuration. The most exhaustive approach. It finds vulnerabilities that would be invisible from outside. Recommended for critical applications and regulatory compliance requirements.

6. Web pentesting prices in Spain [2026]

The price of a professional web pentest in Spain varies depending on the scope, the complexity of the application and the depth of the testing. These are the indicative ranges for 2026:

ScopePrice rangeDurationIdeal for
Simple app (landing page, form, no API)€690 - €1,2001-2 weeksStartups, corporate websites, portfolios
Medium app (login, REST API, user roles)€1,200 - €2,5002-3 weeksSaaS, e-commerce, B2B platforms
Complex app (multiple APIs, WebSockets, microservices)€2,500 - €4,5003-4 weeksFintech, healthtech, apps with sensitive data
Critical app (DORA/PCI-DSS requirements, TLPT)€4,500 - €15,000+4-8 weeksBanks, insurers, critical infrastructure

Why these prices? A professional web pentest is not running an automated scanner. It involves between 20 and 80 hours of work from a senior consultant with certifications such as OSCP, OSWE or BSCP. It includes manual analysis, controlled exploitation, a detailed report with evidence, results presentation and post-remediation follow-up. The average cost of a security incident in a Spanish company is €75,000 according to the National Institute of Cybersecurity.

7. Certifications for web pentesters

If you are looking to hire a web pentest, make sure the consultant holds at least one of these internationally recognized certifications:

OSCP

Offensive Security Certified Professional

The most recognized certification in pentesting. 24-hour practical exam. Demonstrates real exploitation capability.

OSWE

Offensive Security Web Expert

Specialization in advanced web pentesting and exploit development for web applications.

BSCP

Burp Suite Certified Practitioner

PortSwigger's official certification. Demonstrates mastery of Burp Suite Professional for web pentesting.

eWPTXv2

Web Penetration Tester Extreme

Advanced INE Security certification. Covers modern web exploitation techniques.

At MagnoSec, our team holds OSCP, OSWE, OSWP, BSCP and eWPTXv2 certifications. See our full certifications in the certifications guide.

8. How to choose a pentesting company

Not all pentesting companies are the same. Here are 7 criteria to choose well:

  1. 1Team certifications: Ask for the certifications of the consultants who will run your pentest. OSCP, OSWE, CRTO and BSCP are the standard. Be wary of companies that do not publish their team's certifications.
  2. 2Documented methodology: The company should specify which methodology it uses (OWASP, PTES, OSSTMM) and why. If they cannot explain their methodology in 2 minutes, they do not have one.
  3. 3Detailed technical report: Ask to see a sample report (anonymized). A good report includes CVSS scores, evidence, reproduction steps and prioritized recommendations. If the report is 5 pages of automated scanner screenshots, it is not a real pentest.
  4. 4Manual exploitation: Ask explicitly whether they manually exploit vulnerabilities. Many companies sell automated scans as pentesting. The price difference is abysmal for a reason.
  5. 5Verifiable references: Ask for client references in your sector. A pentester who has audited 50 fintechs knows exactly what to look for in yours. Industry experience matters.
  6. 6Post-delivery support: A good pentest includes at least one results presentation meeting and follow-up during remediation. If the company disappears after delivering the PDF, look elsewhere.
  7. 7Professional liability insurance: The company must have liability insurance that covers possible damage during testing. Especially important for production applications. Ask for the insurance certificate.

9. Frequently asked questions about web pentesting

How often should I run a web pentest?
The standard recommendation is at least once a year, or after every major change to the application (new module, migration, new public API). Regulations such as PCI-DSS require quarterly pentesting for applications that handle cardholder data. DORA requires a TLPT every 3 years for financial entities.
Is the pentest performed in production or development?
Ideally in a staging/pre-production environment identical to production. If it does not exist, it can be done in production with the proper precautions (agreed testing window, authorized pentester IPs, rollback plan). Never in development: the code and configuration are different.
Can my application go down during a pentest?
A professional pentester takes precautions to avoid denial of service. Before testing a potentially disruptive payload, the risk is assessed. DoS tests are only included if the client explicitly requests them. In any case, the pentest should be scheduled outside the application's critical hours.
What happens to the data the pentester accesses?
The pentest contract includes a non-disclosure agreement (NDA) and specific clauses on data handling. The pentester only accesses the data needed to demonstrate the impact of the vulnerabilities. All data collected is handed over to the client at the end and deleted from the pentester's systems.
Can I hire a pentest while my application is still in development?
Yes, and it is actually recommended. Incorporating pentesting into the development cycle (DevSecOps model) lets you detect vulnerabilities when they are cheapest to fix. Do not wait until the application is in production to discover it has a critical flaw.

Need a web pentest?

Request a security audit for your web application. Custom quote in less than 24 hours. From €690.

Want more info?