GetPentest

Penetration testing in Canada: types and cost

Start here if an auditor, a customer or an insurer has asked your company for a penetration test and the quotes you are getting back differ by a factor of five.

Last reviewed 2026-08-31Written by Jacob Masse, TrazTech Inc.

Compare the firms yourself, or describe the job once and we will send it to the ones that do this work in Canada. Both are free.

A penetration test in Canada costs between $6,000 and $40,000 CAD depending on scope. Quotes vary that widely because the word covers two different products. One is a person spending days inside your application trying to break it. The other is a vulnerability scanner run by someone who exports the results into a template. Both get sold as a penetration test. Only one of them will survive a serious question from your auditor or your customer's security team.

This site is operated by TrazTech Inc., a Canadian security and compliance practice in Toronto. It is here to help you scope the right test and tell the two apart before you have paid for one.

Five free tools sit behind these guides. Start with the scoping questionnaire: it produces a scope document you can send to several firms so their quotes are comparable.

The fastest way to tell the two products apart is to read the deliverable. TrazTech publishes a specimen penetration test report in full, no email required: nine findings, each with a reference, a severity, the CVSS score beside the tester's own rating, what was affected, what to do about it and where it stands on retest. Ask any firm you are quoting to show you theirs. A scan sold as a test rarely survives the request.

Which test do you actually need

Scope follows the asset, not the buzzword. Work down this table until a row describes the thing you are worried about.

Test type by what you are trying to protect
What you haveTest that fitsWhere to start
A SaaS product with logins, roles and an API Authenticated web application and API test Web application security testing
Servers, firewalls and services exposed to the internet External network penetration test Network penetration testing
A corporate office network, Active Directory, laptops Internal network test, usually assumed-breach Internal network testing
An AWS, Azure or GCP account rather than servers you own Cloud configuration review plus targeted testing Cloud penetration testing
A mature security team that wants its detection tested Red team or purple team exercise Red team assessment
An API that other software calls, or a mobile app API testing, and mobile testing with the backend included API and mobile testing
Systems that handle payment card numbers Internal, external and segmentation testing on a set cadence PCI DSS penetration testing
No idea yet, but a customer contract says "annual penetration test" Whatever holds their data, tested from the outside and while logged in Answer five questions

Which framework is driving this

Most penetration tests in Canada are bought because a framework or a contract requires one, and each asks for something slightly different. Buying the wrong shape of test is the expensive mistake. You find out at evidence review, and by then the deal has a date on it.

What each requirement usually means in practice
RequirementWhat is normally expectedDetail
SOC 2 Type 2 No explicit rule. Auditors expect an independent test annually plus evidence you fixed what it found SOC 2 penetration testing
ISO 27001 Technical vulnerability management and secure development testing under Annex A ISO 27001 penetration testing
PCI DSS Prescriptive. Annual and after significant change, internal and external, with segmentation testing PCI DSS penetration testing
A customer contract or vendor questionnaire A current report, or a summary letter you can share without leaking findings Report or letter
Cyber insurance renewal Evidence of testing and of remediation, usually attested rather than inspected Which framework applies

Worth knowing

Only PCI DSS writes down what a penetration test must contain. SOC 2 and ISO 27001 do not name the word "pentest" as a hard requirement. They require that you identify technical vulnerabilities and act on them, and a penetration test is the evidence most auditors have settled on. The report matters less than the ticket trail showing you fixed the high findings.

Comparing firms for this? Tell us what you need and it goes to the ones in the directory that do this work. No charge, and no phone number required.

A scan is not a test

Most of what is sold as a penetration test under about $5,000 CAD is a vulnerability scan with a logo on it. That is arithmetic, not a moral failing on the vendor's part. A qualified tester in Canada costs between $1,500 and $2,800 CAD a day once you account for salary, tooling and overhead. If the whole engagement is priced at $3,000, there is not enough time in it for anyone to log in, map your authorization model, and try to read another tenant's data.

The findings tell you which one you bought. Scanner output is generic: missing headers, TLS configuration, outdated library versions, a CVE list with severity copied from the vendor advisory. A real test produces findings that could only exist in your application. An identifier in a URL that lets one customer fetch another customer's invoice. A password reset flow where the token does not expire. A role check that runs in the front end but not in the API. No scanner finds those. Finding them means knowing what your application is supposed to allow.

How to tell from a quote which of the two you are being offered is on vulnerability assessment versus penetration test. If you want continuous coverage rather than an annual snapshot, pentest as a service is the model that tries to bridge the two.

The counter-case. A scanner is the right purchase for a company that has not built anything: if you resell software, hold no customer data in a system of your own and nobody has asked you for a test, $200 CAD a month of scanning plus the discipline to fix what it reports beats a $12,000 CAD report nobody reads. The threshold that flips it is holding somebody else's data in something you wrote. When a scan is the right purchase sets out where the line sits.

Ask for a redacted sample report before you sign anything. Not a marketing brochure, a report from a real engagement with the client details removed. Any firm doing this work seriously has one ready.

The rest of the checks that separate a testing firm from a scan-and-reformat shop, and every city we cover, are on penetration testing companies in Canada. There is no honest ranked list of the best penetration testing companies in Canada, and that page gives you the method to rank your own shortlist.

What it costs

Every figure is Canadian dollars and every one is a range. Price tracks tester days, and tester days track scope. A web application with three user roles is a different engagement from a platform with twelve services and a public API.

Typical Canadian penetration test pricing, CAD
EngagementTypical range
External network, small footprint$6,000 to $15,000
Web application, authenticated, one product$10,000 to $30,000
Internal network, assumed breach$12,000 to $35,000
Mobile application, per platform$12,000 to $30,000
Cloud configuration review$8,000 to $20,000
Red team engagement$50,000 and up

What pushes a quote to the top of its range, and which line items are worth refusing, is on penetration testing cost in Canada. The short answer to how much a pentest costs is one paragraph. To price a scope of your own, the cost calculator shows the tester days and the day rate behind the number.

Who runs this site

TrazTech is a security and compliance practice in Toronto, and it sells penetration testing. Web applications, APIs, external and internal networks, and cloud configuration reviews. The practice has delivered more than 20 penetration tests. Its principal is credited with 5 CVEs, which is public work you can look up rather than a claim about quality.

It is one firm among the ones in the directory, and it appears first there because it owns the directory. Get quotes from at least two other firms on the same written scope. Go elsewhere outright for a red team engagement, for hardware or industrial control targets, or when procurement names an accreditation like CREST, because those are separate specializations and a generalist should say so when you ask. The questions to ask a vendor apply here without an exemption.

Tools on this site

Five things you can use without asking anyone. The test finder routes you to the right engagement in five questions. The cost calculator turns a scope into a CAD range with the arithmetic shown. The scoping questionnaire writes a scope document you can send to three firms so their quotes describe the same work. The retest planner works out the last day your fixes can ship and still be verified inside the free window. And the CVSS calculator scores a finding against the version 3.1 specification, with no email form on the page.

The Canadian part

Two things change the shape of a Canadian engagement. The first is privacy law. If your test touches production, the tester may see real personal information, which makes them a service provider handling that data on your behalf. Under PIPEDA, and under Law 25 in Quebec or PIPA in BC and Alberta, accountability follows the data to them. That belongs in the contract, not in an assumption. PIPEDA compliance covers the transfer rules.

The second is that many Canadian buyers sell into the United States, get asked for American frameworks by American procurement teams, and are regulated at home by a different statute. Scope one test that satisfies both rather than paying twice. Testing that supports a SOC 2 report generally supports an ISO 27001 certification too, provided the scope statement matches.

Not sure what to scope

Tell us what you have built and who is asking for the test, and we will tell you what the engagement should cover before you collect quotes.

Get matched

Common questions

How often do we need a penetration test?

Annually is the default expectation for SOC 2 and ISO 27001, and PCI DSS requires it annually and after any significant change to the environment. The more useful trigger is architectural: test after you ship a new authentication flow, a new tenant model, or a new public API, because those are the changes that create the findings worth paying to discover.

Should we test production or staging?

Staging, if it is a genuine mirror of production including the same authentication and the same authorization logic. Most staging environments are not, and testing a stripped-down copy produces a report about an application that nobody uses. If staging differs meaningfully, test production with rate limits agreed in writing and a rollback contact on call.

Is a retest included?

Sometimes, and you should ask explicitly rather than assume. A retest verifies that the fixes you made actually closed the findings, and it is the part an auditor most often wants to see. Firms that include one usually cap it at a window of thirty to ninety days after the report, so plan your remediation inside that window or you will pay for the retest separately.

Does the tester need to be certified?

No framework in Canada requires a specific certification for the person doing the work. Certifications such as OSCP, GPEN or CREST registration are reasonable signals that someone has done hands-on testing rather than tooling, and auditors do sometimes ask. They are evidence of capability, not a substitute for reading a sample report.

Can our developers just run the tools themselves?

They can and should run scanners continuously, in the build. That is good practice and it is cheaper than paying anyone to tell you about an outdated dependency. What it does not give you is independence, which is the property your auditor and your customer are actually buying. A test performed by the team that built the system is not evidence to a third party, however skilled that team is.