GetPentest

The best penetration testing companies in Canada, and why we will not rank them

Every list of the best Canadian penetration testing companies that ranks somebody first was written by the company sitting at the top of it. This page gives you the method instead, so you can rank the shortlist you already have.

Last reviewed 2026-08-27Written by Jacob Masse, TrazTech Inc.

There is no honest ranking of Canadian penetration testing firms, and this site is not going to invent one. Search the phrase and you get a handful of articles, each published by a testing company, each placing that company first and filling the remaining places with firms it does not compete with. None of the authors bought the engagements they are grading. The ranking is marketing in the shape of research. The criterion that decided it was who owns the website.

The method can be published. Below is what separates a firm that will test your product from one that will scan it and reformat the output, in the order the checks are worth running. Every one can be answered before you sign, most from documents, and the whole exercise takes about a week across three firms.

What the directory does and does not tell you

The directory on this site lists firms researched from public records rather than bought as a list. Each carries the checkable facts below and nothing else: no stars, no scores, no ordering that implies a judgement nobody made. TrazTech operates this site and is listed first, labelled.

Start with the sample report, before the price

Ask every firm on the shortlist for a redacted report from a similar engagement. Not a template, not a sample chapter, a report with the client details removed. Firms doing this work seriously have one ready and send it the same day under a mutual non-disclosure agreement.

Then read the findings, not the executive summary. You are looking for one thing: at least one finding that could not exist anywhere but in that client's system, described using that client's own vocabulary. Their roles, their objects, their workflow. If every finding cites a CVE identifier, a library version, a missing HTTP header or a TLS setting, you are reading scanner output that somebody formatted. That single check eliminates more candidates than everything else on this page combined.

Reading a sample report
What you seeWhat it tells you
Findings named in the client's own domain termsA person understood the product
Reproduction steps a developer could followThe finding was demonstrated, not inferred
Severity reasoned in context, not copied from a vendor advisorySomeone judged impact rather than repeating a score
A statement of what was tested and what was not reachedCoverage you can hand an auditor
Every finding at critical or high severitySeverity inflation, usually to justify the fee
Pages of scanner appendix with no narrativeThe appendix is the deliverable

Ask how many tester days, and who

Every honest quote is a day count multiplied by a rate. Ask for both. In Canada a qualified tester costs roughly $1,500 to $2,800 CAD a day once salary, tooling and overhead are counted, and that arithmetic is on penetration testing cost in Canada. If the price divided by the rate gives you two days for an authenticated multi-role application test, the scope and the price disagree and one of them is wrong.

Then ask who. A named person, their background, and whether that person is the one who will do the work rather than the one on the sales call. Firms that rotate work to whoever is free will say so, and that is a legitimate model at scale. What is not legitimate is a senior name on the proposal and a junior on the engagement.

Comparing firms for this? Tell us what you need and it goes to the ones in the directory that do this work. No charge, and no phone number required.

Certifications, and what each one actually evidences

No Canadian framework requires a specific certification for the person testing. They are signals of hands-on capability, and they vary.

Certifications you will see on a proposal
CertificationWhat holding it demonstrates
OSCP and the offensive security seriesA practical exam requiring exploitation under time pressure. Widely recognized as a floor for hands-on work
CREST registrationAssessment of both the individual and the firm's process. Common in the United Kingdom, growing in Canada, and it evidences methodology as well as skill
GPEN and the GIAC seriesStructured knowledge, with a practical component in some tracks
eCPPT, eWPT and similar practical examsHands-on exploitation and reporting, assessed on a submitted report
PenTest+ and CySA+Foundational knowledge. Reasonable early-career evidence, not evidence of senior capability
CISSPSecurity management breadth. It says nothing about whether the holder can test anything
Published CVEs or original researchThe strongest single signal available, because it is verifiable by a third party and cannot be bought

A certification says someone passed an exam. A published vulnerability with an assigned identifier says someone found something real in software other people use, and it is verifiable in a public database. The operator of this site holds eCPPT, PenTest+, eWPT, CySA+ and Security+, and has five published CVEs.

A methodology they can name

Ask which published methodology the engagement follows. Acceptable answers name a document: the OWASP Web Security Testing Guide, the OWASP Application Security Verification Standard, the Mobile Application Security Verification Standard for apps, the Penetration Testing Execution Standard, or NIST Special Publication 800-115. Any of those is fine. The answer has to be a document rather than an adjective. A named methodology makes coverage checkable after the fact, and coverage is what your auditor is buying.

Retest terms, where quotes stop being comparable

A retest verifies that your fixes closed the findings, and it is the piece auditors most often ask to see. Three quotes can differ by thousands of dollars purely on this, so normalize it before you compare.

Retest questions with the answer you want
QuestionGood answer
Is a retest includedYes, in the quoted price
Within what window60 to 90 days from report delivery
Does it cover all findings or only high severityAll findings you claim to have fixed
Does the retest produce its own documentYes, a dated letter or updated report stating what was verified
What happens if a fix introduced a new issueIt is reported, and the terms for testing it are stated in advance

Insurance, independence and the contract

Ask for a certificate of insurance covering professional liability and cyber liability, and read the limit rather than the fact of it. Ask whether testing is subcontracted, and to whom. The firm you signed with may not be the firm on your systems. If your environment holds personal information about people in Canada, the agreement has to cover what the tester may access, where that data is stored, how long it is kept and how it is destroyed, because accountability under PIPEDA and under Quebec's Law 25 stays with you when someone else is handling it on your behalf.

One independence check nobody runs: if the firm also sells you managed security services or remediation work, they are grading their own homework at the next annual test. Not disqualifying, but it should be a deliberate decision rather than something you notice in year two.

Building the shortlist in the first place

Three sources, in order of usefulness. Ask peers in your own industry who they used and whether they would use them again, which is the only signal with no marketing behind it. Ask your auditor or your readiness consultant, who sees the reports and can tell you whose documents survive review. Search for firms publishing original research, conference talks or advisories. A firm that finds and publishes vulnerabilities is demonstrating the skill you are buying.

What not to use: any ranked list, including this one had it been ranked, and any award or badge that does not name its criteria. Once you have three or four names, run the checks above and the ordering produces itself. To send one scope to several firms and compare the answers, the scoping questionnaire writes that document, and choosing a Canadian testing firm covers the same ground from the buying side.

Compare firms on one scope

Tell us what needs testing and who asked for it, and we will put the same scope in front of Canadian firms that do the work.

Get matched

Common questions

Who are the best penetration testing companies in Canada?

Nobody can answer that honestly at a national level, because the answer depends on what you are having tested and no publisher has bought engagements from enough firms to compare them. Every ranked list currently published on this topic was written by a testing company that placed itself first. Use the method on this page against three or four firms you have shortlisted, starting with the sample report, and the ordering will be based on evidence you checked yourself.

Is a bigger firm safer than a boutique?

Not inherently, and the trade is predictable. A national firm brings process, insurance depth and a name your board recognizes, and it charges for all of it while often assigning less experienced testers to mid-size work. A boutique gives you the senior person directly and less process around them. What decides it is who does your testing, so ask for the name and the background either way.

Does the firm need to be Canadian?

No framework requires it. What can require it is your own contracts: some public sector and hospital agreements impose data residency terms that reach the testing firm, and those arrive through the contract rather than through statute. Read yours before you shortlist. Otherwise a Canadian firm mainly buys you a shared time zone and easier contracting, which is worth something and is not a security property.

How many firms should we ask?

Three is the useful number. One gives you no reference point, two makes the cheaper one look correct, and beyond four the marginal quote costs more of your time than it saves. Send all three the same written scope, because quotes against differently understood scopes cannot be compared at all and that is the most common reason buyers say prices vary by a factor of five.

What is a fair price so we know when to walk away?

For an authenticated web application test with a retest, $10,000 to $30,000 CAD covers most Canadian engagements, and the number tracks tester days rather than firm size. Below about $6,000 there is not enough time in the engagement for a person to map your authorization model, whatever the proposal says. The breakdown by test type is on how much a pentest costs.