GetPentest

Canadian penetration testing directory

What each listing means, how the tiers differ, and what to check before you sign with any of the firms below.

Last reviewed 2026-08-16Written by Jacob Masse, TrazTech Inc.

Filtering happens in your browser. Nothing is sent anywhere and the order never changes.

88 firms listed on GetPentest.

Our offerings

TrazTech Inc. VerifiedOperates this site

The security and compliance practice that operates this directory. SOC 2 and ISO 27001 readiness, penetration testing, and fractional security leadership for Canadian companies selling into the United States.

Toronto, Ontario · SOC 2 readiness, ISO 27001, ISO 42001, Penetration testing, vCISO, Compliance advisory, Canadian privacy, Trust center, Cloud compliance, AI-built app QA, AI security, Security questionnaires, Auditor management, Internal audit, Threat and risk assessment, Tabletop and continuity testing, Cyber insurance readiness, Technical due diligence, Outsourced privacy officer

Frameworks: SOC 2, ISO 27001, ISO 42001, NIST CSF, PIPEDA, PHIPA

Verified firms

Verified means the firm exists as a registered business, does the work its listing claims, and holds the credentials it states. It is normally a paid tier, though not every Verified listing was paid for. The order inside the tier is fixed either way and is not for sale. See how listings work.

DeepStrike Verified

An offensive security firm doing manual web, mobile, cloud and network penetration testing and red teaming, with reports written to satisfy SOC 2 and ISO 27001 evidence requirements.

Newark, Delaware, United States · Penetration testing

Frameworks: SOC 2, ISO 27001, HIPAA

Everyone else

Listed from public information and not yet claimed by the firm, so the details here are ours rather than theirs. If this is your firm, claim it and it becomes yours to edit.

3Tenets Consulting Unclaimed

Greater Toronto Area security and privacy consultancy offering governance and virtual CISO work, penetration testing and privacy assessments, aligning clients to frameworks including SOC 2. Not a CPA firm.

Ontario · SOC 2 readiness, Penetration testing, vCISO, Compliance advisory, AI security

Frameworks: SOC 2, NIST CSF, PHIPA

BALANCED+ Unclaimed

IT and security firm providing ISO 27001 gap assessments, policy development, control implementation and audit preparation for clients, and does not issue certificates.

Mississauga, Ontario · SOC 2 readiness, ISO 27001, Penetration testing, Compliance advisory, Canadian privacy, Cloud compliance

Frameworks: SOC 2, ISO 27001, PIPEDA, PHIPA

Bishop Fox Unclaimed

Offensive security firm offering application cloud and network penetration testing plus red teaming and attack surface testing.

Tempe, Arizona, United States · Penetration testing, Cloud compliance, AI security

BreachLock Unclaimed

Pentest as a service provider covering web mobile API network and cloud testing plus red team services with compliance ready reports.

New York, New York, United States · Penetration testing, Compliance advisory

Frameworks: SOC 2, ISO 27001, HIPAA, PCI DSS, NIST CSF

Bugcrowd Unclaimed

Crowdsourced security platform selling pen test as a service across web mobile network API IoT and cloud targets.

Penetration testing

Bulletproof Solutions Unclaimed

Canadian managed security provider whose security testing and audit practice includes penetration testing alongside managed detection and compliance services.

New Brunswick · Penetration testing, Compliance advisory

Frameworks: SOC 2

CAUSMX Unclaimed

Calgary security firm offering internal external web mobile wireless cloud and physical penetration testing plus social engineering assessments.

Calgary, Alberta · Penetration testing

Certi360 Unclaimed

Laval information security consultancy offering compliance and certification support for ISO 27001, SOC 2 and PCI DSS plus penetration testing. Not a CPA firm and does not sign SOC 2 opinions.

Laval, Quebec · SOC 2 readiness, ISO 27001, Penetration testing, Compliance advisory

Frameworks: SOC 2, ISO 27001, PCI DSS

Clavea Security Unclaimed

Montreal area cybersecurity firm serving small and mid-sized businesses with offensive security testing managed monitoring ISO 27001 work and Quebec Law 25 compliance.

Laval, Quebec · ISO 27001, Penetration testing, Compliance advisory

Frameworks: ISO 27001

Coalfire Unclaimed

Cybersecurity advisory and assessment firm combining offensive testing with audit services across a large number of compliance frameworks.

ISO 42001, Penetration testing, Compliance advisory

Frameworks: ISO 42001

Cobalt Unclaimed

Pentest as a service provider covering application network cloud and API testing plus red teaming and secure code review.

Penetration testing, Cloud compliance, AI security

Frameworks: HIPAA

Cognisys Unclaimed

UK consultancy offering SOC 2 consulting to get clients audit ready in about four weeks, plus ISO 27001, ISO 42001, vCISO and penetration testing; it prepares clients for an independent auditor rather than signing the opinion.

United Kingdom · SOC 2 readiness, ISO 27001, ISO 42001, Penetration testing, vCISO, Compliance advisory, Trust center, Security questionnaires

Frameworks: SOC 2, ISO 27001, ISO 42001, NIST CSF

Commissionnaires du Québec Unclaimed

Quebec security organisation whose cybersecurity unit performs penetration tests using OWASP NIST and PTES methods for provincial businesses and public bodies.

Montreal, Quebec · Penetration testing

Frameworks: ISO 27001, NIST CSF

Compass IT Compliance Unclaimed

Firm selling virtual CISO engagements staffed by veteran security professionals on a full or part-time basis, alongside compliance and testing services.

SOC 2 readiness, Penetration testing, vCISO, Compliance advisory, Cloud compliance

Frameworks: SOC 2, HIPAA, PCI DSS, NIST CSF

Cure53 Unclaimed

Testing firm running black box and white box penetration tests of web applications mobile applications and browser technology.

Berlin, Germany · Penetration testing

Cyber Security Pentesting Inc. Unclaimed

Toronto offensive security firm running red team operations Active Directory attacks cloud and web application testing with compliance aligned reporting.

Toronto, Ontario · Penetration testing, Compliance advisory, AI security

Frameworks: SOC 2, ISO 27001, HIPAA, PCI DSS, PIPEDA

CyberHunter Solutions Unclaimed

Ottawa firm offering web application external black box and post breach internal penetration testing plus gap analysis against NIST CSF and CIS Controls.

Ottawa, Ontario · Penetration testing

Frameworks: NIST CSF

CyberSpective Unclaimed

Montreal cybersecurity consultancy providing penetration testing and compliance advisory work for organisations in Ontario Quebec Alberta and British Columbia.

Montreal, Quebec · Penetration testing, Compliance advisory

Frameworks: SOC 2, HIPAA

DarkPoint Security Unclaimed

Toronto firm focused on penetration testing red teaming and security assessments delivered by consultants holding OSCP OSCE and OSWE certifications.

Toronto, Ontario · Penetration testing

Frameworks: SOC 2, ISO 27001, PCI DSS, PIPEDA

Digital Fort Unclaimed

Consultancy offering SOC 2, ISO 27001 and PCI DSS compliance readiness, fractional CISO services and penetration testing, and does not issue certificates.

Winnipeg, Manitoba · SOC 2 readiness, ISO 27001, Penetration testing, vCISO, Compliance advisory

Frameworks: SOC 2, ISO 27001, PCI DSS

Elastify Unclaimed

Advisory and consulting firm that runs SOC 2, ISO 27001 and HIPAA compliance programs for clients, and does not issue certificates.

Toronto, Ontario · SOC 2 readiness, ISO 27001, Penetration testing, Compliance advisory

Frameworks: SOC 2, ISO 27001, HIPAA, NIST CSF

Gennix Consulting Unclaimed

British Columbia consultancy running penetration tests for clinics law firms nonprofits manufacturers and professional services businesses in the Lower Mainland.

Langley, British Columbia · Penetration testing

getHacked.ca Unclaimed

Canadian penetration testing shop offering application network and mobile testing including a pay per vulnerability engagement model.

Mississauga, Ontario · Penetration testing

GlitchSecure Unclaimed

Winnipeg firm providing continuous manual application penetration testing with live status updates and ongoing retesting.

Winnipeg, Manitoba · Penetration testing

GuardsArm Unclaimed

Security firm offering compliance readiness consulting for ISO 27001, SOC 2, HIPAA and PCI DSS alongside vCISO and monitoring services, and does not issue certificates.

Edmonton, Alberta · SOC 2 readiness, ISO 27001, Penetration testing, vCISO, Compliance advisory, Cloud compliance

Frameworks: SOC 2, ISO 27001, HIPAA, PCI DSS

GuidePoint Security Unclaimed

Security consultancy offering penetration testing along with governance risk and compliance services for regulated organisations.

Reston, Virginia, United States · Penetration testing, Compliance advisory

Frameworks: HIPAA, PCI DSS

HackerOne Unclaimed

Security platform offering pentest engagements delivered by vetted researchers alongside vulnerability disclosure and bug bounty programs.

Penetration testing

Frameworks: NIST CSF

Include Security Unclaimed

Security assessment firm running application and infrastructure penetration tests for software companies.

Brooklyn, New York, United States · Penetration testing

IRM Consulting & Advisory Unclaimed

Consultancy offering ISO 27001 and ISO 42001 gap assessments and readiness work, fractional vCISO services and penetration testing, and does not issue certificates.

Toronto, Ontario · SOC 2 readiness, ISO 27001, ISO 42001, Penetration testing, vCISO, Compliance advisory, Cloud compliance, AI security

Frameworks: SOC 2, ISO 27001, ISO 42001, NIST CSF

IS Partners Unclaimed

Describes itself as a CPA firm specializing in IT compliance that performs SOC 1, SOC 2 and SOC 3 audits, with ISO 27001, ISO 42001, penetration testing and virtual CISO services. Now part of Axiom GRC.

Dresher, Pennsylvania, United States · SOC 2 audit, ISO 27001, ISO 42001, Penetration testing, vCISO, Compliance advisory

Frameworks: SOC 2, ISO 27001, ISO 42001, HIPAA, PCI DSS

ISA Cybersecurity Unclaimed

Long established Canadian cybersecurity services firm whose assessments and assurance practice includes penetration testing for organisations from small business to enterprise.

Toronto, Ontario · Penetration testing

KirkpatrickPrice Unclaimed

A licensed CPA firm that performs SOC 1 and SOC 2 audits and signs the opinion, and also delivers penetration testing plus ISO 27001, ISO 42001, HIPAA, PCI DSS and NIST assessments.

Nashville, Tennessee, United States · SOC 2 audit, ISO 27001, ISO 42001, Penetration testing, Compliance advisory

Frameworks: SOC 2, ISO 27001, ISO 42001, HIPAA, PCI DSS, NIST CSF

Kobalt.io Unclaimed

Vancouver security services firm combining penetration testing with SOC 2 and ISO 27001 readiness and virtual CISO support for growing technology companies.

Vancouver, British Columbia · SOC 2 readiness, ISO 27001, Penetration testing, vCISO, Compliance advisory

Frameworks: SOC 2, ISO 27001

LevelBlue Unclaimed

Managed security provider whose CREST certified testing practice covers network application operational technology physical and social engineering penetration testing.

Penetration testing, Compliance advisory

Frameworks: NIST CSF

Linford & Company Unclaimed

A Certified Public Accounting firm founded in 2008 that issues SOC 1 and SOC 2 reports, and also performs ISO 27001, ISO 42001, HIPAA, PCI DSS, HITRUST, FedRAMP and penetration testing engagements.

Denver, Colorado, United States · SOC 2 audit, ISO 27001, ISO 42001, Penetration testing, Compliance advisory

Frameworks: SOC 2, ISO 27001, ISO 42001, HIPAA, PCI DSS

LMG Security Unclaimed

Security consultancy offering network device and web application penetration testing alongside incident response and training.

Missoula, Montana, United States · Penetration testing

Malleum Unclaimed

Ottawa security consultancy offering enterprise penetration testing alongside compliance advisory work for regulated and government adjacent clients.

Ottawa, Ontario · Penetration testing, Compliance advisory

Frameworks: SOC 2, ISO 27001, HIPAA, NIST CSF

Mirai Security Unclaimed

Vancouver consultancy offering a SOC 2 gap assessment against the Trust Services Criteria plus a virtual security office and other GRC work. Not a CPA firm and does not sign SOC 2 opinions.

Vancouver, British Columbia · SOC 2 readiness, ISO 27001, Penetration testing, vCISO, Compliance advisory, Cloud compliance

Frameworks: SOC 2, ISO 27001

Mitnick Security Consulting Unclaimed

Penetration testing and security assessment firm working to OWASP NIST and PTES methodologies.

Las Vegas, Nevada, United States · Penetration testing

Frameworks: NIST CSF

MS Solutions Unclaimed

Quebec IT services firm whose security practice runs external internal cloud SaaS industrial web and Microsoft 365 penetration tests.

Quebec · over 75 people · Penetration testing

NCC Group Unclaimed

Technical assurance firm offering penetration testing and continuous penetration testing with CREST CBEST and STAR accreditations.

Manchester, United Kingdom · Penetration testing

Neotrust Unclaimed

French firm with a Montreal office listing CISO as a service within its security transformation practice, alongside testing and compliance work.

Puteaux, France · Penetration testing, vCISO, Compliance advisory

Frameworks: ISO 27001, NIST CSF

NetSPI Unclaimed

Offensive security company providing application network cloud mainframe hardware and AI penetration testing through a delivery platform.

Minneapolis, Minnesota, United States · Penetration testing, Cloud compliance, AI security

OKIOK Unclaimed

Quebec security consultancy offering penetration testing and vulnerability assessment along with identity management products and advisory services.

Laval, Quebec · Penetration testing

OmniCyber Security Unclaimed

Vancouver and Birmingham firm listing virtual CISO under its GRC practice, oriented to compliance program delivery alongside ISO 27001, ISO 42001 and testing work.

Vancouver, British Columbia · ISO 27001, ISO 42001, Penetration testing, vCISO, Compliance advisory

Frameworks: ISO 27001, ISO 42001, PCI DSS, PIPEDA

OnSite I.T. Unclaimed

Calgary IT services company that runs simulated attacks to identify and document vulnerabilities for small and mid-sized clients.

Calgary, Alberta · Penetration testing

Optiv Unclaimed

Large security solutions integrator whose threat management practice includes attack and penetration testing services.

Penetration testing

Oread Risk & Advisory Unclaimed

Attestation, information security and compliance consulting firm that conducts SOC reporting engagements and IT security reviews; the site names a CPA principal but does not state firm-level CPA licensure for signing SOC 2 opinions.

Kansas, United States · SOC 2 readiness, Penetration testing, Compliance advisory

Frameworks: SOC 2, ISO 27001, HIPAA, PCI DSS

Packetlabs Unclaimed

Canadian offensive security firm offering manual infrastructure application cloud and IoT penetration testing plus adversary simulation for mid-market and enterprise clients.

Toronto, Ontario · Penetration testing, Cloud compliance, AI security

Frameworks: SOC 2

Parabellyx Cybersecurity Unclaimed

Ontario firm delivering penetration testing as a service across applications infrastructure AI and operational technology plus compliance advisory work.

Richmond Hill, Ontario · Penetration testing, Compliance advisory, Cloud compliance, AI security

Frameworks: SOC 2, ISO 27001

PlutoSec Unclaimed

Canadian cybersecurity company selling manual penetration testing across web APIs networks cloud mobile and Active Directory plus red team and wireless testing.

Etobicoke, Ontario · Penetration testing, Compliance advisory, Cloud compliance

Frameworks: SOC 2, ISO 27001, HIPAA, PCI DSS, NIST CSF, PHIPA

Praetorian Unclaimed

Offensive security firm offering continuous penetration testing and attack simulation with reporting mapped to regulatory requirements.

Penetration testing

Frameworks: HIPAA, PCI DSS

Privilege Zero Unclaimed

Toronto offensive security firm founded by security researchers offering web application network cloud and red team assessments using OWASP and MITRE ATT&CK methods.

Toronto, Ontario · Penetration testing, AI security

Pure IT Unclaimed

Calgary managed IT provider selling external and internal network penetration tests with remediation roadmaps for local businesses.

Calgary, Alberta · Penetration testing

Rapid7 Unclaimed

Security company whose consulting arm performs network web application mobile IoT wireless and red team penetration testing.

Penetration testing

Raxis Unclaimed

Manual penetration testing firm covering web APIs cloud internal and external networks mobile IoT operational technology and physical security.

Atlanta, Georgia, United States · Penetration testing, Compliance advisory

Frameworks: SOC 2, ISO 27001, HIPAA, PCI DSS

Redfox Security Unclaimed

Penetration testing firm covering web applications APIs internal and external networks mobile applications and cloud configuration reviews.

Dover, Delaware, United States · Penetration testing

Rhino Security Labs Unclaimed

Boutique offensive security firm offering web application network mobile cloud and social engineering penetration testing.

Penetration testing, Cloud compliance

risk3sixty Unclaimed

GRC and security consulting firm offering SOC 1, SOC 2 and SOC 3 work alongside ISO 27001, ISO 42001, PCI DSS, HITRUST, FedRAMP and penetration testing; the site does not state firm-level CPA licensure for signing opinions.

Roswell, Georgia, United States · SOC 2 readiness, ISO 27001, ISO 42001, Penetration testing, Compliance advisory

Frameworks: SOC 2, ISO 27001, ISO 42001, PCI DSS, NIST CSF

RSM Canada Unclaimed

Canadian arm of the RSM network offering network software social engineering and adversarial penetration testing services to middle market clients.

Penetration testing

Frameworks: PCI DSS

SAV Associates Unclaimed

CPA and cybersecurity advisory firm that consults on ISO 27001 gap analysis, Statement of Applicability and ISMS buildout, and does not issue certificates.

Toronto, Ontario · SOC 2 readiness, ISO 27001, Penetration testing, Compliance advisory, Canadian privacy

Frameworks: SOC 2, ISO 27001, PIPEDA

Schellman Unclaimed

Assessment firm combining penetration testing and red teaming with SOC 2 ISO 27001 and ISO 42001 audit and certification services.

Tampa, Florida, United States · SOC 2 audit, ISO 27001, ISO 42001, Penetration testing, Compliance advisory

Frameworks: SOC 2, ISO 27001, ISO 42001

Secur-IT Data Solutions Unclaimed

Toronto IT security provider listing penetration testing among its services for healthcare finance and manufacturing clients.

Toronto, Ontario · Penetration testing

Secure Ideas Unclaimed

CREST member consultancy offering penetration testing and PCI qualified security assessor services plus security training.

Jacksonville, Florida, United States · Penetration testing, Compliance advisory

Frameworks: PCI DSS

Sedara Security Unclaimed

US provider offering a virtual CISO service for security leadership and program resilience planning, alongside penetration testing.

Buffalo, New York, United States · Penetration testing, vCISO

Frameworks: HIPAA, PCI DSS, NIST CSF

Sherlock Forensics Unclaimed

British Columbia boutique offering penetration testing adversary simulation and digital forensics for small businesses startups SaaS companies and law firms with published pricing.

Burnaby, British Columbia · Penetration testing, Compliance advisory, AI-built app QA, AI security

Frameworks: SOC 2, ISO 27001, PCI DSS, NIST CSF

Sikich Unclaimed

Sikich CPA LLC is a licensed CPA firm providing audit and attest services, and the cybersecurity practice performs service provider reviews covering SOC 1, SOC 2 and SOC 3 plus PCI DSS, HIPAA and penetration testing.

2500 · SOC 2 audit, Penetration testing, Compliance advisory

Frameworks: SOC 2, HIPAA, PCI DSS

Software Secured Unclaimed

Canadian penetration testing firm working mainly with SaaS companies on web API mobile infrastructure cloud and AI testing with compliance ready reporting.

Ottawa, Ontario · Penetration testing, Compliance advisory, Cloud compliance, AI security

Frameworks: SOC 2, ISO 27001, HIPAA, PCI DSS

Sprocket Security Unclaimed

Continuous penetration testing provider covering external internal web application and social engineering testing.

Madison, Wisconsin, United States · Penetration testing, Compliance advisory

Frameworks: SOC 2, ISO 27001, PCI DSS

Stingrai Unclaimed

Toronto penetration testing firm running web mobile network and cloud tests plus red teaming and physical assessments through a testing platform with human validation.

Toronto, Ontario · Penetration testing, Cloud compliance, AI security

Frameworks: SOC 2, ISO 27001, HIPAA, PCI DSS

StreamScan Unclaimed

Montreal cybersecurity company selling penetration testing and managed detection with compliance work aligned to NIST 800-171 and Canadian certification programs.

Montreal, Quebec · Penetration testing, Compliance advisory

Frameworks: NIST CSF

Synack Unclaimed

Crowdsourced penetration testing platform running web host cloud and API tests through a vetted researcher community.

Penetration testing

Systemes Securitech Systems inc. Unclaimed

Montreal firm naming vCISO in its consulting services, delivered alongside SOC monitoring, penetration testing and incident response.

Montreal, Quebec · ISO 27001, Penetration testing, vCISO, Compliance advisory

Frameworks: SOC 2, ISO 27001

TeckPath Unclaimed

Canadian managed IT and security provider offering penetration testing against networks servers firewalls and applications for clients in Alberta and Ontario.

Calgary, Alberta · Penetration testing

Frameworks: SOC 2

Tevora Unclaimed

Firm listing vCISO under resource augmentation, providing executive-level CISO assistance alongside compliance and testing work.

Penetration testing, vCISO, Compliance advisory

Frameworks: ISO 42001, HIPAA, PCI DSS

ThreeShield Information Security Unclaimed

Calgary firm providing penetration testing alongside compliance advisory work mapped to several security and privacy frameworks for Canadian organisations.

Calgary, Alberta · Penetration testing, Compliance advisory

Frameworks: SOC 2, ISO 27001, HIPAA, PCI DSS, NIST CSF, PIPEDA

Trail of Bits Unclaimed

Security research and assessment firm publishing public audit reports across software cryptography blockchain and AI systems.

Penetration testing, AI security

Triaxiom Security Unclaimed

Penetration testing firm offering external internal web application API mobile physical and wireless tests for compliance driven clients.

Penetration testing, Compliance advisory

Frameworks: PCI DSS, NIST CSF

TrustedSec Unclaimed

CREST certified consultancy offering penetration testing red teaming and security program work including CMMC readiness.

Fairlawn, Ohio, United States · Penetration testing, Compliance advisory

Frameworks: NIST CSF

Truvo Cyber Unclaimed

Security consulting firm that builds ISO 27001 and SOC 2 programs and performs internal audits for clients ahead of third party certification, and does not issue certificates.

Ottawa, Ontario · SOC 2 readiness, ISO 27001, ISO 42001, Penetration testing, vCISO, Compliance advisory, Trust center, Security questionnaires

Frameworks: SOC 2, ISO 27001, ISO 42001, HIPAA

Uzado Inc. Unclaimed

Ontario provider offering a fractional vCISO covering security strategy, board reporting and audit ownership, alongside compliance and testing work.

Richmond Hill, Ontario · Penetration testing, vCISO, Compliance advisory

Frameworks: SOC 2, ISO 27001, PCI DSS, NIST CSF

Victrix Unclaimed

Quebec IT and security services firm offering traditional penetration testing and pentest as a service with reporting for common compliance regimes.

Montreal, Quebec · Penetration testing

Frameworks: SOC 2, ISO 27001, HIPAA, PCI DSS

Vumetric Cybersecurity Unclaimed

Canadian penetration testing provider covering network application hardware and cloud testing with reporting aimed at PCI DSS SOC 2 and ISO 27001 requirements.

Toronto, Ontario · Penetration testing, Compliance advisory, Cloud compliance

Frameworks: SOC 2, ISO 27001, PCI DSS

White Tuque Unclaimed

Canadian security company offering penetration tests and offensive security assessments alongside managed security services.

Ontario · Penetration testing

Frameworks: ISO 27001

Workstreet Unclaimed

Security and compliance services firm that prepares clients for the SOC 2 audit through gap analysis, implementation planning and observation period support, and guides them through the external audit rather than signing the opinion.

100+ · SOC 2 readiness, Penetration testing, vCISO, Compliance advisory, Trust center, Cloud compliance, Security questionnaires

Frameworks: SOC 2, ISO 27001

Zero Day CPA Unclaimed

A CPA-led audit practice that performs SOC 1, SOC 2 Type I and Type II and SOC 3 examinations and signs the report, and also offers penetration testing and HIPAA work.

West Bloomfield, Michigan, United States · SOC 2 audit, Penetration testing, Compliance advisory

Frameworks: SOC 2, HIPAA

Browse a shorter list

The whole directory is above. These are the same firms cut down to one service or one province, which is usually the faster way in.

How do I know I can trust one of these firms?

Judge the website the way you would judge a report they wrote for you, because it is the only sample of their work you get free. Look for past work in specifics, an address in every country they claim, writing that could only be about them, and named people doing the work. None is proof alone; two together is a reason to ask direct questions. The four checks in full.

Is a listing here a recommendation?

No. Firms are listed from public information or added by the firm itself, and a Verified badge is a tier rather than an endorsement. Nothing on this page says a firm is the right one for you. Compare at least three.

Does it cost anything to get quotes?

No. Buyers are never charged. Firms can pay for a Verified listing, and higher-intent enquiries are offered to free listings for a fee, which is how the site is funded.

If you came here to find a tester today, the fastest route is the quote form, which puts one written scope in front of firms that do the work you described. If you run a testing firm, list your firm has the terms and the prices, the short version is at the foot of this page, and how to get penetration testing clients is the honest account of where a listing sits among the channels that actually build a practice. If you are trying to work out whether the firm already quoting you is any good, the middle of this page is the part worth reading.

What this directory lists

Firms that perform manual penetration testing for Canadian clients. That is the whole inclusion rule, and it is narrower than it sounds. Managed security providers who resell someone else's scanner, marketplaces that subcontract to whoever is free that week, and consultancies whose testing offer is a compliance gap analysis with a scanner attached are all out of scope, because a buyer who finds them here would be worse off than one who found nothing.

Each listing will carry the province and city the firm operates from, the engagement types it performs, the certifications its testers hold, whether it issues a shareable attestation letter, and whether a retest is included as standard. Those are the fields buyers actually compare, and several of them are awkward to find on a firm's own website, which is the point of collecting them.

How listings work

Listing tiers
TierWhat it isCost
Unclaimed An entry built from public information, with no input from the firm. Marked as unclaimed so a reader knows nobody has confirmed it. Free
Claimed Someone at the firm has confirmed the details, corrected what was wrong and filled in the fields we could not establish from outside. Free
Verified Claimed, plus we have seen evidence for the specific claims a buyer relies on: named tester certifications, a redacted sample report, and current professional liability insurance. $300 CAD/month or $3,000 CAD/year

Two of the three tiers are free and stay free. Verified is the paid tier, at $300 CAD a month or $3,000 CAD a year, and saying so on the page you are reading is better than making a firm write in and ask. What the money buys is the check and the badge, not a better position: Verified entries sit above free ones, and inside each tier the order is fixed and is not for sale. The moment position can be bought, the ordering stops carrying information for you, which is the only reason anyone would read a directory rather than a search result.

Verified is also not an endorsement and does not mean the work is good. It means the things a firm says about itself have been checked against documents rather than taken from a marketing page. The full terms, including what the badge does not buy, are on list your firm.

Narrowing the list

Whether a firm issues an attestation letter is on that list because it is the document you will actually send to a customer, and the choice between it and the report is on report versus attestation letter. Whether a retest is included is there because it is the second purchase almost everyone makes and the term firms leave vaguest.

What a listing shows

The two rows below are illustrations, not firms. The names are invented and no company by either name has been assessed.

Example Testing Co (sample entry, not a real firm)

Halifax, NSWeb, API, external networkOSCP, CREST

Illustration of a verified entry: certifications confirmed against named testers, a redacted sample report reviewed, retest included within 90 days, attestation letter issued.

Verified

Second Example Security (sample entry, not a real firm)

Calgary, ABInternal network, cloud review

Illustration of an unclaimed entry: assembled from public information only. Nobody at the firm has confirmed the details, and the blank fields are blank because we could not establish them from outside.

Unclaimed

How to tell a testing firm from a scan-and-reformat shop

This is the most useful thing this page can do for you, and it does not depend on the directory having anyone in it. A large share of what is sold in Canada as a penetration test is a commercial vulnerability scanner run by someone who exports the output into a branded template. It is a legitimate product at a legitimate price. It is not a penetration test, and telling an auditor or an enterprise customer that it was one is a claim that unravels under a follow-up question.

Six questions separate the two, and you can ask all of them before you sign anything.

Ask for a redacted sample report. Every serious firm has one. Read the findings. If each item maps to a CVE identifier, a missing HTTP security header, or a TLS configuration note, a tool wrote it. A human test produces findings a tool cannot express: a low-privilege user reaching another tenant's records, a password reset flow that can be replayed, an approval step that can be skipped by changing a value in a request. If there is no sample report, there is usually no report worth sampling.

Ask how many tester days are in the quote and how they split. Testing is priced in days. A firm that will not tell you the day count is hiding either a very small number or the fact that it does not think in days because the work is a scan. Divide the fee by a plausible Canadian day rate and see what you get. The arithmetic is set out on penetration testing cost in Canada.

Ask which methodology they follow, by name. The OWASP testing guide, the PTES stages, NIST SP 800-115. A named methodology means there is a checklist that has to be walked and coverage that has to be shown. An answer along the lines of "our own proven approach" means the coverage is whatever the tester felt like doing that week.

Ask who will actually do the work and what they hold. A name, not a team page. OSCP, OSWE, GXPN, CREST registered or certified tester, GPEN. Certifications are a floor rather than a ceiling, but the absence of any of them, combined with an inability to say who is assigned, is a reliable signal. Ask specifically whether the named person is an employee or a subcontractor you have not been told about.

Ask whether findings are manually verified before they appear in the report. Scanners produce false positives at a rate that makes raw output unusable. A firm that reruns and confirms each finding will say so immediately and will be able to describe what it does with the ones that do not reproduce. A firm that does not understand the question is passing tool output to you unfiltered, and you will spend engineering weeks chasing findings that were never real.

Ask what happens after the report. Whether a retest is included and inside what window, whether an attestation letter is issued, and whether someone will sit with your engineers to walk through the findings. The readout call is where the report gets sharper, because that is where your team argues with a finding and either it survives or it does not.

One more, if the price is very low

Ask what is excluded. A quote under about $5,000 CAD for an application test is buying three days at most, including writing the report. Three days can cover a small external perimeter properly. It cannot cover an authenticated multi-tenant product with several roles, and a firm that agrees it can is either going to skip most of the surface or has not understood what you are asking for.

What this directory does not carry

No star ratings, no review scores and no firm counts. Ratings on a directory with a handful of entries are noise dressed as data, and a review system worth having needs a volume of verified buyers that does not exist yet. When there is something real to publish, it will be specific: what a firm was engaged to do and what the buyer said about the report, attributed and dated.

Add your firm

If you perform penetration testing for Canadian clients, list your firm sets out both tiers, what verification checks, and what the paid tier does not buy. The short version: a claimed listing is free and stays free, Verified costs $300 CAD a month or $3,000 CAD a year, and no position in either tier is for sale.

To claim a free listing, send the firm name, the city and province you operate from, the engagement types you perform, the certifications your testers hold, and whether you issue an attestation letter and include a retest, to [email protected]. For Verified, add a redacted sample report and evidence of professional liability insurance.

Buyers looking for firms by city can start from penetration testing companies in Canada, which links to every city page on this site.

Until it fills up, the useful thing to read is how to evaluate a testing firm, which is the method a directory listing would let you shortcut.

Need a tester before the directory fills up

Describe the scope once and we will put it in front of Canadian firms that do that kind of testing, so the quotes you compare are quotes for the same work.

Get matched

Common questions

How did firms get into this directory?

Most were researched from public information: registration records, the firm's own site, and the credentials it publishes. Those listings are ours rather than the firm's until someone there claims it. A claimed listing is free and becomes the firm's to edit. Verified means we checked the firm is real and is what it says it is.

Does a listing cost anything?

A claimed listing is free and stays free. Verified is the paid tier, at $300 CAD a month or $3,000 CAD a year, and it buys the verification check and the badge. Position is not for sale in either tier, and there is no arrangement under which a firm can pay to appear higher or to have another firm excluded. The terms are on list your firm.

What does the Verified badge actually mean?

That the specific claims a buyer relies on have been checked against documents: named testers holding the certifications claimed, a redacted sample report that shows manual findings rather than scanner output, and current professional liability insurance. It is a check on the claims, not a judgement on the quality of the testing, and it does not transfer any responsibility for the engagement to us.

My firm was listed as unclaimed and the details are wrong. How do I fix it?

Email [email protected] from an address at the firm's domain and say what is wrong. Corrections are free and so is claiming the entry. If you would rather not be listed at all, say so in the same email and the entry will be removed.

Can you just tell me which firm to use?

Not honestly, because the right firm depends on what is being tested. An authenticated multi-tenant SaaS test, an Active Directory internal test and an industrial control system assessment call for different specialists. Send the scope through the quote form and the shortlist will be built from firms that do that specific work.