Canadian penetration testing directory
The directory is empty. It launched with no firms in it, and rather than pad it with scraped names we would rather explain what will go in it, how a firm gets listed, and what to check before you sign with anyone.
There are no firms listed here yet. This page will list Canadian penetration testing firms: the boutiques, the independents, the mid-market security consultancies and the testing practices inside the national accounting firms. Nothing has been added because nothing has been verified, and a directory that opens with a hundred scraped company names is a lead list wearing a directory's clothes.
If you came here to find a tester today, the fastest route is the quote form, which puts one written scope in front of firms that do the work you described. If you run a testing firm, the section on getting listed is at the foot of this page. If you are trying to work out whether the firm already quoting you is any good, the middle of this page is the part worth reading.
What this directory will list
Firms that perform manual penetration testing for Canadian clients. That is the whole inclusion rule, and it is narrower than it sounds. Managed security providers who resell someone else's scanner, marketplaces that subcontract to whoever is free that week, and consultancies whose testing offer is a compliance gap analysis with a scanner attached are all out of scope, because a buyer who finds them here would be worse off than one who found nothing.
Each listing will carry the province and city the firm operates from, the engagement types it performs, the certifications its testers hold, whether it issues a shareable attestation letter, and whether a retest is included as standard. Those are the fields buyers actually compare, and several of them are awkward to find on a firm's own website, which is the point of collecting them.
How listings work
| Tier | What it is | Cost |
|---|---|---|
| Unclaimed | An entry built from public information, with no input from the firm. Marked as unclaimed so a reader knows nobody has confirmed it. | Free |
| Claimed | Someone at the firm has confirmed the details, corrected what was wrong and filled in the fields we could not establish from outside. | Free |
| Verified | Claimed, plus we have seen evidence for the specific claims a buyer relies on: named tester certifications, a redacted sample report, and current professional liability insurance. | Free while the directory is being built |
Verified is not an endorsement and does not mean the work is good. It means the things a firm says about itself have been checked against documents rather than taken from a marketing page. No tier can be bought, and paying for placement is not a thing we offer, because the moment position is for sale the ordering stops carrying information.
What a listing will look like
The two rows below are illustrations, not firms. The names are invented and no company by either name has been assessed.
Example Testing Co (sample entry, not a real firm)
Illustration of a verified entry: certifications confirmed against named testers, a redacted sample report reviewed, retest included within 90 days, attestation letter issued.
Second Example Security (sample entry, not a real firm)
Illustration of an unclaimed entry: assembled from public information only. Nobody at the firm has confirmed the details, and the blank fields are blank because we could not establish them from outside.
How to tell a testing firm from a scan-and-reformat shop
This is the most useful thing this page can do for you, and it does not depend on the directory having anyone in it. A large share of what is sold in Canada as a penetration test is a commercial vulnerability scanner run by someone who exports the output into a branded template. It is a legitimate product at a legitimate price. It is not a penetration test, and telling an auditor or an enterprise customer that it was one is a claim that unravels under a follow-up question.
Six questions separate the two, and you can ask all of them before you sign anything.
Ask for a redacted sample report. Every serious firm has one. Read the findings. If each item maps to a CVE identifier, a missing HTTP security header, or a TLS configuration note, a tool wrote it. A human test produces findings a tool cannot express: a low-privilege user reaching another tenant's records, a password reset flow that can be replayed, an approval step that can be skipped by changing a value in a request. If there is no sample report, there is usually no report worth sampling.
Ask how many tester days are in the quote and how they split. Testing is priced in days. A firm that will not tell you the day count is hiding either a very small number or the fact that it does not think in days because the work is a scan. Divide the fee by a plausible Canadian day rate and see what you get. The arithmetic is set out on penetration testing cost in Canada.
Ask which methodology they follow, by name. The OWASP testing guide, the PTES stages, NIST SP 800-115. A named methodology means there is a checklist that has to be walked and coverage that has to be shown. An answer along the lines of "our own proven approach" means the coverage is whatever the tester felt like doing that week.
Ask who will actually do the work and what they hold. A name, not a team page. OSCP, OSWE, GXPN, CREST registered or certified tester, GPEN. Certifications are a floor rather than a ceiling, but the absence of any of them, combined with an inability to say who is assigned, is a reliable signal. Ask specifically whether the named person is an employee or a subcontractor you have not been told about.
Ask whether findings are manually verified before they appear in the report. Scanners produce false positives at a rate that makes raw output unusable. A firm that reruns and confirms each finding will say so immediately and will be able to describe what it does with the ones that do not reproduce. A firm that does not understand the question is passing tool output to you unfiltered, and you will spend engineering weeks chasing findings that were never real.
Ask what happens after the report. Whether a retest is included and inside what window, whether an attestation letter is issued, and whether someone will sit with your engineers to walk through the findings. The readout call is where the report gets sharper, because that is where your team argues with a finding and either it survives or it does not.
One more, if the price is very low
Ask what is excluded. A quote under about $5,000 CAD for an application test is buying three days at most, including writing the report. Three days can cover a small external perimeter properly. It cannot cover an authenticated multi-tenant product with several roles, and a firm that agrees it can is either going to skip most of the surface or has not understood what you are asking for.
What this directory will not carry
No star ratings, no review scores and no firm counts. Ratings on a directory with a handful of entries are noise dressed as data, and a review system worth having needs a volume of verified buyers that does not exist yet. When there is something real to publish, it will be specific: what a firm was engaged to do and what the buyer said about the report, attributed and dated.
Nor will there be a "top ten" ordering. The best firm for an authenticated SaaS test and the best firm for an industrial control system assessment are almost never the same firm, and any ranking that pretends otherwise is selling placement or guessing. The filters that will exist are the ones that narrow by engagement type, province and evidence, and that is deliberate.
Add your firm
If you perform penetration testing for Canadian clients and want to be listed, send the firm name, the city and province you operate from, the engagement types you perform, the certifications your testers hold, and whether you issue an attestation letter and include a retest. Send it to [email protected]. For a Verified entry, add a redacted sample report and evidence of professional liability insurance. Listing is free and there is no placement to buy.
Buyers looking for firms by city can start from penetration testing companies in Canada, which links to every city page on this site.
Need a tester before the directory fills up
Describe the scope once and we will put it in front of Canadian firms that do that kind of testing, so the quotes you compare are quotes for the same work.
Get matchedCommon questions
Why is the directory empty?
Because no firm has been listed or verified yet. The alternative was to scrape a few hundred company names and present them as a directory, which would give you a page of unchecked entries and give us something that looks busier than it is. The listing process is open now and entries will appear as they are confirmed.
Does a listing cost anything?
No. All three tiers are free, including Verified while the directory is being built. Position is not for sale, and there is no arrangement under which a firm can pay to appear higher or to have another firm excluded.
What does the Verified badge actually mean?
That the specific claims a buyer relies on have been checked against documents: named testers holding the certifications claimed, a redacted sample report that shows manual findings rather than scanner output, and current professional liability insurance. It is a check on the claims, not a judgement on the quality of the testing, and it does not transfer any responsibility for the engagement to us.
My firm was listed as unclaimed and the details are wrong. How do I fix it?
Email [email protected] from an address at the firm's domain and say what is wrong. Corrections are free and so is claiming the entry. If you would rather not be listed at all, say so in the same email and the entry will be removed.
Can you just tell me which firm to use?
Not honestly, because the right firm depends on what is being tested. An authenticated multi-tenant SaaS test, an Active Directory internal test and an industrial control system assessment call for different specialists. Send the scope through the quote form and the shortlist will be built from firms that do that specific work.