Penetration testing firms in Canada
Firms in the GetPentest directory that do penetration testing work, ordered by tier and then alphabetically.
88 firms.
Penetration testing firms in Canada
TrazTech Inc. VerifiedOperates this site
The security and compliance practice that operates this directory. SOC 2 and ISO 27001 readiness, penetration testing, and fractional security leadership for Canadian companies selling into the United States.
DeepStrike Verified
An offensive security firm doing manual web, mobile, cloud and network penetration testing and red teaming, with reports written to satisfy SOC 2 and ISO 27001 evidence requirements.
3Tenets Consulting Unclaimed
Greater Toronto Area security and privacy consultancy offering governance and virtual CISO work, penetration testing and privacy assessments, aligning clients to frameworks including SOC 2. Not a CPA firm.
BALANCED+ Unclaimed
IT and security firm providing ISO 27001 gap assessments, policy development, control implementation and audit preparation for clients, and does not issue certificates.
Bishop Fox Unclaimed
Offensive security firm offering application cloud and network penetration testing plus red teaming and attack surface testing.
BreachLock Unclaimed
Pentest as a service provider covering web mobile API network and cloud testing plus red team services with compliance ready reports.
Bugcrowd Unclaimed
Crowdsourced security platform selling pen test as a service across web mobile network API IoT and cloud targets.
Bulletproof Solutions Unclaimed
Canadian managed security provider whose security testing and audit practice includes penetration testing alongside managed detection and compliance services.
CAUSMX Unclaimed
Calgary security firm offering internal external web mobile wireless cloud and physical penetration testing plus social engineering assessments.
Certi360 Unclaimed
Laval information security consultancy offering compliance and certification support for ISO 27001, SOC 2 and PCI DSS plus penetration testing. Not a CPA firm and does not sign SOC 2 opinions.
Clavea Security Unclaimed
Montreal area cybersecurity firm serving small and mid-sized businesses with offensive security testing managed monitoring ISO 27001 work and Quebec Law 25 compliance.
Coalfire Unclaimed
Cybersecurity advisory and assessment firm combining offensive testing with audit services across a large number of compliance frameworks.
Cobalt Unclaimed
Pentest as a service provider covering application network cloud and API testing plus red teaming and secure code review.
Cognisys Unclaimed
UK consultancy offering SOC 2 consulting to get clients audit ready in about four weeks, plus ISO 27001, ISO 42001, vCISO and penetration testing; it prepares clients for an independent auditor rather than signing the opinion.
Commissionnaires du Québec Unclaimed
Quebec security organisation whose cybersecurity unit performs penetration tests using OWASP NIST and PTES methods for provincial businesses and public bodies.
Compass IT Compliance Unclaimed
Firm selling virtual CISO engagements staffed by veteran security professionals on a full or part-time basis, alongside compliance and testing services.
Cure53 Unclaimed
Testing firm running black box and white box penetration tests of web applications mobile applications and browser technology.
Cyber Security Pentesting Inc. Unclaimed
Toronto offensive security firm running red team operations Active Directory attacks cloud and web application testing with compliance aligned reporting.
CyberHunter Solutions Unclaimed
Ottawa firm offering web application external black box and post breach internal penetration testing plus gap analysis against NIST CSF and CIS Controls.
CyberSpective Unclaimed
Montreal cybersecurity consultancy providing penetration testing and compliance advisory work for organisations in Ontario Quebec Alberta and British Columbia.
DarkPoint Security Unclaimed
Toronto firm focused on penetration testing red teaming and security assessments delivered by consultants holding OSCP OSCE and OSWE certifications.
Digital Fort Unclaimed
Consultancy offering SOC 2, ISO 27001 and PCI DSS compliance readiness, fractional CISO services and penetration testing, and does not issue certificates.
Elastify Unclaimed
Advisory and consulting firm that runs SOC 2, ISO 27001 and HIPAA compliance programs for clients, and does not issue certificates.
Gennix Consulting Unclaimed
British Columbia consultancy running penetration tests for clinics law firms nonprofits manufacturers and professional services businesses in the Lower Mainland.
getHacked.ca Unclaimed
Canadian penetration testing shop offering application network and mobile testing including a pay per vulnerability engagement model.
GlitchSecure Unclaimed
Winnipeg firm providing continuous manual application penetration testing with live status updates and ongoing retesting.
GuardsArm Unclaimed
Security firm offering compliance readiness consulting for ISO 27001, SOC 2, HIPAA and PCI DSS alongside vCISO and monitoring services, and does not issue certificates.
GuidePoint Security Unclaimed
Security consultancy offering penetration testing along with governance risk and compliance services for regulated organisations.
HackerOne Unclaimed
Security platform offering pentest engagements delivered by vetted researchers alongside vulnerability disclosure and bug bounty programs.
Include Security Unclaimed
Security assessment firm running application and infrastructure penetration tests for software companies.
IRM Consulting & Advisory Unclaimed
Consultancy offering ISO 27001 and ISO 42001 gap assessments and readiness work, fractional vCISO services and penetration testing, and does not issue certificates.
IS Partners Unclaimed
Describes itself as a CPA firm specializing in IT compliance that performs SOC 1, SOC 2 and SOC 3 audits, with ISO 27001, ISO 42001, penetration testing and virtual CISO services. Now part of Axiom GRC.
ISA Cybersecurity Unclaimed
Long established Canadian cybersecurity services firm whose assessments and assurance practice includes penetration testing for organisations from small business to enterprise.
KirkpatrickPrice Unclaimed
A licensed CPA firm that performs SOC 1 and SOC 2 audits and signs the opinion, and also delivers penetration testing plus ISO 27001, ISO 42001, HIPAA, PCI DSS and NIST assessments.
Kobalt.io Unclaimed
Vancouver security services firm combining penetration testing with SOC 2 and ISO 27001 readiness and virtual CISO support for growing technology companies.
LevelBlue Unclaimed
Managed security provider whose CREST certified testing practice covers network application operational technology physical and social engineering penetration testing.
Linford & Company Unclaimed
A Certified Public Accounting firm founded in 2008 that issues SOC 1 and SOC 2 reports, and also performs ISO 27001, ISO 42001, HIPAA, PCI DSS, HITRUST, FedRAMP and penetration testing engagements.
LMG Security Unclaimed
Security consultancy offering network device and web application penetration testing alongside incident response and training.
Malleum Unclaimed
Ottawa security consultancy offering enterprise penetration testing alongside compliance advisory work for regulated and government adjacent clients.
Mirai Security Unclaimed
Vancouver consultancy offering a SOC 2 gap assessment against the Trust Services Criteria plus a virtual security office and other GRC work. Not a CPA firm and does not sign SOC 2 opinions.
Mitnick Security Consulting Unclaimed
Penetration testing and security assessment firm working to OWASP NIST and PTES methodologies.
MS Solutions Unclaimed
Quebec IT services firm whose security practice runs external internal cloud SaaS industrial web and Microsoft 365 penetration tests.
NCC Group Unclaimed
Technical assurance firm offering penetration testing and continuous penetration testing with CREST CBEST and STAR accreditations.
Neotrust Unclaimed
French firm with a Montreal office listing CISO as a service within its security transformation practice, alongside testing and compliance work.
NetSPI Unclaimed
Offensive security company providing application network cloud mainframe hardware and AI penetration testing through a delivery platform.
OKIOK Unclaimed
Quebec security consultancy offering penetration testing and vulnerability assessment along with identity management products and advisory services.
OmniCyber Security Unclaimed
Vancouver and Birmingham firm listing virtual CISO under its GRC practice, oriented to compliance program delivery alongside ISO 27001, ISO 42001 and testing work.
OnSite I.T. Unclaimed
Calgary IT services company that runs simulated attacks to identify and document vulnerabilities for small and mid-sized clients.
Optiv Unclaimed
Large security solutions integrator whose threat management practice includes attack and penetration testing services.
Oread Risk & Advisory Unclaimed
Attestation, information security and compliance consulting firm that conducts SOC reporting engagements and IT security reviews; the site names a CPA principal but does not state firm-level CPA licensure for signing SOC 2 opinions.
Packetlabs Unclaimed
Canadian offensive security firm offering manual infrastructure application cloud and IoT penetration testing plus adversary simulation for mid-market and enterprise clients.
Parabellyx Cybersecurity Unclaimed
Ontario firm delivering penetration testing as a service across applications infrastructure AI and operational technology plus compliance advisory work.
PlutoSec Unclaimed
Canadian cybersecurity company selling manual penetration testing across web APIs networks cloud mobile and Active Directory plus red team and wireless testing.
Praetorian Unclaimed
Offensive security firm offering continuous penetration testing and attack simulation with reporting mapped to regulatory requirements.
Privilege Zero Unclaimed
Toronto offensive security firm founded by security researchers offering web application network cloud and red team assessments using OWASP and MITRE ATT&CK methods.
Pure IT Unclaimed
Calgary managed IT provider selling external and internal network penetration tests with remediation roadmaps for local businesses.
Rapid7 Unclaimed
Security company whose consulting arm performs network web application mobile IoT wireless and red team penetration testing.
Raxis Unclaimed
Manual penetration testing firm covering web APIs cloud internal and external networks mobile IoT operational technology and physical security.
Redfox Security Unclaimed
Penetration testing firm covering web applications APIs internal and external networks mobile applications and cloud configuration reviews.
Rhino Security Labs Unclaimed
Boutique offensive security firm offering web application network mobile cloud and social engineering penetration testing.
risk3sixty Unclaimed
GRC and security consulting firm offering SOC 1, SOC 2 and SOC 3 work alongside ISO 27001, ISO 42001, PCI DSS, HITRUST, FedRAMP and penetration testing; the site does not state firm-level CPA licensure for signing opinions.
RSM Canada Unclaimed
Canadian arm of the RSM network offering network software social engineering and adversarial penetration testing services to middle market clients.
SAV Associates Unclaimed
CPA and cybersecurity advisory firm that consults on ISO 27001 gap analysis, Statement of Applicability and ISMS buildout, and does not issue certificates.
Schellman Unclaimed
Assessment firm combining penetration testing and red teaming with SOC 2 ISO 27001 and ISO 42001 audit and certification services.
Secur-IT Data Solutions Unclaimed
Toronto IT security provider listing penetration testing among its services for healthcare finance and manufacturing clients.
Secure Ideas Unclaimed
CREST member consultancy offering penetration testing and PCI qualified security assessor services plus security training.
Sedara Security Unclaimed
US provider offering a virtual CISO service for security leadership and program resilience planning, alongside penetration testing.
Sherlock Forensics Unclaimed
British Columbia boutique offering penetration testing adversary simulation and digital forensics for small businesses startups SaaS companies and law firms with published pricing.
Sikich Unclaimed
Sikich CPA LLC is a licensed CPA firm providing audit and attest services, and the cybersecurity practice performs service provider reviews covering SOC 1, SOC 2 and SOC 3 plus PCI DSS, HIPAA and penetration testing.
Software Secured Unclaimed
Canadian penetration testing firm working mainly with SaaS companies on web API mobile infrastructure cloud and AI testing with compliance ready reporting.
Sprocket Security Unclaimed
Continuous penetration testing provider covering external internal web application and social engineering testing.
Stingrai Unclaimed
Toronto penetration testing firm running web mobile network and cloud tests plus red teaming and physical assessments through a testing platform with human validation.
StreamScan Unclaimed
Montreal cybersecurity company selling penetration testing and managed detection with compliance work aligned to NIST 800-171 and Canadian certification programs.
Synack Unclaimed
Crowdsourced penetration testing platform running web host cloud and API tests through a vetted researcher community.
Systemes Securitech Systems inc. Unclaimed
Montreal firm naming vCISO in its consulting services, delivered alongside SOC monitoring, penetration testing and incident response.
TeckPath Unclaimed
Canadian managed IT and security provider offering penetration testing against networks servers firewalls and applications for clients in Alberta and Ontario.
Tevora Unclaimed
Firm listing vCISO under resource augmentation, providing executive-level CISO assistance alongside compliance and testing work.
ThreeShield Information Security Unclaimed
Calgary firm providing penetration testing alongside compliance advisory work mapped to several security and privacy frameworks for Canadian organisations.
Trail of Bits Unclaimed
Security research and assessment firm publishing public audit reports across software cryptography blockchain and AI systems.
Triaxiom Security Unclaimed
Penetration testing firm offering external internal web application API mobile physical and wireless tests for compliance driven clients.
TrustedSec Unclaimed
CREST certified consultancy offering penetration testing red teaming and security program work including CMMC readiness.
Truvo Cyber Unclaimed
Security consulting firm that builds ISO 27001 and SOC 2 programs and performs internal audits for clients ahead of third party certification, and does not issue certificates.
Uzado Inc. Unclaimed
Ontario provider offering a fractional vCISO covering security strategy, board reporting and audit ownership, alongside compliance and testing work.
Victrix Unclaimed
Quebec IT and security services firm offering traditional penetration testing and pentest as a service with reporting for common compliance regimes.
Vumetric Cybersecurity Unclaimed
Canadian penetration testing provider covering network application hardware and cloud testing with reporting aimed at PCI DSS SOC 2 and ISO 27001 requirements.
White Tuque Unclaimed
Canadian security company offering penetration tests and offensive security assessments alongside managed security services.
Workstreet Unclaimed
Security and compliance services firm that prepares clients for the SOC 2 audit through gap analysis, implementation planning and observation period support, and guides them through the external audit rather than signing the opinion.
Zero Day CPA Unclaimed
A CPA-led audit practice that performs SOC 1, SOC 2 Type I and Type II and SOC 3 examinations and signs the report, and also offers penetration testing and HIPAA work.
Get quotes instead of browsing
Describe what you need once and it reaches the firms on this page that match it.
Get quotesOther ways to narrow the list
Same directory, cut a different way.
- AI security firms in Canada, 14 firms
- Cloud compliance firms in Canada, 17 firms
- Compliance advisory firms in Canada, 49 firms
- ISO 27001 firms in Canada, 20 firms
- ISO 42001 firms in Canada, 11 firms
- Security questionnaires firms in Canada, 4 firms
- SOC 2 audit firms in Canada, 6 firms
- SOC 2 readiness firms in Canada, 17 firms
- Trust center firms in Canada, 4 firms
- vCISO firms in Canada, 18 firms
- Penetration testing firms in Alberta, 6 firms
- Penetration testing firms in British Columbia, 5 firms
- Penetration testing firms in Ontario, 23 firms
- Penetration testing firms in Quebec, 9 firms
How do I know I can trust one of these firms?
Judge the website the way you would judge a report they wrote for you, because it is the only sample of their work you get free. Look for past work in specifics, an address in every country they claim, writing that could only be about them, and named people doing the work. None is proof alone; two together is a reason to ask direct questions. The four checks in full.
How were these firms chosen?
They were listed from public information or added by the firm itself. Being listed is not a recommendation, and GetPentest does not rank firms by quality. Verified listings sit above free ones and the order inside each band is fixed.
Does it cost anything to get quotes?
No. Buyers are never charged. Firms can pay for a Verified listing, and higher-intent enquiries are offered to free listings for a fee, which is how the site is funded.
How many firms should I approach?
Three is the number that makes a quote comparable. One quote tells you a price, and two tell you which is cheaper. Three tells you what the work actually costs and which firm understood your scope.