How much does a pentest cost in Canada?
The short answer, then the arithmetic that produces it, then the four things that move a quote inside its range.
A penetration test costs between $6,000 and $40,000 CAD in Canada. A small external network test sits at the bottom, around $6,000 to $14,000. An authenticated web application test, which is what most companies buying for SOC 2 or a customer contract actually need, runs $10,000 to $30,000. A red team exercise starts around $50,000 and is a different product bought for a different reason. Anything under about $5,000 is a vulnerability scan with a report template around it. The arithmetic below is why.
The arithmetic behind every quote
Every honest penetration testing price is one calculation: tester days multiplied by a day rate, plus reporting time. In Canada a qualified tester costs roughly $1,500 to $2,800 CAD a day once salary, tooling, insurance and overhead are accounted for. Reporting adds one to two days on top of the testing. Run that against any quote you receive.
| Test | Tester days | Typical price |
|---|---|---|
| External network, small footprint | 3 to 5 | $6,000 to $14,000 |
| Internal network, one site | 5 to 10 | $12,000 to $28,000 |
| Web application, authenticated | 5 to 10 | $10,000 to $30,000 |
| API, single product | 4 to 8 | $8,000 to $25,000 |
| Mobile app, one platform plus backend | 7 to 12 | $14,000 to $30,000 |
| Cloud configuration and identity review | 4 to 7 | $8,000 to $18,000 |
| PCI DSS segmentation testing | 2 to 4 | $5,000 to $12,000 |
| Red team engagement | 15 and up | $50,000 and up |
The pentest cost calculator runs the same day counts against a scope you describe and shows which choices moved the number.
Four things move a quote inside its range
Authentication. Testing while logged in, across several roles, is where the serious findings are, and it roughly doubles the work against testing the public surface. Every role added is another set of authorization comparisons.
Count. Applications, live hosts, endpoints, tenants, platforms. Firms quote on these. The better predictor is the number of distinct authorization decisions your product makes, roughly roles multiplied by object types.
Retest. Included or not, and within what window. This alone separates two otherwise identical quotes by $2,000 to $5,000 CAD, and it is the piece your auditor most wants to see.
Who is doing it. The same scope quoted by an independent, a mid-market consultancy and a national firm's security practice commonly varies by a factor of two, and much of that gap is overhead rather than tester capability.
Why three quotes for the same thing differ by five times
Because the three firms understood the scope differently, not because two of them are overcharging. One quoted an unauthenticated scan of your public surface. One quoted five days of authenticated testing across two roles. One quoted twelve days across every service and included a retest. All three answered the question you asked, and you asked it three slightly different ways.
Write the scope once and send the same document to every firm. The scoping questionnaire produces that document, and it converts three incomparable numbers into three comparable ones.
Where the price floor comes from
At $1,500 CAD a day at the low end of the Canadian range, a $3,000 engagement is two days, and reporting consumes at least one of them. That leaves a single day for a person to learn your product, obtain credentials, map your roles, and test authorization across them. It cannot be done, and the deliverable that arrives instead is scanner output. That is why the floor for a real test sits near $6,000.
Costs that are not on the quote
Your own engineering time to fix what is found, normally the largest number in the exercise and never on anyone's proposal. Remediation for a serious authorization finding can run weeks. Budget for it before the report arrives, and book the retest window with the fix work in mind.
Then the smaller ones: a second retest if remediation slips past the included window, a summary letter you can share with customers without leaking findings, travel for on-site wireless or physical work, and re-testing after a significant change if a framework requires it. The line items worth refusing are on penetration testing cost in Canada.
Spending less without buying less
Scope tightly to what holds customer data rather than testing everything you own. Hand over credentials, documentation and an API specification so the days go to testing rather than discovery. Combine surfaces into one engagement so reporting overhead is paid once. Fix the obvious things first, because a report full of missing patches is a report you paid senior day rates to generate. And ask for the retest to be included in writing rather than assuming it.
Do not shorten the engagement to fit a budget while keeping the scope. A ten-day scope tested in four days is an incomplete test with a full-looking report attached, and the gap shows up when your auditor asks what was covered.
If you already know the number and the problem is getting it approved, how to get a penetration test funded covers the argument that works and the objections you will get.
Get comparable quotes
Tell us the scope once and we will put it in front of Canadian firms that do this work, so the prices you get back describe the same engagement.
Get matchedCommon questions
How much does a penetration test cost for a small company?
For a company under fifty people with one SaaS product, expect $10,000 to $20,000 CAD for an authenticated web application and API test with a retest included. If the product is small and has two roles, the lower end is realistic. What pushes a small company higher is tenancy: a multi-tenant product with delegated access has far more authorization surface than its size suggests.
Is a $3,000 penetration test worth buying?
It is worth buying if you know you are buying a vulnerability scan and that is what you need. It is not worth buying if you expect it to satisfy an auditor or a customer's security team, because the report will contain only tool output and both audiences have learned to recognize that. Two days does not contain enough time for a person to test an authorization model.
Does the price include a retest?
Sometimes, and it is the first thing to check because it moves the price by $2,000 to $5,000 CAD. Firms that include one usually cap it at thirty to ninety days after the report, so plan remediation inside that window. Get the answer in writing, including whether the retest covers all findings or only the high-severity ones.
How much does an annual penetration test cost over time?
Budget the same range each year, with a reduction in year two only if nothing structural changed. The second test is usually a little cheaper in practice because the firm already understands your product, and that is a real argument for staying with one firm. The counter-argument is that a new tester finds different things, which is why some companies alternate.
Do we pay more for testing in Toronto or Vancouver?
No. Testing is remote work and the day rate does not change with the postal code, so a quote from a firm in another province for the same scope should be within the same range. The exception is work needing someone physically present, which is wireless testing, physical assessment and the physical component of a red team, where travel is billed.