GetPentest

How to get penetration testing clients

Penetration testing has a demand problem most security services do not: almost nobody buys it because they want it. They buy it because an auditor, a customer or a contract made them. Find the people the requirement just landed on and you have found your pipeline.

Last reviewed 2026-09-01Written by Jacob Masse, TrazTech Inc.

The single highest-yield thing a small Canadian testing practice can do is partner with the people who create the requirement: SOC 2 and ISO 27001 readiness consultants, fractional CISOs, QSAs, and the compliance platforms whose customers hit a control that says annual penetration test. Those referrals arrive pre-qualified, pre-budgeted and with a deadline attached. Everything else on this page is worth doing and none of it competes with that.

We run this directory and sell listings on it. Read the section about directories with the scepticism that deserves.

Why selling testing is not like selling other security work

Three things shape every channel decision. Firms that ignore them spend money on marketing built for a different business.

Demand is triggered, not created
Nobody wakes up wanting a penetration test. A SOC 2 auditor, a customer security schedule, PCI DSS requirement 11.4 or an insurance renewal creates the need on a specific date. Content that argues testing is valuable persuades nobody. Content that helps somebody who has just been told to get one wins the work.
The buyer cannot evaluate you
They have three quotes from $3,500 to $28,000 CAD and no way to tell what differs. Whoever makes the comparison legible usually wins, even at the higher price. This is why a redacted sample report converts better than any case study.
It repeats, if you let it
Testing is annual by contract. A client acquired once is revenue for several years at near-zero acquisition cost, which changes what you can afford to pay for the first engagement.

What each channel costs a Canadian testing practice

Acquisition by channel for a boutique Canadian penetration testing firm, 2026
ChannelCost per signed client (CAD)Close rateScales
Referral from a compliance consultant or vCISORevenue share, 10 to 20 percentHighSomewhat
Referral from a past clientNear zeroHighNo
Subcontracting to a larger firmNear zero, paid in marginHighYes, with a ceiling
Your own technical content and searchHigh upfront, near zero laterMediumYes
Paid search on testing terms$4,000 to $18,000MediumYes
Cold outbound by a founder$2,000 to $7,000 in timeLowYes
Conference sponsorship$10,000 to $45,000LowNo
Directory listing$600 to $4,000MediumCapped
The number that mattersCost per signed client, then divided across the years they renew

Paid search needs a warning. Penetration testing terms carry some of the highest costs per click in Canadian B2B, and "penetration testing toronto" competes with firms that have a marketing budget you do not. If you buy search at all, buy the long tail: framework and asset phrasings that signal a real requirement rather than someone researching a category.

Comparing firms for this? Tell us what you need and it goes to the ones in the directory that do this work. No charge, and no phone number required.

The partnership motion, in detail

  1. List who creates your demand. Readiness consultancies, fractional CISO practices, QSAs, MSPs with compliance clients, and the Canadian resellers of compliance platforms. In most metros this is a list of twenty to fifty firms, not a market of thousands.
  2. Approach with the thing they lack. They are not short of vendors. They are short of a testing partner who will not embarrass them in front of their client, will hit a date, and will not try to sell their client advisory work. Say the last part explicitly. It is the fear that stops most referrals.
  3. Make it easy to refer. A one-page scope template, a fixed turnaround commitment, and a rate card they can quote from without calling you. A partner who has to schedule a call to get a number will refer to whoever answers faster.
  4. Agree the commercial terms in writing. A referral fee of 10 to 20 percent of first engagement value, or a wholesale rate they mark up. Both work. Ambiguity does not.
  5. Report back. Tell the referrer what happened. The biggest cause of a partnership producing one referral instead of ten is that nobody closed the loop on the first one.

Do not compete with your referrers

The fastest way to end a compliance partnership is to mention to their client that you also do readiness work, gap assessments or vCISO retainers. If you offer those, keep a clean line: partner-sourced clients get testing only, and you say so in the agreement. Firms that stay narrow get referred. Firms that look like a competitor with a testing team get referred once.

Content that actually converts in this market

The buyer arrives mid-problem, not mid-research. Write for the moment the requirement lands. Four formats do the work, and the ranking is not close.

Content by conversion, for a testing practice
FormatWhy it convertsEffort
A redacted sample reportIt is the only artifact that proves you test rather than scan. Buyers ask for it and most firms are slow to produce oneDays, once
Published pricing method, in CADDay rates times days. Buyers comparing three opaque quotes will call whoever showed the arithmeticHours
Framework mapping pagesSomeone searching PCI DSS 11.4 or ISO 27001 A.8.29 has a requirement and a dateDays per framework
Technical writing on your actual specialismWins the engineer who later writes the scope, and recruits testersOngoing
Generic "why security matters" postsNothing. The reader already knows and did not choose to be hereAvoid

The sample report is the most useful document a small firm can produce and it is routinely neglected. Buyers are told to ask for one, and the firms that answer within a day of the request win a disproportionate share. Build it from a real engagement with the client's permission and every identifier removed, or from a deliberately built vulnerable application if you have no client who will consent.

Pick a surface and be the obvious answer

A generalist boutique competes with every other generalist boutique on price, because the buyer has no other axis. A firm that is visibly the Canadian answer for a specific surface competes with two or three others and often on availability rather than rate.

Surfaces where Canadian supply is thin, and where the work is priced accordingly: embedded and connected products, industrial control and operational technology, thick client and desktop applications, Kubernetes and cloud-native platforms, and mobile with a real backend focus. Each of those has buyers who currently phone US or UK firms because they could not find a Canadian one. The buyer-side pages on this site exist for those searches.

Outbound, if you must

Untargeted outbound to security leaders performs badly, because the recipient gets forty of those a week and has no trigger. Trigger-based outbound works. The triggers visible from outside a company are a new SOC 2 or ISO 27001 badge on the trust page, a job posting for a compliance or security role, a funding round that implies enterprise sales, a new public API or developer portal, and an acquisition.

Write to the person who will have to solve it, which is usually a VP of Engineering or a head of platform rather than a CISO, and lead with the specific thing you noticed. Twenty of those a week from a founder beats two thousand generic sends, and it is roughly the same time.

Directories, including this one

A directory listing is a modest, capped channel. It will not replace partnerships or build a practice on its own. It puts you in front of buyers at the moment they are comparing, for less than the cost of a single conference badge.

Two limits. Volume is a function of the directory's traffic, so ask about that rather than assume it. And a listing converts on what it says. A description naming your surfaces, your accreditations, your typical tester-day counts and your turnaround out-performs one that says you deliver tailored security solutions. What buyers are told to look for is on how to choose a penetration testing firm in Canada and questions to ask a vendor. Write your listing against those pages.

Where to go next

Four pages cover the parts of the motion that cost firms money when they get them wrong: pricing a penetration test, white label and subcontracted testing, why penetration test proposals lose, and the scoping call.

List your firm

Free and Verified listings, both prices published, and a claim form. One channel among several. Read the page above first.

List your firm

Common questions

How do penetration testing firms find clients?

Mostly through the people who create the requirement: compliance consultants, fractional CISOs, QSAs and MSPs whose clients have just hit a control demanding an annual test. After that, past-client referrals, subcontracting to larger firms, and technical content that ranks for framework and asset queries. Cold outbound and conference sponsorship are the expensive ends of the list.

What is a reasonable referral fee for a penetration testing lead?

Ten to twenty percent of first engagement value is the common Canadian range, paid on collection rather than on signature. The alternative is a wholesale rate the partner marks up, which suits partners who want to own the client relationship. Both are fine. Agree which one in writing before the first referral, because renegotiating after a deal closes damages the relationship more than the money is worth.

Should a small testing firm buy paid search?

Only on long-tail terms, and only with a landing page that answers a specific requirement. Head terms in this vertical are among the most expensive in Canadian B2B and you will be outbid by firms with a marketing department. A framework-specific or surface-specific phrase attracts a buyer with a real trigger and costs a fraction as much.

Is a redacted sample report worth the effort to produce?

It returns more than anything else a small firm can make. Buyers are routinely advised to ask for one, and the firm that sends a good one within a day of the request converts far above its share. Build it from a real engagement with permission and all identifiers removed, or against a deliberately vulnerable application if no client will consent.

How long does it take to build a pipeline from nothing?

Partnerships produce work in one to two quarters if you approach the right twenty firms and make referring easy. Content takes two to four quarters to produce anything and then compounds. Plan for subcontracted work to carry utilisation in the first year while the other two build, which is what white label and subcontracted testing covers.