GetPentest

Penetration testing companies in Canada

Choosing a testing firm is mostly a document exercise. Five things decide whether you are buying a test or a scan, and all five can be checked before you sign.

Last reviewed 2026-08-16Written by Jacob Masse, TrazTech Inc.

Plenty of firms in Canada will sell you something called a penetration test, and they are not all selling the same product. The useful way to choose between them is not reputation or office location. It is five documents: the certifications held by the people who will be assigned, the methodology they name, a redacted sample report, the retest terms in the statement of work, and a certificate of insurance. A firm that produces all five quickly is a different kind of business from one that produces none of them, and you can establish which you are dealing with in one email.

Pricing barely varies by city, because testing is remote work and the day rate does not care where the tester sits. What varies is who is asking you for the report, which is a local question, and that is what the city pages below cover.

Certifications that mean something

Certifications are a floor, not a ranking. A strong tester without one is common, and a weak tester with three is possible. What the list tells you is whether the firm invests in demonstrable practical skill or in credentials that can be passed by reading.

Testing certifications and what each actually demonstrates
CertificationWhat it demonstrates
OSCP A hands-on exam requiring real compromise of live machines under time pressure. The common baseline for a network or infrastructure tester.
OSWE Source-code-led web application exploitation. Relevant when your product is the thing being tested.
OSEP, GXPN Evasion, pivoting and advanced exploitation. Relevant to internal network work and red team engagements.
CREST registered or certified tester An assessed standard at the firm level as well as the individual level, including process and reporting quality. Commonly asked for by financial services buyers.
GPEN, GWAPT Broad practical coverage of penetration testing and web application testing method.
CISSP, CISA, CISM Management and governance credentials. Useful in the firm, but they say nothing about whether the person can test.

The question that matters more than the acronyms: which named individual is assigned to your engagement, are they an employee or a subcontractor, and what do they hold. Firms quote with a capability page and staff with whoever is free. Put the name in the statement of work.

A methodology you can name

Ask which published methodology the firm works to. Acceptable answers are the OWASP Web Security Testing Guide, the PTES stages, NIST SP 800-115, or an internal methodology mapped to one of those and shown to you. The reason this matters is coverage: a named methodology is a checklist someone has to walk and account for, which is what lets a report state what was tested and what was deliberately not. Without it there is no way to distinguish thorough work from a tester who ran out of interest on day two.

Follow up by asking how coverage appears in the report. Good firms include a section listing the test cases attempted, including the ones that found nothing. That section is worth more to an auditor than the findings list, because it is the part that proves absence of a result rather than presence of one.

The sample report

Ask for a redacted sample before you ask for a quote. It is the single most informative document in the process and every serious firm has one ready.

Read the findings rather than the layout. If everything maps to a CVE identifier, a missing HTTP security header or a TLS configuration note, the report was written by a scanner and reformatted. Human testing produces findings a tool cannot express: broken authorization between tenants, a workflow step that can be skipped, a password reset that can be replayed, a role that can escalate through your own permission model. Check that each finding carries reproduction steps, evidence, an impact statement written for your business rather than a generic severity label, and remediation advice specific enough to hand to an engineer.

Check the executive summary too. It should be readable by someone non-technical and should say what the tester concluded about the overall security posture, not just count findings by colour.

Retest policy, which is where quotes stop being comparable

A retest verifies that what you fixed is actually fixed, and it is the piece auditors and enterprise customers most often want to see. Firms handle it three ways: included within a window of thirty to ninety days, sold separately at ten to twenty percent of the engagement, or not offered. Two quotes that look $4,000 CAD apart are often identical once the retest is added to the cheaper one.

Get the specifics in writing: how long the window is, whether it covers all findings or only high and critical ones, whether the retest produces an updated report or a letter, and what happens if remediation takes longer than the window. Engineering schedules slip, and a thirty-day window on a finding that needs an architectural change is a window you will miss.

Insurance and the contract

Ask for a certificate of professional liability insurance, also called errors and omissions, and check that the coverage is meaningful next to the value of the system being tested. Ask whether cyber liability is carried as well. This is routine for established firms and awkward for one-person operations working without cover, which is exactly the information you wanted.

In the engagement agreement, look for four things: rules of engagement including the testing window and an escalation contact, who owns the report and whether you may share it with customers and auditors, how any personal information the tester encounters is handled and destroyed, and where the report and any collected data are stored. That last pair matters under Canadian privacy law, since accountability for personal information stays with you when you hand it to a service provider. If a public sector or hospital contract imposes data residency terms, they arrive through your contract, so they have to reach the tester's contract too.

Independence

The firm that built or operates your system should not be the firm that tests it, and a serious buyer will reject that arrangement. If your managed service provider offers to test the environment they run for you, treat their work as internal assurance and buy the external test elsewhere. Enterprise procurement teams and certification auditors both check this.

Boutique, mid-market or national firm

The same scope quoted across the three tiers commonly varies by a factor of two, and much of the difference is overhead rather than tester capability. Independents and boutiques are usually the strongest technically per dollar and the weakest on scheduling, insurance limits and report polish. Mid-market security consultancies sit in the middle and are the common answer for a SaaS company. The security practices of the national accounting firms cost the most and are occasionally worth it, when your customer's procurement team recognizes the name or when the test has to sit alongside an audit relationship. Quote all three tiers at least once so you know what you are paying for.

Penetration testing by city

Each page below covers the privacy law that applies in that province, the local industries that drive testing demand, and who is likely to be asking you for the report.

Ontario

Quebec

British Columbia

Alberta, Saskatchewan and Manitoba

Atlantic Canada

Firms serving these cities will appear in the directory as listings are confirmed. Until then, the quote form is the working route to a shortlist.

Compare firms on one scope

Describe what needs testing and who asked for it, and we will put the same scope in front of Canadian testing firms so the numbers coming back are comparable.

Get matched

Common questions

Does the testing firm need to be in our city?

For application, network and cloud testing, no. The work is remote and insisting on a local firm narrows your options without improving the test. Three engagement types do need someone physically present: wireless testing of an office, physical security assessment, and the physical component of a red team. A local firm also makes an in-person readout easier, which is genuinely more useful than a video call when your engineers want to argue with a finding.

How many firms should we ask for a quote?

Three, drawn from different tiers: an independent or boutique, a mid-market consultancy, and one larger practice. Give all three the same written scope, including role counts, endpoint counts and whether testing is authenticated. If you describe the scope differently to each, the quotes will not be comparable and the exercise tells you nothing.

Is a Canadian firm better than an American or offshore one?

Not automatically, and no Canadian framework requires a domestic tester. What a Canadian firm more reliably understands is the provincial privacy statute that applies to you and what a Canadian buyer's security review will ask. Where location becomes a hard requirement is data residency terms written into a specific contract, which is a question about where information is processed and stored rather than where a company has an office.

How far ahead do we need to book?

Four to eight weeks for a firm worth waiting for, and longer near a quarter end or fiscal year end when audit-driven demand peaks. If a signed deal or an audit window depends on the report, start scoping about two months out, because scoping and reporting together take roughly as long as the testing does.

Why is there no ranked list of the best firms here?

Because the best firm for an authenticated SaaS test and the best firm for an industrial control system assessment are almost never the same firm. Any single ranking either sells placement or guesses. The useful filters are engagement type, province and evidence, which is what the directory is being built around.