GetPentest

Penetration testing companies in Canada

Choosing a testing firm is mostly a document exercise. Five things decide whether you are buying a test or a scan, and all five can be checked before you sign.

Last reviewed 2026-08-16Written by Jacob Masse, TrazTech Inc.

Plenty of firms in Canada will sell you something called a penetration test, and they are not all selling the same product. Choose between them on five documents rather than on reputation or office location: the certifications held by the people who will be assigned, the methodology they name, a redacted sample report, the retest terms in the statement of work, and a certificate of insurance. A firm that produces all five quickly is a different kind of business from one that produces none, and one email tells you which you are dealing with.

5 documents All obtainable in one email

Barely varies Pricing by city, because testing is remote

4 to 8 weeks Lead time at a firm worth waiting for

Pricing barely varies by city. Testing is remote work and the day rate does not care where the tester sits. What varies is who is asking you for the report, which is what the city pages below cover.

If you came here for a ranked list, there is not an honest one to publish. Every article ranking Canadian testing firms was written by a firm that placed itself first, and the best penetration testing companies in Canada explains why and gives you the method to rank your own shortlist instead.

Certifications that mean something

Certifications are a floor, not a ranking. A strong tester without one is common, and a weak tester with three is possible. The list tells you whether the firm invests in demonstrable practical skill or in credentials that can be passed by reading.

Testing certifications and what each actually demonstrates
CertificationWhat it demonstrates
OSCP A hands-on exam requiring real compromise of live machines under time pressure. The common baseline for a network or infrastructure tester.
OSWE Source-code-led web application exploitation. Relevant when your product is the thing being tested.
OSEP, GXPN Evasion, pivoting and advanced exploitation. Relevant to internal network work and red team engagements.
CREST registered or certified tester An assessed standard at the firm level as well as the individual level, including process and reporting quality. Commonly asked for by financial services buyers.
GPEN, GWAPT Broad practical coverage of penetration testing and web application testing method.
CISSP, CISA, CISM Management and governance credentials. Useful in the firm, but they say nothing about whether the person can test.

The question that matters more than the acronyms: which named individual is assigned, are they an employee or a subcontractor, and what do they hold. Firms quote with a capability page and staff with whoever is free. Put the name in the statement of work.

A methodology you can name

Ask which published methodology the firm works to. Acceptable answers are the OWASP Web Security Testing Guide, the PTES stages, NIST SP 800-115, or an internal methodology mapped to one of those and shown to you. A named methodology is a checklist someone has to walk and account for, which is what lets a report state what was tested and what was deliberately not. Without it there is no way to tell thorough work from a tester who ran out of interest on day two.

Then ask how coverage appears in the report. Good firms include a section listing the test cases attempted, including the ones that found nothing. That section is worth more to an auditor than the findings list: it proves absence of a result rather than presence of one.

Comparing firms for this? Tell us what you need and it goes to the ones in the directory that do this work. No charge, and no phone number required.

The sample report

Ask for a redacted sample before you ask for a quote. It is the most informative document in the process and every serious firm has one ready.

Read the findings rather than the layout. If everything maps to a CVE identifier, a missing HTTP security header or a TLS configuration note, the report was written by a scanner and reformatted. Human testing produces findings a tool cannot express: broken authorization between tenants, a workflow step that can be skipped, a password reset that can be replayed, a role that can escalate through your own permission model. Each finding should carry reproduction steps, evidence, an impact statement written for your business rather than a generic severity label, and remediation advice you can hand to an engineer.

Check the executive summary too. It should be readable by someone non-technical and say what the tester concluded about the security posture, not count findings by colour.

Retest policy, which is where quotes stop being comparable

What an included window is worth in CAD, and what auditors accept as closure evidence, is on retest and remediation verification.

A retest verifies that what you fixed is fixed, and it is the piece auditors and enterprise customers most often want to see. Firms handle it three ways: included within a window of thirty to ninety days, sold separately at ten to twenty percent of the engagement, or not offered. Two quotes that look $4,000 CAD apart are often identical once the retest is added to the cheaper one.

Get the specifics in writing: how long the window is, whether it covers all findings or only high and critical ones, whether the retest produces an updated report or a letter, and what happens if remediation takes longer than the window. Engineering schedules slip, and a thirty-day window on a finding that needs an architectural change is one you will miss.

Insurance and the contract

Ask for a certificate of professional liability insurance, also called errors and omissions, and check that the coverage is meaningful next to the value of the system being tested. Ask whether cyber liability is carried as well. It is routine for established firms and awkward for one-person operations working without cover, which is the information you wanted.

In the engagement agreement, look for four things: rules of engagement including the testing window and an escalation contact, who owns the report and whether you may share it with customers and auditors, how any personal information the tester encounters is handled and destroyed, and where the report and any collected data are stored. That last pair matters under Canadian privacy law: accountability for personal information stays with you when you hand it to a service provider. Data residency terms in a public sector or hospital contract arrive through your contract, so they have to reach the tester's contract too.

Independence

The firm that built or operates your system should not be the firm that tests it, and a serious buyer will reject that arrangement. If your managed service provider offers to test the environment they run for you, treat their work as internal assurance and buy the external test elsewhere. Enterprise procurement teams and certification auditors both check this.

Boutique, mid-market or national firm

The same scope quoted across the three tiers commonly varies by a factor of two, and much of the difference is overhead rather than tester capability. Independents and boutiques are the strongest technically per dollar and the weakest on scheduling, insurance limits and report polish. Mid-market security consultancies sit in the middle and are the common answer for a SaaS company. The security practices of the national accounting firms cost the most, and are worth it when your customer's procurement team recognizes the name or the test has to sit alongside an audit relationship. Quote all three tiers once so you know what you are paying for.

Send all three the same written scope, or the prices cannot be compared. The scoping questionnaire writes that document from a handful of answers, and the cost calculator tells you which end of the range is realistic for it.

Penetration testing by city

Each page below covers the privacy law that applies in that province, the local industries that drive testing demand, and who is likely to be asking you for the report.

Ontario

Quebec

British Columbia

Alberta, Saskatchewan and Manitoba

Atlantic Canada

Firms serving these cities will appear in the directory as listings are confirmed. Until then, the quote form is the working route to a shortlist.

Selling to, or buying from, the public sector

Public bodies do not buy testing the way a company does. The value decides whether the requirement is competed openly, pre-qualified supplier arrangements decide who realistically bids, and the privacy schedule decides where the working evidence is allowed to live. Those rules are provincial, so three of them are written up separately: Ontario, where vendor of record arrangements and the broader public sector directive set the shape; Quebec, where French deliverables and the assessment before personal information leaves the province are the real filters; and British Columbia, where the question that ends most conversations is where the evidence is stored.

Compare firms on one scope

Describe what needs testing and who asked for it, and we will put the same scope in front of Canadian testing firms so the numbers coming back are comparable.

Get matched

Common questions

Does the testing firm need to be in our city?

For application, network and cloud testing, no. The work is remote and insisting on a local firm narrows your options without improving the test. Three engagement types do need someone physically present: wireless testing of an office, physical security assessment, and the physical component of a red team. A local firm also makes an in-person readout easier, which is genuinely more useful than a video call when your engineers want to argue with a finding.

How many firms should we ask for a quote?

Three, drawn from different tiers: an independent or boutique, a mid-market consultancy, and one larger practice. Give all three the same written scope, including role counts, endpoint counts and whether testing is authenticated. If you describe the scope differently to each, the quotes will not be comparable and the exercise tells you nothing.

Is a Canadian firm better than an American or offshore one?

Not automatically, and no Canadian framework requires a domestic tester. What a Canadian firm more reliably understands is the provincial privacy statute that applies to you and what a Canadian buyer's security review will ask. Where location becomes a hard requirement is data residency terms written into a specific contract, which is a question about where information is processed and stored rather than where a company has an office.

How far ahead do we need to book?

Four to eight weeks for a firm worth waiting for, and longer near a quarter end or fiscal year end when audit-driven demand peaks. If a signed deal or an audit window depends on the report, start scoping about two months out, because scoping and reporting together take roughly as long as the testing does.

Why is there no ranked list of the best firms here?

Because the best firm for an authenticated SaaS test and the best firm for an industrial control system assessment are almost never the same firm. Any single ranking either sells placement or guesses. The useful filters are engagement type, province and evidence, which is what the directory is being built around.