GetPentest

Penetration testing cost in Canada

Quotes for the same application routinely differ by a factor of five. Almost all of that variance comes from three things: how many tester days are in the engagement, what methodology is being followed, and whether a retest is included.

Last reviewed 2026-09-15Written by Jacob Masse, TrazTech Inc.

A penetration test in Canada usually costs between $6,000 and $40,000 CAD. A single external network test on a small footprint sits near the bottom of that. An authenticated test of a multi-tenant SaaS product with an API sits in the middle. A red team engagement sits well above it. The breakdown by test type is below, then the part that matters more: why one firm quotes $8,000 for work another firm quotes $28,000 for.

$6,000 to $40,000 What most Canadian companies pay, CAD

$1,500 to $2,800 Tester day rate in Canada, CAD

Under $5,000 Where it stops being a test

Price by test type and scope

Why almost nobody else publishes these

Pricing in this industry is gated on purpose. Firms that rank for pricing queries run a pricing page with no figures on it, or put the guide behind an email form. A quote you cannot compare is easier to defend, and the buyer ends up holding three numbers between $3,500 and $28,000 CAD with no way to tell them apart. We do not sell tests through this site. Every figure below is CAD and reduces to tester days times a day rate, so you can check any quote against it.

Every number is a range for a first-time engagement at a mid-market Canadian firm. Boutiques and independents come in lower. National accounting firms and the security arms of the large consultancies come in higher, sometimes by half again, on overhead rather than tester quality.

Canadian penetration test price ranges by engagement type Ranges run from $5,000 to $12,000 CAD for an unauthenticated web application test up to $12,000 to $35,000 CAD for an internal network test. The same figures are in the table above. $0k $10k $20k $30k $40k External network $6,000 to $15,000 Web app, unauthenticated $5,000 to $12,000 Cloud config review $8,000 to $20,000 API $8,000 to $22,000 Web app, authenticated $10,000 to $30,000 Mobile, per platform $12,000 to $30,000 Internal network $12,000 to $35,000
Typical first engagement at a mid-market Canadian firm, 2026, in CAD. Red team engagements start at $50,000 and are left off so the rest stays readable. The same figures are in the table below.
Canadian penetration testing price ranges by engagement type, CAD
Engagement Typical scope Price (CAD)
External network Up to roughly 50 live hosts, internet facing $6,000 to $15,000
Internal network Assumed breach from a workstation, one Active Directory domain $12,000 to $35,000
Web application, unauthenticated One public application, no login $5,000 to $12,000
Web application, authenticated One product, two or three roles, tenant isolation checked $10,000 to $30,000
API One REST or GraphQL surface with documentation supplied $8,000 to $22,000
Mobile application Per platform, including the backend it talks to $12,000 to $30,000
Cloud configuration review One AWS, Azure or GCP account or subscription $8,000 to $20,000
Wireless One office, corporate and guest networks $5,000 to $12,000
Social engineering Phishing campaign with reporting, no physical access $5,000 to $15,000
Red team Objective based, multi-week, detection and response in scope. See red team assessment $50,000 to $150,000

Ask where your quote lands inside its range. A firm that cannot explain the difference between its low end and its high end is pricing off a menu, not off your scope.

Why there is no price list for this work

There is a reason no honest firm publishes a rate card by test type, and it is worth understanding before you compare quotes.

Two companies can both ask for a web application test and need work that differs by a factor of five. One has a single product, one user role, and forty screens. The other has four tenants, six roles, an admin console, a partner portal, and an API that predates all of it. The phrase on the purchase order is identical. The work is not remotely the same, and any published number that covers both is either wrong for one of them or padded enough to be wrong for both.

So the useful published figures are narrow. A penetration test of a small web application in Canada commonly lands between C$5,000 and C$12,000. Enterprise scope commonly runs C$20,000 to C$50,000 and beyond. A Canadian tester day costs roughly C$1,500 to C$2,800 once salary, tooling, insurance and overhead are accounted for. Those three numbers are worth more to you than a table of twenty, because they let you do the only calculation that matters.

Everything else, including API, internal and external network, cloud review and mobile, is priced from the same arithmetic against a different amount of surface. Rather than looking for your test type in a table, ask the two questions in the next section and work the number out yourself. It takes a minute and it tells you more than any benchmark could.

Comparing firms for this? Tell us what you need and it goes to the ones in the directory that do this work. No charge, and no phone number required.

The number underneath every quote

Penetration testing is priced in tester days. A fixed-fee quote is a day count times a rate with a margin applied and the arithmetic hidden. Canadian day rates run $1,500 to $2,800 CAD per consultant, independents at the low end and large-firm practices at or above the high end.

The cost calculator applies that model to a scope you describe and shows the day count it used. How much does a pentest cost answers the same question in a paragraph.

Divide the quote by a plausible day rate and you get the honest scope. A $6,000 CAD quote is three days of work, at most, including reporting. Three days is enough to test a small external perimeter properly. It is not enough for a SaaS platform with role-based access control. Buy that for $6,000 and the difference comes out of depth.

The line worth drawing

Most of what is sold as a penetration test under about $5,000 CAD is a vulnerability scan with a logo on it. The tell is in the findings: if every item in the report maps to a CVE identifier or a missing HTTP header, a tool wrote it. Business logic flaws, broken authorization between tenants, and privilege escalation through your own role model are what a human finds, and those are the ones that get exploited. The distinction is on vulnerability assessment versus penetration test.

And when the cheap thing is the right thing

That line cuts both ways. If your whole external surface is a marketing site and a few hosts, you hold no card or health data, and nobody has asked you for a penetration test by name, then continuous automated scanning at $2,000 to $5,000 CAD a year is the correct purchase and a $20,000 CAD manual engagement is money set on fire. Scanning finds the expired certificate, the unpatched service and the exposed admin panel, which is what compromises small companies. The failure is not buying a scan. It is calling it a test and handing the output to a customer who asked for one. Buy the scan deliberately, name it accurately, and move to manual testing when you have an authorisation model worth attacking or a contract that demands one.

What actually drives the price

Scope size, counted the way a tester counts it. Not "one application". The units that matter are distinct user roles, distinct tenants, number of API endpoints, number of live hosts, and how many of those differ from each other. Fifty near-identical hosts behind one load balancer is a smaller job than five hosts running five different stacks.

Authenticated or not. This is the largest single multiplier in application testing. An unauthenticated test looks at what an anonymous attacker sees. An authenticated test has to be run once per role, and then across roles to check that a low-privilege user cannot reach a high-privilege function or another tenant's data. Three roles is roughly three times the testing surface, not three extra hours.

Methodology and evidence depth. A firm working to a published methodology such as the OWASP testing guide, the PTES stages, or the NIST SP 800-115 structure has to walk the checklist and show its coverage. That takes longer than freestyle poking, and it is what makes a report defensible to an auditor who asks what was tested and what was not.

Retest included or not. A retest is typically ten to twenty percent of the original engagement if bought separately, and it is the piece auditors most often want. Some firms include one within thirty days, some within ninety, some not at all. Two quotes that look $4,000 apart can be identical once you add the retest to the cheaper one.

Reporting standard. Ask whether you get a full technical report, an executive summary, and a shareable attestation letter. The letter is the artifact you hand to a customer's procurement team so you do not have to send them a document listing your unfixed vulnerabilities. Firms that do not produce one are creating a problem for you later.

Timeline. Rush work carries a premium, commonly fifteen to thirty percent, because it displaces booked work. Good Canadian testers are often booked four to eight weeks out, and the end of a quarter is worse. If your audit window closes in three weeks, that is a budget line, not a scheduling detail.

What your scope left open. The driver nobody puts on a quote, because it is folded into the other lines. A firm that cannot see how many roles exist, whether credentials will be ready, or whether the API is in scope assumes the largest case it can still win with and adds days for being wrong. The same effect runs through fixed-price professional work. On one compliance engagement handled by TrazTech, which operates this site, an audit firm revised a five-figure SOC 2 quote down by $11,000 CAD once the client's readiness position was documented and a prep firm was confirmed. Not a discount, a smaller estimate. That was an audit and the figure does not carry across, but the mechanism does. Why two firms quote different numbers takes a real spread apart line by line.

What a quote should include before you compare it

  • The number of tester days and how they split between testing and reporting.
  • The methodology being followed, named rather than described.
  • Whether testing is authenticated, and how many roles are covered.
  • Whether a retest is included, and the window it must be used in.
  • What deliverables you get: technical report, executive summary, and an attestation letter you can send to a customer.
  • Who owns the report and whether you may share it with customers.
  • Rules of engagement, including testing hours and the escalation contact.
  • Whether findings are re-verified manually before they appear in the report, or lifted from tool output.

Two quotes are only comparable once all eight are answered. About half the gap between a cheap quote and an expensive one disappears once you normalize for retest and role coverage. The other half is depth.

Costs that are not in the quote

The engagement fee is not the whole spend. Budget for remediation engineering time, which for a first test routinely costs more than the test. Budget for a retest if one is not included. Budget for the internal hours spent scoping, provisioning test accounts and sitting on kickoff and readout calls, usually a week of someone's attention spread across a month.

First year of testing an authenticated SaaS product, all in, CAD
LineRangeNotes
Authenticated application and API test $10,000 to $30,000 The engagement fee itself
Retest, if not included $0 to $6,000 Free inside the window. See retest terms
Attestation letter, if charged $0 to $750 Ask at scoping, not after the report
Remediation engineering $8,000 to $40,000 Usually the largest line, and never in the quote
Your own scoping and readout hours $2,000 to $6,000 Roughly a week of someone's attention across a month
First year, all in$20,000 to $82,000Against a quoted fee of $10,000 to $30,000

Take the bottom row to whoever approves the budget, not the quoted fee. Remediation moves most: a first test finds years of accumulated decisions, a fourth finds a quarter's worth.

If the test is for an audit, the test fee sits alongside the audit fee rather than replacing part of it. A first SOC 2 engagement and the penetration test it requires are separate purchases from separate providers. The independence is the point.

How to spend less without buying less

If the obstacle is approval rather than price, how to get a penetration test funded leads with the blocked deal or audit rather than with risk.

Four levers, in the order they save the most per unit of effort. None of them is asking for a discount.

  1. Reduce scope honestly. One well-tested application beats three superficially tested ones, and an auditor will accept a scoped test with a written rationale for what was excluded far more readily than a thin test of everything.
  2. Fix the cheap findings before the test starts. Patch levels, TLS configuration, default credentials and exposed admin interfaces are things a scanner finds in an hour. Paying a senior tester to rediscover them spends day rate on work a free tool does, and it crowds out the hours that would have gone into your authorization model.
  3. Write the scope down once and send the same document to every firm. Most of the variance buyers report comes from three firms understanding the request three different ways. The scoping questionnaire produces that document, and questions to ask a vendor makes the answers comparable too.
  4. Supply documentation and working test accounts on day one. Testers lose real time to accounts that do not work, environments that fall over and a missing API specification. Every hour lost to setup is an hour not spent testing, and you pay for it either way.

None of these change the cadence. Buying a test more often than your system changes is the most common way Canadian companies overspend, which is the argument on how often you should test.

Who runs this site

TrazTech operates GetPentest and sells penetration testing, priced the way this page describes: tester days at a day rate, with the reporting days named separately. The practice has delivered more than 20 penetration tests, and its principal is credited with 5 CVEs. It is listed first in the directory because it owns the directory.

Buy elsewhere when the work sits outside that. Red team engagements, hardware and industrial control targets, and procurement that names CREST accreditation all point to a specialist. On price, the useful comparison is another firm's quote against the same written scope, and the scoping questionnaire produces the document that makes the two comparable.

Compare quotes on the same scope

Compare quotes on the same scope

Tell us what needs testing and why, and we will put the same scope in front of Canadian firms so the numbers you get back mean something.

Get matched

Red flags in penetration testing pricing

None of these mean a firm is bad. Each one means you should ask a follow-up question before money moves.

A flat rate quoted before anyone has scoped the environment. If a price arrives before anyone has asked how many applications you have, how many roles exist, whether testing is authenticated, or how many API endpoints are in play, the number was not calculated from your environment. It was calculated from a template. A firm that asks harder questions during scoping is usually the one that will ask harder questions during testing.

A report that is mostly automated scanner output. Covered above, and detectable in thirty seconds from a redacted sample. Look at whether the findings are written in the firm's own words or in the scanner's.

No retest included, and no retest priced. A test without a retest leaves you with a list of problems and no document saying you fixed them. Ask for the retest price up front so it does not arrive later as a change order.

No named tester. Ask who will do the work, what their background is beyond a baseline certification, and whether they have tested applications like yours before. The answer does not need to be a famous name. It needs to be a name. Work that arrives anonymous is work you cannot assess.

No redacted sample report offered before signing. Every firm has one. A firm that will not show you the shape of its deliverable before you commit is asking you to buy the one thing you have no other way to evaluate.

Common questions

Why is one quote $8,000 and another $28,000 for the same application?

Almost always because they are not the same engagement. Check whether both are authenticated, how many roles each covers, whether a retest is included, and how many tester days each represents. Divide each quote by roughly $2,000 CAD a day and compare the day counts rather than the dollars. If one is three days and the other is twelve, you now know what you are choosing between.

Is a cheaper test better than no test at all?

For a company with nothing, a scan finds real problems and is worth running. The failure mode is buying a scan, calling it a penetration test, and telling a customer or an auditor that your application has been tested. That is a claim you cannot support, and it tends to unravel in the vendor security review rather than quietly.

Do we pay more for testing production?

Sometimes, because production testing usually happens outside business hours and carries extra coordination. The more significant cost is the control work around it: agreed rate limits, a rollback contact, and a written agreement covering any personal information the tester may see. Under Canadian privacy law that data transfer stays your accountability, so it belongs in the contract.

How much should we budget for fixing what the test finds?

For a first test, plan on remediation costing more than the test. A reasonable planning assumption is two to six weeks of engineering effort spread over a quarter, weighted toward whatever the report marks high or critical. Ask the firm to rank findings by exploitability in your environment rather than by generic severity, so you are not spending sprints on a critical that is unreachable behind your VPN.

Are annual retainers cheaper than one-off tests?

Per test, usually yes, and a firm that already knows your architecture spends less time on discovery each round. The trade-off is familiarity: the same tester on the same application for four years stops finding new things. A reasonable pattern is a retainer with a different lead tester every second engagement, or rotating firms every third year.