GetPentest

What a penetration test quote should itemise

A quote is a document about how someone plans to spend their time. If it does not tell you how many days, who is working them and what you get at the end, it is a price rather than a proposal.

Last reviewed 2026-09-01Written by Jacob Masse, TrazTech Inc.

A penetration testing quote should itemise eleven things: the assets in scope, the tester days, the day rate, the seniority of the people assigned, the testing window, the methodology it follows, the deliverables, the severity scoring method, the retest terms and window, the data handling terms, and the exclusions. Most Canadian quotes contain four of those. The two lines that matter most and go missing most often are tester days and day rate, because together they are the only way to tell whether $12,000 CAD buys six days of a senior tester or two days of a junior running tools and three days of report formatting.

$1,500 to $2,800 Canadian tester day rate, CAD, loaded cost

11 Lines a serious quote itemises

20 to 30% Of an engagement spent writing the report

The eleven lines

What each line in a quote tells you
LineWhat it should sayWhat its absence means
Assets in scopeNamed hosts, applications, APIs, ranges, with live host countsThe firm has not read your scope
Tester daysA number, split between testing and reportingThe single most important omission. Ask before anything else
Day rateCAD per day, so the arithmetic checks outThe price was set by what they think you will pay
Who is assignedSeniority, certifications, whether work is subcontractedYou may be buying a name and getting a contractor
Testing windowStart and end dates, hours, timezoneScheduling will slip and you will find out in month three
MethodologyPTES, OWASP WSTG, NIST SP 800-115 or their own, namedThere may not be one
DeliverablesTechnical report, executive summary, attestation letter, raw outputYou will get whatever their template produces
Severity methodCVSS v3.1, CVSS v4.0, or a stated in-house scaleSeverities will be assigned by feel and argued about later
Retest termsIncluded or not, and the window in daysAssume not included, and assume you will pay again
Data handlingWhere evidence is stored, for how long, under whose lawA PIPEDA problem you have not noticed yet
ExclusionsWhat they will not do and whyDisagreement in week two of the engagement

Check the arithmetic yourself

Days times rate should approximately equal the price. When it does not, the gap is the information. A quote of $8,000 CAD that claims ten tester days implies $800 CAD a day, which does not pay a qualified tester in Canada once salary, tooling licences, insurance and overhead are counted. Either the days are notional or the work is being done by someone very junior or offshore, and in both cases you would rather know now.

Worked example: a mid-size SaaS application test, CAD
LineDaysAmount
Scoping and kickoff0.5$1,000
Authenticated application testing, three roles5.0$10,000
API testing against the specification2.0$4,000
Reporting and executive summary1.5$3,000
Readout call and question time0.5$1,000
Retest within 60 days1.0$2,000
Total at $2,000 CAD a day10.5$21,000

That is what a real quote looks like when it is written out. You can disagree with any line, and that is the point: an itemised quote is negotiable and a lump sum is not. The cost calculator builds the same arithmetic from your own scope, and penetration testing cost in Canada gives the ranges by engagement type.

Comparing firms for this? Tell us what you need and it goes to the ones in the directory that do this work. No charge, and no phone number required.

Warning signs

None of these is proof on its own. Two or more together and you are looking at a scan with a cover page, the position set out on vulnerability assessment versus penetration test.

In the pricing

  • A fixed price per IP address or per application with no reference to complexity. Manual effort does not scale that way.
  • A price under $5,000 CAD for anything described as a full application test. There is not enough time in it to log in and map an authorization model.
  • Turnaround promised in 48 or 72 hours. Tools finish in 72 hours. People do not.
  • No day count anywhere in the document, and reluctance to supply one when asked.

In the language

  • The scope is described in tools rather than in questions. "We use Burp Suite, Nessus and Metasploit" tells you nothing about what they will attempt.
  • Coverage claimed against a vulnerability count rather than a methodology. "Checks for over 60,000 vulnerabilities" is a scanner's marketing line.
  • "Certified report" or "certified penetration test". No such certification exists. Firms and individuals are accredited or certified. Reports are not.
  • A guarantee of no findings, or of a clean report. Nobody can promise the contents of a report they have not written.

In the process

  • No sample report offered, or only a marketing brochure offered in place of one. Ask for a redacted real report before signing.
  • No clarifying questions about roles, tenancy or environment. A firm that quotes your scope without asking anything has not read it.
  • No named tester, and no answer when you ask who will do the work.
  • Contract silent on where your data and their evidence will live, which matters in Canada and is covered on data residency during a penetration test.

The counter-case

A cheap quote is not automatically dishonest. A firm quoting $4,500 CAD for an external network test on eleven live hosts, described accurately as automated scanning with manual verification of the results, is selling exactly what it says and may be the right purchase. The problem is not the price, it is the price attached to the words "penetration test" when the work is not one. Read the description, not the number.

Work through your quotes

0 of 0 checked ·

What is worth negotiating and what is not

  1. Negotiate scope before price. Dropping a low-value asset removes real days and the saving is honest.
  2. Negotiate the schedule. Firms discount for a window they can slot into a gap rather than one fixed to your date.
  3. Ask for the retest to be included rather than for the price to come down. It is worth more to you and costs them less.
  4. Do not negotiate the day rate down while keeping the day count. The days will quietly leave anyway.
  5. Do not accept a discount in exchange for a case study or a logo until you have read the report. You are agreeing to publicise work you have not seen.

Have a quote read before you sign it

Send us the scope and the proposals and we will tell you what the numbers imply about the work.

Get matched

Common questions

How many quotes should I get for a penetration test?

Three, from the same written scope. Fewer than three and you have no reference point for what the work should cost. More than three and you are spending your own time on a comparison that stopped adding information after the third, unless the spread between the first three was very wide, which usually means the scope was ambiguous rather than the market was.

Why is one quote five times another for the same scope?

Almost always because one is manual testing priced in tester days and the other is a scan priced as a product. Ask both for the day count. The spread between two genuine manual quotes for an identical written scope is usually under 40 percent, and anything wider than that means the two firms read your scope differently.

Should the quote include the retest?

Ask for it to. A retest verifies your fixes actually closed the findings, and it is the artifact auditors most often want alongside the report. Firms that include one typically cap it at 30 to 90 days after delivery, so check the window against your engineering calendar before you agree the date.

Is a day rate of $2,500 CAD reasonable?

Yes, for a senior tester at a Canadian firm with insurance, tooling and a quality review process. The working range is roughly $1,500 to $2,800 CAD a day. Below $1,200 CAD you are usually looking at a junior, an offshore team or a notional day count attached to automated work.

What if a firm refuses to give a day count?

Treat it as the answer. Every firm that prices manual work knows its day count, because that is how it decided the price and how it staffs the calendar. Refusing to share it means either the number is embarrassing or the engagement is not costed in days at all, and both tell you what you needed to know.