GetPentest

Public sector penetration testing procurement in British Columbia

British Columbia posts its requirements openly and pre-qualifies suppliers heavily, and the question that decides most engagements is not price but where the working evidence is allowed to be stored.

Last reviewed 2026-08-31Written by Jacob Masse, TrazTech Inc.

British Columbia public bodies post competitive opportunities on BC Bid and buy a great deal of professional services through supply arrangements competed in advance, so the first question for a testing firm is whether you are qualified on one rather than what you would charge. The second, and the one that ends more conversations than price, is where the personal information touched during the test may be stored and accessed. A public body in BC has to answer that under FOIPPA.

BC Bid Where provincial opportunities are posted

FOIPPA The statute governing BC public bodies

$6,000 to $40,000 The test itself, CAD, unchanged by the province

FOIPPA, residency, and what actually changed

British Columbia used to be the clearest data residency jurisdiction in the country: personal information in the custody of a public body had to be stored and accessed only in Canada, with narrow exceptions. That requirement was amended in 2021, and disclosure outside Canada is now possible subject to the conditions in the Act. A lot of published guidance, including guidance written by security vendors, still describes the old rule.

What did not change is the accountability. A BC public body remains responsible for the personal information it holds, is expected to assess privacy risk before a new use or disclosure, and will push those obligations down to you through the contract. Many BC institutions still require Canadian storage as a matter of policy even though the statute no longer compels it, and health authorities are the least likely to move. Read the schedule rather than assuming either version of the rule.

What this means for your tooling

Assume you will be asked to name every system that will hold evidence: the collaboration platform, the ticketing system, the reporting tool, the storage the draft report sits in, and any subcontractor. Firms that cannot produce that list quickly lose time they had allocated to testing. Firms that can, and that can say which of those systems are Canadian hosted, are unusually competitive in this province.

Who buys, and what shapes the requirement

British Columbia public buyers and what drives their testing
BuyerPrivacy statuteWhat usually drives the test
Ministries and provincial agenciesFOIPPADigital service launches and internal audit findings
Health authoritiesFOIPPA, plus health information rulesClinical systems, remote access, and vendor reviews
Municipalities and regional districtsFOIPPAInsurance renewals and ransomware exposure
Post-secondary institutionsFOIPPAStudent systems, research networks, federated identity
Crown corporationsFOIPPABoard level risk reporting and regulatory expectations
Private firms selling to any of the abovePIPA (BC)A security schedule in the public body's contract

That last row is where most readers of this page sit. A private BC company is regulated by PIPA rather than FOIPPA, and the public sector requirements reach it through the contract it signed, not through the statute. If a schedule in your agreement names annual testing, the scope you need is whatever holds the public body's data, and the document you send them afterwards is normally a letter rather than the report, which is covered on report versus attestation letter.

Getting into the process

  1. Register on BC Bid and watch for supply arrangement refreshes in information technology and professional services. Those refreshes, not individual opportunities, are how a firm gets into the pool.
  2. Read a closed solicitation end to end. The privacy schedule and the security schedule are where the real requirements live, and they are usually appendices rather than part of the main document.
  3. Prepare the systems inventory described above before you need it, with the hosting location of each system written down.
  4. Confirm insurance limits and whether named personnel require criminal record checks. Both are mandatory conditions in many BC documents.
  5. Price the retest and say what the window is. The public sector asks for remediation verification more consistently than private buyers do.

Scoping a BC engagement so it survives review

The scope written into a BC public sector statement of work has to hold up in front of a privacy reviewer as well as a security lead, and the two want different things. The security lead wants coverage. The privacy reviewer wants to know what personal information the tester will encounter, why encountering it is necessary, and what happens to it afterwards. A scope that answers both reads as three extra paragraphs in the statement of work and saves weeks.

Say which environment is being tested and whether it holds real records. Say whether testing will be performed against masked or synthetic data, and where it will not, say why. Name the retention period for evidence, the destruction method and who confirms it. None of that is unusual practice for a competent firm, and writing it down converts an open-ended review into a checklist. The rest of what a statement of work should contain is on penetration testing services, and the pricing behind it is on penetration testing cost in Canada.

Scope a British Columbia public sector test

Tell us the systems, the hosting constraints and the deadline, and the scope goes to Canadian firms that can meet them.

Get matched

Common questions

Does BC still require personal information to stay in Canada?

Not as an absolute statutory rule. FOIPPA was amended in 2021 and disclosure outside Canada is now possible subject to the conditions in the Act. Many BC public bodies nonetheless require Canadian storage through their contracts, and health organisations are the most conservative. Treat residency as a contract question in every engagement rather than a settled legal one.

Do we need to be on a supply arrangement to win BC work?

Not always, since larger requirements are still competed openly on BC Bid, but a great deal of mid-sized professional services work is awarded through pre-qualified pools. If you are not in one, your realistic pipeline is the open competitions, which are fewer and slower. Watch for refresh windows, because they are the only entry point.

We are a private BC company. Does FOIPPA apply to us?

No. Private-sector personal information in British Columbia is governed by PIPA. FOIPPA reaches you only through a contract with a public body, and when it does the obligations arrive as schedule terms about storage, access, retention and breach notification. Read the schedule, because it is usually stricter than PIPA on its own.

Is a Victoria or Vancouver firm preferred?

No, and trade agreements make an explicit local preference difficult. Proximity helps only for the parts of an engagement that need someone present, such as wireless testing or physical assessment. The pages for Victoria, Vancouver and Kelowna cover the local market in more detail.