Public sector penetration testing procurement in Ontario
Ontario public bodies do not buy testing the way a company does. The rules that decide who can bid, at what value, and where the report may be stored sit in procurement directives and in FIPPA or MFIPPA, not in the security requirement itself.
An Ontario public body buying a penetration test runs a competitive process whose shape is set by value, not by risk. Below roughly $100,000 CAD most broader public sector organisations may invite a small number of suppliers. Above it, and above the trade agreement threshold that sits a little higher and is adjusted every two years, the requirement goes out openly on the provincial tenders portal. Nothing about that is specific to security, which is why security buyers and finance departments talk past each other on timelines.
$100,000 CAD, common competitive threshold in BPS directives
8 to 16 weeks Open competitive process, posting to award
$6,000 to $40,000 The test itself, CAD, same as anywhere
Which Ontario bodies buy this, and under which rules
The phrase "Ontario public sector" covers organisations with very different procurement obligations. Work out which one you are dealing with first. It decides the paperwork and the timeline.
| Buyer | Privacy statute | Procurement rules |
|---|---|---|
| Ministries and provincial agencies | FIPPA | Ontario Public Service procurement directive, vendor of record arrangements |
| Municipalities, police services, libraries | MFIPPA | The municipality's own by-law, which varies council to council |
| Hospitals and health service providers | FIPPA and PHIPA | Broader public sector procurement directive |
| School boards, colleges, universities | FIPPA or MFIPPA | Broader public sector procurement directive |
| Crown agencies and commissions | FIPPA | Their own directive, usually mirroring the provincial one |
Health information is the fork that matters most. A hospital is a health information custodian under PHIPA, and a testing firm that touches records in that environment is normally an agent or a service provider under the Act, which brings written terms about use, retention and secure disposal that a standard statement of work does not contain. If your test scope includes a clinical system, expect the contract to be negotiated by a privacy office rather than by procurement.
Vendor of record and why it decides who bids
Ontario makes heavy use of pre-qualified supplier arrangements. A vendor of record arrangement is competed once, and for its term the buyer can go to the firms on it through a much shorter second-stage process instead of running a fresh open competition. For a testing firm this is the whole game: if the category you sell into is covered by an arrangement you are not on, you will watch requirements you could have delivered go to firms already qualified, and there is no appeal against that.
- Find out whether the work you sell sits inside an existing arrangement, and when that arrangement expires. Refresh windows are the only entry point.
- Register on the provincial tenders portal and set alerts on the security and professional services categories, not on the word pentest, which almost never appears in a title.
- Read one closed solicitation in full before writing anything. The mandatory requirements are where bids die, and they are usually about insurance, references and screening rather than technical merit.
- Confirm you can meet the screening and insurance conditions before bidding. Commercial general liability and professional liability limits are stated in the documents and are not negotiable after the fact.
- Price on the published evaluation weighting. Where price is forty per cent of the score, a strong technical response that is twice the median price loses to a competent one at the median.
What the security requirement usually says
Ontario solicitations for testing are typically written by a security team and reviewed by procurement, which produces a recognisable shape. Expect named methodology requirements, usually the OWASP testing guide or NIST SP 800-115, named certifications for the assigned testers, a requirement that findings be manually verified, and a mandatory retest. That last one appears more often in public sector documents than in private ones, and the retest and remediation verification terms are worth pricing carefully because the obligation can run months past the report.
The clause most often missed by bidders is about where the evidence lives. FIPPA and MFIPPA do not impose a general rule that records must stay in Canada, but a great many Ontario institutions impose one by contract anyway, and some health sector agreements go further. Read the data handling schedule before you price, since a requirement to keep all working notes, screenshots and the draft report inside Canadian infrastructure changes which tooling you may use.
Directives change and thresholds move
Procurement thresholds in Ontario are adjusted, and trade agreement values are revised on a fixed cycle. Every figure on this page is a planning approximation. Before you bid or budget, read the directive and the solicitation currently in force rather than a summary of them, including this one.
If you are the Ontario buyer rather than the bidder
Two things from the buying side. Write the scope before the solicitation. A requirement that says "penetration testing services" with no asset list produces bids that cannot be compared and an award that gets challenged. The scoping questionnaire produces a scope document you can attach as an appendix, which is the cheapest way to get comparable pricing.
And separate the annual test from the ongoing work. Ontario institutions routinely bundle a penetration test, a vulnerability management service and advisory hours into one award, then discover the test is a small part of a large contract and the testing quality was never evaluated. What the different products are is set out on assessment versus test, and pricing for each is on penetration testing cost in Canada.
Scope an Ontario public sector test
Tell us the systems, the statute they sit under and the deadline, and the scope goes to Canadian firms that have delivered into this sector.
Get matchedCommon questions
Does an Ontario public body have to run an open competition for a penetration test?
It depends on the value and on which directive applies. Broader public sector organisations commonly use an invitational process below about $100,000 CAD and an open competitive process above it, and trade agreement thresholds apply on top. A pre-qualified vendor of record arrangement lets a buyer run a much shorter second-stage process instead, which is why those arrangements matter so much to suppliers.
Must the testing firm be Ontario based?
No, and trade agreements make an outright local preference difficult to write. What does appear is a requirement that data stay in Canada, or that named personnel hold particular screening, and those conditions narrow the field far more effectively than geography ever would.
Is the test report subject to a freedom of information request?
A record held by an Ontario institution can be requested under FIPPA or MFIPPA, and the institution then applies the exemptions in the Act, which include harm to security of a system. In practice full findings are routinely withheld or heavily severed, but plan on the assumption that the existence of the engagement and its cost are disclosable, and write the report accordingly.
What documents does a public buyer usually ask for at award?
Proof of commercial general liability and professional liability insurance at the stated limits, WSIB clearance where applicable, signed confidentiality undertakings for each named tester, and evidence of the certifications claimed in the bid. Have the certificates ready before you bid, because award timelines rarely leave room to obtain them.