GetPentest

Retest and remediation verification

The second thing almost every buyer purchases is proof that the findings were fixed. It is cheap if you plan for it, expensive if you discover the retest window closed while the tickets sat in a backlog.

Last reviewed 2026-08-31Written by Jacob Masse, TrazTech Inc.

A retest costs $1,500 to $6,000 CAD when it is charged separately, and nothing at all when it is included in the original engagement, which it should be. The catch is the window: most firms include a retest only within 30 to 90 days of the report, and most remediation takes longer than the team promised at the readout. Miss the window and you buy the retest at day rate, or worse, you hand your customer a report full of open high findings.

$1,500 to $6,000 Retest priced separately, CAD

30 to 90 days Typical included-retest window

1 to 3 days Tester days a retest actually consumes

What remediation verification actually is

A retest is a short, targeted engagement in which the original tester attempts the same attack again against the fixed system. It is not a fresh test and it is not a rerun of the whole scope. The tester works from the finding list, reproduces each issue in the same way it was originally proved, and records one of three outcomes.

Closed
The original proof of concept no longer works and the tester could not find a variation that does. This is the outcome that changes the report status and that an auditor will accept.
Partially remediated
The exact request no longer works but a small change to it does. Common where a fix was applied at one endpoint rather than at the authorisation layer, and it is the most useful thing a retest produces because it catches a fix that would have failed the next test anyway.
Risk accepted
You decided not to fix it and said so in writing, with the reason and who approved it. An auditor is generally content with a documented acceptance at the right level of seniority and unhappy with silence.

A retest is not a re-scan. Verifying closure by running the scanner again and diffing the output only works for findings a scanner found in the first place. The findings that matter, the authorisation flaws and the business logic problems described on assessment versus test, have to be attempted by hand. No tool knows what your application was supposed to allow.

Why this is the evidence auditors chase

Buyers assume the report is the artifact. It is half of it. A SOC 2 or ISO 27001 auditor expects to see a test, and examines what happened next. A control that identifies vulnerabilities and never remediates them is a control that does not operate. The evidence set they ask for is consistent across firms.

  1. The report, dated, naming the scope and the firm.
  2. A ticket for each finding above your own severity threshold, created within days of the report rather than weeks.
  3. A remediation date on each ticket, and the target implied by your own policy. An SLA you wrote and then missed is worse evidence than no SLA.
  4. The retest letter or memo, naming which findings were confirmed closed and on what date.
  5. A written, approved acceptance for anything left open.

The gap between step one and step four is where audit findings come from, and it is why the retest is the part of the engagement worth negotiating hardest. What each framework expects is covered on SOC 2 penetration testing, ISO 27001 penetration testing, and for card environments PCI DSS, which is explicit that exploitable vulnerabilities must be corrected and testing repeated to verify the correction.

Comparing firms for this? Tell us what you need and it goes to the ones in the directory that do this work. No charge, and no phone number required.

The window, and how buyers lose it

Almost every included retest is time limited. The clause is one line in the statement of work, read after the deadline has passed. The report lands, the readout happens, engineering agrees the fixes, a release goes out, a customer escalation eats three weeks, and by the time someone asks about the retest the ninety days are gone.

What a retest costs, by how it was bought, CAD 2026
ArrangementCostWhat to check before signing
Included, one retest inside 30 days $0 Too short for most teams. Push for 90
Included, one retest inside 90 days $0 The realistic default. Ask what counts as the start date
Included, unlimited inside 12 months $0 Rare and worth paying more for at the original quote
Retest of high and critical findings only $1,500 to $3,000 Usually a day. Fine if the mediums are genuinely accepted
Full retest of all findings, out of window $3,000 to $6,000 Two to three days at the firm's normal rate
Fresh test because the window closed and the code moved $10,000 to $30,000 What you are trying to avoid
Worst case, first year, test plus a repeat test$20,000 to $70,000Against $10,000 to $30,000 done once with the retest used

The retest planner works out the dates from your report date and your window, and tells you the latest day the fixes can land and still be verified for free.

Ask what the start date is

Windows are counted from the report date in some contracts and from the last day of testing in others, and the difference is often two weeks because report writing takes that long. Where a draft report and a final report both exist, ask in writing which one starts the clock. This is a one-line question before signing and an argument afterwards.

Planning remediation so the window is enough

Assume engineering capacity for security findings is smaller than everyone believed at the readout. Two things fix that without more capacity. Agree a severity threshold before the test, so nobody is negotiating which mediums matter while the clock runs. Book the retest date at the same time as the test, which turns a vague intention into a date other people plan around.

0 of 0 done ยท

The retest letter, and who you can send it to

The output of a retest should be a short document you can hand to somebody outside the company. It names the original engagement and its date, states which findings were retested, gives the outcome of each, and confirms no new testing was performed. That last line stops a reader treating the letter as a fresh clean bill of health.

Send the letter, not the report. A full penetration test report is a map of how to attack you, and the version of it that includes open findings should never go to a prospect's procurement inbox. Which document to send to whom is set out on report versus attestation letter.

Where retesting stops being enough

A retest verifies fixes against a snapshot. If you ship weekly, that snapshot is out of date almost immediately. An annual test plus a retest is usually still the right shape for the evidence, but the security value comes from testing closer to the release cadence. The models are compared on pentest as a service, including where a subscription substitutes for a scoped annual test and where it does not.

Get the retest terms in writing before you sign

Tell us the scope and the deadline you are working to, and the same written request goes to Canadian firms with the retest terms asked for up front.

Get matched

Common questions

How much does a pentest retest cost in Canada?

Between $1,500 and $6,000 CAD if it is charged separately, which corresponds to one to three tester days. Many firms include one retest in the original fee inside a window of 30 to 90 days. If a quote does not mention a retest at all, assume it is not included and ask for the price in writing before you compare it with a quote that includes one.

Do we need a retest for SOC 2 or ISO 27001?

Neither names a retest as a requirement. Both expect evidence that identified vulnerabilities were remediated, and a retest is the cleanest form that evidence takes. A ticket marked done by the developer who wrote the fix is weaker evidence than an independent confirmation, and auditors treat it that way.

Can we verify the fixes ourselves instead?

You can and you should, before the retest, because paying a firm to find that a fix was never deployed is an expensive way to check a release. What self-verification does not give you is independence, which is the property the auditor and the customer are buying. Do both: your team confirms the fix shipped, the firm confirms the attack no longer works.

What if the retest finds the fix introduced a new problem?

It happens, most often where a fix added an authorisation check in one place and changed behaviour somewhere else. A good firm reports it and tells you whether it sits inside the original scope. Expect to pay for testing genuinely new functionality, and expect not to pay where the new issue is a direct consequence of the fix they recommended.

Our window closed. What are the options?

Ask anyway. Firms will often honour a lapsed window by a few weeks rather than lose the following year's engagement. Failing that, buy a high-and-critical-only retest for $1,500 to $3,000 CAD rather than a full one, since those are the findings a customer or auditor will ask about. Then move the retest date into the contract for next year.