Free penetration testing tools
Ten tools, all free. The CVSS calculator asks for nothing at all. The rest give you the whole answer on screen and offer the written version afterwards.
Buying a penetration test is hard to do well. The product is not standardised, so three firms quoting the same request describe three different engagements, and the cheapest is often the one that understood the least. These ten run in the order a purchase happens: work out which test, check what you were quoted, price it, write the scope down, get ready for the tester, then deal with what comes back.
| Tool | What it answers | Questions |
|---|---|---|
| Scoping questionnaire | What am I asking three firms to quote, written as one document I can send them | 12 |
| Pentest cost calculator | What this scope should cost in CAD, and how many tester days that is | 7 |
| Which test do you need | Which engagement type fits what you have and who asked for it | 6 |
| Retest planner | The last day your fixes can ship and still be verified for free | 5 |
| CVSS 3.1 calculator | A finding's base score, severity band and vector string | 8 |
| Scan or penetration test | Whether the proposal in front of you is a test or an automated scan with a report | 6 |
| Pentest readiness check | Whether the tester can start work on the first morning, and what to clear first | 7 |
| Finding severity triage | What severity one finding should carry, by when it has to be fixed, and what to tell a customer | 6 |
| Pentest frequency planner | How often to test, as a twelve month calendar with out-of-cycle triggers | 5 |
| Attestation letter checker | Whether your summary letter supports what a customer security review will ask | 4 |
Start here: the scoping questionnaire
The most useful thing on this site. Three quotes for the same test differ by five times because all three understood the request differently: one priced an unauthenticated scan of a marketing site, one priced authenticated testing of every user role, and one included a retest.
Answer the questions and it produces a scope document you can copy and send to several firms at once, including what you want them to quote line by line. Then the quotes are comparable, which is the whole problem. Build your scope.
Then price it before anyone quotes you
Seven questions, then a range in Canadian dollars along with the tester days and the day rate it was built from. The days matter more than the dollars. Once you know how many days the work should take, you can tell whether a quote is cheap because the firm is efficient or because it has scoped half the job. Estimate the cost, then read what moves the number.
If you are not sure what to buy at all
The phrase penetration test covers seven or eight different engagements. Buying the wrong one is the most expensive mistake in this category. You find out at evidence time, when the auditor asks for something the report does not contain and the money is already spent.
It will not recommend a red team assessment to a company with nobody watching alerts. There would be nothing to measure. Find the right test.
After the report, the part everyone misses
Most included retests expire 30 to 90 days after the report, and most teams discover the deadline by missing it. Give the planner your report date, your window and your release cadence and it returns the day the fixes have to be in production, the day to book the retest, and whether your release schedule makes that possible at all. Plan the window, and the terms to negotiate before signing are on retest and remediation verification.
And one for the engineers
Eight questions, a base score, a severity rating and the vector string to paste into a report or a ticket. No email field on the page, and nothing is sent anywhere. It implements the published CVSS v3.1 base specification, including the changed-scope impact formula and coefficient that most quick online versions get wrong. Score a finding.
Before you sign: is it a test at all
The same three words are sold for both an automated scan exported to a template and a person spending a week inside your application. The wording in the two proposals is often identical, and the price difference is not. Six questions about the deliverable, the tester and the day count return a verdict with the signals that decided it. Check what you were quoted.
Before kickoff: will the tester be able to start
You bought days. A missing test account, a firewall nobody can change and an unassigned point of contact can take the first two of them, and the tester cannot hand them back at the end. The loss never shows on the invoice, only in a report that covers the login page well and the permissions model barely. Check your readiness, and clear the blockers before the window opens.
After the report: severity and deadlines
Report severities are the testing firm's judgement about a system they saw for a week. Sometimes your engineers are right to argue. Six questions about one finding return a band, a fix-by deadline for the ticket, and the sentence to send a customer who asks about it. Triage a finding.
Then check the document you will actually hand to customers. A summary letter without dates, scope or severity counts confirms that money changed hands and nothing else. Check your letter, and see what the two documents are for on report against attestation letter.
Then work out when the next one happens
Annual testing is a habit rather than a rule. A team shipping twice a day has released several hundred times between reports, and a team that froze its product two years ago is buying the same findings again. Five questions produce a twelve month calendar and the events that should pull a test forward. Plan the cadence.
Common questions
Do I have to give you an email address to use these?
No. The CVSS calculator has no email field at all. On the other nine the result renders in full as soon as you finish the questions, and the field underneath sends the written version with the reasoning set out. Skipping it costs you nothing.
Can I send the scope document to firms that are not in your directory?
Yes, and you should. It is your document. The point of it is that you get comparable quotes, and that works better the more firms you send it to. We would rather be the site that made your purchase go well than the one that fenced you in.
Why does the cost calculator show tester days as well as dollars?
Because the day count is the part you can actually check. Day rates in Canada sit in a fairly narrow band, so a quote well below the range almost always means fewer days rather than better value, and a quote well above it usually means the firm has scoped something you did not ask for. Either is worth a conversation before you sign.
In what order should I use them?
Which test, then cost, then scope, then quotes, then the readiness check before kickoff, then the retest planner once you have a report date. Skipping the scope document is the one that costs the most, because without it the quotes you compare are quotes for different work, and the difference stays invisible until the reports arrive.
Get quotes with your scope attached
Tell us what you need tested and we will put it in front of Canadian firms that do that work.
Get matched