Penetration testing cost calculator
Six questions, then a range in Canadian dollars with the tester days and the day rate it was built from, so you can check the arithmetic against any quote you have been sent.
Every penetration testing quote is tester days multiplied by a day rate, plus reporting. This applies that model to a scope you describe, using Canadian day rates of roughly $1,500 to $2,800 CAD. The result is a range, not a number. Anyone quoting a precise figure without seeing your system is guessing.
The estimate appears on this page. Nothing is emailed anywhere unless you ask for it at the end.
On its way
Check your inbox shortly. If you would rather talk it through, book a time.
The model this uses
Base tester days by surface, multiplied by a factor for how much of it there is and another for how many roles are being tested, plus reporting time and an optional retest. Days are then priced at $1,500 to $2,800 CAD, which is what a qualified tester in Canada costs once salary, tooling, insurance and overhead are counted. The derivation is on penetration testing cost in Canada.
| Surface | Base days |
|---|---|
| Web application | 5 to 9 |
| API | 4 to 7 |
| External network | 3 to 5 |
| Internal network | 5 to 9 |
| Cloud account | 4 to 7 |
| Mobile app and backend | 5 to 9 |
| PCI segmentation | 2 to 4 |
Checking a quote you already have
Divide the quoted price by $2,000 CAD, the middle of the Canadian day rate range. That gives you roughly the number of days the firm can afford to spend, reporting included. Then ask whether that many days is enough for the scope you described. A $4,000 quote is two days. Two days does not include a person learning your product, obtaining credentials, and comparing what two accounts can reach, whatever the proposal says about methodology.
Then ask the firm how many tester days are in the engagement. A firm that costed the work properly answers in a sentence. One that answers only in tools and coverage has told you something useful.
Get real quotes on one scope
Tell us the scope once and we will put it in front of Canadian firms, so the numbers you get back describe the same engagement.
Get matchedCommon questions
Why is the range so wide?
Because two firms doing the same competent work at different overheads genuinely differ by that much, and because scope details we have not asked about move the day count. The width is the honest answer at this stage. It narrows once someone has seen your architecture, which is what a scoping call is for.
Does this include the cost of fixing what is found?
No, and that is usually the largest number in the whole exercise. A serious authorization finding can take weeks of engineering to fix properly. Budget for remediation before the report arrives, and book the retest window with the fix work in mind rather than the other way round.
Is it cheaper to combine several tests into one engagement?
Yes, moderately. Reporting overhead is paid once and the tester carries context across surfaces, which is also where the better findings come from. Expect a combined quote close to the sum of the tester days rather than a large discount on them. What should not happen is the days for each part shrinking to fit a combined price.
Do Canadian firms charge more than American ones?
Rates are broadly comparable once currency is accounted for, and the variable that matters more is firm size. The same scope quoted to an independent, a mid-market consultancy and a national firm's security practice commonly varies by a factor of two, and much of that gap is overhead rather than tester capability.
How do we make three quotes comparable?
Send all three the same written scope. Most of the five-fold variance buyers report comes from three firms understanding the request three different ways rather than from anyone overcharging. The scoping questionnaire produces that document.