GetPentest

Which penetration test do you need?

The word penetration test covers seven or eight different engagements. Buying the wrong one is the most expensive mistake in this category, because you find out at evidence review and by then the deal has a date on it.

Last reviewed 2026-08-27Written by Jacob Masse, TrazTech Inc.

Scope follows the asset and the requirement, not the vocabulary in the proposal. Five questions gets to the right engagement for almost every Canadian company. The answer appears on this page with the range it should cost and a page explaining what that test contains.

What are you trying to protect?

Pick the thing that would hurt most if someone reached it.

Who asked for this?

Have you been tested before?

Is anyone watching your alerts today?

This decides whether a red team exercise would tell you anything you do not already know.

How many people work there?

When do you need it?

The version without the questions

If you would rather read the table than answer anything, this is the same routing.

Asset to engagement
What you haveWhat to buyCAD
A SaaS product with rolesAuthenticated web application test, with the API named separately$10,000 to $30,000
An API with no front endAPI penetration test across two roles and two tenants$8,000 to $25,000
A mobile appMobile test plus the backend it calls$14,000 to $30,000
An office networkInternal network test, assumed breach$12,000 to $28,000
A cloud accountConfiguration and identity review$8,000 to $18,000
Card data in your systemsInternal, external and segmentation testing$20,000 to $40,000
A mature program testing its defendersRed team, and only then$50,000 and up

The two mistakes this exists to prevent

The first is buying an unauthenticated test of a product whose entire risk lives behind the login. It is cheaper, it produces a shorter report, and it answers a question nobody asked. The second is buying a red team before there is anything to detect it, which spends $50,000 CAD to learn that nobody was watching, a fact available for free by asking.

If a scan is what you are being sold, the difference is on vulnerability assessment versus penetration test and the price arithmetic that exposes it is on how much a pentest costs.

Get quoted for whichever it turned out to be

Tell us the scope and we will put it in front of Canadian firms that do that work.

Get matched

Common questions

Can one engagement cover several of these?

Yes, and most do. A common shape is an authenticated application test plus the API plus a cloud configuration review, quoted as one engagement with one report. Combining pays the reporting overhead once and gives the tester context across surfaces, which is where the better findings come from. What it must not do is shrink the day count for each part to fit a combined price.

We were told we need a red team. Do we?

Almost certainly not, unless you have monitoring and someone whose job is to respond. A red team measures detection, so with nothing detecting, the exercise succeeds on day two and tells you what you already knew. The order that works is application and network testing until findings stop being structural, then detection engineering, then purple teaming, then a red team.

Our auditor just said penetration test. What does that mean?

It means an independent test of the systems named in your scope statement, with evidence that you fixed what it found. Neither SOC 2 nor ISO 27001 specifies a test type, so the answer comes from your architecture rather than from the framework. Test what holds customer data, from the outside and while logged in.

Is a cheaper scan enough to satisfy a customer questionnaire?

Read the clause. Most say penetration test and mean a dated independent report, and security teams reviewing it have learned to recognize scanner output. Where a questionnaire asks only whether you perform vulnerability scanning, scanning answers it honestly and you should not over-buy.

What do we do with the answer?

Write the scope down and send the same document to three firms. The scoping questionnaire produces it, and it is the only reliable way to get quotes that describe the same engagement.