GetPentest

Wireless penetration testing in Canada

Wireless testing is on-site work, which makes it one of the few engagements where geography changes the price. It is also one of the few nobody is required to buy, so the question is less what it costs and more whether your network shape justifies it at all.

Last reviewed 2026-09-01Written by Jacob Masse, TrazTech Inc.

A wireless penetration test in Canada costs between $6,000 and $18,000 CAD and runs two to four tester days, most of which are spent physically inside or beside your building. The price spread is almost entirely site count and travel: one office in the tester's own city sits at the bottom of that range, and three sites across two provinces sits at the top before anyone has looked at a single access point. The finding that justifies the engagement is usually not the wireless encryption at all. It is what the wireless network is connected to.

$6,000 to $18,000 Canadian wireless engagement, CAD

2 to 4 days Tester days, including travel

$2,500 to $5,000 Cost as an add-on to an internal network test

What the engagement actually covers

Wireless testing has two halves that get sold as one thing. The first is whether somebody in the parking lot can get onto your network. The second is what happens to them once they are on it, and that half is where the findings worth paying for live. A tester who only reports on the first half has run a survey, not a test.

Getting on the network

How hard this is depends on which authentication model you run, and the four in common use are not close to equivalent.

WPA2-PSK
One shared passphrase for everyone. A tester captures the four-way handshake, or the PMKID from the access point without waiting for a client at all, and cracks it offline against a wordlist. If your passphrase is your company name and a year, this takes minutes. The structural problem is not the cracking, it is that every employee who has ever left still knows the passphrase.
WPA3-SAE
The handshake is designed to resist offline dictionary attack, so the capture-and-crack route closes. Worth deploying. The common mistake is transition mode, which runs WPA3 and WPA2 on the same network name so older devices still connect, and a tester will simply ask to be treated as an older device.
802.1X with EAP-TLS
Per-device certificates, no passwords on the wire, and the strongest thing in ordinary use. Findings here tend to be about certificate lifecycle and which devices were exempted rather than about the protocol.
802.1X with PEAP or EAP-TTLS
Per-user credentials, which sounds better than a shared passphrase and often is not. If client devices are not configured to validate the RADIUS server certificate, a tester stands up a network with the same name, your laptops authenticate to it, and the credentials arrive. This is the single most common serious finding on Canadian enterprise wireless, and it is a device configuration problem rather than a network one.

What happens once they are on

This is the half that decides whether the engagement was worth the money. A tester who reaches your corporate wireless and finds themselves on the same broadcast domain as the file server, the domain controllers and the finance workstations has found something that costs real money to fix and would never have appeared in a report about encryption. The equivalent question on the guest network is whether guest traffic is genuinely isolated or merely on a different subnet that still routes to everything.

If that sounds like internal network testing, it is, which is why wireless is usually better bought as a bolt-on. The lateral movement work is set out on network penetration testing, and adding a wireless day to an internal engagement costs a fraction of commissioning wireless on its own.

Rogue and evil twin access points

Two different problems share a name. A rogue access point is something somebody in your own company plugged in: a consumer router under a desk, a printer with an open ad-hoc mode, a test lab that was never taken down. An evil twin is a tester or an attacker broadcasting your network name from their own hardware to collect connections. The first is an inventory and monitoring failure. The second is a client configuration failure. A useful report separates them, because the fixes are owned by different teams.

What it costs, itemised

Wireless engagement pricing by shape, Canadian firms, CAD
Engagement shapeTypical range
Single office, tester in the same city$6,000 to $10,000
Two or three sites, same metropolitan area$9,000 to $14,000
Multiple sites, travel and accommodation required$12,000 to $18,000
Added to an internal network test already scheduled$2,500 to $5,000

Written out as a quote for a two-site engagement at a $2,000 CAD day rate, with one site out of province, it looks like this. If your proposal does not break down this way, the section on what a quote should itemise covers what to ask for.

Worked example: two sites, one requiring travel, CAD
LineDaysAmount
Planning, network diagrams, site access arrangements0.5$1,000
On-site testing, head office1.0$2,000
On-site testing, second site1.0$2,000
Guest and corporate segmentation checks0.5$1,000
Reporting and readout1.0$2,000
Travel and accommodation, second site0$1,400
Total at $2,000 CAD a day plus expenses4.0$9,400

Comparing firms for this? Tell us what you need and it goes to the ones in the directory that do this work. No charge, and no phone number required.

Who should not buy this

Most Canadian companies under about 100 staff should not commission a standalone wireless test. If your office is leased space with an internet connection, a consumer-grade access point and a printer, your corporate wireless is functionally a coffee shop network. Everything of value is in a cloud tenancy that a tester in the parking lot cannot reach any better than a tester in Ottawa can. Buying a wireless test in that situation produces a report about a network that does not guard anything, and the money would find more in an authenticated test of the product itself, which is covered on web application security testing.

The shapes that justify it are specific. You run 802.1X and want to know whether the client certificate validation is enforced on every device. Your wireless reaches manufacturing equipment, building controls or medical devices that cannot be moved onto a wired segment. You have retail or branch locations where the same network carries payments and staff traffic. Or a customer questionnaire has asked the question directly, in which case the answer they want may be documentation rather than a test, and answering security questionnaires is the cheaper route.

The one framework that comes close

No major framework requires a wireless penetration test by name. PCI DSS requirement 11.2 comes closest: it requires that wireless access points be identified and monitored and that unauthorised ones be addressed, on a quarterly basis. That is a detection and inventory duty rather than a testing duty, and it can be satisfied with a documented scan and an access point inventory. SOC 2 and ISO 27001 say nothing specific about wireless at all. Anyone quoting you a wireless test to satisfy SOC 2 is guessing at what your auditor wants.

Scoping it properly

Wireless scoping needs two facts most buyers do not have to hand: the number of physical sites and the authentication model at each. A company with one office and WPA2-PSK is a two-day engagement. A company with nine branches, mixed WPA2 and 802.1X, and a corporate network that reaches point-of-sale terminals is a different purchase entirely and should be scoped against PCI DSS penetration testing requirements rather than as a general wireless review.

Say in the scope whether the tester may deauthenticate clients. Capturing a handshake the passive way means waiting for a device to connect on its own, which can take hours. Forcing it takes seconds and briefly disconnects real users. Both are legitimate, but the second needs to be authorised in writing before anyone arrives, and it belongs in the rules of engagement rather than in a hallway conversation. The scoping questionnaire produces a document you can send to several firms so the quotes describe the same visit.

Not sure wireless is the right spend

Tell us what your network looks like and who is asking, and we will say whether this engagement is worth commissioning.

Get matched

Common questions

Can a wireless test be done remotely?

No, not the part you are paying for. Wireless testing requires radio proximity, which means somebody has to be physically within range of your access points. A firm offering a remote wireless assessment is offering to review your controller configuration, which is a configuration review and worth having, but it will not tell you whether a laptop in your lobby accepts a forged RADIUS certificate.

Does WPA3 mean we can skip this?

It closes the offline cracking route, which is the attack most people have in mind, so it removes a real class of finding. It does not answer the question of what your wireless network is connected to, whether guest traffic is isolated, or whether a consumer router has been plugged in under somebody's desk. Check whether you are running WPA3 in transition mode as well, because that keeps the WPA2 path open for anyone who asks for it.

How much extra does travel add in Canada?

Budget $800 to $2,000 CAD per out-of-province site for flights, accommodation and the day lost getting there, and confirm whether travel time is billed at the day rate or at a reduced rate. Some firms bill it in full and some absorb it, and on a three-site engagement the difference is a four-figure number. Ask before you compare two proposals.

Will the test knock our staff offline?

It can, briefly, if you authorise deauthentication. Forcing a device to reconnect so the handshake can be captured drops that device for a few seconds. A careful tester targets one device rather than the whole network, and schedules it outside your busiest hours. If any interruption is unacceptable, say so in the scope and accept that the passive capture takes longer and costs more.

Do we need this every year?

Almost certainly not. Wireless changes slowly, so unless you have replaced the access point estate, changed authentication model, opened a site or moved office, an annual repeat finds the same things. Retest when the estate changes rather than on a calendar, and put the recurring budget into the testing your customers and auditors actually ask about. The reasoning behind test frequency generally is on how often you should test.