If you've started calling around for a penetration test, you've probably noticed the quotes don't line up. One firm sends back $4,000. Another wants $45,000 for what sounds like the same scope. Neither number is wrong. They're pricing different things, done by different people, to different standards.
Here's what actually drives the cost of a penetration test in Canada in 2026, and how to scope one so you're not overpaying or underbuying.
The short answer
For a single web application or a small external network, most Canadian buyers land somewhere between $8,000 and $25,000 for a properly scoped, human-led test with a written report and a retest. Cloud environment reviews (AWS, Azure, GCP configuration and IAM testing) tend to run $10,000 to $30,000 depending on account complexity. Full external plus internal network tests for mid-market companies commonly land in the $20,000 to $60,000 range. Anything under $5,000 for a real application test is almost certainly automated scanning with a template report, not a person actually trying to break in.
Those ranges hold whether you're a SaaS company prepping evidence for a SOC 2 audit, a fintech dealing with PCI DSS, or a company that just wants to know where the holes are before an attacker finds them.
What actually moves the price
Scope size and complexity
Testers price by the number of authentication roles, API endpoints, subdomains, IP ranges, or cloud accounts in scope, not by a flat "per test" rate. A marketing site with a contact form costs almost nothing to test properly. A multi-tenant SaaS platform with five user roles, an API, and a partner integration is a different job entirely, because a tester has to walk every role's permission boundary, not just log in and poke around.
Human-led versus automated
A lot of what gets sold as "penetration testing" is a vulnerability scanner (Nessus, Qualys, Burp automated scan) with a consultant's name on the cover page. That's legitimate as a scanning service, but it isn't the same product as a person manually chaining findings together to see what an attacker could actually do. Human-led testing costs more because it takes longer and requires someone who understands how real exploitation works, not just what a scanner flags. This is the model we run at traztech: manual web, network, and cloud penetration testing led by a published security researcher, not a scan-and-report shop.
Who's actually doing the work
Three delivery models dominate the Canadian market, and they price differently for good reason:
- Solo consultant. Lowest cost, often $3,000 to $10,000 for a small scope. You get one person's methodology and one person's availability. Fine for a startup's first test if the consultant is genuinely skilled, but there's no second set of eyes and limited bench strength if they get sick mid-engagement.
- Platform / marketplace pentest-as-a-service. Mid-range pricing, usually $8,000 to $20,000, delivered through a subscription or credits model with rotating testers pulled from a crowdsourced pool. Fast to book, decent for continuous low-stakes testing, but you rarely know who's testing you or what their track record is, and report quality varies by whoever picked up the job that week.
- Boutique firm with senior-led delivery. Higher cost, typically $15,000 to $60,000+ depending on scope, but you're paying for named expertise, direct communication with the person doing the testing, and findings written for both engineers and auditors. This is where deep offensive-security experience (published CVEs, real exploit development, not just OSCP certification) shows up in the quality of what you get back.
The right choice depends on what the test needs to accomplish. A quick sanity check before a minor release is a different job than evidence for a Type II audit or a board-level risk assessment.
Compliance requirements
If the test needs to satisfy SOC 2, PCI DSS, or a customer's security questionnaire, the report has to be structured to hold up under an auditor's or a client's security team's scrutiny, not just list findings. That adds cost, but it also means the test does double duty: you get your security answer and your compliance evidence from one engagement instead of paying for both separately.
Retesting
Ask whether retesting is included. A test that finds critical vulnerabilities but doesn't verify they were actually fixed is only half finished. Retest fees, when not bundled, typically add $1,500 to $5,000. Get this in writing before you sign.
How to scope a test without overpaying
- Write down what's actually in scope before you ask for quotes. Domains, IP ranges, number of user roles, cloud accounts, API endpoints. Vague scopes get vague, inflated quotes because the tester is pricing in uncertainty.
- Decide what the test is for. A SOC 2 evidence requirement, a pre-launch check, and a response to a specific incident all call for different depth and different report formats.
- Ask who's doing the testing, not just who's selling it. Get names, backgrounds, and sample (redacted) report pages. A firm that won't tell you who's testing your production environment is a red flag regardless of price.
- Confirm retesting and report turnaround in the quote. These are the two line items most often left out and added back as surprise costs later.
- Don't scope everything at once if you don't need to. Testing your highest-risk external application first, then expanding to internal network and cloud in a later phase, is often cheaper overall and gets you answers faster on what matters most.
If you want current market rates for your specific environment, our pricing page breaks out ranges by test type, and it's a reasonable starting point before you get on calls with vendors.
Where traztech fits
We run human-led web, network, and cloud penetration testing, delivered with our offensive-security partner Lorikeet, and led by a researcher with five published CVEs including a CVSS 9.1 finding that functioned as a kill-switch for the Mirai botnet. Every engagement is scoped to double as SOC 2 or PCI evidence when you need it, so you're not paying for a security answer and a compliance answer separately.
Get a real number, not a guess
Price ranges are useful for budgeting, but the only accurate quote is one built around your actual scope. Contact us and we'll walk through your environment, tell you honestly what a proper test should cost, and scope it so you're not paying for more than you need.
Reverse-engineer the quote into tester days
Every quote you receive is a day rate multiplied by a number of days, with some margin and project management on top. Senior offensive-security day rates in Canada sit roughly between $1,800 and $3,000, and once you know that, a quote stops being a mystery number. A $12,000 engagement is somewhere near five testing days plus reporting. A $4,000 engagement is a day and a half, which is not enough time to authenticate as five different roles and walk their permission boundaries, so you now know what you are buying.
Ask any vendor two questions: how many days of hands-on testing are in this, and how many of those days are reporting rather than testing. A firm that quotes eight days and spends three of them writing is selling you five days of testing. That is not automatically bad, since the report is the artifact your buyer reads, but you should know the split before you compare two quotes that look identical on price. Vendors who refuse to break out days are usually protecting a margin they do not want examined, and that refusal tells you as much as the answer would have.
The line items that show up after you sign
Retesting is the one most buyers now think to ask about. The ones they miss are less obvious. Remediation support, meaning the tester's time on calls with your engineers while they fix things, is frequently billed separately at an hourly rate. An executive readout for your board or your customer's security team may be extra. A letter of attestation, the one-page summary you can hand to a prospect who is not entitled to the full report, is sometimes a paid deliverable and sometimes free, and it is worth confirming because that letter is what most procurement teams actually accept.
Then there is rescoping. If the tester arrives and finds nine subdomains where the scope document said four, or an admin portal nobody mentioned, the change order lands mid-engagement when you have no leverage. The fix is on your side: build the asset inventory before you request quotes, not after. Finally, check whether the price is quoted in Canadian or US dollars. A meaningful share of firms serving this market price in USD, and a $20,000 quote is not a $20,000 quote when it settles.
Environment choices that move the price more than scope does
Testing against production costs less than testing against a staging environment that has to be built for the purpose. Testing against a staging environment that already exists and mirrors production is the cheapest option of all, because the tester can be aggressive without a change freeze conversation. Where teams lose money is the middle case: a staging environment that exists but has no realistic data, no third-party integrations wired up, and half the features behind flags. The tester spends two of the five days getting the environment into a testable state, and you paid a senior rate for setup work.
The same applies to test accounts. If the tester needs one account per role and you provision them on day two instead of before kickoff, you have lost a day. If your application has an email verification step or a manual KYC approval that takes 48 hours, say so during scoping so accounts can be created in advance. And decide early whether your WAF or bot protection stays on. Testing through a WAF measures your WAF, which is a legitimate thing to measure, but if the goal is finding application flaws you want the tester allowlisted at the edge, and that decision needs to be made by someone who can actually change the firewall.
What the buyer asking for the test will accept
Cost follows from the standard you are being held to, so find out what that standard is before you scope. A SOC 2 auditor generally wants evidence that a test happened in the audit period, that findings were tracked, and that remediation was managed. They rarely dictate methodology. PCI DSS is far more prescriptive: segmentation testing is required where you rely on segmentation to reduce scope, internal and external testing are both in play, and the methodology has to be documented and followed. A bank partner or an enterprise security team may have its own template, and some large buyers will insist the test cover an authenticated attack path rather than an unauthenticated perimeter sweep.
Cyber insurance underwriters are the least demanding on methodology and the most demanding on recency. Most want a test within the last twelve months, which means a cheap test done early in the year is worth less than a properly scoped test timed to your renewal. Ask the person requesting the report what they will do with it. If the honest answer is that they file it, a smaller scope satisfies them. If the answer is that their security engineer reads the findings section, buy the depth.
A worked scoping example
Take a Canadian SaaS company with one customer-facing web application, three roles being admin, standard user and read-only auditor, a REST API with about sixty endpoints, a single AWS account, and a marketing site on a separate host. A reasonable scope is an authenticated web and API test covering all three roles with a focus on horizontal and vertical authorization, plus an external perimeter check on the AWS footprint. That is realistically six to eight testing days, so expect quotes clustering between $12,000 and $20,000 including report and retest.
Now change one variable. Add a second product line with its own authentication, and you have not doubled the work, but you have added the tenant isolation question, which is where multi-tenant SaaS actually breaks. Expect three or four more days. Alternatively, drop the marketing site from scope, since it holds no data and runs on a hosted CMS, and you save perhaps half a day. Scoping discipline is mostly the ability to say what is genuinely worth a senior tester's time and what is being included because it appeared on an inventory.
When you should not buy a penetration test
If nobody has asked for one and you have never run a vulnerability scan, patched your dependencies, or turned on multi-factor authentication for administrative access, a penetration test is the wrong first purchase. You will pay senior rates for someone to write down what a free scanner would have told you in an afternoon. Run the scanner, fix what it finds, get your cloud provider's own security tooling switched on, and then buy the test so the tester spends the time on things a tool cannot find.
If the requirement is a security questionnaire that asks whether you perform regular vulnerability scanning, buy scanning. It is a fraction of the cost and it is the honest answer to the question asked. Some buyers genuinely will accept a scan plus a documented remediation process, and the vendors who tell you otherwise are the ones selling the more expensive product.
If you have no engineering capacity to remediate for the next quarter, delay. A report full of critical findings you cannot fix is worse than no report, because you now hold documented knowledge of an unremediated flaw, which changes your position materially if something happens. Test when there is a team ready to act on the output.
And if you are pre-launch with no users, no production data and a product that changes weekly, wait until the architecture settles. A test against a codebase that will be rewritten in two months is money spent on a snapshot nobody will refer to again.
The sample report tells you what you are paying for
Ask every vendor for a redacted sample before you compare prices, and read the findings rather than the cover design. A finding written by a tool contains a generic description, a generic remediation paragraph, and a reference to a CVE. A finding written by a person contains the specific request that triggered it, the specific response, what the tester was able to reach as a result, and remediation advice that names your framework or your cloud provider rather than describing the vulnerability class in general.
Check the executive summary too. If it says the environment demonstrated a moderate security posture and lists counts by severity, it was written to a template. If it explains the most serious attack path in plain language and states what an attacker would have achieved, someone thought about your business. The difference between those two documents is most of the price difference between two quotes, and it is the only part of the deliverable your customer's security reviewer will ever read closely.
Buying patterns that quietly cost more
Multi-year contracts with annual credits look economical and often are not, because credits expire on the vendor's calendar rather than when your release schedule allows testing. Per-asset pricing models penalize you for having a tidy inventory, since every subdomain you honestly declare adds cost while a competitor's messier client declares four hosts and pays less. Subscription testing sold as continuous coverage can be excellent for regression checks and weak for depth, because short recurring bursts rarely leave time to chain findings together.
The most expensive pattern is the annual rush. A test booked three weeks before an audit deadline attracts a premium, leaves no room for remediation before the report is issued, and produces the outcome you were trying to avoid. Booking six to eight weeks out costs the same and gets you a retest inside the same cycle.
If you want the current fixed-scope ranges, they are published at /pricing, and the methodology behind our testing work sits under /solutions/security. If you would rather have testing tied into an ongoing remediation and evidence cadence rather than bought once a year, that is what the retainer at /engage covers.
Need the testing done? Penetration testing and vulnerability management, with the retest that proves a finding is actually closed.
Penetration testingOr talk about a retainerWhat we charge for this. The figures above are market ranges. Our own fixed-scope prices are on the pricing page, alongside every cost breakdown we have written.