If you've started calling around for a penetration test, you've probably noticed the quotes don't line up. One firm sends back $4,000. Another wants $45,000 for what sounds like the same scope. Neither number is wrong. They're pricing different things, done by different people, to different standards.
Here's what actually drives the cost of a penetration test in Canada in 2026, and how to scope one so you're not overpaying or underbuying.
The short answer
For a single web application or a small external network, most Canadian buyers land somewhere between $8,000 and $25,000 for a properly scoped, human-led test with a written report and a retest. Cloud environment reviews (AWS, Azure, GCP configuration and IAM testing) tend to run $10,000 to $30,000 depending on account complexity. Full external plus internal network tests for mid-market companies commonly land in the $20,000 to $60,000 range. Anything under $5,000 for a real application test is almost certainly automated scanning with a template report, not a person actually trying to break in.
Those ranges hold whether you're a SaaS company prepping evidence for a SOC 2 audit, a fintech dealing with PCI DSS, or a company that just wants to know where the holes are before an attacker finds them.
What actually moves the price
Scope size and complexity
Testers price by the number of authentication roles, API endpoints, subdomains, IP ranges, or cloud accounts in scope, not by a flat "per test" rate. A marketing site with a contact form costs almost nothing to test properly. A multi-tenant SaaS platform with five user roles, an API, and a partner integration is a different job entirely, because a tester has to walk every role's permission boundary, not just log in and poke around.
Human-led versus automated
A lot of what gets sold as "penetration testing" is a vulnerability scanner (Nessus, Qualys, Burp automated scan) with a consultant's name on the cover page. That's legitimate as a scanning service, but it isn't the same product as a person manually chaining findings together to see what an attacker could actually do. Human-led testing costs more because it takes longer and requires someone who understands how real exploitation works, not just what a scanner flags. This is the model we run at traztech: manual web, network, and cloud penetration testing led by a published security researcher, not a scan-and-report shop.
Who's actually doing the work
Three delivery models dominate the Canadian market, and they price differently for good reason:
- Solo consultant. Lowest cost, often $3,000 to $10,000 for a small scope. You get one person's methodology and one person's availability. Fine for a startup's first test if the consultant is genuinely skilled, but there's no second set of eyes and limited bench strength if they get sick mid-engagement.
- Platform / marketplace pentest-as-a-service. Mid-range pricing, usually $8,000 to $20,000, delivered through a subscription or credits model with rotating testers pulled from a crowdsourced pool. Fast to book, decent for continuous low-stakes testing, but you rarely know who's testing you or what their track record is, and report quality varies by whoever picked up the job that week.
- Boutique firm with senior-led delivery. Higher cost, typically $15,000 to $60,000+ depending on scope, but you're paying for named expertise, direct communication with the person doing the testing, and findings written for both engineers and auditors. This is where deep offensive-security experience (published CVEs, real exploit development, not just OSCP certification) shows up in the quality of what you get back.
The right choice depends on what the test needs to accomplish. A quick sanity check before a minor release is a different job than evidence for a Type II audit or a board-level risk assessment.
Compliance requirements
If the test needs to satisfy SOC 2, PCI DSS, or a customer's security questionnaire, the report has to be structured to hold up under an auditor's or a client's security team's scrutiny, not just list findings. That adds cost, but it also means the test does double duty: you get your security answer and your compliance evidence from one engagement instead of paying for both separately.
Retesting
Ask whether retesting is included. A test that finds critical vulnerabilities but doesn't verify they were actually fixed is only half finished. Retest fees, when not bundled, typically add $1,500 to $5,000. Get this in writing before you sign.
How to scope a test without overpaying
- Write down what's actually in scope before you ask for quotes. Domains, IP ranges, number of user roles, cloud accounts, API endpoints. Vague scopes get vague, inflated quotes because the tester is pricing in uncertainty.
- Decide what the test is for. A SOC 2 evidence requirement, a pre-launch check, and a response to a specific incident all call for different depth and different report formats.
- Ask who's doing the testing, not just who's selling it. Get names, backgrounds, and sample (redacted) report pages. A firm that won't tell you who's testing your production environment is a red flag regardless of price.
- Confirm retesting and report turnaround in the quote. These are the two line items most often left out and added back as surprise costs later.
- Don't scope everything at once if you don't need to. Testing your highest-risk external application first, then expanding to internal network and cloud in a later phase, is often cheaper overall and gets you answers faster on what matters most.
If you want current market rates for your specific environment, our pricing page breaks out ranges by test type, and it's a reasonable starting point before you get on calls with vendors.
Where traztech fits
We run human-led web, network, and cloud penetration testing, co-delivered with our offensive-security partner Lorikeet, and led by a researcher with six published CVEs including a CVSS 9.1 finding that functioned as a kill-switch for the Mirai botnet. Every engagement is scoped to double as SOC 2 or PCI evidence when you need it, so you're not paying for a security answer and a compliance answer separately.
Get a real number, not a guess
Price ranges are useful for budgeting, but the only accurate quote is one built around your actual scope. Contact us and we'll walk through your environment, tell you honestly what a proper test should cost, and scope it so you're not paying for more than you need.