Security

Real offensive depth

Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Security

How Much Does Threat and Risk Assessment Cost in Canada? (2026)

A formal threat and risk assessment (TRA) in Canada typically runs from $6,000 to $15,000 for a single-application or vendor-scoped engagement, and $18,000 to $45,000 or more for a multi-system, enterprise-wide, or government-procurement-grade assessment. The final number depends less on company size and more on scope, documentation depth, and whether the deliverable has to satisfy a specific framework like Harmonized TRA (HTRA) for federal procurement or a bank's third-party vendor review.

What a Threat and Risk Assessment Actually Costs in Canada

Most Canadian buyers searching for TRA pricing are trying to answer one question: is the quote in front of them fair. Here is a realistic breakdown by engagement type, in CAD, based on typical scope and deliverable depth seen across the market:

  • Lightweight / single-application TRA: $6,000 to $10,000. One system, one business owner, a threat model and a risk register with mitigations.
  • Standard vendor or product TRA: $10,000 to $18,000. Includes architecture review, data flow mapping, and a formal report suitable for a bank, insurer, or enterprise procurement team.
  • Government-aligned TRA (HTRA-style): $20,000 to $40,000+. Structured statement of sensitivity, threat agent analysis, and residual risk sign-off, formatted to what federal and provincial procurement officers expect.
  • Enterprise, multi-system TRA: $30,000 to $60,000+. Multiple applications, cloud environments, or business units assessed under one program, often tied to an existing ISO 27001 or SOC 2 program.

These ranges assume a documented, defensible deliverable, not a checklist. A TRA produced for a bank's vendor risk team or a federal procurement officer has to hold up under scrutiny, which is a different deliverable than an internal risk memo nobody outside the company will read.

Why Prices Vary So Much: The Real Cost Drivers

The spread between a $6,000 TRA and a $40,000 one is not markup, it is scope. The variables that actually move price:

  • Number of systems and data flows in scope. A single SaaS product is a few days of work. A payment platform touching three environments and two third-party processors is weeks.
  • Who the deliverable is for. An internal risk exercise is cheaper than a document that has to satisfy a Canadian federal procurement evaluator or an enterprise vendor security team, because the latter demands a specific structure and level of evidence.
  • Regulatory context. A TRA that has to demonstrate PIPEDA alignment, or Quebec Law 25 compliance for a Montreal-based company handling personal information, needs privacy-specific threat scenarios built in, not bolted on afterward.
  • Access and evidence quality. If your architecture diagrams, data inventories, and system owners are ready, the assessor spends time analyzing risk instead of chasing documentation. Disorganized evidence adds days.
  • Interviews and stakeholder count. Every additional business owner, developer team, or third-party contact adds coordination time that shows up in the invoice.

Boutique Firm vs Compliance Platform vs Solo Consultant

Canadian buyers generally choose between three delivery models, and each has a distinct price-to-quality tradeoff.

Compliance Platforms

Automated platforms (the Vanta and Drata category) are built for continuous control monitoring, not for producing a standalone, human-authored threat and risk assessment document. Some offer templated risk assessment modules, but a bank, insurer, or federal procurement reviewer asking for a TRA usually wants a named analyst's judgment behind the threat modelling, not a generated report. Platforms are excellent for ongoing SOC 2 evidence collection; they are a weak substitute for a defensible, one-off TRA deliverable.

Solo Consultants

Independent consultants can be the cheapest option and, if experienced, produce solid work. The risk is bandwidth and bench depth: a solo practitioner juggling multiple clients can stretch timelines, and there is no second reviewer checking the threat model before it goes out the door. For a low-stakes internal assessment, this is often fine. For a document going in front of a government evaluator, it is a gamble.

Boutique Security and Compliance Firms

A boutique firm sits between the two: senior-led delivery like a solo consultant, but with process discipline, quality review, and enough capacity to hit procurement deadlines. traztech runs its threat and risk assessment engagements this way, led directly by a security researcher rather than handed to a junior analyst working off a template. That matters most when the TRA is going to a Canadian government buyer or an enterprise vendor risk team that will actually read it line by line.

Want this handled? Tell us what your buyer is asking for and we will tell you what the work involves, what it costs, and what you can do yourself. Talk to us

Government Procurement and Enterprise Vendor Review Requirements

If your TRA is feeding a Canadian federal, provincial, or municipal procurement process, the bar is higher than a generic risk assessment. Evaluators expect a structured statement of sensitivity, defined threat agents, likelihood and impact ratings tied to a recognized methodology, and clear residual risk sign-off. Cutting corners here does not save money, it gets the submission bounced back for rework, which costs more in elapsed time than paying for a properly scoped assessment the first time.

The same discipline applies to enterprise vendor security reviews. A Toronto fintech or a Calgary energy company doing due diligence on a new SaaS vendor wants a TRA that maps threats to actual data flows and third-party dependencies, not a boilerplate document swapped out with a new company name. If your TRA is part of a broader push toward a security certification, it is worth pairing it with the underlying compliance work so the risk register and the control framework stay consistent instead of drifting apart.

How to Scope a TRA Without Overpaying

The fastest way to control cost is to control scope before you request a quote, not after.

  • Define the boundary first. Is this one application, one vendor relationship, or the whole environment? Vague scope is the single biggest driver of quote inflation.
  • Name the audience. A procurement officer, an enterprise vendor risk team, and your own board want different levels of formality. Tell the assessor who reads the final document.
  • Gather your artifacts early. Architecture diagrams, a data inventory, and a list of third-party integrations before kickoff can cut a week off the timeline.
  • Ask what happens after year one. A TRA is a snapshot. If your risk profile changes with every product release, ask whether the firm offers a lighter-touch annual refresh instead of a full re-scope each time.
  • Get the price in writing against a fixed scope, not an hourly estimate. Fixed-fee scoping is how you avoid a $10,000 quote turning into $22,000 halfway through.

Where Canadian Companies Are Buying TRAs From

Demand for formal threat and risk assessments is concentrated wherever regulated or venture-backed tech is growing: Toronto and Waterloo for fintech and SaaS scaling into the US market, Ottawa for companies touching federal contracts and government IT, Vancouver and Calgary for energy, resource, and cross-border SaaS plays, and Montreal where Quebec's Law 25 adds a privacy-specific layer most generic risk templates miss. A Canadian-based assessor who already understands PIPEDA and Law 25 produces a tighter, faster TRA than a US-based platform retrofitting Canadian context onto an American template.

Getting a Real Quote

The only way to get an accurate number is to have the scope conversation with someone who will actually do the work, not a sales rep reading off a pricing tier. traztech scopes threat and risk assessments the same way for a solo SaaS founder in Waterloo and an enterprise vendor review out of Toronto: define the boundary, quote a fixed fee, and deliver a document a procurement officer or auditor can actually rely on. Contact traztech for a scoped quote, or if your TRA is part of a larger SOC 2 or ISO 27001 push, start with the broader security program review first so the assessment fits the bigger picture instead of duplicating work later.

What You Are Actually Buying: The Anatomy of the Deliverable

Quotes are hard to compare because "threat and risk assessment" describes documents of wildly different weight. Before you compare two numbers, get both firms to tell you which of these sections the report will contain.

Statement of sensitivity. A classification of the information in scope against confidentiality, integrity and availability, with an injury assessment describing what happens at each level if it is compromised. Federal and provincial evaluators expect this and will send the document back without it.

Asset and data flow inventory. What is in scope, where it runs, who administers it, and how data crosses trust boundaries. This is the section that determines whether the rest of the report is grounded or generic.

Threat agent analysis. Named categories of adversary with capability and motivation, plus deliberate non-adversarial threats such as system failure, supplier collapse and human error. A report that only discusses hackers is half a report.

Vulnerability and control assessment. The current safeguards, tested or at least evidenced, not assumed from a questionnaire.

Risk matrix with method stated. Likelihood and impact scales defined in writing before scoring, so a reader can reproduce a rating rather than take it on faith.

Recommendations with effort and cost. Prioritised, owned, and costed at least roughly. Recommendations without effort estimates are a wish list.

Residual risk statement and sign-off page. What remains after the recommended safeguards, and space for an accountable executive to accept it.

The last item is where cheap assessments consistently stop short, and it is the section the buyer's audience cares most about. Procurement evaluators and bank vendor risk teams are looking for evidence that somebody with authority looked at the remaining exposure and accepted it deliberately.

Where the Days Actually Go

A mid-range engagement in the $10,000 to $18,000 band is usually eight to fifteen consulting days, and the split is less flattering to the analysis than buyers expect. Roughly two days go into scoping and document collection, three to five into interviews and technical review, two to four into analysis and risk scoring, and two to three into writing, internal review and the walkthrough. Writing and review are not padding. A report going to a procurement evaluator is read adversarially, and a sloppy one costs the client the contract it was bought to win.

Elapsed time runs longer than consulting days, typically three to six weeks for that band, because interviews depend on other people's calendars. The single largest schedule risk on any TRA is a system owner on vacation. If you have a submission deadline, name it at scoping and book the interviews before the contract is signed, not after.

Government-grade work stretches for structural reasons rather than effort inflation. There is more formality in the statement of sensitivity, more evidence expected behind each control assertion, and usually a review cycle with the client's own security authority before submission. Budget two extra weeks for that review cycle and do not treat the draft delivery date as the finish line.

Red Flags in a TRA Proposal

Some proposals are cheap because the scope is small, and some are cheap because the document will not do the job. Signals worth checking:

No named author. Ask who writes the report and who reviews it. If the proposal will not name the individual, or names a senior person who turns out to be a sales contact, the work is going to a template and a junior.

No interviews in the schedule. A TRA built entirely from a questionnaire is a control gap analysis with a different cover page. Threat modelling requires somebody to ask why an architecture is the way it is, and the answer is never in the questionnaire.

The methodology is unnamed. The firm should be able to say what method the risk scoring follows and show you the scales. "Our proprietary methodology" without a defined scale means the ratings are one person's intuition, which is fine internally and indefensible in front of an evaluator.

Fixed page count. Pricing by report length rewards padding. Long TRAs are common and mostly padded with framework boilerplate that the reader skips to reach the risk register.

No revision round included. Your stakeholders will have comments and your audience may come back with questions. If a revision round is a change order, the quoted price is not the price.

What Is Usually Excluded, and What That Costs Later

Read the exclusions before the fee. The items most often outside scope, in rough order of how much they cost when you need them:

Remediation. The TRA tells you what to fix. Fixing it is separate work and frequently larger than the assessment itself. If a firm's recommendations conveniently require exactly the services they sell, read them with that in mind.

Retest or verification. If your buyer wants confirmation that the high risks were closed, somebody has to check. Ask whether a verification pass is quoted and what it costs.

Penetration testing. A TRA assesses risk. It does not attempt exploitation. Some buyers expect both and discover the gap at submission. Where technical validation genuinely matters, scope a test alongside rather than assuming the assessment covers it.

Presenting the report to your customer. Enterprise vendor reviews and government evaluations sometimes involve a call where the assessor defends the methodology. That call is worth having a real analyst on. Ask whether it is included.

Updates within the year. Your architecture will change. A refresh clause negotiated at signature is far cheaper than a new engagement in month seven.

TRA, PIA, Pentest and Gap Assessment Are Four Different Purchases

A surprising share of TRA enquiries turn out to be for something else, and buying the wrong document wastes the whole budget.

A vulnerability assessment lists technical weaknesses found by scanning. It is cheap, automated, and answers nothing about business risk. A penetration test attempts exploitation to prove what an attacker could achieve, and at traztech starts from $1,000 depending on the target. A gap assessment measures you against a named control framework and outputs a remediation plan. A threat and risk assessment reasons about what could harm your specific information assets and what residual exposure remains.

Separately, a privacy impact assessment is a distinct instrument concerned with personal information handling, lawful basis, retention and individual rights. Quebec's Law 25 requires a privacy impact assessment in defined circumstances, including certain projects involving personal information and transfers outside the province. A TRA does not discharge that obligation, and a firm that offers to fold it in should be asked to show which sections address it. The two documents share inputs and can be run together economically, but they answer to different readers.

If your customer's request simply says "send us your risk assessment", ask them which of these four they mean before you buy anything. The answer is often a gap assessment against their own framework, which is cheaper than everything above.

Who Owns the Report and Who You Are Allowed to Send It To

This is the clause buyers skip and later regret. A TRA is written for an audience, and the contract usually says something about who that audience is. If the wording restricts distribution to the named recipient, and six months later a second prospect asks for the same document, you are either negotiating an amendment or paying for a fresh assessment.

Ask for distribution rights up front. The version most firms will agree to is unlimited internal use plus disclosure to customers, prospects and regulators under NDA, with resale or public posting excluded. That covers every realistic use and costs the firm nothing, but it is far easier to agree before signature than after delivery.

Ask whether a redacted version is included. A full TRA names hostnames, internal architecture and unremediated weaknesses. Sending that to a prospect during a sales cycle is not sensible. What you usually want to circulate is a summary carrying the scope, the methodology, the risk profile and the sign-off, with the specifics of live weaknesses stripped. Some firms produce that as standard, some bill for it, and almost none volunteer it unless asked.

Settle what happens to the evidence. The assessor will hold diagrams, configuration exports and interview notes describing exactly how to attack you. The contract should say where that material lives during the engagement, how long it is retained afterwards, and that it is destroyed or returned on request. Your own customers will eventually ask you this about your suppliers, so answering it about your assessor is good practice.

Check the language obligation before you sign. If the report is going to a Quebec buyer or a provincial body, ask whether a French version is included or billed separately, and whether the translation is done by someone who understands the subject matter. A machine-translated risk register reads badly to the person evaluating you.

Where the TRA exists because of a wider certification push, the same ownership questions apply to the risk register underneath it, and that register should stay with you rather than with the firm. Our compliance engagements treat it as shared infrastructure for exactly that reason, and retainer options are on /engage.

When You Should Not Buy One

Three situations where the honest advice is to keep the money.

If nobody outside your company has asked for a TRA and you simply want to understand your exposure, run it yourself first. A workshop with your engineering leads, a whiteboard of data flows, and a risk register with owners and dates will surface most of what a paid assessment surfaces at your size. The free traztech Workspace includes a risk register and vendor questionnaires at no cost, which covers the mechanics. Buy an external assessment when the document needs to be independent, not when you need the thinking.

If the request came from a customer whose questionnaire actually asks for SOC 2 or ISO 27001 evidence, a TRA will not satisfy it, and buying one delays the work they wanted. Read the underlying request rather than the covering email.

If you are pre-revenue with one application and no regulated data, a $20,000 government-grade assessment is the wrong instrument even when a prospective partner mentions it, because the assessment cost exceeds the value of everything it protects. Say that out loud to the partner. In our experience the requirement is often softer than the email implied, and a shorter scoped assessment or a completed security questionnaire clears it. If it does not, the scoped conversation is free: tell us what your buyer asked for and we will tell you which of the four documents above you actually need.

Want this handled? Tell us what your buyer is asking for and we will tell you what the work involves, what it costs, and what you can do yourself.

Talk to usOr talk about a retainer

What we charge for this. The figures above are market ranges. Our own fixed-scope prices are on the pricing page, alongside every cost breakdown we have written.

Before you go

Want the rest of this by email?

If this was useful, I send a few short notes on security posture. Unsubscribe in one click, and replies reach me directly.

From Jacob Masse, principal of traztech. No spam, unsubscribe in one click.

Want a second opinion on where you stand?

We run SOC 2, ISO 27001 and the rest of the compliance stack for startups and SMEs, and the security testing that sits behind it. The first call is free, and we will tell you if you are not ready to start yet.

Book a free call

Track record

Who is actually doing the work

5
Published CVEs, including a CVSS 9.1
76
Controls taken from nothing to a passed SOC 2 Type II
Zero
Exceptions on that Type II report
20+
Penetration testing engagements delivered

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.