Testing and defence led by a published security researcher with six CVEs, including a CVSS 9.1 Mirai botnet kill-switch.
All security →SOC 2, ISO, CPCSC, and the Canadian privacy stack, run end to end with an independent auditor.
All frameworks →Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.
Read the blog →Who the genuine specialists are, what a test costs here, and the question almost nobody asks until it is too late: what happens to the findings after the report lands.
Most penetration testing guides rank firms by how good they are at breaking in. That is the right question if you are buying offensive security. It is the wrong question if you are buying a penetration test because an auditor, an enterprise customer or an insurer asked for one, which is why most Canadian companies buy their first test.
This guide covers both. Who the genuine specialists are, what a test costs in Canada, and the question almost nobody asks until it is too late: what happens to the findings afterwards.
Three different purchases get called "a pen test".
A compliance test. Somebody asked for one. SOC 2, ISO 27001, PCI DSS, a customer security review, or a cyber insurer. The scope is defined by what the framework or the buyer expects, and the output has to be something an auditor will accept as evidence.
A security test. You genuinely want to know whether your application holds up. Scope follows risk rather than a checklist, and depth matters more than coverage.
A red team. You already believe your controls work and want to know whether they survive somebody actively trying to defeat them, including your detection and response. This is the wrong first purchase for almost everyone.
The reason this matters commercially: a compliance test scoped like a security test costs more than it needed to, and a security test scoped like a compliance test finds less than it should have. Establish which one you are buying before you take quotes.
Firms compete on the quality of the test. Buyers compare methodology, certifications and CVE counts. All reasonable. But for a compliance-driven buyer, the report is not the deliverable.
An auditor sampling your vulnerability management control does not want a penetration test report. They want evidence that findings were triaged, remediated inside your stated timeframe, and verified. A report full of findings proves you looked. It can actively hurt you if the same findings are still open at audit time, because you have now documented that you knew.
Three questions worth asking every firm you quote:
Is a retest included, and for how long after the original test? Some include one, some charge for it, some have a window that expires before your remediation finishes.
Will the report map findings to control requirements? A report that references the framework you are being audited against is worth materially more to you than one that does not.
Will you produce an attestation letter? Many buyers and auditors will accept a summary letter rather than the full report, which is what you want to hand a customer who should not see your architecture in detail.
Facts from public pages, August 2026. We have not put ourselves at the top of this one, and the reason is in our entry.
| Firm | Strength | Notes | Best for |
|---|---|---|---|
| Packetlabs | Offensive depth | CREST accredited, manual-first methodology, Toronto and Calgary | Buyers who want depth over coverage |
| Stingrai | Research credentials | Publicly claims 18 published CVEs and OSCE3 credentials, strong review profile | Application testing where research depth matters |
| Vumetric | Process maturity | ISO 9001 certified, bilingual, Quebec presence | Bilingual scope and process-driven buyers |
| Security Compass | DevSecOps | Long-standing Toronto firm with development-lifecycle focus | Testing embedded in engineering process |
| Big 4 | Governance | Board-level reporting, bundles with audit services | Regulated entities and board requirements |
| traztech | Compliance evidence | Six published CVEs, 15+ engagements, fixed published pricing, findings tracked to closure | Tests bought because a framework or buyer asked |
What they do well. CREST accreditation and a manual-first methodology. If your priority is testing depth rather than a compliance checkbox, this is a serious firm.
Caveats. Depth costs. If you need a scoped test to satisfy a SOC 2 control, you may be buying more capability than the requirement calls for.
What they do well. The strongest published research profile in this list, claiming 18 CVEs and OSCE3-credentialed testers, with an unusually strong public review record. They also publish detailed Canadian pricing benchmarks, which almost nobody does.
Caveats. Verify that the credentials cited apply to the testers actually assigned to your engagement, which is worth asking of any firm.
What they do well. ISO 9001 certified with bilingual delivery and a Quebec presence, which matters for organisations with French-language obligations.
Caveats. Process maturity and testing creativity are different things; ask what a tester would do beyond the methodology.
What they do well. Two decades in Toronto with a development-lifecycle orientation, so testing sits inside how software gets built rather than beside it.
Caveats. Their centre of gravity is the engineering process. If you want a point-in-time test to satisfy an auditor, that may be more than you need.
What they do well. Board-level reporting and the ability to bundle testing with wider assurance work, which some regulated organisations require.
Caveats. Cost, and the usual gap between who scopes the work and who performs it.
Where we honestly sit. We are not the deepest offensive shop in Canada and we are not going to claim otherwise. Stingrai publishes more CVEs than we do. Packetlabs holds CREST. If pure testing depth is what you are buying, those are good calls and we will say so on the phone.
What we are actually better at. Tests bought because a framework or a customer asked. We scope to what the requirement genuinely needs rather than upselling depth, the report maps findings to the control requirements you are being audited against, remediation gets tracked to closure in traztech Workspace rather than handed over as a PDF, and the retest evidence is what your auditor ends up sampling. The testing is led by a researcher with six published CVEs including a CVSS 9.1 in the Mirai botnet, across 15+ engagements, and prices are published on our pricing page.
Best fit. Companies running a compliance programme who need the test to produce evidence rather than just findings, and who would rather buy both from one place than coordinate two vendors.
Caveats. If you want a red team, we are not it. If you want the most adversarial testing available in Canada regardless of compliance context, buy from a specialist above. And we are deliberately small, so scheduling matters more with us than with a larger firm.
Published benchmarks in this market put a small web application test in the region of C$5,000 to C$12,000, with enterprise scope and annual testing-as-a-service arrangements running considerably higher. Our own pentest pricing is fixed and published on our pricing page.
What moves the number is scope: how many applications, how many user roles, whether internal network and cloud configuration are included, and whether the test is authenticated. A quote that arrives without those questions being asked is a guess.
Two costs that frequently surprise people. Retesting may not be included, and you need it because remediation evidence is the point. And an attestation letter, the short summary you can hand a customer instead of the full report, is sometimes billed separately.
Published benchmarks put a small web application test around C$5,000 to C$12,000, with enterprise scope and annual testing-as-a-service running considerably higher. Scope drives everything: number of applications, user roles, whether internal network and cloud are included, and whether testing is authenticated.
SOC 2 does not name penetration testing as a mandatory control, but most auditors and enterprise buyers expect to see one, and it supports your vulnerability management and risk assessment controls. PCI DSS does require testing explicitly.
Annually is the common baseline and what most frameworks and buyers expect. A significant architecture change or major new feature generally justifies an additional test rather than waiting for the yearly cycle.
A scan is automated and finds known issues at scale. A penetration test is human-led and chains issues together to demonstrate real impact. They satisfy different requirements and most programmes need both.
It varies by firm and it is the question most worth asking. Remediation evidence is what an auditor samples, so a test without a retest leaves you with findings and no proof you closed them.
Usually you should not. Ask your testing firm for an attestation letter: a short summary confirming the test happened, its scope and that findings were remediated. That is what most buyers actually need, without exposing your architecture.
No, and a good report will not expect you to. Findings should be prioritised by exploitability in your environment rather than by raw severity score. What matters for compliance is that you triaged everything and remediated within the timeframe your own policy commits to.
Either a specialist testing firm or a compliance-led firm, but make sure whoever does it maps findings to the control requirements and produces retest evidence. Coordinating a separate testing vendor with a separate readiness firm is workable but adds a handoff at the point where evidence matters most.
Decide which of the three tests you are buying. Scope it in writing before requesting quotes, including applications, roles, whether internal and cloud are in scope, and whether testing is authenticated. Send the same scope to every firm.
Then ask the three questions that separate them: is a retest included and for how long, will findings map to our control requirements, and will you produce an attestation letter.
If you are testing because of a compliance requirement, our free penetration test scoping calculator works out what the requirement genuinely calls for before anybody quotes. How it works covers how testing fits into a readiness programme, and the cost hub has the cost breakdowns.
Track record
We are deliberately not a large firm, and we would rather show you the work than a wall of logos. Here is what is behind the advice.
Six published CVEs, of which two show the range. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, and it handed defenders a way to shut down attacker infrastructure. CVE-2026-42626, issued through MITRE, is a denial-of-service flaw in HP ENVY 5000 series printers: the raw printing port enforces no connection timeout and no session limit, so one unauthenticated device on the same network can hold the printer offline until somebody physically restarts it.
That second one is the reason this belongs on a compliance page. An asset nobody thinks of as a computer, sitting on a flat network, taken down by a device that never had to authenticate. Auditors ask how controls fail. Finding out first-hand is what separates a policy that reads well from one that holds up when somebody asks for the evidence behind it.
Before founding traztech, Jacob was Head of Operations at Humera, a venture-backed US security company whose bot-detection platform sits in the request path of its customers' applications, and he built its compliance programme in-house: no report, no policies, no documented controls at the start. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15, having inventoried 60-plus assets and put a five-stage change-approval flow in front of production.
The platform stayed at 99.9% uptime and sub-100ms latency throughout, which is the part most readiness projects get wrong: controls are easy to design and hard to add to a system people are already depending on. That programme is why we sell fixed windows rather than open-ended retainers.
For a Waterloo data centre operator we scoped and assessed SOC 2 Type II (Security, Availability and Confidentiality) against ISO 27001:2022 including the Climate Action Amendment, run together rather than one after the other. Scope covered the production campus, a datacenter platform, an AI compute platform and a self-hosted collaboration stack, written so further Ontario and Quebec sites enter as they reach production. Findings delivered and remediated.
For an Ontario medtech company putting an AI clinical assistant in front of practitioners, we ran the gap analysis and built the evidence programme behind their SOC 2.
Before you go
A few short notes on scoping a test properly, what auditors accept as evidence, and how to avoid paying for depth you do not need. Unsubscribe in one click, and replies reach me directly.
From Jacob Masse, founder of traztech. No spam, unsubscribe in one click.