Back to Blog
Security Testing
4 min read

What a Penetration Test Costs in Canada, and What Drives the Price

Quotes for the same job routinely differ by a factor of four. The variables that actually move the number, and how to make bids comparable.

GuardsArm Team

Security Experts

September 25, 2026

Penetration testing cost drivers in Canada

Ask four firms to quote the same penetration test and the spread will often be four to one. That is not always a sign that three are overcharging. It usually means they scoped four different pieces of work, because the request was ambiguous enough to permit it.

Penetration testing is sold by effort. Almost every pricing question reduces to how many days a qualified tester will spend, and what they will do with them.

Sold by effort
Nearly every pricing question is really a day-count question
4:1 quote spreads
Usually four different scopes, not four different margins
Cheapest day rate costs most
An inexperienced tester takes longer to find less

What drives the day count

What moves a penetration testing quoteScope size, whether testing is authenticated, the proportion of manual work, tester seniority, whether retesting is included, and reporting depth.Scope sizeHosts, applications, roles, segments — measured per test typeAuthenticationRoughly doubles application effort; where the real findings liveManual versus automated proportionThe single biggest quality and price differentiatorTester seniorityDay rate up, day count down — often cheaper overallRetestingFrequently excluded from the headline numberReporting depthAn attack narrative costs more than a findings table
Fix these six in the request and the bids become comparable.

Scope size is the obvious one, but it is measured differently by test type: external testing by live hosts and exposed services, internal by network size and segment count, application testing by authenticated roles and distinct functionality rather than page count.

Authentication roughly doubles application testing effort, because each role is effectively a separate perspective, and authorisation flaws — the findings that matter most — only appear once you are inside.

Retesting is frequently excluded from the headline number and then quoted separately at an awkward moment. Ask whether remediation retesting is included and for how long after the original test.


Indicative bands

These are bands, not quotes, and they assume a competent Canadian provider using experienced testers rather than a scan-and-report exercise:

EngagementTypical effortWhat moves it
External network, small estate3-5 daysLive host count, number of exposed applications
Internal network, single site5-10 daysSegment count, Active Directory complexity
Web application, unauthenticated4-6 daysFunctionality breadth
Web application, multi-role authenticated8-15 daysNumber of roles, business logic complexity
Mobile application, both platforms10-15 daysBackend API scope, offline behaviour
Full red team20-40+ daysObjectives, duration, stealth requirements

Multiply by a day rate. Canadian day rates vary widely with seniority and firm overhead, and the cheapest day rate is frequently the most expensive outcome — an inexperienced tester takes longer to find less.


Why cheap quotes are cheap

A scan with a cover page is not a penetration test
Automated scanning finds missing patches and weak configuration. It cannot find broken authorisation, business logic flaws or chained attack paths, because those require understanding what your application is for. If a quote looks impossibly cheap, ask what proportion of the work is manual.

A vulnerability scan with a cover page can be produced in a day and sold as a penetration test. It will find missing patches and weak TLS. It will not find the authorisation flaw that lets one customer read another's records, because no scanner understands what your identifiers mean. See vulnerability scanning vs penetration testing.

Questions that separate the two:

  • Who does the testing, by name and certification, and are they the person who will actually do it
  • What proportion is manual, and what does the manual work cover
  • Can I see a sample report, redacted
  • What is excluded, explicitly
  • Is retesting included

Making bids comparable

The reason quotes diverge is almost always the request. A specification that fixes the variables produces bids you can actually compare:

  1. Exact scope — IP ranges, URLs, application roles, in writing
  2. Test type and methodology referenced explicitly
  3. Testing window and any constraints on timing
  4. Deliverables — report format, executive summary, retest, attestation letter
  5. Evidence requirements — reproduction steps for every finding

The penetration testing RFP template sets these out in a form vendors can bid against consistently.


Where the money is wasted

  • Testing annually because the calendar says so, on an estate that has not changed, while a new application ships untested
  • Buying a wide, shallow test across everything instead of a deep test of the systems that matter
  • Paying for findings you already know about from your own scanning — fix those first and buy the tester's time for what scanning cannot see
  • No remediation budget. A test with nothing set aside to fix what it finds converts money into a document

Where to start

Decide what question you want answered before you ask for a price. "Can an attacker on the internet reach patient data" and "does our new portal have authorisation flaws" are different engagements with different costs, and a vendor cannot scope either from a request that just says "penetration test".

GuardsArm scopes and delivers testing against a written specification. See penetration testing services or book a scoping call.

Written by GuardsArm Team

Our team of cybersecurity experts brings decades of combined experience in penetration testing, compliance auditing, and incident response. We're dedicated to helping organizations strengthen their security posture.

Take the next step on this topic

Talk to the GuardsArm team about how these services apply to your environment.