
What a Penetration Test Costs in Canada, and What Drives the Price
Quotes for the same job routinely differ by a factor of four. The variables that actually move the number, and how to make bids comparable.
GuardsArm Team
Security Experts

Ask four firms to quote the same penetration test and the spread will often be four to one. That is not always a sign that three are overcharging. It usually means they scoped four different pieces of work, because the request was ambiguous enough to permit it.
Penetration testing is sold by effort. Almost every pricing question reduces to how many days a qualified tester will spend, and what they will do with them.
What drives the day count
Scope size is the obvious one, but it is measured differently by test type: external testing by live hosts and exposed services, internal by network size and segment count, application testing by authenticated roles and distinct functionality rather than page count.
Authentication roughly doubles application testing effort, because each role is effectively a separate perspective, and authorisation flaws — the findings that matter most — only appear once you are inside.
Retesting is frequently excluded from the headline number and then quoted separately at an awkward moment. Ask whether remediation retesting is included and for how long after the original test.
Indicative bands
These are bands, not quotes, and they assume a competent Canadian provider using experienced testers rather than a scan-and-report exercise:
| Engagement | Typical effort | What moves it |
|---|---|---|
| External network, small estate | 3-5 days | Live host count, number of exposed applications |
| Internal network, single site | 5-10 days | Segment count, Active Directory complexity |
| Web application, unauthenticated | 4-6 days | Functionality breadth |
| Web application, multi-role authenticated | 8-15 days | Number of roles, business logic complexity |
| Mobile application, both platforms | 10-15 days | Backend API scope, offline behaviour |
| Full red team | 20-40+ days | Objectives, duration, stealth requirements |
Multiply by a day rate. Canadian day rates vary widely with seniority and firm overhead, and the cheapest day rate is frequently the most expensive outcome — an inexperienced tester takes longer to find less.
Why cheap quotes are cheap
A vulnerability scan with a cover page can be produced in a day and sold as a penetration test. It will find missing patches and weak TLS. It will not find the authorisation flaw that lets one customer read another's records, because no scanner understands what your identifiers mean. See vulnerability scanning vs penetration testing.
Questions that separate the two:
- Who does the testing, by name and certification, and are they the person who will actually do it
- What proportion is manual, and what does the manual work cover
- Can I see a sample report, redacted
- What is excluded, explicitly
- Is retesting included
Making bids comparable
The reason quotes diverge is almost always the request. A specification that fixes the variables produces bids you can actually compare:
- Exact scope — IP ranges, URLs, application roles, in writing
- Test type and methodology referenced explicitly
- Testing window and any constraints on timing
- Deliverables — report format, executive summary, retest, attestation letter
- Evidence requirements — reproduction steps for every finding
The penetration testing RFP template sets these out in a form vendors can bid against consistently.
Where the money is wasted
- Testing annually because the calendar says so, on an estate that has not changed, while a new application ships untested
- Buying a wide, shallow test across everything instead of a deep test of the systems that matter
- Paying for findings you already know about from your own scanning — fix those first and buy the tester's time for what scanning cannot see
- No remediation budget. A test with nothing set aside to fix what it finds converts money into a document
Where to start
Decide what question you want answered before you ask for a price. "Can an attacker on the internet reach patient data" and "does our new portal have authorisation flaws" are different engagements with different costs, and a vendor cannot scope either from a request that just says "penetration test".
GuardsArm scopes and delivers testing against a written specification. See penetration testing services or book a scoping call.
Written by GuardsArm Team
Our team of cybersecurity experts brings decades of combined experience in penetration testing, compliance auditing, and incident response. We're dedicated to helping organizations strengthen their security posture.
Take the next step on this topic
Talk to the GuardsArm team about how these services apply to your environment.


