Contracting services filed 17 percent and engineering and architectural services 10 percent of the more than 1,400 ransomware complaints the FBI's Internet Crime Complaint Center received in 2025 from organizations outside the 16 critical infrastructure sectors, according to the FBI 2025 Internet Crime Report, published in April 2026. Verizon's 2026 Data Breach Investigations Report counted 843 security incidents and 828 confirmed data breaches in construction, and in a 2016 to 2017 scheme the Department of Justice described at sentencing in October 2024, fraudsters researched large construction projects, registered a domain resembling the contractor's, and persuaded a university to wire more than US$1.9 million. Contractors and design firms hold drawings, bid data and payment instructions, and owners, primes and insurers now ask how they are protected.
Where Stingrai fits: Stingrai is a CREST-accredited penetration testing service provider at firm level, headquartered in Toronto with a London office and founded in 2021, and it has run internal, network and web penetration tests for an engineering firm, published as a case study. Two named penetration testers from a team holding OSCE³, OSWE, OSEP, CREST CRT and CISSP certifications staff each human-led engagement, and the team has published 18 CVEs. For a contractor or design firm that means Microsoft 365 and Entra ID tested as the route to project mailboxes and pay applications, Active Directory and the segmentation between the office, project file servers and job-site connections, project and bid portals tested across every company and role, job-site Wi-Fi, and phishing and vishing aimed at accounts payable and the help desk. It is delivered as a one-time annual engagement or a continuous program through the PTaaS portal, with retesting and an attestation letter included. Published pricing is US$3,000 for an Autonomous Pentest and US$6,800 for a Hybrid Pentest covering one web application and its APIs (pricing); firm-wide scopes are quoted.
Quick answer: who are the best penetration testing companies for construction and engineering firms in 2026?
The best penetration testing companies for construction and engineering firms in 2026 are Stingrai, CBIZ Pivot Point Security, Plante Moran, RSM, CLA, Sherlock Forensics, LevelBlue, Kroll, LBMC and Schneider Downs. Stingrai ranks first for named, certified penetration testers on the systems contractors lose money and drawings through, with retesting and an attestation letter included, one-time or continuous. CBIZ Pivot Point Security, Plante Moran and RSM follow for the most construction-specific practice page, CREST-accredited testing inside a firm with a construction practice, and testing teams on both sides of the border.

What construction and engineering firms are actually required to test
No statute in either country names penetration testing for construction, engineering or architecture firms. What exists is a set of contract clauses, owner specifications and underwriting questions, and each one decides what the report has to prove. Only the insurance questions and CMMC Level 3, which cannot be designated during the suspension, ask for penetration testing by name.
DFARS 252.204-7012 and NIST SP 800-171 on defense construction and design work
The Department of War's Class Deviation 2026-O0025, Revision 3, signed on 3 September 2026, is the DFARS text contracting officers use today. Its section 240.370-5(c) prescribes clause 252.204-7012 "in solicitations and contracts, including solicitations and contracts using FAR part 12 procedures for the acquisition of commercial products and commercial services, except for solicitations and contracts solely for the acquisition of COTS items." There is no exception for construction or for architect and engineering services.
The clause protects covered defense information, and the deviation's definition of technical information lists "research and engineering data, engineering drawings, and associated lists, specifications, standards." That is the daily output of a design firm on a defense facility. A drawing is covered defense information when it is controlled technical information (technical information with military or space application that is subject to dissemination controls and would meet the criteria for distribution statements B through F) or other controlled unclassified information, and it is marked or identified in the contract and provided by DoD, or developed or handled by the contractor in performing the contract. The CMMC program rule summarizes what 7012 demands: "adequate security on all covered contractor information systems by implementing the 110 security requirements specified in NIST SP 800-171." The clause also requires cyber incidents to be reported within 72 hours, requires a contractor that keeps covered defense information with an external cloud service provider to ensure the provider meets security requirements equivalent to the FedRAMP Moderate baseline, and must be flowed to subcontractors whose work involves covered defense information.
NIST SP 800-171 Revision 2 does not use the word penetration. Requirement 3.11.2 asks contractors to "Scan for vulnerabilities in organizational systems and applications periodically and when new vulnerabilities affecting those systems and applications are identified." Requirement 3.12.1 asks them to "Periodically assess the security controls in organizational systems to determine if the controls are effective in their application." A penetration test is one of the most direct ways to evidence the second.
CMMC on 1 October 2026: suspended Phase 2, live clauses
The CMMC program rule at 32 CFR part 170 took effect on 16 December 2024, and the DFARS rule that puts it into contracts took effect on 10 November 2025. Level 1 (Self) covers the 15 security requirements of FAR 52.204-21 for Federal Contract Information, all of which "must be met in full." Level 2 (Self) covers "the 110 Level 2 security requirements derived from NIST SP 800-171 R2" for Controlled Unclassified Information. Level 3 adds selected NIST SP 800-172 requirements and is the only level that names a test: requirement CA.L3-3.12.1e reads "Conduct penetration testing at least annually or when significant security changes are made to the system, leveraging automated scanning tools and ad hoc tests using subject matter experts."
On 13 July 2026 the Department of War Chief Information Officer suspended the move to Phase 2. The Under Secretary of War for Acquisition and Sustainment's implementing memorandum of the same day says in its attachment that program managers "may not designate CMMC Level 2 (C3PAO) or Level 3 (DIBCAC) assessments during this period. The allowed designations are CMMC Level 1 (Self) or CMMC Level 2 (Self)." It also says the requirements of DFARS 252.204-7012 "remain in effect" and that "no waivers shall be granted during the review of the program." Revision 3 of the class deviation, still the current version on 1 October 2026, prescribes the CMMC clause until 9 November 2028 only where a program office requires a specific level, and from 10 November 2028 wherever the contractor will use its own information systems to process, store or transmit FCI or CUI. That 2028 date is in the current deviation text, although the DoW CIO's memorandum of 13 July 2026 says "all pending and future CMMC implementation milestones across DoW solicitations and contracts are held in abeyance until further notice." The clause flows to subcontractors that handle FCI or CUI, and the prime must confirm each subcontractor's CMMC status before award.
Construction was raised by name when the contract rule was finalized. Commenters on the DFARS rule said added clarity was needed "to ensure small business construction firms can compete for DoD procurements," and a few recommended that applicability to "fundamental research and architect and engineering services should be considered and carefully implemented." DoD's answer narrowed the rule to FCI and CUI. It did not exempt either kind of work.
Two definitions matter for a testing calendar. The program rule defines periodically as "occurring at regular intervals," with "an interval length of no more than one year," so the 3.12.1 assessment is at least annual under CMMC. And a senior Affirming Official must affirm continuing compliance after every assessment "and annually thereafter." The CMMC defense contractor ranking covers how a test maps to those requirements.
CPCSC for Canadian defence work
Public Services and Procurement Canada describes the Canadian Program for Cyber Security Certification as "an official cyber security certification in Canada for defence suppliers." Its 14 April 2026 backgrounder says Level 1 was available to suppliers on 1 April 2026, requires suppliers to "identify the implementation status of 13 security requirements and controls" in an annual self-assessment, and "will be introduced in select defence contracts beginning in summer 2026," while "Level 2 will be added to select defence contracts beginning in spring 2027." Level 2 means an external assessment of 98 controls by a certification body accredited through the Standards Council of Canada, plus an annual affirmation; Level 3 is assessed by National Defence. The launch release adds: "During the initial phase, certification will not be required throughout the bidding process, rather, only upon contract award."
The program names no industry, so construction is neither named nor excluded. PSPC's January 2026 evaluation says requirements "will be determined on a contract-by-contract basis," which means an engineering or construction firm on a Government of Canada defence contract inherits whatever level the solicitation sets. Canadian firms under US primes face the second regime too: neither DFARS 252.204-7012 nor the CMMC clause has a nationality test. The CMMC and CPCSC guide for Canadian defence suppliers compares the two.
Owner specifications: cybersecurity during construction on DoD projects
DoD builds its owner requirements into the specification. UFGS 25 05 11, Cybersecurity for Facility-Related Control Systems, the August 2024 guide specification prepared by USACE for USACE, NAVFAC and AFCEC, which designers edit for each project, contains "Cybersecurity requirements to be included on every DoD project which includes a facility-related control system," which it defines to include building control systems, utility control systems, electronic security systems, and fire and life safety systems.
Its section on cybersecurity during construction reaches the contractor directly, for equipment that touches the control system. Contractor computers connected to the control system must run a supported, patched operating system and anti-malware with a full scan at least once a day, use unique accounts and passwords changed from their default values, and be covered by signed Contractor Computer Cybersecurity Compliance Statements, and "The Government has the right to require demonstration of computer compliance with these requirements at any time during the project." Temporary contractor networks connected to the control system "must not extend outside the project site," access from outside the site "is prohibited," and temporary Wi-Fi, where permitted, must use WPA2 and must not broadcast its network name. The specification adds that these requirements "are not related to the networks contractors will often establish in their project offices/trailers." Delivered devices must be scannable "by industry standard IP network scanning utilities without harm." A company signs those statements. Testing the laptop build and the temporary network before signing costs far less than failing a government check.
Owner requirements on utility and critical infrastructure projects
Utilities subject to NERC CIP-013-2 must have supply chain risk plans whose procurement processes address, among other things, "Notification by the vendor of vendor-identified incidents," "Disclosure by vendors of known vulnerabilities," "Notification by vendors when remote or onsite access should no longer be granted to vendor representatives," and "Coordination of controls for vendor-initiated remote access." Those processes often reach the contractors and integrators that supply or install the systems as procurement questions or contract language, although the standard leaves "the actual terms and conditions of a procurement contract" out of scope.
In Canada, the Critical Cyber Systems Protection Act, enacted by section 11 of chapter 9 of the Statutes of Canada 2026, received royal assent on 15 June 2026 and is not yet in force. Once it is, operators designated under it in vital services that include interprovincial or international pipeline and power line systems, nuclear energy systems and federally regulated transportation must run a cyber security program that will "identify and manage any organizational cyber security risks, including risks associated with the designated operator's supply chain and its use of third-party products and services," and must mitigate those risks once identified. The Act does not contain the word penetration. The Bill C-8 guide explains what is in force and what is not.
Cyber insurance applications
Underwriters ask directly. The AXIS Cyber Application (form AXIS 1012098 0122) asks: "Does the Applicant conduct regular penetration testing?" It then asks how often, from monthly to biannually, and whether testing is conducted in-house or outsourced. The same form states that if a policy is issued, the application "will be deemed attached to and will form a part of the policy." A yes is a representation, and the guide to what underwriters actually ask covers the evidence to keep behind it.
The threat record behind the clauses

The FBI's 2025 report lists the most reported industries among ransomware complaints from organizations outside the critical infrastructure sectors: legal services 18 percent, contracting services 17 percent, with "electricians, general contractors" as the FBI's examples, engineering and architectural services 10 percent, with "engineering firms, land surveying," consulting services 7 percent and non-critical manufacturing 5 percent, which includes building materials. The same report counts US$3.05 billion in business email compromise losses across 24,768 complaints in 2025, across all industries.
Verizon's 2026 report, published on 19 May 2026, profiles construction in its table of industries: 843 incidents, 828 of them confirmed breaches, with "System Intrusion, Social Engineering and Basic Web Application Attacks" representing 95 percent of breaches. External actors account for 99 percent of breaches, financial motives for 97 percent and espionage for 5 percent, and credentials were among the data compromised in 34 percent. Of the 828 breaches, 524 hit organizations with 1,000 or fewer employees, 8 hit larger ones and 296 were of unknown size. In Canada, the Canadian Centre for Cyber Security's National Cyber Threat Assessment 2025-2026, the current edition, reports that ransomware incidents affecting construction that it observed rose 133 percent from 2022 to 2023.
Payment fraud is the other half of the record. In the case DOJ described in October 2024, covering a scheme that ran from August 2016 to January 2017, the fraudsters "obtained information about significant construction projects occurring throughout the United States," registered a domain "similar to that of the legitimate construction company in charge of the University's project," and directed the university to wire more than US$1.9 million; the same defendant's Texas schemes targeted local government entities, construction companies and a Houston-area college. Owners are attacked from the other side of the same transaction. In February 2025 a scammer posing as an employee of a City of Portland contractor gained access to a payment system and changed the contractor's bank account information, and the FBI seized US$6,748,680 of the diverted funds in April 2025, according to the US Attorney's Office for Oregon.
The industry has noticed. Advancing Construction Cybersecurity 2026, a summit run by the Advancing Construction division of Hanson Wade Group, meets in Austin on 7 to 9 December 2026, bills itself as "the only dedicated forum built specifically for construction cybersecurity leaders," and lists speakers from Turner Construction, Kiewit, Hensel Phelps and Balfour Beatty. It is a conference, not a standard: nothing presented there binds a contractor.
Driver | Names penetration testing? | Cadence | What the evidence has to show |
|---|---|---|---|
DFARS 252.204-7012 and NIST SP 800-171 Rev. 2 | No | Periodic scanning and control assessment | 110 requirements implemented, controls effective, incidents reported within 72 hours |
CMMC, 32 CFR part 170 | Only at Level 3 (CA.L3-3.12.1e, at least annually), which cannot be designated during the suspension | Level 1 (Self) yearly; Level 2 (Self) every three years; affirmations yearly | Level 1 (Self) or Level 2 (Self) during the suspension |
CPCSC Levels 1 and 2 | Not in the program's level descriptions | Level 1 self-assessment yearly; Level 2 external assessment plus yearly affirmation | Controls implemented for the contract's level |
UFGS 25 05 11 on DoD projects | No; requires scannable devices | Throughout construction and at acceptance | Signed compliance statements for laptops and temporary networks connected to the control system |
NERC CIP-013-2, utility owners | No | Each procurement of BES Cyber Systems | Vendor incident, vulnerability and remote access processes |
Critical Cyber Systems Protection Act | No | Not yet in force | Supply chain risks identified and mitigated by designated operators |
Cyber insurance applications | Yes, as a question | Applicant states, monthly to biannually | A truthful answer that becomes part of the policy |
The construction and engineering attack surface: what a good scope covers
A test that stops at the head office firewall misses the places where drawings and money actually move.

Project portals and common data environments. Procore, Autodesk Construction Cloud and similar platforms hold drawings, RFIs and submittals, and often pay applications, shared between the owner, the general contractor and the trades. Test authorization between companies, projects and roles, shared links, integrations and the API tokens that connect estimating and accounting systems.
BIM and design data. Models, drawing sets and CAD file servers are the design firm's product and, on defense work, can be covered defense information. Check permissions, version history, external sharing, and whether a cloud platform holding those drawings meets the clause's cloud requirement.
Microsoft 365 and Entra ID. Guest access for owners and subcontractors, OAuth consent grants, Conditional Access exceptions, legacy authentication and mailbox rules that hide payment emails from the person who should see them. Stingrai's cloud penetration testing treats the tenant as an attack path.
Accounts payable and progress payments. The bank change process for pay applications, edits to the vendor master, vishing of accounts payable and the help desk, and lookalike domains registered against live projects. The social engineering testing guide explains how those campaigns are scoped.
Active Directory and the office network. Kerberos and delegation paths, ACL abuse and certificate template misconfigurations, and segmentation between office systems, project file servers and job-site VPNs, through an Active Directory assessment and internal and external network testing.
Job sites and field devices. Trailer networks, site Wi-Fi, cellular routers, cameras, tablets and plotters, and the remote access path from the site back to the office. A Wi-Fi security assessment covers the wireless side.
Building systems at turnover. Building automation, access control and video systems scanned before handover, default passwords removed, and isolated from the contractor's own network. On DoD work the specification makes some of this a contract obligation.
Subcontractor and joint-venture access. Stale VPN and portal accounts for trades that finished months ago, shared credentials, remote support tools, and the trust granted to partner tenants in a joint venture.
How we ranked them
Ten vendors were scored against ten criteria. Every accreditation was checked on the CREST Marketplace and every vendor entry links to a page on the vendor's own site, verified on 1 October 2026. One pattern stood out: few specialist penetration testing firms publish construction or engineering work, and most construction-specific security material on vendor sites comes from advisory firms with construction practices. That is not a weakness in itself, but it makes named testers, retest terms and independence the criteria to press.
Published construction, engineering or architecture security work on the vendor's own site.
Firm-level accreditation on the CREST Marketplace, plus the company certifications listed there.
Coverage of the construction attack surface described above, including payment processes and site networks.
Named testers, identified with their certifications before signing.
Retest policy stated in writing.
Delivery: a portal for findings, and both one-time and continuous options.
Evidence for owners, primes and insurers, such as a report and attestation letter they will accept.
Pricing transparency.
North American delivery in the United States, Canada or both.
Independence from the firm's IT provider, CMMC consultant and auditor.
The 10 companies at a glance
# | Company | HQ | Accreditations (CREST Marketplace) | Delivery model | Named testers | Retest | Published pricing | Best for |
|---|---|---|---|---|---|---|---|---|
1 | Stingrai | Toronto, ON (London, UK office) | Penetration Testing, firm level | Human-led, hybrid or autonomous; one-time or continuous; PTaaS portal | Yes, two per human-led engagement | Included | Yes, US$3,000 and US$6,800 | Named testers, retest and an attestation letter for owners, primes and insurers |
2 | CBIZ Pivot Point Security | Hamilton, NJ | Penetration Testing; ISO 27001 | Consultant-led, beside CMMC and cyber insurance readiness | Not stated | Not stated | No | Federal construction work and payment fraud controls |
3 | Plante Moran | Southfield, MI | Penetration Testing; SOC 2 Type 2; CMMC Registered Practitioner Organization listed | Testing inside an advisory firm with a construction practice | Not stated | Not stated | No | CREST-accredited testing from a construction advisor |
4 | RSM | Chicago, IL (RSM Canada in Toronto) | Not listed for RSM US or RSM Canada | Testing inside an advisory firm, in the US and Canada | Not stated | Not stated | No | Cross-border firms; ICS, SCADA and IoT testing |
5 | CLA | Minnesota LLP; 120+ US locations | Not listed | Testing inside an advisory firm, beside CMMC assessments | Not stated | Not stated | No | Federal contractors that want CMMC guidance and testing together |
6 | Sherlock Forensics | Burnaby, BC | Not listed | Testing specialist with published packages | Not stated | 90-day retest in the comprehensive tier | Yes, starting at C$1,500 | A defined construction test at a published starting price |
7 | LevelBlue | Plano, TX | Penetration Testing, Threat Led Penetration Testing, application and mobile testing (UK entity) | Testing inside a managed security provider; PTaaS option | Not stated | Yes, no added cost | No | Large contractors with OT and IoT on site |
8 | Kroll | New York, NY (Toronto office) | Penetration Testing, Incident Response, Security Operations Centre | Consultant-led, beside incident response | Not stated | Not stated | No | Testing from a provider on cyber insurers' panels |
9 | LBMC | Brentwood, TN | Not listed | Testing inside an advisory firm | Not stated | Not stated | No | Contractors already using LBMC for construction accounting |
10 | Schneider Downs | Pittsburgh, PA; Columbus, OH; McLean, VA | Not listed | Testing inside an accounting and advisory firm | Not stated | Not stated | No | Contractors already using Schneider Downs for construction accounting |
"Not stated" means the vendor's own site does not say. Ask for it in writing.
1. Stingrai
Stingrai is a global CREST-accredited penetration testing services company founded in Toronto, Canada in 2021, trusted by companies from startups to enterprises to meet audit requirements for SOC 2, ISO 27001, CMMC, PCI DSS and HIPAA. OSCE³, OSWE, OSEP, CREST CRT certified pentesters, who are also world-class security researchers and bug bounty hunters. Choose from fully human-led or hybrid (AI agents plus human penetration testers) engagements across web, API, mobile, AI and LLM, cloud, network, Active Directory and social engineering penetration tests and red team engagements.
What an owner, prime or insurer can check. The firm-level accreditation is on the CREST Marketplace supplier page for Stingrai Inc, separate from the CREST CRT certifications individual testers hold. Ratings are 5.0 out of 5 across 20 reviews on Clutch. The team has published 18 CVEs, including CVE-2025-50674, a privilege escalation to root in OpenMediaVault, and CVE-2024-32136, an SQL injection in a WordPress plugin. Two named penetration testers run each human-led engagement, reviewed by the team lead and an engagement partner. In engineering, Stingrai ran internal, network and web penetration tests for a Toronto forensic engineering firm in December 2025, and the client's case study says the team "found vulnerabilities that even our team and vulnerability management systems missed."
How a construction or engineering engagement is tested. Cloud testing treats Microsoft 365 and Entra ID as the route to project mailboxes and pay applications: app registrations, service principals, consent grants, Conditional Access gaps and hybrid-join trust back to on-premises Active Directory. The Active Directory assessment follows ACL abuse and Kerberos and delegation paths to domain admin, and network testing covers the external perimeter and remote access, lateral movement from a site connection, and segmentation between the office, project file servers and job-site networks. Wi-Fi assessments run on site or remotely with a Wi-Fi Pineapple. Project, bid and subcontractor portals are tested black, grey or white box, authenticated across every company and role, for broken authorization, IDOR and business logic under OWASP Top 10 and ASVS. Social engineering covers phishing and vishing of accounts payable and the help desk, and physical security assessments test office perimeters and facility entry.
Evidence and delivery. Findings post to the PTaaS portal as they are confirmed, each with a working proof of concept and prioritized remediation guidance, with live chat to the assigned testers and Jira and Slack integration. Reports are redactable, which helps when an owner or prime asks for evidence without the full detail. Retesting is included, and every human-led and hybrid report ships with an attestation letter and a verified badge. Stingrai's penetration testing supports your CMMC and NIST SP 800-171 program and your CPCSC preparation, and gives an insurance application a documented answer. Stingrai runs both one-time annual engagements timed to a contract, a renewal or a turnover date and continuous programs that test every release.
Where Snipe fits. Snipe, Stingrai's autonomous AI penetration testing agent for web applications and their APIs, covers the bid, owner and subcontractor portals and any in-house construction software in scope. It hunts broken authorization, IDOR and business logic flaws, reviews code, and opens AutoFix pull requests. The Autonomous tier is Snipe alone, with no penetration testers; in a Hybrid engagement Snipe and the penetration testers test together throughout, with the testers directing its focus. Microsoft 365, Active Directory, network, Wi-Fi, social engineering and physical scopes are tested by penetration testers.
Pricing: US$3,000 for an Autonomous Pentest and US$6,800 for a Hybrid Pentest per assessment of one web application and its APIs, or US$650 and US$1,275 per month on 12-month continuous plans, on the pricing page. The "No High or Critical Finding = Don't Pay" guarantee applies to the Autonomous tier only. Every other scope is quoted through get a quote.
Strength: every claim an owner, prime or underwriter will ask about has a public source, from the CREST listing to the CVE records, the review profile and an engineering-sector case study. Limitation: a deliberately small team, which the CREST listing reflects, so multi-site physical work needs scheduling lead time. Building automation and OT controllers are not among Stingrai's published services, so test the segmentation around them in the network scope and bring in an OT specialist for the controllers themselves. The fixed-price packages cover web applications and their APIs only. Best for: mid-size and large contractors, engineering and architecture firms in the US and Canada that need named, certified penetration testers and an attestation letter for owners, primes and insurers, one-time or continuous.
2. CBIZ Pivot Point Security
CBIZ Pivot Point Security lists its headquarters in Hamilton, New Jersey, with staff across the United States, and publishes the most construction-specific practice page in this ranking. Its construction and engineering page says the firm "provides cybersecurity services to construction and engineering businesses, helping them protect project payments from fraud, secure critical project data, and meet the cyber insurance and compliance requirements that accompany federal and commercial work." The services it names are construction BEC prevention, protection of blueprints, bid documents and CAD files against ransomware, jobsite network security, subcontractor cybersecurity requirements, CMMC compliance for federal construction and cyber insurance readiness. Its penetration testing page covers external and internal networks, wireless, applications, physical controls such as access cards, guards and cameras, and social engineering including tailgating, phishing and vishing calls. CREST lists Penetration Testing and ISO 27001, with nine years of membership. Named testers, retest terms, a findings portal and pricing are not stated.
Strength: a practice written around how contractors actually lose money and data, from payment fraud to job-site networks. Limitation: the page describes a program as much as a test, so confirm which items testers deliver and keep testing separate from any CMMC readiness work the same firm does for you. No Canadian office is listed. Best for: US contractors and engineering firms on federal work that want payment-fraud controls and testing from one CREST-accredited provider.
3. Plante Moran
Plante Moran moved its corporate headquarters to Southfield, Michigan in 2021 and lists offices in Colorado, Illinois, Massachusetts, Michigan, New York and Ohio. Its construction industry page offers cybersecurity consulting in a line that reads: "We can work with you to develop, test, and strengthen your organization's cybersecurity framework." Its penetration testing page lists external and internal network tests, red and purple team exercises, social engineering assessments, web, mobile and API reviews, cloud and Microsoft 365 configuration assessments, ransomware simulation and detection assessments, and wireless assessments. The firm announced CREST accreditation for penetration testing in February 2025, and its CREST listing also shows a SOC 2 Type 2 report and a US CMMC Registered Practitioner Organization listing. Named testers, retest terms, a findings portal and pricing are not stated.
Strength: CREST-accredited testing, including Microsoft 365 and ransomware simulation, inside an advisory firm that already serves contractors. Limitation: the construction page mentions cybersecurity in a single line, so the construction context has to come from your scoping brief. No Canadian office is listed. Best for: Midwest and national US contractors that already work with Plante Moran and want CREST-accredited testing.
4. RSM
RSM US LLP describes itself as headquartered in Chicago, and RSM Canada opened in Toronto in 2017. RSM's May 2024 article on cyber issues in real estate and construction says "Ransomware, fraudulent wire transfers and data theft are commonplace among middle market real estate and construction firms," and that field-to-office communication and payment volume "creates a playground for criminals to unleash social engineering, phishing attacks and other scams." Its US and Canadian penetration testing pages both list external, internal, cloud, wireless and PCI testing, ICS and SCADA, IoT and embedded device testing, API, mobile and application testing, email phishing, vishing, SMS phishing and physical testing, and red and purple teaming, and RSM says its cyber testing team "performs hundreds of offensive security assessments each year." Neither RSM US nor RSM Canada is on the CREST Marketplace, and named testers, retest terms and pricing are not stated.
Strength: one network with testing teams on both sides of the border, with ICS, SCADA and IoT testing listed in both countries. Limitation: the construction material is an advisory article rather than a testing practice, so confirm which entity's team will test and where the data will sit. Best for: cross-border contractors and engineering firms in the middle market.
5. CLA
CLA (CliftonLarsonAllen) is a Minnesota limited liability partnership with more than 120 locations across the United States. Its June 2025 article Align Your Construction Firm With Cybersecurity Compliance Changes explains CMMC for contractors on federal work, names "project schedules, internal communications, and billing records" as Federal Contract Information, says "CMMC pushes companies to treat job-site technology as part of the threat surface," and reminds primes to verify that subcontractors handling sensitive information meet the right CMMC level. Its construction industry page names reducing "cyber and other threats" among the problems it addresses for contractors, and CLA's cybersecurity services include a CMMC assessment and penetration testing, where "our experienced cybersecurity professionals try to gain entry to your systems and data." CLA is not on the CREST Marketplace, and test types, named testers, retest terms and pricing are not stated.
Strength: construction-specific CMMC guidance that treats job-site technology as part of the assessed environment. Limitation: the penetration testing page publishes little about methods or retesting, and if CLA also prepares your CMMC assessment, ask how its testers are kept independent of that work. Best for: US contractors on federal projects that want CMMC guidance and testing from their accounting and advisory firm.
6. Sherlock Forensics
Sherlock Forensics is based in Burnaby, British Columbia, and has worked since 2006. Its construction cybersecurity page is the most construction-specific testing scope published by any firm here: network penetration testing aimed at ransomware deployment, lateral movement and data exfiltration, a ransomware readiness assessment, a subcontractor access review of "how subcontractors connect to your network and access your systems," and a BIM and project data review of "access controls on BIM platforms, version control security, sharing permissions." It describes an assessment of a British Columbia construction firm of about 200 employees that found no segmentation between corporate workstations, project file servers and job-site VPN connections, and 14 former subcontractor VPN accounts still active. Its penetration testing page publishes starting prices: quick audits start at C$1,500, standard penetration tests are C$5,000 and comprehensive assessments with internal testing start at C$12,000, and its comparison table lists a 90-day retest only in the comprehensive tier. It is not on the CREST Marketplace, and named testers and a findings portal are not stated.
Strength: a test scope written for construction, with published starting prices and a 90-day retest in the comprehensive tier. Limitation: a small firm whose published packages are sized for small and mid-size companies, with no firm-level accreditation. Best for: Canadian contractors, especially in British Columbia, that want a defined construction test at a published starting price.
7. LevelBlue
LevelBlue lists its headquarters at 6010 West Spring Creek Parkway in Plano, Texas. Its construction evidence is a case study on why LevelBlue was chosen as managed security services provider for a global construction company, "A North American-based international construction services company, managing over 1,000 projects annually." Its penetration testing page covers "IT, OT/IoT, Physical, People," offers testing as a service, includes red, purple and tiger team exercises, and promises to "Validate test findings with retesting services at no additional cost." CREST lists LevelBlue Cyber Solutions Ltd, a UK entity, with Penetration Testing, Threat Led Penetration Testing, Vulnerability Assessment, Application Security Testing and Mobile Application Security Testing, and 15 years of membership. Named testers and pricing are not stated.
Strength: OT, IoT and physical testing listed, retesting included, and an enterprise construction client. Limitation: the construction case study concerns managed security rather than testing, and the CREST listing belongs to a UK entity, so confirm which entity delivers North American work. Best for: large contractors consolidating managed detection and testing, including OT and IoT on sites.
8. Kroll
Kroll is headquartered in New York and has a Toronto office. Its architecture-sector material is an April 2020 joint paper with Mullen Coughlin on cyberattacks against architectural firms, which notes that "Conducting basic tasks, from sending an email to submitting an invoice or sharing designs, opens individuals and organizations to various cyber risks." Its penetration testing page describes a six-phase approach across web, API, cloud, AI and LLM, mobile, network and IoT testing, plus red teaming, informed by its incident response practice. CREST lists Penetration Testing, Incident Response and Security Operations Centre accreditations with eight years of membership, and says Kroll is "present in over 60 cyber insurance carriers and brokers' preferred panels." Named testers, retest terms, a findings portal and pricing are not stated.
Strength: testing beside an incident response team that many cyber insurers already know. Limitation: the architecture-sector material dates from 2020 and comes from incident response, and no commercial terms are published. Best for: firms that want testing from the provider their insurer may send after an incident.
9. LBMC
LBMC lists its headquarters at 201 Franklin Road in Brentwood, Tennessee. Its real estate and construction page says "As construction and real estate operations become more connected, protecting systems and using data effectively is critical," and lists penetration testing services and incident response and digital forensics among the related services. Its penetration testing page covers external, internal and wireless testing, social engineering, web application, mobile and cloud testing and purple teaming, and names real estate and construction among its featured industries. LBMC is not on the CREST Marketplace, and named testers, retest terms and pricing are not stated.
Strength: construction appears on both its industry page and its testing page. Limitation: the testing description is generic, and no firm-level accreditation is listed. Best for: contractors that already use LBMC for construction accounting and want testing from the same firm.
10. Schneider Downs
Schneider Downs lists offices in Pittsburgh, Columbus and McLean, Virginia. Its October 2023 article on cybersecurity in the construction industry describes a cybersecurity practice "offering a comprehensive set of information technology security services, including penetration testing, intrusion prevention/detection review, ransomware security, vulnerability assessments and a robust digital forensics and incident response team," written for the firm's construction clients. Its penetration testing page covers network, API, cloud, web application, wireless and physical testing, with phishing simulations. It is not on the CREST Marketplace, and named testers, retest terms and pricing are not stated.
Strength: a construction accounting practice and a testing team, including physical testing, under one roof. Limitation: three offices, no firm-level accreditation and no published retest terms. Best for: Pennsylvania, Ohio and Virginia contractors already working with Schneider Downs.
Firms considered and not ranked
Several firms publish construction material that is not penetration testing, or could not be tied to a current testing service. eSentire says it protects more than 50,000 employees across 40 architecture, engineering and construction companies, but its service there is managed detection and response, and its offensive product uses AI agents to validate attack paths rather than a penetration testing team. Summit 7 publishes architecture, engineering and construction case studies on CMMC certification and Microsoft environments, with no penetration testing service. Rapid7 published a threat landscape series on the building and construction sector, including a November 2025 report on ransomware, but no construction-specific testing page we could verify. Wipfli and CohnReznick publish construction cybersecurity guidance, but neither publishes a construction-specific testing page we could verify. IOActive's December 2024 guidance on building management systems recommends security assessments through design and build, with the final one at site acceptance, which owners commissioning a building automation system may find useful. MNP's construction-tagged penetration testing article dates from 2017. A firm's managed IT provider is a different case: whoever runs the network should not test it. The Canada ranking covers the national market.
How much does construction penetration testing cost in 2026?
Construction and engineering scopes usually span Microsoft 365, Active Directory, the perimeter and remote access, at least one portal and a social engineering campaign aimed at payments. Stingrai publishes its package prices: US$3,000 for an Autonomous Pentest, which is Snipe alone with no penetration testers, and US$6,800 for a Hybrid Pentest, where penetration testers and Snipe test together, each per assessment of one web application and its APIs. The same tiers run at US$650 and US$1,275 per month on 12-month continuous plans, and the "No High or Critical Finding = Don't Pay" guarantee applies to the Autonomous tier only. Every other scope is quoted through get a quote, with current figures on the pricing page.
The bands below are indicative, taken from our penetration testing cost guide for US dollars and the Canadian cost guide for standard Canadian scopes.
Construction scope | Indicative US band | Indicative Canadian band (standard scope) |
|---|---|---|
Project, bid or subcontractor portal (web application) | US$5,000 to US$30,000 | C$12,000 to C$25,000 |
External perimeter and remote access | US$5,000 to US$40,000 (network) | C$15,000 to C$35,000 |
Internal network and Active Directory | US$5,000 to US$40,000 (network) | C$20,000 to C$35,000 internal; C$25,000 to C$35,000 Active Directory |
Microsoft 365, Entra ID and cloud | US$10,000 to US$50,000 (cloud) | C$25,000 to C$40,000 (cloud) |
Firm-wide testing, mid-market organization | US$20,000 to US$50,000 a year | Quoted per scope |
Annual program | US$50,000 to US$150,000 or more (enterprise) | C$60,000 to C$90,000 (PTaaS) |
Wi-Fi, social engineering, physical and building-system scopes are quoted separately. Three things move a construction quote most: the number of offices and active job sites in scope, whether social engineering includes vishing of accounts payable and the help desk, and whether building systems or OT are in scope. The cost calculator gives a starting figure.
Buyer checklist: questions to put to every vendor
The RFP template turns these into procurement language.
Who exactly will test, and can we see their names and certifications before we sign?
Where is your firm-level accreditation listed, and which legal entity will sign our statement of work?
Will you test Microsoft 365 and Entra ID as the route to payment fraud, including guest access, consent grants and mailbox rules?
How will you test our project portals across companies and roles without touching live owner or subcontractor data? Test accounts on a test project are the usual answer.
Do you run vishing against accounts payable and the help desk, and will you test how we verify a bank change request on a pay application?
Can you test job-site networks and Wi-Fi, on site or remotely, and the path from a site back to the office?
For defense work, will the report map findings to NIST SP 800-171 requirement identifiers, and how will you keep any CUI out of your own systems?
What can we hand an owner, prime or insurer? Ask for the attestation letter, an executive summary and a redacted report.
Is retesting included, and within what window?
Are you independent of our IT provider, CMMC consultant and auditor?
Frequently Asked Questions
Who are the best penetration testing companies for construction and engineering firms in 2026?
The best penetration testing companies for construction and engineering firms in 2026 are Stingrai, CBIZ Pivot Point Security, Plante Moran, RSM, CLA, Sherlock Forensics, LevelBlue, Kroll, LBMC and Schneider Downs. Stingrai ranks first: a CREST-accredited penetration testing service provider at firm level with two named penetration testers from a team holding OSCE³, OSWE, OSEP, CREST CRT and CISSP certifications on every human-led engagement, testing Microsoft 365, Active Directory, project portals, job-site networks and payment-fraud social engineering, with retesting and an attestation letter included on one-time or continuous terms. CBIZ Pivot Point Security, Plante Moran and RSM follow.
Is there a regulation that requires construction companies to do penetration testing?
No. No statute in the United States or Canada names penetration testing for construction, engineering or architecture firms, and of the contract requirements covered here only CMMC Level 3, which cannot be designated during the suspension, names it. What creates pressure to test is a set of contracts, owner specifications and insurer questions that ask for evidence controls work: DFARS 252.204-7012 and NIST SP 800-171 on defense work, the CMMC clause, Canada's CPCSC on defence contracts, owner specifications such as DoD's UFGS 25 05 11 for facility-related control systems, the vendor processes utilities must address in procurement under NERC CIP-013-2, and cyber insurance applications, which ask about penetration testing by name.
Does CMMC apply to construction contractors and architecture and engineering firms?
Yes, when the solicitation sets a CMMC level and the work involves Federal Contract Information or Controlled Unclassified Information; construction and A/E work is not exempt. Until 9 November 2028 the clause goes in only where the program office requires a level, and since 13 July 2026 Phase 2 has been suspended, so solicitations may require only Level 1 (Self) or Level 2 (Self). When DoD finalized the CMMC contract rule in September 2025, commenters asked for clarity for small construction firms and careful treatment of architect and engineering services, and the final rule applies to FCI and CUI without carving either out. From 10 November 2028 the clause is prescribed wherever contractor systems process, store or transmit FCI or CUI under the current deviation text, although the DoW CIO's 13 July 2026 memo holds all pending and future CMMC milestones in abeyance until further notice.
Does CMMC or NIST SP 800-171 require a penetration test?
Not at Levels 1 and 2. NIST SP 800-171 Revision 2 does not use the word penetration. Requirement 3.11.2 calls for vulnerability scanning of systems and applications, and 3.12.1 calls for periodic assessment of whether security controls are effective, and the CMMC rule defines periodically as no more than one year. CMMC Level 3 does name it: requirement CA.L3-3.12.1e calls for penetration testing at least annually or after significant security changes, but Level 3 cannot be designated while Phase 2 is suspended. At Levels 1 and 2, a penetration test is one of the most direct ways to evidence that controls work, which is why some primes ask subcontractors for one.
Does CPCSC apply to Canadian construction and engineering firms?
It applies to suppliers on Government of Canada defence contracts, and requirements are set contract by contract, so a construction or engineering firm on such a contract inherits the level in the solicitation. Level 1, 13 security requirements self-assessed each year, has been available since 1 April 2026, and PSPC said it would be introduced in select defence contracts from summer 2026, with certification required at contract award rather than at bid during the initial phase. Level 2, 98 controls assessed by an accredited certification body, is expected in select contracts from spring 2027.
What should a construction penetration test cover?
Eight areas: project portals and common data environments such as Procore and Autodesk Construction Cloud, BIM and design data, Microsoft 365 and Entra ID, the accounts payable and progress payment process, Active Directory and the office network, job-site networks and field devices, building systems before turnover, and subcontractor and joint-venture access. Social engineering of accounts payable and the help desk belongs in scope because fraudsters research live projects and redirect progress payments, as a Department of Justice case covering a 2016 to 2017 scheme describes.
How does penetration testing help prevent progress-payment and wire fraud?
In a 2016 to 2017 scheme the Department of Justice described at sentencing in October 2024, fraudsters researched large construction projects, registered a domain resembling the contractor's, and persuaded a university to wire more than US$1.9 million. A test checks the controls that stop that: Microsoft 365 mailbox rules and consent grants that let an attacker read payment threads, phishing and vishing of accounts payable and the help desk, lookalike domains, and whether a bank change request is verified out of band before money moves.
Do cyber insurers require penetration testing from contractors?
Insurers ask about it on the application. The AXIS Cyber Application, for example, asks whether the applicant conducts regular penetration testing, how often, from monthly to biannually, and whether it is done in-house or outsourced, and states that the application forms part of any policy issued. A yes answer should be backed by a dated report and retest evidence, because the answer becomes part of the contract.
How much does penetration testing cost for a construction company in 2026?
Stingrai publishes US$3,000 for an Autonomous Pentest (Snipe alone, no penetration testers) and US$6,800 for a Hybrid Pentest per assessment of one web application and its APIs, or US$650 and US$1,275 per month on 12-month continuous plans; every other scope is quoted. Indicative bands from our cost guides put a US network test at US$5,000 to US$40,000, a mid-market firm-wide program at US$20,000 to US$50,000 a year, and a standard Canadian internal network test at C$20,000 to C$35,000.
Related reading
Best Penetration Testing Companies for CMMC Defense Contractors (2026)
Does a Pentest Lower Your Cyber Insurance Premium? What Underwriters Actually Ask
Ready to scope a construction or engineering penetration test?
The loss that ends in a forfeiture action rarely starts at the firewall. It starts with a mailbox rule nobody reviewed, a help desk that resets a password for a convincing caller, a subcontractor VPN account that outlived the job, or a portal that shows one trade another's pay application. Stingrai is a CREST-accredited penetration testing service provider whose testing supports the evidence CMMC, NIST SP 800-171, CPCSC, owner specifications and cyber insurers ask for, delivered as a one-time annual engagement or as continuous coverage, with named penetration testers, retesting and an attestation letter. Book a free scoping call, get a quote for a firm-wide scope, or see the published package prices on the pricing page.



