The City of Hamilton, Ontario spent C$18.3 million on response, recovery and outside experts between the ransomware attack of 25 February 2024 and 30 June 2025, according to the city's July 2025 update. The attackers entered through an external internet-facing server and demanded about C$18.5 million, which the city did not pay. Its insurer denied the claim on the policy's coverage terms, and a pre-breach analysis for the city's Auditor General found the January 2024 renewal had already been extended to 21 March 2024 because the city had not met key requirements such as multi-factor authentication. In Texas, the City of Dallas ratified US$8,578,629 in vendor invoices after the Royal ransomware attack of 3 May 2023, under Council Resolution 23-1087.
Neither city's rulebook told it how often to run a penetration test. That is normal in state, local, provincial and municipal government: the rules name control assessments, vulnerability scanning, personnel screening and evidence far more often than a penetration test. Where a clock exists, it is narrow: every three years for federal tax information under IRS Publication 1075, every two years for Texas state agencies under a 2025 statute, and every 12 months for cloud vendors holding GovRAMP Ready or Authorized status.
Where Stingrai fits: Stingrai is a CREST-accredited penetration testing service provider at firm level, headquartered in Toronto with a London office. Each human-led engagement is staffed with two named penetration testers holding OSCE³, OSWE, OSEP, CREST CRT and CISSP, with 18 published CVEs across the team and Hall of Fame listings at the US Department of Defense and the US Federal Reserve. For a public body that means the external perimeter and remote access, the shared Active Directory domain behind every department, Microsoft 365 and Entra ID, resident portals tested role by role, and phishing and vishing against staff, delivered one-time or continuously through its PTaaS portal with retesting and an attestation letter included. Published pricing is US$3,000 for an Autonomous Pentest and US$6,800 for a Hybrid Pentest of one web application and its APIs (pricing); networks and estate-wide scopes are quoted.
This guide is for US state agencies, counties, cities, special districts, courts and police, Canadian provinces, territories, municipalities, agencies and Crown corporations, and GovTech vendors. Universities have their own higher education ranking, federal cloud providers should start with FedRAMP penetration testing requirements, and US federal buyers with the Washington DC guide. Every vendor entry links to the vendor's own site, checked on 25 September 2026.
Quick answer: who are the best penetration testing companies for government and the public sector in 2026?
The best penetration testing companies for government and the public sector in 2026 are Stingrai, Optiv, Securance Consulting, CGI, ISA Cybersecurity, Crowe, Coalfire, Raxis, Kroll, CDW Canada, Rapid7 and BDO Canada. Stingrai is a CREST-accredited penetration testing service provider at firm level, with two named penetration testers on every human-led engagement holding OSCE³, OSWE, OSEP, CREST CRT and CISSP and 18 published CVEs across the team. For a public body it tests the perimeter and remote access, the shared Active Directory domain, Microsoft 365 and Entra ID, resident portals and staff, one-time or continuously, with retesting and an attestation letter included. Optiv, Securance Consulting and CGI follow for cooperative contract reach, a state and local specialist practice, and onshore Canadian municipal coverage.
What public sector buyers are actually required to test
Public sector rules fall into three groups: data regimes that follow the information, control frameworks that follow the system, and vendor programs that follow the cloud product. Most name assessments, scanning and screening; only three set a penetration testing clock.

Does the CJIS Security Policy require penetration testing?
No. The FBI's CJIS Security Policy version 6.1, dated 25 June 2026, contains no CA-8 penetration testing control; the catalogue moves from CA-7 to CA-9. Penetration testing appears only in passing, as a developer testing technique and as testing the FBI may run against connections to its own network. What the policy does require is a control assessment "at least once every three years" under CA-2, and vulnerability scanning "at least monthly" under RA-5, with fix windows of 15 days for critical, 30 for high, 60 for medium and 90 for low findings.
Since 1 October 2024, carried-over requirements and those marked Priority 1, including RA-5, are sanctionable. CA-2 sits in a zero-cycle that ends on 30 September 2027. The personnel rules reach the testers themselves: PS-3 requires "state of residency and national fingerprint-based record checks" for anyone with unescorted access to unencrypted CJI, and PS-7 lists "testing or assessment services" among the external providers held to the agency's personnel rules. Contractors performing criminal justice functions sign the CJIS Security Addendum.
Does IRS Publication 1075 require penetration testing?
Yes. Publication 1075, revision 11-2021, is still the current edition and states at CA-8: "Conduct penetration testing every 3 years on the FTI environment." RA-5 adds scanning every 30 days. Any agency that receives federal tax information inherits it, typically revenue, human services and child support programs.
Two clauses decide who may test. Section 2.C.7 bars access to FTI by "contractors, or sub-contractors located outside of the legal jurisdictional boundary of the United States", and section 2.C.3 requires a background investigation, including FBI fingerprinting, before a contractor gets access. Disclosing FTI to a contractor also triggers a 45-day notice to the IRS Office of Safeguards. A well-scoped test proves the controls without handing the testers tax data.
What does NIST SP 800-53 CA-8 require?
Less than most RFPs assume. CA-8 reads: "Conduct penetration testing [Assignment: organization-defined frequency] on [Assignment: organization-defined systems or system components]." NIST SP 800-53B places CA-8, and CA-8(1) for independent testers, in the High baseline only, so a Moderate system inherits no penetration testing control unless the state's own standard adds one. Many state standards build on this catalogue, so the assignment values in your own standard matter more than the NIST text.
Which state laws name penetration testing?
Texas does, twice. Government Code section 2063.405, formerly 2054.516, requires every state agency whose website or mobile application processes sensitive personal or confidential information to "subject the website or application to a vulnerability and penetration test and address any vulnerability identified in the test." Section 2063.409, in force since 1 September 2025, goes further: "At least once every two years, the command shall require each state agency to complete an information security assessment and a penetration test," performed by the Texas Cyber Command or a vendor it selects. Universities are excluded, and neither section reaches local governments.
Other statutes aim at local governments through programs and reporting. Florida section 282.3185 requires counties and cities to adopt cybersecurity standards consistent with the NIST framework, Ohio Revised Code section 9.64 requires every political subdivision to adopt a cybersecurity program, and New York's General Municipal Law requires incident reports within 72 hours and ransom payment reports within 24 hours. None names a penetration test.
What do GovRAMP and TX-RAMP require of GovTech vendors?
StateRAMP announced on 14 February 2025 that it would operate as GovRAMP, keeping StateRAMP as its legal name, and it lists 72 participating government organizations. Its Security Assessment Framework states that penetration tests "are required" for GovRAMP Ready or Authorized status and for continuous monitoring, while Core providers "may optionally submit a Pen Test". The Penetration Testing Requirements Guide says the initial test must be completed by a 3PAO no more than six months before the security assessment report, then repeated at least every 12 months.
TX-RAMP, now at Government Code section 2063.408, bars Texas state agencies from buying cloud services from non-compliant vendors. Its program manual does not name penetration testing and accepts GovRAMP and FedRAMP statuses.
Can the State and Local Cybersecurity Grant Program pay for a test?
Possibly, but plan without it. The program at 6 U.S.C. 665g passes at least 80 percent of funds to local governments. Public Law 119-75 extended its authority to 30 September 2026, and FEMA had published no FY2026 funding notice when this guide was checked. The FY2025 notice made US$91.75 million available and requires recipients to enroll in CISA's Cyber Hygiene vulnerability scanning. It does not list penetration testing as a named cost, but it says CISA "recommends" that governments move toward "conducting regular penetration testing."
What does the Government of Canada require?
The Treasury Board Directive on Security Management, in effect since 1 July 2019, asks departments to identify and report vulnerabilities and to assess whether security controls are effective, without naming penetration testing. ITSG-33 does include CA-8 in its control catalogue, with the frequency set by the department. Federal procurement, clearances and Protected B cloud are covered in the Ottawa penetration testing guide.
What do Ontario and British Columbia require?
Ontario's standards bind ministries, not municipalities. GO-ITS 25.0 says a vulnerability assessment or penetration test "must be performed" after significant changes or for environments processing sensitive information, and GO-ITS 42 requires a penetration test before any major change to an external-facing application reaches production. The Enhancing Digital Security and Trust Act, 2024 reaches municipalities only through regulation, and O. Reg. 51/26, in force since 1 July 2026, prescribes colleges and universities, public hospitals, children's aid societies and school boards. They must run a cyber security program, complete maturity assessments and report critical incidents within 72 hours. The regulation never mentions penetration testing.
British Columbia's Information Security Policy, version 5.0 of August 2025, directs ministries to "apply vulnerability scanning, security testing, and system acceptance processes." Its Defensible Security framework for public sector organizations asks for vulnerability scans and assessments. Neither names penetration testing.
What does the Canadian Centre for Cyber Security recommend for municipalities?
The Cyber Centre's municipal advice sits in threat bulletins and sector guidance rather than a testing standard. Its March 2025 threat bulletin on activity against provincial, territorial, Indigenous and municipal governments recommends phishing-resistant MFA, "a robust vulnerability management program for all systems and services that are accessible from the internet", and an incident response and recovery plan. Its guidance on Canada's water systems, many of them municipally owned, goes further and advises "conducting penetration tests and using automated vulnerability scanning tools."
What do cyber insurers ask a municipality for?
Insurers often set the most practical standard. Hamilton's policy had already been extended over unmet requirements such as MFA before the attack, and its claim was then denied on coverage terms. Carrier questionnaires ask about MFA, backups and how the applicant validates its controls, and some name a penetration test in the last year as one acceptable answer. The cyber insurance underwriting guide covers what to attach at renewal.
The public sector attack surface a good scope covers
A municipal or state estate is several organizations sharing one network: police, finance, water, courts and the clerk's office, often in one Active Directory domain. Hamilton's attackers came in through an internet-facing server. That is where a scope should start, not stop.

External perimeter and legacy remote access. VPN and remote access appliances, exposed management interfaces, old file transfer servers and forgotten hosts. Check each against CISA's Known Exploited Vulnerabilities catalog.
Active Directory across departments. One domain shared by public safety, finance and utilities means one path to domain admin. Test ACL abuse, Kerberos and delegation, service accounts and the trust between departmental segments. See the network penetration testing guide.
Microsoft 365 and Entra ID. Conditional Access gaps, legacy authentication, consent grants, guest access and hybrid identity. CISA publishes free Secure Cloud Business Applications baselines that make a useful yardstick.
Resident portals and payments. Permitting, licensing, property tax, parking and utility billing portals, tested authenticated across every role for broken authorization, IDOR and business logic. Card flows bring PCI DSS into scope.
Courts, records and CJI. Case management, records management and anything that touches criminal justice information. Screening rules apply to the testers themselves, as the CJIS section above explains.
911 and public safety. Test the networks and segmentation around dispatch, and leave live computer-aided dispatch out of active exploitation unless the public safety answering point agrees in writing.
Staff and the service desk. Phishing, vishing of the help desk, payment redirection requests and physical entry. See social engineering testing services.
Election-adjacent systems. Public-facing information sites and the administrative network around election offices only, with written authority from the responsible election official. Voting systems follow their own certification and testing programs and sit outside a general penetration test.
Mature programs add an assumed-breach red team exercise.
How we ranked them
Twelve vendors were scored against nine criteria. Every claim traces to a vendor's own page or a public register.
A published public sector practice. A page on the vendor's own site for state, local, provincial or municipal government.
Penetration testing as a named service with a described method.
Independent accreditation that a procurement officer can check: firm-level CREST accreditation, GovRAMP or FedRAMP 3PAO status. Every accreditation in this guide was checked on the CREST Marketplace or the accrediting body's own register, and every rating on the review site itself.
Coverage of the public sector surface: perimeter and remote access, internal networks and Active Directory, Microsoft 365 and Entra ID, resident portals and staff.
Regime fluency: whether the evidence can be shaped for CJIS, IRS Publication 1075, GovRAMP, NIST SP 800-53 or provincial programs.
Procurement access: cooperative contracts, OECM, a vendor of record arrangement, or a quote process that fits a small purchase threshold.
Personnel and data handling: where testers sit, whether they can be background checked, and where findings are stored.
Evidence and retest: reproduction steps, a remediation record and a retest result.
Delivery model and price transparency: one-time and continuous options, and whether a buyer can see a number before a sales call.
Firms whose government offer is audit, advisory or managed detection without offensive testing were not ranked.
The 12 companies at a glance
# | Company | HQ | Accreditations verified | Delivery model | Named testers | Retest | Published pricing | Best for |
|---|---|---|---|---|---|---|---|---|
1 | Stingrai | Toronto, ON (London, UK office) | CREST Penetration Testing, firm level | Human-led, hybrid or autonomous; one-time or continuous | Yes, two per human-led engagement | Included | Yes, US$3,000 and US$6,800 | Named, certified testers with retesting and an attestation letter |
2 | Optiv | Leawood, KS | CREST Penetration Testing | Consultant-led inside a large integrator | Not stated | Add-on | Not published | Buying through cooperative contracts |
3 | Securance Consulting | Tampa, FL | None listed | Senior-consultant projects | Not stated | Not stated | Not published | Counties and cities led by internal audit |
4 | CGI | Montréal, QC | CREST held by its UK entity only | Autonomous validation plus consultants | Not stated | Yes | Not published | Provinces and large municipalities |
5 | ISA Cybersecurity | Toronto, ON | None listed | Consultant-led, with incident response | Not stated | Not stated | Not published | Ontario municipalities |
6 | Crowe | Chicago, IL | None listed for the US practice | Consultant-led projects | Leaders named, testers not | Not stated | Not published | Existing public sector clients |
7 | Coalfire | Chicago, IL | CREST Penetration Testing; GovRAMP and FedRAMP 3PAO | Consultant-led; OnDemand program | Not stated | Not stated | Not published | GovTech vendors pursuing GovRAMP |
8 | Raxis | Atlanta, GA | None listed | Point-in-time and continuous; Raxis One portal | Senior US engineers, not named | Every fix | Not published | CJI and FTI environments |
9 | Kroll | New York, NY | CREST Penetration Testing, Incident Response, SOC | Consultant-led projects | Not stated | Not stated | Quote on request | Testing tied to incident response |
10 | CDW Canada | Toronto, ON (OECM record) | None listed | Consultant-led, national IT provider | Not stated | Not stated | OECM price list, login only | Existing CDW customers in Ontario |
11 | Rapid7 | Boston, MA | None listed; platform holds GovRAMP | Consulting beside its platform | Not stated | Not stated | Not published | Existing platform customers |
12 | BDO Canada | Toronto, ON (OECM record) | None listed for BDO Canada | Consultant-led | Not stated | Not stated | Not published | OECM buyers |
"Not stated" means the vendor does not publish the detail on its own site, not that it lacks the capability. Ask for it in writing during scoping.
1. Stingrai (top rated for government and the public sector)
Stingrai is a global CREST-accredited penetration testing services company founded in Toronto, Canada in 2021, trusted by companies from startups to enterprises to meet audit requirements for SOC 2, ISO 27001, CMMC, PCI DSS and HIPAA. OSCE³, OSWE, OSEP, CREST CRT certified pentesters, who are also world-class security researchers and bug bounty hunters. Choose from fully human-led or hybrid (AI agents plus human penetration testers) engagements across web, API, mobile, AI and LLM, cloud, network, Active Directory and social engineering penetration tests and red team engagements.
What a public body can verify. The firm-level accreditation is listed on the CREST Marketplace under Penetration Testing. Every human-led and hybrid engagement is staffed with two named penetration testers, reviewed by the team lead and an engagement partner. The team has published 18 CVEs, including CVE-2025-50674 and CVE-2024-32136, and holds Hall of Fame listings at the US Department of Defense and the US Federal Reserve. Founder Arafat Afzalzada has 11 years of offensive security work, including for government. Customers rate the firm 5.0 out of 5 across 19 reviews on Clutch, with further reviews on G2.
How a government estate is tested. External work starts with VPN appliances and exposed management interfaces. Internal work follows lateral movement across the shared domain, with an Active Directory assessment of ACL abuse and Kerberos and delegation paths to domain admin, plus segmentation testing between departments. Entra ID is tested for app registrations, consent grants and Conditional Access gaps. Resident portals are tested authenticated across every role for broken authorization, IDOR and business logic, and phishing and vishing test staff and the service desk.
Evidence and delivery. Findings post to the PTaaS portal as they are confirmed, each with a working proof of concept, with live chat to the assigned penetration testers and Jira and Slack integration. Retesting is included, and every report ships with an attestation letter and a verified badge. Stingrai delivers both one-time annual engagements and continuous programs.
Where Snipe fits. Snipe, Stingrai's autonomous agent for web applications and their APIs, applies to resident portals only, where it hunts broken authorization, IDOR and business logic flaws. The Autonomous tier is Snipe alone, with no penetration testers. In a Hybrid engagement, Snipe and the penetration testers test together throughout.
Delivery: human-led, hybrid or autonomous; one-time or continuous. Named testers: yes, two per human-led engagement. Retest: included. Portal: yes. Pricing: published, at US$3,000 for an Autonomous Pentest and US$6,800 for a Hybrid Pentest per assessment of one web application and its APIs, or US$650 and US$1,275 per month on 12-month plans (pricing); other scopes via get a quote. Accreditation: CREST Penetration Testing, firm level. Strength: every claim a procurement file needs has a public source, from the CREST listing to the CVE records to the review profiles. Limitation: headquartered in Toronto with a London office, so for FTI or CJI environments the location and screening of each tester must be agreed at scoping. Best for: state agencies, counties, cities, provinces and municipalities that want named, certified penetration testers, included retesting and an attestation letter, on an annual or continuous basis.
2. Optiv
Optiv lists its corporate headquarters in Leawood, Kansas, and runs a state, local and education practice whose page lists 31 contract vehicles, including NASPO, Sourcewell, OMNIA, GSA, Texas DIR, New York OGS and VITA. Its OMNIA Partners contract R250305 prices "Attacker Simulation (Pen Testing)", and Optiv Federal's GSA schedule includes Highly Adaptive Cybersecurity Services open to state and local buyers. Its attack and penetration practice covers network, application and red team testing.
Delivery: consultant-led, inside a large integrator. Named testers: not stated. Retest: add-on. Portal: not described. Pricing: not published. Accreditation: CREST Penetration Testing. Strength: the widest procurement reach in this guide. Limitation: some listed vehicles cover products, not services, so confirm the line that carries penetration testing. Best for: agencies, counties and cities that buy security through an existing cooperative contract.
3. Securance Consulting
Securance is headquartered in Tampa, Florida and was founded in 2002. Its state, local and education page cites more than 22 years serving government agencies, with consultants who each bring over 15 years of public sector experience, and links a City of Tucson cooperative contract (240160-10) through its partnership with Axia. Its penetration testing page is the most specific here on method: networks, applications, APIs, wireless, IoT devices such as badge readers, and ICS and OT including SCADA, switching to passive methods where active testing could take control systems offline.
Delivery: senior-consultant projects, often beside IT audit. Named testers: not stated. Retest: not stated. Portal: none described. Pricing: not published. Accreditation: none listed on the CREST Marketplace. Strength: published methodology and a passive-first approach to water and building control systems. Limitation: a small, audit-led firm, so confirm capacity for concurrent departmental scopes. Best for: counties and cities whose internal audit office sponsors testing.
4. CGI
CGI's head office is in Montréal. Its municipal cybersecurity page sets out a municipal framework of posture review, managed detection and response, exposure management and awareness training, aligned to Ontario's Enhancing Digital Security and Trust Act, 2024. Its continuous offensive security validation pairs autonomous internal and external penetration testing with consultants, identity, phishing and segmentation testing, and remediation validation, delivered from "30 offices in Canada".
Delivery: autonomous validation plus consultants, inside managed services. Named testers: not stated. Retest: yes. Portal: not described. Pricing: not published. Accreditation: the CREST listing belongs to CGI IT UK Ltd, not the Canadian practice. Strength: onshore Canadian delivery across IT and OT, with a framework written for municipalities. Limitation: the offensive service leads with autonomous testing, so confirm the manual depth on resident portals. Best for: provinces and large municipalities that want assessment, detection and validation from one Canadian integrator.
5. ISA Cybersecurity
ISA Cybersecurity's head office is in Toronto, where it was founded in 1992. Its government page cites more than 200 public sector clients across municipal, provincial and federal agencies, Canadian data residency and data centres, a place on Ontario's IT security arrangement (Tender-17543), and the LAS CIMOM program for incident response to Ontario municipalities. Its penetration testing services cover internal, external, wireless, mobile and web testing, plus red and purple teaming.
Delivery: consultant-led, beside managed services and incident response. Named testers: not stated. Retest: not stated. Portal: not described. Pricing: not published. Accreditation: none listed on the CREST Marketplace. Strength: a municipal incident response program and Canadian data residency under one firm. Limitation: the published methodology is brief, so ask for a sample report and written retest terms. Best for: Ontario municipalities and agencies that want testing and incident response together.
6. Crowe
Crowe is headquartered in Chicago. Its public sector cybersecurity page names state and local government as a client group and lists offensive security and penetration testing beside tabletop exercises. Its penetration testing page covers internal red team exercises, external, physical and wireless testing, web, API and mobile applications, phishing and vishing, and purple teaming.
Delivery: consultant-led projects. Named testers: leaders named, testers not. Retest: not stated. Portal: not described. Pricing: not published. Accreditation: none listed for the US practice. Strength: physical, wireless and social engineering alongside network and application testing. Limitation: Crowe LLP is also a licensed CPA firm, so settle independence if it audits your financial statements. Best for: state and local clients of its public sector practice.
7. Coalfire
Coalfire lists its mailing address in Chicago. It appears on GovRAMP's list of A2LA-accredited assessors participating in the program, is an accredited FedRAMP 3PAO, and holds CREST Penetration Testing accreditation as Coalfire Systems. Testing runs through its DivisionHex practice, whose OnDemand program puts testing under one contract with rollover funds and a web platform for scheduling and reports.
Delivery: consultant-led, optionally through OnDemand. Named testers: not stated. Retest: not stated. Portal: web platform for scheduling and reports. Pricing: not published. Accreditation: CREST Penetration Testing, GovRAMP 3PAO, FedRAMP 3PAO. Strength: a GovTech vendor gets its GovRAMP assessor and its offensive testing from one firm. Limitation: an assessor cannot independently assess work it helped remediate, and no state and local page is published. Best for: GovTech SaaS vendors working toward GovRAMP Ready or Authorized status.
8. Raxis
Raxis is headquartered in Atlanta, Georgia. Its government penetration testing page says every test "is done by hand by a senior U.S. engineer", maps findings to NIST SP 800-53, NIST SP 800-171 and CMMC, and states "We retest every fix". Its continuous service adds unlimited retesting through the Raxis One portal.
Delivery: point-in-time and continuous. Named testers: not stated. Retest: every fix. Portal: Raxis One. Pricing: not published. Accreditation: none listed on the CREST Marketplace. Strength: senior US-based testers, which simplifies the location and screening questions CJIS and Publication 1075 raise. Limitation: the government page is written for federal contractors, not state and local agencies. Best for: agencies, courts and police with CJI or FTI in scope.
9. Kroll
Kroll is headquartered at One World Trade Center in New York, and its CREST listing covers Penetration Testing, Incident Response and Security Operations Centre. Its penetration testing page describes a six-phase approach across web, cloud, API, mobile, network, IoT and AI, and links an election security case study testing VotingWorks' Arlo audit software, which states, counties and municipalities use.
Delivery: consultant-led projects and agile programs. Named testers: not stated. Retest: not stated. Portal: not described. Pricing: quoted on request. Accreditation: CREST Penetration Testing, Incident Response and SOC. Strength: testing and incident response from one firm. Limitation: no state or local government page. Best for: agencies and election technology vendors that want testing tied to an incident response retainer.
10. CDW Canada
CDW Canada lists an Etobicoke, Toronto address on its OECM supplier record and is one of seven supplier partners on OECM's penetration testing agreement. Its penetration testing page claims "one of the largest penetration testing teams in Canada" across networks, cloud, OT, applications and social engineering, and its testing data sheet states "The team is 100% based in Canada."
Delivery: consultant-led from a national IT provider. Named testers: not stated. Retest: not stated. Portal: not described. Pricing: OECM price lists behind a customer login. Accreditation: none listed on the CREST Marketplace. Strength: OECM access and Canadian-based testers. Limitation: the practice sits inside a reseller, so confirm tester seniority and independence from products you bought. Best for: Ontario public bodies already buying IT through CDW.
11. Rapid7
Rapid7 is headquartered in Boston, Massachusetts. Its government page describes a "TX-RAMP and COV-RAMP-certified platform" for state and local customers, and in June 2026 it announced GovRAMP Authorization for its InsightGovCloud platform. Its penetration testing services are point-in-time network, application and social engineering assessments.
Delivery: consulting beside a platform. Named testers: not stated. Retest: not stated. Portal: not described for testing. Pricing: not published. Accreditation: none listed on the CREST Marketplace; the state authorizations apply to the platform. Strength: platform customers can add testing without onboarding a new vendor. Limitation: the authorizations cover the platform, not the consulting, so write retest terms into the statement of work. Best for: agencies already on the Rapid7 platform.
12. BDO Canada
BDO Canada LLP lists a Toronto address on its OECM supplier record, runs more than 100 offices nationally, and is also an OECM supplier partner. Its Active Assure service includes penetration testing, active threat simulation, purple teaming and tabletop simulation.
Delivery: consultant-led, beside managed services. Named testers: not stated. Retest: not stated. Portal: not described. Pricing: not published. Accreditation: none for BDO Canada; the CREST listing belongs to BDO LLP in the UK. Strength: tabletop simulation beside testing, which suits council-level exercises. Limitation: the published testing description is summary level. Best for: Ontario municipalities buying through OECM from an advisory firm.
Free and shared public options worth knowing (not ranked)
These are not competitors to a commissioned test and are not ranked. They are the first calls a small county or town should make.
CISA Cyber Hygiene. Vulnerability scanning and web application scanning at no cost for state, local, tribal and territorial governments. It is required of SLCGP recipients, and it scans rather than exploits.
CISA penetration testing. CISA's services catalogue describes penetration testing as a service "offered to federal agencies through the federal shared services program" and points other stakeholders to Cyber Hygiene. A state or local body should not plan around it.
MS-ISAC. CISA's cooperative agreement funding the Multi-State ISAC ended on 30 September 2025, and the MS-ISAC moved to paid membership from 1 October 2025.
CISA SCuBA and ScubaGear. Free secure configuration baselines for Microsoft 365, and a tool that checks a tenant against them. Run it before a test.
State shared services. Texas DIR's Managed Security Services, described below, is the clearest example of a state buying testing on behalf of local governments.
How public sector procurement changes the buy
The procurement route often sets the shortlist before security has a view, so plan it first.
Thresholds and RFPs. Above a threshold set by statute or policy, the purchase must be competed. A precise statement of work and RFP questions keep the evaluation technical. Canadian municipalities also work inside trade agreement thresholds: for 2026 to 2027 the Canadian Free Trade Agreement covers MASH sector purchases of goods or services from C$139,000.
US cooperative contracts. GSA's Cooperative Purchasing Program lets state, county and city governments buy Highly Adaptive Cybersecurity Services, which include penetration testing. NASPO ValuePoint's cybersecurity portfolio, awarded in November 2025, covers risk assessment and incident response but does not name penetration testing. Sourcewell's technology contract 121923 lists penetration testing among its cybersecurity services, and OMNIA Partners' 2025 cybersecurity contract includes Optiv's "Attacker Simulation (Pen Testing)" line.
State shared services. Texas DIR's Managed Security Services, run under a contract with SAIC, includes penetration testing and election security assessments, is open to local government entities, and carries a 2.75% DIR fee. DIR funds some tests for state agencies, community colleges and public universities "as long as funds are available", with application tests limited to one per fiscal year.
Canadian arrangements. OECM's vulnerability assessment and penetration testing agreement is open to Ontario municipalities, school boards, hospitals and agencies through seven supplier partners until 30 January 2027, with no extensions left. Supply Ontario's IT security vendor of record arrangement (Tender-17543) is open to ministries and broader public sector buyers, and British Columbia's IM/IT Security Advisory Services arrangement includes a penetration testing service area until 30 April 2027. Open tenders appear on CanadaBuys, MERX, Biddingo, bids&tenders, BC Bid, SEAO and the Alberta Purchasing Connection.
Insurance and screening. Public contracts fix minimum insurance limits and certificate requirements. Settle background checks for anyone who may touch CJI or FTI before award.
Data residency. IRS Publication 1075 keeps FTI inside the United States. Nova Scotia's PIIDPA requires public bodies, including municipalities, and their service providers to store and access personal information only in Canada unless an exception applies, until its repeal on 1 April 2027. British Columbia's section 33.1 allows disclosure outside Canada only in accordance with the regulations. Say in the contract where findings and reports will be stored.
How much does a government penetration test cost in 2026?
Public sector engagements price above a single application test because scope usually spans a network, a shared domain, Microsoft 365, several portals and staff, and the report must satisfy a council, an auditor or an insurer.
Stingrai's own prices are the only hard figures in this section. An Autonomous Pentest (Snipe only, no penetration testers) is US$3,000 and a Hybrid Pentest is US$6,800 per assessment, each for one web application and its APIs, or US$650 and US$1,275 per month on 12-month continuous plans (pricing). Every other scope is quoted through get a quote.
The bands below are indicative, drawn from our penetration testing cost guide and our Canadian cost analysis.
Scope | Indicative US band | Indicative Canadian band |
|---|---|---|
Single resident portal or web application | US$5,000 to US$30,000 | C$5,000 to C$25,000 |
External or internal network test | US$5,000 to US$40,000 | C$15,000 to C$35,000 (external) |
Annual program across a multi-department estate | US$50,000 to US$150,000 or more | C$40,000 to C$120,000 or more per year (continuous) |
Three things move a public sector quote: the number of departmental segments and domains in scope, whether on-site or screened testers are needed, and whether findings must map to a regime such as CJIS or Publication 1075.
Buyer checklist: ten questions for every shortlisted vendor
Who exactly will test, and what do they hold? Put names and certifications in the statement of work.
Where can we verify your accreditation? A public register should take two minutes to check.
Where will each tester be physically located, and can they pass our screening? Essential if CJI or FTI could be reached.
Does the scope cover the internal network and Active Directory, not just the perimeter?
How will you test Microsoft 365 and Entra ID? Ask for the baseline you test against.
What is excluded, and how will you handle 911, SCADA and election-adjacent systems? Get the rules of engagement in writing.
Is retesting included, and within what window?
What does the report look like? Ask for a redacted sample.
Where will findings and evidence be stored, and for how long?
Which contract vehicle, if any, can we use, and does it cover professional services?
Frequently Asked Questions
Who are the best penetration testing companies for government and the public sector in 2026?
The best penetration testing companies for government and the public sector in 2026 are Stingrai, Optiv, Securance Consulting, CGI, ISA Cybersecurity, Crowe, Coalfire, Raxis, Kroll, CDW Canada, Rapid7 and BDO Canada. Stingrai is a CREST-accredited penetration testing service provider at firm level, with two named penetration testers on every human-led engagement holding OSCE³, OSWE, OSEP, CREST CRT and CISSP and 18 published CVEs across the team. For a public body it tests the perimeter, the shared Active Directory domain, Microsoft 365, resident portals and staff, one-time or continuously, with retesting and an attestation letter included. Optiv, Securance Consulting and CGI follow for cooperative contract reach, a state and local specialist practice, and onshore Canadian municipal coverage.
Does the CJIS Security Policy require penetration testing?
No. CJIS Security Policy version 6.1, dated 25 June 2026, contains no CA-8 penetration testing control. It requires a control assessment at least every three years, vulnerability scanning at least monthly, and fingerprint-based record checks for anyone, testers included, with unescorted access to unencrypted CJI.
Does IRS Publication 1075 require penetration testing?
Yes. Publication 1075, revision 11-2021, states at CA-8: "Conduct penetration testing every 3 years on the FTI environment." It also bars access to FTI by contractors outside the United States and requires a background investigation before any contractor gets access.
Which state laws require a penetration test?
Texas is the clearest example. Government Code section 2063.405 requires a vulnerability and penetration test of any state agency website or mobile application that processes sensitive or confidential information, and section 2063.409 requires each state agency to complete an information security assessment and a penetration test at least once every two years. Florida, Ohio and New York impose programs or incident reporting on local governments without naming penetration testing.
Do GovTech vendors need a penetration test for GovRAMP?
Yes, for Ready and Authorized status. GovRAMP, the operating name StateRAMP adopted in February 2025, requires a penetration test by a 3PAO no more than six months before the security assessment report, and at least every 12 months during continuous monitoring. Core providers may submit one optionally.
Do Canadian municipalities have to run penetration tests?
Not under any provincial rule reviewed for this guide. Ontario's O. Reg. 51/26 does not prescribe municipalities, and British Columbia's policies name scanning and security testing without a cadence. The pressure comes from insurers, auditors and Canadian Centre for Cyber Security guidance, which advises water utilities, many of them municipal, to run penetration tests.
Can a Canadian firm test a US state or local government?
Yes, with two conditions agreed at scoping. IRS Publication 1075 bars access to federal tax information from outside the United States, and the CJIS Security Policy requires fingerprint-based checks for anyone with unescorted access to unencrypted CJI. Scopes without CJI or FTI carry neither constraint.
How much does a government penetration test cost in 2026?
Stingrai's published prices are US$3,000 for an Autonomous Pentest and US$6,800 for a Hybrid Pentest of one web application and its APIs, or US$650 and US$1,275 per month on 12-month continuous plans. Indicative market bands run from US$5,000 to US$40,000 for a single application or network test and US$50,000 to US$150,000 or more for an annual multi-department program.
Related reading
Ready to scope a public sector penetration test?
Hamilton's attackers came in through one internet-facing server, and its 2021 audit recommendations were still largely unimplemented when they did. Stingrai puts two named, certified penetration testers on the perimeter, the shared domain, Microsoft 365, resident portals and staff, with retesting and an attestation letter included, one-time or continuously. Book a free scoping call, get a quote for a network or estate-wide scope, or read the published package prices on the pricing page.



