US commercial gaming revenue reached a record US$78.72 billion in 2025, with online casino revenue up 27.6% to US$10.74 billion and sports betting up 22.8% to US$16.96 billion, according to the American Gaming Association. Ontario's regulated igaming market generated more than C$4.2 billion in gaming revenue from over C$103 billion wagered in the year to 31 March 2026, on unaudited figures from iGaming Ontario. That money moves through player accounts, wallets and help desks. In September 2023 attackers socially engineered MGM Resorts' tech call center, which its chief executive later called "the layer that got engineered," and the company told the SEC it estimated a negative impact of about US$100 million on its September Adjusted Property EBITDAR.
Where Stingrai fits: Stingrai is a CREST-accredited penetration testing service provider at firm level, headquartered in Toronto with a London office and founded in 2021. Every human-led engagement is staffed with two named penetration testers holding OSCE³, OSWE, OSEP, CREST CRT and CISSP, backed by 18 published CVEs across the team and bug bounty Hall of Fame listings that include Zynga, PaySafe, the US Federal Reserve, Apple, Google and the US Department of Defense. For an operator or supplier that means player accounts, wallets, bonus logic and platform and game server APIs tested authenticated across every role, iOS and Android apps, vishing against the help desk and player support, and the corporate network and Active Directory behind the casino floor, delivered as a one-time annual engagement or a continuous program with retesting and an attestation letter included. Published pricing is US$3,000 for an Autonomous Pentest and US$6,800 for a Hybrid Pentest covering one web application and its APIs (pricing); every other scope is quoted.
This guide is written for casino and sportsbook operators, igaming platform and content suppliers, land-based resorts, provincial lottery corporations and game studios in the United States and Canada. Every vendor entry links to the vendor's own site and every rule is quoted from its owner's text, all checked on 25 September 2026.
Quick answer: who are the best penetration testing companies for iGaming, sportsbooks and casinos in 2026?
The best penetration testing companies for iGaming, sportsbooks and casinos in 2026 are Stingrai, GLI, BMM Testlabs, Gaming Associates, Coalfire, NCC Group, IOActive, Cobalt, Bishop Fox, LevelBlue and Packetlabs. Stingrai ranks first as a CREST-accredited penetration testing service provider with two named penetration testers on every engagement, 18 published CVEs across the team and Hall of Fame listings that include Zynga and PaySafe. It tests player accounts, wallets, bonus logic, platform and game server APIs, mobile apps, the help desk and the casino corporate network, as a one-time annual test or a continuous program, with retesting and an attestation letter included. GLI, BMM Testlabs and Gaming Associates follow as gaming test labs that sell penetration testing measured against the standards regulators already use.

What operators and suppliers are actually required to test
Some gaming rules name penetration testing, some require an annual independent assessment and let the regulator approve how it is done, and several never mention it.
Does Ontario require penetration testing for igaming operators?
Before launch, yes. The AGCO's Internet Gaming Go-Live Compliance Guide states that "results from internal and external penetration testing of their Ontario production infrastructure and applications, conducted by an independent and qualified security firm, must be provided," with management responses and remediation plans, and that "remediations should be verified through an additional scan."
After launch, the Registrar's Standards for Internet Gaming, last updated 14 May 2026, never use the phrase. Standard 5.11 requires that "independent assessments shall be regularly performed by a qualified individual to verify the adequacy of gaming system security and all of its related components." Two player-facing standards shape the test plan: 3.02 requires mechanisms "to detect software, programs, virtualization and other programs capable of circumventing player location detection," and 3.12 requires that players "be given the option to use multi-factor authentication when logging in." For land-based systems, section 14.1.2 of the AGCO's casino gaming systems technical standards requires each new publicly exposed gaming system to undergo "penetration testing through the use of Dynamic Application Security Testing (DAST) tools," with "manual testing to confirm the results from the tools," before it goes live.
What does iGaming Ontario add through the Operating Agreement?
iGaming Ontario conducts and manages igaming through operating agreements with AGCO-registered operators. Its 2026-2029 Business Plan, published 17 February 2026, commits to "working with operators to ensure a coordinated and unified approach to cybersecurity threats" and to "exploring changes to the Operating Agreement for GenAI and cybersecurity." It also reports filing "over 200,000 regulatory reports with FINTRAC," and AGCO Standard 6.02 requires operators' anti-money laundering controls to "align with those of the designated reporting entity."
Does New Jersey require an annual penetration test?
It requires an annual independent assessment, which the Division of Gaming Enforcement has described as a penetration test. N.J.A.C. 13:69O-1.2(q) states: "Each casino licensee offering Internet gaming shall perform an annual system integrity and security assessment conducted by an independent professional selected by the licensee, subject to the approval of the Division." The report must carry the scope, the assessors' names and affiliation, the date, findings, corrective action and the licensee's response. Land-based casino networks carry the same duty under N.J.A.C. 13:69D-2.4(e), amended effective 4 December 2017, and the Division's notice of proposal said "casinos must now perform a mandatory penetration test on their computer systems, even for land-based casino operations." Neither rule sets a methodology, so the approved scope defines the test.
What does Pennsylvania require?
58 Pa. Code § 809a.6(d)(3) requires "an annual security audit" by "an independent third party," which "may take the form of any of the following: (A) Penetration test. (B) Vulnerability assessment. (C) Compliance audit. (D) Risk assessment." Paragraph (d)(4) adds internal and external vulnerability scans at least quarterly, re-run "until all medium risk (CVSS4.0 or higher) vulnerabilities are resolved." A vulnerability assessment meets the letter of the audit clause. It will not find a withdrawal flow that trusts a new payment method, which is the case for choosing the penetration test.
What does Michigan require?
Michigan is the clearest. Mich. Admin. Code R 432.638 requires each internet gaming operator or platform provider, "within 90 days after commencing operations, and annually thereafter," to have a board-approved independent professional run an assessment that includes "a penetration test of all internal, external, and wireless networks to confirm if identified vulnerabilities of all devices, the internet gaming platform, and applications are susceptible to compromise," plus a vulnerability assessment and an ISO 27001 policy review. R 432.738 applies the same words to internet sports betting, and R 432.633 adopts GLI-19 version 3.0 by reference.
Does Nevada require penetration testing?
No. Nevada Gaming Commission Regulation 5.260, adopted in December 2022 and last amended in January 2026, covers nonrestricted casino licensees, race books, sports pools and interactive gaming without using the phrase. It requires a risk assessment, notice to the Board Chair "no later than 24 hours after activating the response procedures" of the incident response plan, and, for Group I licensees, annual checks by "its internal auditor or other independent entity with expertise in the field of cybersecurity." A penetration test is how a licensee shows its practices work, but the method is left to the licensee.
What do GLI-19, GLI-33 and GLI-GSF-2 expect?
The most specific testing rules in this guide. Appendix B.9 of GLI-19 version 3.0 calls for technical security tests on production "on an annual basis, or as required by the regulatory body," run as "an attack simulation by a third-party following a known methodology," with "manual testing to confirm the results from the tools and to identify the impact of the weaknesses." GLI-33 version 1.1, for event wagering, uses the same design and leaves the cadence to the regulator. GLI-GSF-2, published 7 February 2025, is blunter: "Simply running a Vulnerability Scan and providing those results is not sufficient to comply with Penetration Test requirements." It sets an assessment within 90 days of launch and within twelve months of the last, expects critical and high findings fixed immediately with the regulator told within 30 days, asks for five years of remediation records, and names OSCP, GPEN, GWAPT and GXPN among certifications that may show a tester's suitability.
What do tribal casinos need under NIGC rules?
The NIGC's information technology controls at 25 CFR 543.20 never mention penetration testing. They require restricted access, that "unused services and non-essential ports must be disabled whenever possible," that "all remote access must be performed via a secured method," incident response, and recovery procedures tested at least annually. Part 543 covers Class II gaming. Class III gaming must follow a tribal-state compact under 25 U.S.C. 2710(d)(1)(C), so any testing duty sits in the compact and the tribal regulator's own controls.
Where PCI DSS, FinCEN and FINTRAC fit
Card deposits bring PCI DSS 4.0.1 requirement 11.4: internal (11.4.2) and external (11.4.3) penetration tests at least every 12 months and after significant change, segmentation testing under 11.4.5 and 11.4.6, and retesting under 11.4.4. The AML rules ask for no penetration test. FinCEN's casino rule at 31 CFR 1021.210 requires "internal and/or external independent testing for compliance" scoped to money laundering risk, and section 156 of Canada's PCMLTF Regulations requires an effectiveness review of the compliance program every two years. Both test the AML program. Neither asks whether an attacker can empty a wallet.
What attackers go after in gaming, and what a good scope covers
What the 2023 casino attacks and a sportsbook credential stuffing case show
MGM Resorts' Form 8-K of 5 October 2023 says it shut down systems after detecting the attack, which "resulted in disruptions at some of the Company's properties," and that criminals obtained personal data, including driver's license numbers, for some customers who transacted before March 2019. Five days later chief executive Bill Hornbuckle told the Global Gaming Expo, as reported by the Las Vegas Review-Journal, that MGM's tech call center for the technical crew was "the layer that got engineered." Caesars Entertainment's September 2023 Form 8-K blamed "a social engineering attack on an outsourced IT support vendor," after which the intruder "acquired a copy of, among other data, our loyalty program database."
The joint advisory on the group behind both, AA23-320A, co-authored by the FBI, CISA, the RCMP and the Canadian Centre for Cyber Security and updated in July 2025, says Scattered Spider "targets large companies and their contracted information technology (IT) help desks," calling staff to "reset passwords and/or transfer MFA tokens." Our SIM swap statistics and social engineering testing guides trace the playbook.
Online, the US Attorney for the Southern District of New York has sentenced three defendants for a credential stuffing attack launched on or about 18 November 2022 against "a fantasy sports and betting website." About 60,000 accounts were accessed. In some, the attackers added a payment method, deposited US$5 to verify it, then withdrew the whole balance, taking about US$600,000 from roughly 1,600 accounts. Throttling and breached-password checks at login, and step-up authentication before a new payment method can receive a withdrawal, would have broken that chain.
What a good iGaming and casino scope covers
Player accounts and account takeover. Credential stuffing resistance, MFA enrollment and recovery, session handling across web and app, and lockout logic. AGCO Standard 3.12 requires an MFA option, and Pennsylvania requires an Authentication Log kept at least 90 days.
Wallet, deposits and withdrawals. Adding a payment method and withdrawing without step-up, race conditions on concurrent withdrawals, limits, currencies and reversals. This is the exact chain in the New York case.
Bonus and promotion logic. Multi-accounting, bonus stacking, wagering requirement bypass, referral abuse and free bet replay. Pennsylvania requires a Promotions Log, which a good test reconciles against what the application actually granted.
Geolocation and KYC. VPN, proxy, emulator and virtualization evasion, spoofed location, and identity document and liveness bypass, the controls AGCO Standard 3.02 requires.
Remote game servers and platform APIs. Object-level authorization on wagers, balances and game rounds, round replay, and trust between the platform, the game server and third-party content. Our API penetration testing ranking covers the method.
Mobile apps. Local storage, certificate pinning and root or jailbreak detection bypass, and client-side tampering, tested against OWASP MASVS and MASTG. See the mobile app penetration testing ranking.
Help desk and player support. Vishing against the IT help desk and player support, with password reset and MFA re-enrollment checks tested live and agent tooling checked for over-broad access.
Loyalty and rewards. Points transfer and redemption, comp issuance and bulk export from the loyalty database, which is what Caesars reported copied.
Casino corporate network and Active Directory. The path from a phished workstation to the cashier cage, hotel, surveillance and slot management networks, Active Directory attack paths, and segmentation between each internal security domain, which Pennsylvania asks to be tested separately.

Card-not-present fraud and checkout logic overlap with retail, covered in the retail and e-commerce ranking.
How we ranked them
Eleven vendors were scored against nine criteria specific to regulated gaming. Every claim traces to a page the vendor publishes itself, read on 25 September 2026.
A published gaming practice or gaming engagement on the vendor's own site. A casino logo without a description of the work scored nothing.
Fluency in gaming rules and standards, such as GLI-19, GLI-33, GLI-GSF-2 and the AGCO, New Jersey, Pennsylvania and Michigan assessment clauses.
Account, wallet and bonus logic depth: authenticated testing across player, VIP, affiliate and support roles, where the losses happen.
Social engineering and help desk testing, because both 2023 casino incidents started there.
Casino floor and corporate network coverage: Active Directory, segmentation between corporate, cage and slot networks, and gaming equipment.
Firm-level accreditation. Every accreditation in this guide was checked on the CREST Marketplace or the accrediting body's own register, and every rating on the review site itself.
Named penetration testers and published research, as evidence the firm tests rather than scans.
Evidence quality: retesting, a remediation record and a report that fits a regulator-approved scope.
Delivery and price transparency: one-time and continuous options, portal or tracker delivery, and a published price.
Firms whose published gaming work is investigations or audit rather than testing were not ranked. Kroll is CREST-accredited for penetration testing, incident response and SOC services, but its published gaming work is gaming and gambling investigations. BerryDunn publishes SOC audits for gaming and lotteries, which is assurance rather than a penetration test.
The 11 companies at a glance
# | Company | HQ | Accreditations verified | Delivery model | Named testers | Retest | Published pricing | Best for |
|---|---|---|---|---|---|---|---|---|
1 | Stingrai | Toronto, ON | CREST Penetration Testing, firm level | Human-led, hybrid or autonomous; one-time or continuous; PTaaS portal | Yes, two per engagement | Included | Yes, US$3,000 and US$6,800 | Named penetration testers from wallet to help desk |
2 | GLI | Lakewood, NJ | Not on the CREST Marketplace | Test-lab security services | Not stated | Not stated | Not published | GLI-19, GLI-33 and GLI-GSF-2 assessments |
3 | BMM Testlabs | Las Vegas, NV | Not on the CREST Marketplace | Test-lab testing plus a managed SOC | Not stated | Not stated | Not published | Tribal and commercial casinos |
4 | Gaming Associates | London, UK | Not on the CREST Marketplace | Gaming compliance firm with a testing line | Not stated | Re-validation stated | Not published | Geolocation plus penetration testing |
5 | Coalfire | Chicago, IL | CREST Penetration Testing | Consultant-led, including red team | Not stated | Not stated | Not published | Full casino red team |
6 | NCC Group | Manchester, UK | CREST Penetration Testing, Threat Led Penetration Testing, Incident Response and more | Consultant-led, research-heavy | Not stated | Not stated | Not published | Game-logic research |
7 | IOActive | Seattle, WA | CREST Penetration Testing | Research consultancy with a hardware lab | Not stated | Not stated | Not published | Casino floor devices |
8 | Cobalt | Boston, MA | CREST Penetration Testing | PTaaS with a vetted community, credit-based | No, community pool | Unlimited in contract term | No dollar figures | Igaming platform teams on Jira |
9 | Bishop Fox | Tempe, AZ | CREST Penetration Testing | Consultant-led plus a platform | Not stated | Not stated | Not published | Game studios and esports |
10 | LevelBlue | Plano, TX | CREST Penetration Testing and Threat Led Penetration Testing | Managed security with SpiderLabs testing | Not stated | No additional cost | Not published | Casino resorts in managed detection |
11 | Packetlabs | Toronto, ON | CREST Penetration Testing | Consultant-led, manual | Not stated | Not stated | Not published | Canadian lotteries and payout logic |
"Not stated" means the vendor does not publish the detail on its own site, not that it lacks the capability. Ask for it in writing.
1. Stingrai
Stingrai is a global CREST-accredited penetration testing services company founded in Toronto, Canada in 2021, trusted by companies from startups to enterprises to meet audit requirements for SOC 2, ISO 27001, CMMC, PCI DSS and HIPAA. OSCE³, OSWE, OSEP, CREST CRT certified pentesters, who are also world-class security researchers and bug bounty hunters. Choose from fully human-led or hybrid (AI agents plus human penetration testers) engagements across web, API, mobile, AI and LLM, cloud, network, Active Directory and social engineering penetration tests and red team engagements.
Proof anyone can check. The firm-level accreditation is listed on the CREST Marketplace, separate from the CREST CRT certifications individual penetration testers hold, and makes Stingrai one of a handful of CREST-accredited firms headquartered in Canada. Stingrai is rated 5.0 out of 5 from 19 reviews on Clutch, with further reviews on G2. Two named penetration testers run each engagement, reviewed by the team lead and an engagement partner. The team has published 18 CVEs, including CVE-2025-50674 and CVE-2024-32136, and includes a founding member of Uber's offensive security team, a researcher with more than 400 Hall of Fame reports at Apple, Facebook, Google, Yahoo and the US Department of Defense, and a penetration tester in the Halls of Fame of the US Federal Reserve, PaySafe and Zynga. Founder Arafat Afzalzada has 11 years in offensive security.
How a gaming engagement runs. Player, VIP, affiliate, support agent and back-office roles are tested authenticated for broken authorization, IDOR and business logic in wallet, withdrawal, bonus and loyalty flows. Geolocation and KYC controls are tested for evasion, platform and game server APIs for trust between components, and iOS and Android apps against OWASP MASVS and MASTG with Frida and objection. Social engineering combines phone pretexting against the IT help desk and player support with targeted phishing. The corporate network and Active Directory are tested for ACL abuse and Kerberos and delegation paths toward the systems behind the casino floor, and red team engagements run full chains against your SOC.
Delivery and evidence. Findings post to the PTaaS portal as they are confirmed, each with a working proof of concept and prioritized remediation guidance, with live chat to the assigned penetration testers and Jira and Slack integration. Retesting is included, and every report ships with an attestation letter and a verified badge, the evidence an AGCO go-live file or a New Jersey, Pennsylvania or Michigan annual assessment draws on. Stingrai delivers both one-time annual engagements and continuous programs that test each release.
Where Snipe fits. For the player-facing web application and its APIs, Snipe, Stingrai's autonomous AI penetration testing agent, hunts broken authorization, IDOR and business logic in wallet and bonus flows, runs black-box and white-box testing, and opens AutoFix pull requests. The Autonomous tier is Snipe alone with no penetration testers; on Hybrid, Snipe and the penetration testers test together throughout. Pricing is US$3,000 (Autonomous) and US$6,800 (Hybrid) per assessment of one web application and its APIs, or US$650 and US$1,275 per month on 12-month continuous plans (pricing). Networks, apps, help desks and casino estates are quoted.
Strength: named, certified penetration testers across every surface in this guide, from the withdrawal flow to the help desk, with accreditation, ratings and CVEs checkable on public registers. Limitation: game, RNG and platform certification is a separate engagement with a registered test lab such as GLI or BMM, so certification-driven buyers run two relationships. Best for: casino and sportsbook operators, platform and content suppliers, resorts and lotteries in the US and Canada that want named penetration testers and regulator-ready evidence, as a one-time annual test or a continuous program.
2. GLI (Gaming Laboratories International)
Gaming Laboratories International lists its world headquarters in Lakewood, New Jersey, with Canadian offices in Burnaby, British Columbia and New Brunswick, and has folded the security assessment work of Bulletproof, a GLI company, into its compliance network. Its penetration testing for gaming page describes external and internal testing of operator environments, repeated segmentation testing of gaming networks, and multiplayer game weaknesses such as insecure APIs, insufficient rate limiting and client-side manipulation. Its security auditing services add network scanning, application security testing and ISO 27001 and PCI audits. GLI also wrote GLI-19, GLI-33 and GLI-GSF-2. Named penetration testers, retest terms and pricing are not published, and GLI is not listed on the CREST Marketplace.
Strength: the test lab that wrote the standards your assessment is measured against. Limitation: the same group certifies games and systems, so confirm in writing how its security team is separated from certification work on your products. Best for: operators and suppliers running GLI-19, GLI-33 or GLI-GSF-2 assessments across several states and provinces.
3. BMM Testlabs
BMM Testlabs is headquartered on Pilot Road in Las Vegas and describes itself as the longest established private independent gaming testing laboratory, founded on 27 November 1981, with 15 offices in 14 countries. Its security testing for iGaming and land-based products covers information security management system audits, live studio compliance audits, vulnerability assessments, penetration testing, social engineering evaluations and cloud infrastructure assessments, plus PCI ASV services. Sister company BIG Cyber, also in Las Vegas, runs a 24/7 monitoring SOC whose clients include tribal gaming operators and casinos. Named penetration testers, retest terms and pricing are not published, and BMM is not listed on the CREST Marketplace.
Strength: land-based, tribal and online coverage from one gaming-only group, social engineering included. Limitation: the testing page describes services rather than methodology, so ask for a redacted sample report and tester credentials. Best for: tribal and commercial casino operators that want testing and monitoring from a gaming specialist.
4. Gaming Associates
Gaming Associates is headquartered in London with a Canadian office in Toronto and a presence across Europe, North America, Latin America and Australasia. Its penetration testing runs from scoping through exploitation and post-exploitation to reporting, remediation guidance and re-validation, and addresses the OWASP Top 10. The same firm sells social engineering testing, geolocation testing, vulnerability scanning, PCI ASV scans and World Lottery Association assessments alongside games and platform certification. Its testers are described as certified but not named, pricing is not published, and it is not listed on the CREST Marketplace.
Strength: geolocation testing sold next to penetration testing, which maps directly onto AGCO Standard 3.02. Limitation: headquartered outside North America, so confirm which office staffs a US or Canadian engagement. Best for: igaming operators and lotteries that want geolocation, social engineering and penetration testing from one gaming specialist.
5. Coalfire
Coalfire lists its mailing address on North Wabash Avenue in Chicago, and Coalfire Systems holds CREST accreditation for penetration testing. Its published casino case study is a full red team across physical, social and logical vectors, from spearphished logins and the casino's VPN to administrator access. The team reached hotel guest data through the reservation systems, added points to reward cards that could be converted to cash, and gained access to vault and cashier cage computers "sufficient to set up a false line of credit and perform wire transfers at will," then showed access to the gaming and slot machine networks without attacking them. Named penetration testers, retest terms and pricing are not published.
Strength: a published casino engagement that reached the cage, the loyalty system and the slot network. Limitation: the case study is anonymized, and Coalfire publishes no mapping to gaming regulators' assessment clauses. Best for: casino resorts that want a full-scope red team across people, premises and networks.
6. NCC Group
NCC Group is headquartered in Manchester, with its North American regional headquarters in Chicago and an office in Waterloo, Ontario. Its CREST listing is the broadest in this guide, spanning penetration testing, threat-led penetration testing, incident response, SOC, vulnerability assessment and threat intelligence over 19 years of membership. Its gaming evidence is research: a September 2020 guideline for penetration testers on online casino roulette covers session token prediction, time-of-check to time-of-use race conditions, tampering with winning amounts, circumventing table limits and weak pseudorandom number generators. Named penetration testers, retest terms and pricing are not published.
Strength: game-logic research and incident response under one CREST-accredited roof. Limitation: no gaming industry service page, and its casino research dates from 2020. Best for: multinational operators and suppliers that need research-grade testing of game logic.
7. IOActive
IOActive is headquartered at its Seattle hardware lab and has been independent since 1998, and IOActive Inc holds CREST accreditation for penetration testing. Its gaming work is equipment research: work published in August 2023 examined the DeckMate 2, described as the "Official Shuffler of the World Series of Poker," for flaws that could help someone cheat at cards. Its services cover full stack security assessments, red and purple teaming and silicon security. Named penetration testers, retest terms and pricing are not published.
Strength: hardware and embedded depth for table-game and floor devices that most firms decline. Limitation: gaming appears as research rather than as a gaming service line with regulatory context. Best for: gaming equipment manufacturers and casinos testing devices on the floor.
8. Cobalt
Cobalt lists its US headquarters at One Boston Place in Boston, and Cobalt Labs holds CREST accreditation for penetration testing. Testing is delivered by the Cobalt Core community through its platform and bought in credits, each equal to eight hours of testing, sold in annual packages with unlimited retesting during the contract term. Its published gaming customer is Sportingtech, an online gaming platform provider, which credits the Jira integration with letting it fix issues as they were uncovered and reports fixing over 75% of all findings. No dollar pricing is published.
Strength: findings land in the engineering tracker while the test runs, which suits platform teams shipping weekly. Limitation: community staffing gives less continuity release over release, and no gaming regulator mapping is published. Best for: igaming platform and content suppliers that want application testing wired into Jira.
9. Bishop Fox
Bishop Fox lists its global headquarters in Tempe, Arizona, and holds CREST accreditation for penetration testing. Its gaming evidence is a research series on cheating at online video games, published from October 2020, that examines client and server trust in multiplayer game design and what it teaches application security. Its services span application, mobile, cloud and network testing, red teaming and the Cosmos continuous testing platform. Named penetration testers, retest terms and pricing are not published.
Strength: multiplayer architecture and anti-cheat thinking applied to application security. Limitation: no regulated wagering or casino practice page. Best for: game studios and esports platforms where cheating and client trust are the main risks.
10. LevelBlue
LevelBlue lists its global headquarters in Plano, Texas. Its SpiderLabs team delivers penetration testing with retesting of findings at no additional cost, and the CREST Marketplace lists LevelBlue Cyber Solutions Ltd. for penetration testing, threat-led penetration testing and application security testing. It sells into gaming through a retail and hospitality practice, and SpiderLabs published a March 2024 analysis of ransomware groups targeting the casino and entertainment industry. Named penetration testers and pricing are not published.
Strength: testing, managed detection and incident response under one relationship. Limitation: hospitality-led rather than gaming-specific, with no gaming regulator mapping. Best for: casino resorts that want testing inside a managed detection and response contract.
11. Packetlabs
Packetlabs is headquartered on Bay Street in Toronto and holds CREST accreditation for penetration testing and AI-enabled penetration testing. Its lottery and gaming page promises practitioner-led testing with threat models aligned to fraud, prize manipulation, insider risk and platform abuse, manual testing of transactional logic, jackpot workflows and account systems, and scenarios including jackpot manipulation, identity abuse and payout exploitation across POS systems, mobile apps and APIs. Named penetration testers, retest terms and pricing are not published on the page.
Strength: a dedicated lottery and gaming page built around transactional and payout logic. Limitation: the page names no gaming regulator or standard, so the AGCO, GLI or state mapping comes from your side. Best for: Canadian lotteries and gaming operators that want a domestic firm focused on prize and payout logic.
How much does iGaming and casino penetration testing cost in 2026?
Gaming engagements price above a generic application test because the scope usually spans several player roles, a wallet and payment flow, a mobile app and either a help desk or a corporate network. Stingrai's own prices are the only hard figures here. A one-time Autonomous Pentest with Snipe is US$3,000, with no penetration testers on that tier and a No High or Critical Finding, Don't Pay guarantee, and a one-time Hybrid Pentest is US$6,800, each covering one web application and its APIs. The same tiers run at US$650 and US$1,275 per month on 12-month continuous plans. Every other scope is quoted, and current packages are on the pricing page.
The bands below are indicative ranges from our US cost guide and Canadian cost guide, not quotes.
Scope | Indicative US band | Indicative Canadian band |
|---|---|---|
Web application | US$5,000 to US$30,000 or more | C$5,000 to C$40,000 or more |
API | US$6,000 to US$30,000 | C$8,000 to C$40,000 |
Mobile app, per platform | US$7,000 to US$35,000 | C$10,000 to C$45,000 |
External or internal network | US$5,000 to US$40,000 or more | C$8,000 to C$50,000 or more |
Red team | Not broken out | C$30,000 to C$80,000 or more |
Annual program | US$50,000 to US$150,000 or more | C$40,000 to C$120,000 or more |
Buyer's checklist: what to ask every shortlisted vendor
Will the regulator accept you as the independent professional? New Jersey and Michigan approve the assessor and the scope, so ask where the vendor has been approved.
Who exactly is testing, and what do they hold? Names and certifications belong in the statement of work.
How much of the test is manual? GLI-GSF-2 says a scan alone is not a penetration test. Ask for two anonymized findings no scanner would have produced.
Will you test withdrawal, bonus and loyalty logic authenticated, in every role? Player, VIP, affiliate, support agent and back office.
Is the help desk in scope, and what counts as a successful reset?
How will you test geolocation and KYC? VPN, emulator and spoofing evasion, not a check that a vendor SDK is installed.
Does the scope cross from corporate IT to the cage, hotel and slot networks, with each internal security domain tested separately?
Is retesting included, and what does the remediation record look like? GLI-GSF-2 expects critical and high fixes immediately and five years of records.
Can the same vendor run the annual assessment and continuous testing between releases?
How is independence documented if the firm also certifies your games or audits your controls?
The paperwork lives in the statement of work template and the penetration testing RFP template.
Frequently Asked Questions
Who are the best penetration testing companies for iGaming, sportsbooks and casinos in 2026?
The best penetration testing companies for iGaming, sportsbooks and casinos in 2026 are Stingrai, GLI, BMM Testlabs, Gaming Associates, Coalfire, NCC Group, IOActive, Cobalt, Bishop Fox, LevelBlue and Packetlabs. Stingrai is a CREST-accredited penetration testing service provider with two named penetration testers on every engagement, 18 published CVEs across the team and Hall of Fame listings that include Zynga and PaySafe. It tests player accounts, wallets, bonus logic, platform and game server APIs, mobile apps, the help desk and the casino corporate network, as a one-time annual test or a continuous program, with retesting and an attestation letter included. GLI, BMM Testlabs and Gaming Associates follow as gaming test labs that sell penetration testing measured against the standards regulators already use.
Does Ontario require penetration testing for igaming operators?
Before launch, yes. The AGCO's Internet Gaming Go-Live Compliance Guide requires results of internal and external penetration testing of Ontario production infrastructure and applications by an independent and qualified security firm. After launch, Standard 5.11 of the Registrar's Standards for Internet Gaming requires regular independent assessments by a qualified individual to verify the adequacy of gaming system security, without naming the method.
Does New Jersey require an annual penetration test?
New Jersey requires an annual system integrity and security assessment by an independent professional approved by the Division of Gaming Enforcement, under N.J.A.C. 13:69O-1.2(q) for internet gaming and N.J.A.C. 13:69D-2.4(e) for land-based casino networks. The rule text does not say penetration test, but the Division's 2017 notice of proposal described the land-based requirement as a mandatory penetration test.
Which US states name penetration testing in their igaming rules?
Michigan names it outright: R 432.638 and R 432.738 require a penetration test of all internal, external and wireless networks within 90 days of launch and annually after. Pennsylvania lists a penetration test as one of four forms its annual independent security audit may take, alongside quarterly scans. New Jersey requires an annual independent assessment. Nevada's Regulation 5.260 does not name penetration testing.
What does GLI-19 require for security testing?
Appendix B.9 of GLI-19 version 3.0 calls for technical security tests on production annually or as the regulator requires, run as a third-party attack simulation following a known methodology, with manual testing to confirm what the tools find. GLI-GSF-2, published in February 2025, adds that a vulnerability scan alone does not meet penetration test requirements.
Do tribal casinos have to run penetration tests under NIGC rules?
Not under federal rules. The NIGC's information technology controls at 25 CFR 543.20 cover Class II gaming and require restricted access, disabled unused ports, secured remote access, incident response and annually tested recovery procedures, but never mention penetration testing. Class III gaming follows a tribal-state compact, so any testing duty sits in the compact and the tribal regulator's own controls.
How much does iGaming and casino penetration testing cost in 2026?
Stingrai publishes its prices: a one-time Autonomous Pentest at US$3,000 and a one-time Hybrid Pentest at US$6,800 for one web application and its APIs, or US$650 and US$1,275 per month on 12-month continuous plans, with other scopes quoted. Our cost guides put a web application test at roughly US$5,000 to US$30,000 or more in the US and C$5,000 to C$40,000 or more in Canada, as indicative bands rather than quotes.
Related reading
Social Engineering Testing Services (2026): Phishing, Vishing and Physical Assessments Compared
Best Mobile Application Penetration Testing Companies (2026 Ranked)
PCI DSS Penetration Testing: Requirement 11.4 Explained (2026)
Best Retail and E-commerce Penetration Testing Companies (2026)
SIM Swap Statistics 2026: FBI Losses, Scattered Spider, and Carrier Defenses
References
American Gaming Association. Commercial gaming revenue release, 26 February 2026. https://www.americangaming.org/commercial-gaming-revenue-hits-78-7-billion-in-2025-driving-record-18-1-billion-in-gaming-taxes-nationwide/
iGaming Ontario. Year 4 results, 21 May 2026, and 2026-2029 Business Plan. https://igamingontario.ca/en/news/ipsos-channelization-study-year-4-results
Alcohol and Gaming Commission of Ontario. Registrar's Standards for Internet Gaming, Internet Gaming Go-Live Compliance Guide and casino gaming systems technical standards, section 14. https://www.agco.ca/en/book/export/html/245361
New Jersey Division of Gaming Enforcement. N.J.A.C. 13:69O and 13:69D-2.4. https://www.nj.gov/lps/ge/docs/Regulations/CHAPTER69O.pdf
Pennsylvania Code. 58 Pa. Code § 809a.6. https://www.pacodeandbulletin.gov/Display/pacode?file=/secure/pacode/data/058/chapter809a/s809a.6.html&d=reduce
Michigan Administrative Code. R 432.633, R 432.638 and R 432.738. https://www.law.cornell.edu/regulations/michigan/Mich-Admin-Code-R-432-638
Nevada Gaming Commission. Regulation 5.260. https://www.gaming.nv.gov/siteassets/content/regs/regulation-5-as-of-09-26.pdf
Gaming Laboratories International. GLI-19 v3.0, GLI-33 v1.1 and GLI-GSF-2 v1.0. https://gaminglabs.com/gli-standards/
Federal and Canadian rules. 25 CFR 543.20, 25 U.S.C. 2710, 31 CFR 1021.210 and PCMLTF Regulations section 156. https://www.ecfr.gov/current/title-25/section-543.20
MGM Resorts International and Caesars Entertainment. Forms 8-K, 2023. https://www.sec.gov/Archives/edgar/data/789570/000119312523251667/d461062d8k.htm
FBI, CISA, RCMP, CCCS and partners. Advisory AA23-320A, updated 29 July 2025. https://www.cisa.gov/sites/default/files/2025-08/aa23-320a-scattered-spider-508c.pdf
US Attorney's Office, Southern District of New York. Sentencing releases, 2024 to 2026. https://www.justice.gov/usao-sdny/pr/third-defendant-sentenced-prison-hacking-fantasy-sports-and-betting-website
CREST. CREST Marketplace supplier listings, checked 25 September 2026. https://marketplace.crest.org/
Ready to scope an iGaming or casino penetration test?
The loss in gaming is rarely a missing patch. It is a withdrawal flow that trusts a new payment method, or a help desk that resets the wrong person's MFA. Stingrai's CREST-accredited penetration testing supports AGCO go-live files, New Jersey, Pennsylvania and Michigan annual assessments and PCI DSS programs with the scope statement, technical report, remediation record and retest evidence they consume, as a one-time annual engagement or continuous coverage through the year. Book a free scoping call, get a quote, or read the published prices on the pricing page.



