In the first half of 2025, nearly 300 data breaches were reported impacting as many as 250,000 clients of tax professionals, the IRS and its Security Summit partners said as they closed their 2025 summer series. The fraud that follows is larger still. Business email compromise produced US$3.05 billion in reported losses across 24,768 complaints in 2025, second only to investment fraud, according to the FBI Internet Crime Complaint Center's 2025 report. An accounting firm sits on both sides of that ledger. It holds the returns, statements and bank details a thief wants, and it runs the mailbox a client trusts when payment instructions change.
US regulation now names the control. The FTC Safeguards Rule treats accountants and tax preparers as financial institutions and, since 9 June 2023, has required annual penetration testing unless effective continuous monitoring is in place. Canada has no equivalent clause, but PIPEDA, Quebec Law 25, the CRA and the provincial CPA bodies all require safeguards a penetration test directly evidences.
Where Stingrai fits: Stingrai is a CREST-accredited penetration testing service provider at firm level, founded in Toronto in 2021 with a London office, serving firms across the United States and Canada. Every human-led engagement is staffed by two named penetration testers holding OSCE³, OSWE, OSEP, CREST CRT and CISSP, reviewed by the team lead and an engagement partner, with 18 published CVEs across the team. For an accounting firm that means the Microsoft 365 and Entra ID tenant tested for MFA gaps and consent-grant abuse, the client portal tested across every role, Active Directory tested from a phished workstation toward domain admin, and phishing and vishing run against staff in tax season. Findings post to the PTaaS portal as they are confirmed, retesting and an attestation letter are included, and engagements run as a one-time annual test on the Safeguards Rule calendar or as a continuous program. Published pricing covers one web application and its APIs (pricing); every other scope is quoted.
This guide is for CPA firms from local practices to the top 100, tax preparers, outsourced bookkeepers, payroll bureaus and fractional CFO firms in the US and Canada. Every vendor entry was checked on its own site on 25 September 2026.
Quick answer: who are the best penetration testing companies for accounting and CPA firms in 2026?
The best penetration testing companies for accounting and CPA firms in 2026 are Stingrai, Raxis, TrustedSec, Plante Moran, GuidePoint Security, Schellman, CLA (CliftonLarsonAllen), MNP, Black Hills Information Security, Sikich and BDO Canada. Stingrai ranks first: a CREST-accredited penetration testing service provider at firm level whose two named penetration testers cover the Microsoft 365 tenant, client portal, internal network, Active Directory and staff phishing, with retesting and an attestation letter included on one-time annual and continuous engagements. Raxis, TrustedSec and Plante Moran follow for Safeguards-specific testing, foothold-to-escalation depth, and Microsoft 365 and AI impersonation testing respectively.

What accounting and CPA firms are actually required to test
Nine instruments come up when an accounting firm buys a penetration test. One names the test. The rest require safeguards, a written plan or a quality system and leave the method to the firm.
Does the FTC Safeguards Rule apply to accounting and CPA firms?
Yes, by name. The scope section, 16 CFR 314.1(b), lists "tax preparation firms" among the financial institutions under FTC jurisdiction, and 314.2(h)(2)(viii) gives the accountant example directly:
An accountant or other tax preparation service that is in the business of completing income tax returns is a financial institution because tax preparation services is a financial activity listed in 12 CFR 225.28(b)(6)(vi) and referenced in section 4(k)(4)(G) of the Bank Holding Company Act, 12 U.S.C. 1843(k)(4)(G).
One carve-out causes confusion. Under 15 U.S.C. 6803(d), a licensed CPA bound by state rules that prohibit disclosure without consent is exempt from GLBA's privacy notice disclosures. That exemption covers the notice. It does not reach the Safeguards Rule, which the FTC issued under section 6801(b). Payroll bureaus, bookkeepers and fractional CFO firms should test their own services against 314.2(h)(1): a business significantly engaged in a financial activity is covered.
Does the FTC Safeguards Rule require penetration testing?
Yes, unless the firm runs effective continuous monitoring. 16 CFR 314.4(d)(2) opens: "For information systems, the monitoring and testing shall include continuous monitoring or periodic penetration testing and vulnerability assessments." Absent effective continuous monitoring, it requires "Annual penetration testing of your information systems determined each given year based on relevant identified risks in accordance with the risk assessment," plus vulnerability assessments at least every six months and after material changes.
The rule defines the test at 314.2(n) as one in which "assessors attempt to circumvent or defeat the security features of an information system by attempting penetration of databases or controls from outside or inside your information systems." An external vulnerability scan does not meet that definition. The clause has applied since 9 June 2023, after the Commission delayed the original December 2022 date (87 FR 71509). The alternative is monitoring that detects vulnerability-creating changes "on an ongoing basis"; a quarterly scan is periodic rather than ongoing.
Three other elements shape scope. Section 314.4(c)(5) requires multi-factor authentication "for any individual accessing any information system" unless the Qualified Individual approves an equivalent in writing. Section 314.4(c)(4) requires procedures for "testing the security of externally developed applications," such as a licensed portal or hosted tax software. And 314.4(i) puts "results of testing" in the Qualified Individual's annual report.
Are small firms exempt from the annual penetration test?
Some are. 16 CFR 314.6 exempts institutions that "maintain customer information concerning fewer than five thousand consumers" from the annual test, the written risk assessment, the written incident response plan and the annual report. Consumers are individuals obtaining a financial service "primarily for personal, family, or household purposes" (314.2(b)(1)), so business clients do not count. Multi-factor authentication, encryption, training and the FTC breach notice still apply.
What does a firm have to tell the FTC after a breach?
Since 13 May 2024, 314.4(j) has required notice to the FTC "as soon as possible, and no later than 30 days after discovery" of a notification event involving the information of at least 500 consumers. Unauthorized access to unencrypted customer information is presumed to be acquisition unless the firm has reliable evidence otherwise, so a compromised mailbox holding 500 or more clients' records can become reportable unless the logs show nothing was taken. A good test exercises the audit trail as well as the controls.
Do IRS Publications 4557, 5708 and 3112 require a penetration test?
No. They require a written plan. Publication 5708 (Rev. 8-2024) states that "tax and accounting professionals are considered financial institutions, regardless of size," and that a written information security plan is something "the law requires you to have." Publication 4557 (Rev. 6-2024) asks firms to "design and implement a safeguards program, and regularly monitor and test it." Publication 3112 (Rev. 11-2025) says Authorized IRS e-file Providers "must have security systems in place to prevent unauthorized access by third parties to taxpayer accounts and personal information," and IRS monitoring visits may include "Observing office and security procedures." Form W-12 (Rev. 10-2025) makes every PTIN applicant confirm that "paid tax return preparers are required by law to create and maintain a written information security plan."
None of the three publications uses the phrase penetration testing. The test comes from the rule they cite, and the IRS connects the two itself: tax professionals "should review, test and update" the plan regularly, adjusting it for "security testing and monitoring results" (IR-2025-79).
What does SQMS No. 1 mean for a firm's IT?
SQMS No. 1 requires systems of quality management "to be designed and implemented by December 15, 2025," with the first evaluation "performed within one year following December 15, 2025." Paragraph 33f requires appropriate technological resources, and the application material puts the IT processes that "manage access to the IT environment, program changes or changes to the IT environment, and IT operations" inside that scope (A102), listing "Confidentiality of the data is preserved" among the matters to consider (A105).
SQMS No. 1 does not name penetration testing. It does make access, change and monitoring over the audit technology stack a quality matter, with the first evaluation due by 15 December 2026. For firms that issue SOC reports, the evidence portals engagement teams use are technological resources under A103, and clients handing over control evidence have reason to ask how it is protected.
What do CPA Canada, CPA Ontario and CSQM 1 expect?
Outcomes, not a method. CPA Ontario's guidance on Rule 208, Confidentiality of information (March 2021) says members who hold confidential information "must establish and maintain appropriate security policies and processes to protect it and limit its access to authorized users," add "passwords, firewalls and backup/disaster recovery plans" for electronic and cloud data, and "monitor these measures and update them as technologies change." CPA Canada's January 2025 guidance, Cybersecurity: protecting your business and your clients, asks practitioners to segment networks, monitor gateways and wireless access points for anomalies, train staff against phishing and protect their CRA account access. CSQM 1 applied from 15 December 2022 for assurance engagements and 15 December 2023 for related services. None of the three names penetration testing.
What do PIPEDA, CRA EFILE and Quebec Law 25 require?
Safeguards proportionate to the data, and fast reporting when they fail. PIPEDA Principle 4.7 says personal information "shall be protected by security safeguards appropriate to the sensitivity of the information." Section 10.1 requires reporting any breach creating "a real risk of significant harm," and the Breach of Security Safeguards Regulations require a record of every breach for 24 months.
The CRA's EFILE responsibilities require filers to "take proper care to protect the confidentiality of taxpayer information" and to report immediately "any loss, suspected loss, or unauthorized disclosure of client information obtained through electronic filing." Failure to protect that information is a ground for suspension.
Quebec is the strictest. The Act respecting the protection of personal information in the private sector, as amended by Law 25, requires at section 10 "the security measures necessary to ensure the protection of the personal information" that are "reasonable given the sensitivity of the information." Section 3.5 requires prompt notice to the Commission d'accès à l'information when an incident presents a risk of serious injury, and section 3.8 an incident register. Failing section 10 can draw an administrative penalty of up to C$10 million or 2% of worldwide turnover (section 90.12) and penal fines of up to C$25 million or 4% (section 91). Neither statute mentions penetration testing.
Regime | Names penetration testing? | Cadence | What the evidence must show |
|---|---|---|---|
FTC Safeguards Rule, 16 CFR 314.4(d)(2) | Yes | Annual, plus vulnerability assessments every six months, unless continuously monitored | Testing from outside and inside, tied to the written risk assessment |
FTC breach notice, 16 CFR 314.4(j) | No | 30 days from discovery, 500 or more consumers | Logs showing what was, or was not, acquired |
IRS Publications 4557, 5708, 3112 and Form W-12 | No | Regular monitoring and testing of the plan | A written plan that is reviewed, tested and updated |
AICPA SQMS No. 1 | No | Designed by 15 December 2025, evaluated within one year | Access, change and monitoring over firm technology |
CPA Ontario Rule 208 guidance and CSQM 1 | No | None published | Security policies and processes, monitored and updated |
PIPEDA and CRA EFILE | No | Report real risk breaches as soon as feasible; immediate EFILE loss reports | Safeguards matched to sensitivity and a 24-month breach record |
Quebec Law 25, sections 3.5 and 10 | No | Prompt notice where there is a risk of serious injury | Reasonable security measures and an incident register |
What a penetration test for an accounting firm should cover
The clause is annual; the attack is seasonal. The IRS's 2026 warnings point at the mailbox: "new client" spear phishing that disguises malware as tax documents, phishing for EFINs, PTINs and CAF numbers, and whaling aimed at "payroll offices, human resource departments, and financial offices" (IR-2026-81, IR-2026-85).

Microsoft 365 and Entra ID. MFA on every account and sign-in path, legacy protocols, Conditional Access exclusions, OAuth consent grants, app registrations, and mailbox forwarding and inbox rules. Under 314.4(c)(5) every exception needs the Qualified Individual's written approval of an equivalent control, so the exception list is worth testing.
Email and business email compromise. Phishing and vishing campaigns timed to tax season, pretexts built on the lures the IRS documents, and payment-change requests aimed at whoever can release funds. Payroll bureaus should add direct deposit change requests; see social engineering testing services.
Client portals and file exchange. Authenticated testing across every role: client, staff, manager, partner and administrator. Document identifiers, share links and upload handling are where one client's return becomes visible to another.
Tax and accounting software. Hosted platforms tested through the firm's own tenant, roles and integrations, with the vendor's written permission where its terms require it. On-premise installations tested through the server, the database, the shares and the service accounts that run them.
Remote access. VPN, remote desktop gateways and remote support tools, including what is reachable after hours. Publication 5708 warns that "Nights and Weekends are high threat periods for Remote Access Takeover data theft."
Document management and backups. Permission inheritance, external sharing, and whether one compromised workstation reaches the archive and backups.
Multi-office networks and Active Directory. Flat links between offices, over-privileged service accounts, Kerberos and delegation paths and ACL abuse toward domain admin. See network and Active Directory penetration testing.
AI tools that handle client financial data. Assistants with access to mailboxes and shared drives, prompt injection through client-supplied documents, and oversharing that lets one user's assistant retrieve files that user should never see.
How we ranked them
Eleven vendors were scored against ten criteria specific to accounting, tax and bookkeeping firms. Every accreditation below was checked on the CREST Marketplace or the accrediting body's own register, and every rating on the review site itself. Every other claim traces to a page the vendor publishes, read on 25 September 2026.
Published Safeguards Rule or accounting-sector testing work.
Coverage of the accounting attack surface: Microsoft 365, email and business email compromise, remote access, client portals and Active Directory.
Firm-level accreditation on the CREST Marketplace, distinct from individual certifications.
Named or directly accessible testers, stated before signature.
Retest policy stated in writing.
Delivery model: one-time annual testing, continuous testing and portal delivery.
Evidence quality for the Qualified Individual's report and the written information security plan.
Independence from the buyer's competitors and auditors, since several vendors here are accounting firms.
Coverage of both the United States and Canada.
Pricing transparency before a sales call.
The 11 companies at a glance
# | Company | HQ | Accreditations verified | Delivery model | Named testers | Retest | Published pricing | Best for |
|---|---|---|---|---|---|---|---|---|
1 | Stingrai | Toronto, ON (London office) | CREST Penetration Testing, firm level | Human-led, hybrid or autonomous; one-time or continuous | Yes, two per engagement | Included | Yes, US$3,000 and US$6,800 | Safeguards Rule testing across tenant, portal, network and staff |
2 | Raxis | Atlanta, GA | None on CREST Marketplace | Point-in-time or PTaaS | Tester on the scoping call does the work | Standard | Not published | Safeguards-scoped testing by a US team |
3 | TrustedSec | Fairlawn, OH | CREST Penetration Testing | Consultant-led | Not stated | Stated | Not published | Foothold-to-escalation testing with retest |
4 | Plante Moran | Southfield, MI | CREST Penetration Testing | Project-based consulting | Not stated | Not stated | Not published | Microsoft 365 and AI impersonation testing |
5 | GuidePoint Security | Reston, VA | CREST Penetration Testing | Consultant-led plus PTaaS | Not stated | Not stated | Not published | Large firms consolidating testing and phishing |
6 | Schellman | Tampa, FL | CREST Penetration Testing | Consultant-led | Not stated | Not stated | Not published | Existing Schellman assessment clients |
7 | CLA | Virtual headquarters | None on CREST Marketplace | Project-based, observed option | Not stated | Not stated | Not published | Smaller practices training in-house IT |
8 | MNP | Calgary, AB | None on CREST Marketplace | Consulting through MNP Digital | Not stated | Not stated | Not published | Canadian firms pairing testing with privacy work |
9 | Black Hills Information Security | Sturgis, SD | None on CREST Marketplace | Consultant-led | Not stated | Not stated | Not published | Microsoft 365 and identity exposure |
10 | Sikich | Chicago, IL | None on CREST Marketplace | Consultant-led | Not stated | Not stated | Not published | Physical and phone social engineering |
11 | BDO Canada | Not stated (Toronto cyber centre) | None on CREST Marketplace | Consulting through Active Assure | Not stated | Not stated | Not published | Canadian firms adding tabletop exercises |
"Not stated" means the vendor does not publish the detail on its own site, not that it lacks the capability. Ask for it in writing.
1. Stingrai (top rated for accounting and CPA firms)
Stingrai is a global CREST-accredited penetration testing services company founded in Toronto, Canada in 2021, trusted by companies from startups to enterprises to meet audit requirements for SOC 2, ISO 27001, CMMC, PCI DSS and HIPAA. OSCE³, OSWE, OSEP, CREST CRT certified pentesters, who are also world-class security researchers and bug bounty hunters. Choose from fully human-led or hybrid (AI agents plus human penetration testers) engagements across web, API, mobile, AI and LLM, cloud, network, Active Directory and social engineering penetration tests and red team engagements.
For an accounting, tax or bookkeeping firm, Stingrai's penetration testers start where the IRS says attacks start. Phishing campaigns and vishing run against partners, staff and whoever releases payments. The Microsoft 365 and Entra ID tenant is tested through the cloud penetration testing methodology: app registrations, service principals, consent grants, Conditional Access gaps and hybrid-join trust. The client portal is tested authenticated across every role, hunting IDOR and broken authorization on document identifiers. Internal and external network testing runs from the perimeter and from a single workstation through lateral movement, with an Active Directory assessment of ACL abuse and Kerberos and delegation paths to domain admin, and segmentation testing between offices. AI and LLM testing covers assistants that touch client files against the OWASP LLM Top 10.
Two named penetration testers staff every human-led engagement, reviewed by the team lead and an engagement partner. Findings post to the PTaaS portal as they are confirmed, each with a working proof of concept, with live chat to the testers and Jira and Slack integration. Retesting is included, and every report ships with an attestation letter and a verified badge, the evidence a Qualified Individual's report and a WISP review consume. Stingrai delivers one-time annual tests on the Safeguards Rule calendar and continuous programs that test through the year. For the client portal, Snipe, Stingrai's autonomous AI agent for web applications and their APIs, adds a second route: the Autonomous tier is Snipe alone with no penetration testers, while on a Hybrid engagement Snipe and the penetration testers test the portal together throughout, with the testers directing where it digs.
Every claim can be checked. The firm-level accreditation is on the CREST Marketplace, separate from testers' individual CREST CRT certifications. Stingrai holds 5.0 out of 5 from 19 reviews on Clutch, with further reviews on G2. The team's 18 CVEs include CVE-2025-50674, a privilege escalation to root in OpenMediaVault, and CVE-2024-32136, an SQL injection in the BWL Advanced FAQ Manager plugin, and its testers hold bug bounty Hall of Fame listings at Apple, Google, the US Department of Defense and the US Federal Reserve. Founder Arafat Afzalzada has 11 years in offensive security.
HQ: Toronto, Ontario, with a London, UK office; on site where scoped.
Delivery model: human-led, hybrid or autonomous; one-time annual or continuous.
Named testers: yes, two per human-led engagement.
Retest: included.
Portal: yes, with live tester chat, Jira and Slack.
Pricing: published for one web application and its APIs; other scopes quoted.
Accreditations: CREST Penetration Testing at firm level.
Strength: one team covers the whole accounting attack surface, from the tenant and the portal to Active Directory and the staff who answer the phone, with evidence shaped for the Safeguards Rule file. Limitation: headquartered in Toronto with a London office rather than a US metro, so on-site physical testing at US offices is scheduled as travel during scoping. Best for: CPA, tax and outsourced accounting firms in the US and Canada that need an annual Safeguards Rule test or continuous coverage from named penetration testers. Get a scoped quote.
2. Raxis
Raxis publishes the most specific Safeguards Rule testing page in this ranking. It names tax preparers among the businesses GLBA covers, scopes engagements around where customer data flows, including portals, document management systems and third-party integrations, and tests the rule's controls directly: whether MFA can be bypassed "through session hijacking, token manipulation, or social engineering," whether access controls enforce least privilege, and whether encrypted data is exposed. Reports are structured for the Qualified Individual's board reporting, and Raxis states that the tester on the scoping call does the testing and the retest.
HQ: Atlanta, Georgia.
Delivery model: point-in-time testing or PTaaS by what it calls senior U.S. engineers.
Named testers: the tester on the scoping call does the work (stated).
Retest: "Retesting Comes Standard"; unlimited on PTaaS.
Portal: Raxis One.
Pricing: not published.
Accreditations: no CREST Marketplace listing; testers hold OSCP, CEH, GPEN and GFACT (stated).
Strength: a GLBA page that tests the Safeguards Rule's controls rather than restating them. Limitation: no firm-level accreditation to verify, and no Canadian regimes on the page. Best for: US tax preparation and CPA firms that want a Safeguards-scoped test from a US team.
3. TrustedSec
TrustedSec, at 3485 Southwestern Boulevard in Fairlawn, Ohio, runs a consultant-led practice built around scoping, reconnaissance, vulnerability identification, exploitation, reporting and validation testing. Exploitation includes "attempts to access sensitive data, escalate privileges, or disrupt operations," and the team walks the client through the report. The page cites PCI DSS, HIPAA and SOC 2 rather than the Safeguards Rule, but the method fits an accounting firm's internal network: start from a foothold and prove how far it goes.
HQ: Fairlawn, Ohio.
Delivery model: consultant-led.
Named testers and portal: not stated.
Retest: "After you've addressed identified vulnerabilities, we retest to confirm they've been successfully mitigated."
Pricing: not published.
Accreditations: CREST Penetration Testing.
Strength: a published method that runs from reconnaissance through privilege escalation to validation retesting. Limitation: no accounting-sector or Safeguards Rule page and no portal described. Best for: multi-office firms that want consultant-led internal testing with retesting included.
4. Plante Moran
Plante Moran, which moved its corporate headquarters to Southfield Town Center in Southfield, Michigan, delivers offensive work through what it calls "credentialed penetration testers." Two published services match the accounting threat model closely: a Microsoft 365 security configuration assessment, and social engineering exercises that "Simulate AI-powered voice and video impersonation and deception tactics," the technique behind a fake partner calling to move money. Red and purple teaming, ransomware simulation and wireless assessments round it out.
HQ: Southfield, Michigan.
Delivery model: project-based consulting.
Named testers, retest and portal: not stated.
Pricing: not published.
Accreditations: CREST Penetration Testing.
Strength: Microsoft 365 configuration and AI impersonation testing from one CREST-accredited team. Limitation: its CREST listing describes it as the 13th largest public accounting and management consulting firm in the US, so a CPA firm buyer is hiring a competitor. Best for: regional and national firms that want Microsoft 365 and impersonation-style social engineering tested together.
5. GuidePoint Security
GuidePoint Security, headquartered in Reston, Virginia, tests internal and external networks, applications, cloud, security awareness and facilities, alongside social engineering built on "in-depth reconnaissance & hand-crafted campaigns," phishing services, an Active Directory security review, and red and purple team assessments. Its PTaaS offering pairs point-in-time testing with recurring, automated testing on a platform with on-demand reporting.
HQ: Reston, Virginia.
Delivery model: consultant-led testing plus PTaaS.
Named testers and retest: not stated.
Portal: PTaaS platform.
Pricing: not published.
Accreditations: CREST Penetration Testing.
Strength: testing, phishing simulation, Active Directory review and incident response from one partner. Limitation: on the PTaaS tier automation carries the continuous testing and a tester can be paired in to audit results, so confirm how much recurring coverage is human-led. Best for: large and top-100 firms consolidating testing, phishing and incident response.
6. Schellman
Schellman, in Tampa, Florida, describes itself as "the only Top 50 CPA firm focused exclusively on IT Compliance and Cybersecurity." Its catalogue covers application, network, cloud and physical testing, red teaming, social engineering against "targeted phishing, vishing, and smishing attacks," and Active Directory services. Testing sits with Schellman Compliance, LLC, which holds the CREST accreditation; attest work sits with the licensed CPA firm, Schellman & Company, LLC.
HQ: Tampa, Florida.
Delivery model: consultant-led, separate from the attest practice.
Named testers, retest and portal: not stated.
Pricing: not published.
Accreditations: CREST Penetration Testing (Schellman Compliance LLC).
Strength: phishing, vishing, smishing, physical and Active Directory testing from a CREST-accredited team that knows attest engagements from the inside. Limitation: it issues SOC reports itself, so SOC-issuing firms are buying from a competitor, and existing assessment clients should document independence. Best for: firms already using Schellman for assessment work that want testing under the same relationship.
7. CLA (CliftonLarsonAllen)
CLA operates with what it calls "a virtual headquarters" and more than 120 US locations, and is registered as a Minnesota LLP. Its testing looks for "ways to chain multiple vulnerabilities together to identify high risks and potential exposure," and it offers a format few firms publish: the client's team can follow along while the planned attacks run, with hands-on guidance on stopping them. Its professional services guidance names phishing, ransomware and third-party payroll and bookkeeping vendors as leading risks.
HQ: virtual headquarters; Minnesota LLP.
Delivery model: project-based, with an observed follow-along option.
Named testers, retest and portal: not stated.
Pricing: not published.
Accreditations: no CREST Marketplace listing.
Strength: an observed test that builds in-house IT capability while it runs. Limitation: a peer accounting firm, and its Safeguards Rule content is a 2022 pointer rather than a testing method. Best for: smaller practices and outsourced accounting providers that want their IT staff to learn from the test.
8. MNP
MNP, a national Canadian accounting, tax and consulting firm founded in 1958 with its head office in Calgary, Alberta and 162 offices, sells offensive security through MNP Digital that assesses "systems, networks (internal, external, and wireless), mobile and web applications, and even people," with detailed remediation guidance, alongside privacy and data protection programs and 24x7 incident management.
HQ: Calgary, Alberta.
Delivery model: consulting through MNP Digital.
Named testers, retest and portal: not stated.
Pricing: not published.
Accreditations: no CREST Marketplace listing.
Strength: offensive testing, privacy program work and incident response under one Canadian firm. Limitation: a competitor for most Canadian CPA buyers, with thin published testing detail. Best for: Canadian practices that want testing and privacy program work from one domestic firm.
9. Black Hills Information Security
Black Hills Information Security, in Sturgis, South Dakota, lists "Microsoft 365 and cloud identity attacks," "Password spraying and credential abuse," "Email and data exposure," internal network pivoting and wireless among the attacks its testing reflects. Engagements include mid-engagement daily check-ins, and the firm states that it verifies vulnerabilities manually rather than trusting scanner output.
HQ: Sturgis, South Dakota.
Delivery model: consultant-led.
Named testers, retest and portal: not stated.
Pricing: not published.
Accreditations: no CREST Marketplace listing.
Strength: explicit Microsoft 365 and identity attack coverage, with daily communication during the test. Limitation: no published accreditation, retest terms, pricing or accounting-sector page. Best for: firms whose exposure is concentrated in Microsoft 365, cloud identity and password reuse.
10. Sikich
Sikich tests internal and external networks and web applications against the OWASP Top 10, and adds two scopes accounting firms often skip: physical testing using impersonation, shoulder surfing and dumpster diving, and phishing and phone-based social engineering. Its reports are written for "IT teams, auditors, and examiners," and in September 2026 the PCI Security Standards Council approved it as a Qualified PIN Assessor company.
HQ: Chicago, Illinois (news releases datelined Chicago).
Delivery model: consultant-led.
Named testers, retest and portal: not stated.
Pricing: not published.
Accreditations: no CREST Marketplace listing.
Strength: physical entry and phone pretexting in the same engagement as the network test. Limitation: a peer accounting firm whose CPA-firm content covers financial compliance rather than security testing. Best for: firms that want office entry and phone-based social engineering tested alongside the network.
11. BDO Canada
BDO Canada, with 79 offices and a Cybersecurity and Digital Innovation Centre opened in Toronto in May 2025, sells penetration testing inside its Active Assure line alongside active threat simulation, purple teaming and tabletop exercises, using "industry-recognized attack methodologies to gauge your resilience against common threats and ensure compliance."
HQ: head office not stated on its site; cybersecurity centre in Toronto.
Delivery model: consulting inside BDO's Perpetual Defence framework.
Named testers, retest and portal: not stated.
Pricing: not published.
Accreditations: none for BDO Canada on the CREST Marketplace; the BDO LLP listing there is the UK member firm.
Strength: testing paired with purple team and tabletop exercises, so the incident response plan is exercised too. Limitation: a peer accounting firm with thin published testing methodology. Best for: Canadian firms that want testing and tabletop exercises in one engagement.
How much does penetration testing cost for an accounting firm in 2026?
Price follows scope: a one-office firm with a hosted portal buys a different test from a top-100 firm with a dozen offices and an on-premise tax server. The bands below are indicative Stingrai 2026 benchmark ranges from our penetration testing cost guide and our Canadian cost guide.
Scope | Indicative US band | Indicative Canadian band |
|---|---|---|
Client portal or other web application | US$5,000 to US$30,000 | C$5,000 to C$25,000 |
External network | US$5,000 to US$40,000 | C$8,000 to C$35,000 |
Internal network and Active Directory | US$5,000 to US$40,000 | C$12,000 to C$35,000 |
Cloud (IaaS or PaaS) | US$10,000 to US$50,000 | C$13,000 to C$40,000 |
Combined scope, firm up to 150 employees | US$8,000 to US$20,000 | Quoted |
Combined scope, firm of 150 to 500 employees | US$20,000 to US$50,000 | Quoted |
Annual program or PTaaS subscription | US$50,000 to US$150,000 or more (enterprise program) | C$40,000 to C$90,000 (PTaaS subscription) |
Only Stingrai's own prices are hard figures here. An Autonomous Pentest, Snipe alone with no penetration testers, is US$3,000 per assessment, and a Hybrid Pentest, with penetration testers and Snipe testing together throughout, is US$6,800 per assessment, each for one web application and its APIs, which for an accounting firm usually means the client portal. The same tiers run at US$650 and US$1,275 per month on 12-month continuous plans. Every other scope, including the Microsoft 365 tenant, the internal network, Active Directory and social engineering, is quoted through get a quote. Current figures are on the pricing page. A one-time annual engagement fits the Safeguards Rule calendar; the one-time penetration test guide explains when that is enough.
Buyer checklist: ten questions to put to every vendor
Which clause are you testing against? The answer should name 16 CFR 314.4(d)(2) and the firm's risk assessment, not a generic "GLBA test."
Who exactly will test, and what do they hold? Names and certifications belong in the statement of work.
Is the firm accredited, and where can we check? A CREST Marketplace listing is firm level.
Does the scope cross the perimeter? The rule's definition says outside or inside.
How will you test MFA? Every sign-in path, legacy protocols and Conditional Access exclusions.
Will you run phishing and vishing in tax season, and how do you handle payment-change pretexts safely?
How will you test our hosted tax software and client portal? Expect role-by-role testing and written vendor permission where needed.
Is retesting included, and what does the remediation record look like? The Qualified Individual's report includes results of testing.
What do you deliver for the WISP and the partners? Scope, methods, findings with proof, retest evidence and an attestation letter.
Do you sell audit, tax or advisory services to firms like ours? If so, put confidentiality and competing-practice terms in the engagement letter.
Frequently asked questions
Who are the best penetration testing companies for accounting and CPA firms in 2026?
The best penetration testing companies for accounting and CPA firms in 2026 are Stingrai, Raxis, TrustedSec, Plante Moran, GuidePoint Security, Schellman, CLA (CliftonLarsonAllen), MNP, Black Hills Information Security, Sikich and BDO Canada. Stingrai ranks first: a CREST-accredited penetration testing service provider at firm level whose two named penetration testers cover the Microsoft 365 tenant, client portal, internal network, Active Directory and staff phishing, with retesting and an attestation letter included on one-time annual and continuous engagements. Raxis, TrustedSec and Plante Moran follow for Safeguards-specific testing, foothold-to-escalation depth, and Microsoft 365 and AI impersonation testing respectively.
Does the FTC Safeguards Rule require CPA firms to do penetration testing?
Yes, unless they run effective continuous monitoring. 16 CFR 314.2(h)(2)(viii) makes an accountant or other tax preparation service that completes income tax returns a financial institution, and 16 CFR 314.4(d)(2) requires annual penetration testing of its information systems, plus vulnerability assessments at least every six months, absent effective continuous monitoring. The clause has applied since 9 June 2023. The CPA exemption at 15 U.S.C. 6803(d) covers GLBA's privacy notice disclosures only, not the Safeguards Rule.
Are small accounting firms exempt from the annual penetration test?
Firms that maintain customer information concerning fewer than 5,000 consumers are exempt under 16 CFR 314.6 from the annual penetration test, the written risk assessment, the written incident response plan and the annual report. Consumers are individuals obtaining a financial service for personal, family or household purposes, so business clients do not count. Multi-factor authentication, encryption, training and the 30-day FTC breach notice still apply.
Does IRS Publication 4557 or 5708 require a penetration test?
No. Neither publication uses the phrase penetration testing. Publication 5708 states that tax and accounting professionals are financial institutions regardless of size and must have a written information security plan, and Publication 4557 asks firms to regularly monitor and test their safeguards. The penetration testing requirement comes from the FTC Safeguards Rule they cite, at 16 CFR 314.4(d)(2).
When does an accounting firm have to notify the FTC of a breach?
As soon as possible and no later than 30 days after discovering a notification event involving the information of at least 500 consumers, under 16 CFR 314.4(j), in force since 13 May 2024. Unauthorized access to unencrypted customer information is presumed to be acquisition unless the firm has reliable evidence otherwise. The IRS separately asks tax professionals to report data theft to their IRS Stakeholder Liaison.
Do Canadian accounting firms need a penetration test?
No Canadian regime names one. PIPEDA Principle 4.7 requires safeguards appropriate to the sensitivity of the information, CPA Ontario's Rule 208 guidance requires security processes that are monitored and updated, the CRA's EFILE responsibilities require filers to protect taxpayer information and report any loss immediately, and Quebec Law 25 requires reasonable security measures, with penalties of up to C$25 million or 4% of worldwide turnover.
How much does a penetration test cost for an accounting firm?
Indicative 2026 bands run from US$5,000 to US$30,000 for a client portal and US$5,000 to US$40,000 for a network test; Canadian bands run from C$5,000 to C$25,000 for a web application and C$12,000 to C$35,000 for an internal network. Stingrai publishes US$3,000 for an Autonomous Pentest and US$6,800 for a Hybrid Pentest per assessment for one web application and its APIs, or US$650 and US$1,275 per month on 12-month continuous plans; every other scope is quoted.
Should a CPA firm hire another accounting firm to test it?
It can, with conditions. Several strong testing practices sit inside accounting firms, including Plante Moran, Schellman, CLA, MNP, Sikich and BDO Canada. The tester will see client files, fee structures and security weaknesses, so confidentiality, non-solicitation and competing-practice terms belong in the engagement letter, and a firm that uses the same provider as its own assessor should document how independence is maintained.



