On 19 June 2024, CDK Global shut down the systems behind its dealer management software, the platform dealers use to run sales, financing, service, inventory and back-office work. Within five days, six publicly listed US dealer groups had filed Form 8-K reports describing the disruption and the workarounds keeping their stores open, and AutoNation later estimated that the outage cut its second-quarter 2024 earnings by US$1.55 a share, including US$0.79 of one-time costs. In Canada, AutoCanada reported that the outage ran from 19 June to 1 July 2024, with recovery and cleanup not finished until the end of July. In its last annual report as a public company, CDK described itself as serving nearly 15,000 retail locations in North America.
The outage landed on top of a federal testing mandate. Since 9 June 2023, the FTC's amended Safeguards Rule has required covered financial institutions with customer information on 5,000 or more consumers to run annual penetration testing and vulnerability assessments at least every six months unless they run effective continuous monitoring, and the FTC's June 2025 guidance for dealers says the rule covers "most automobile dealers who finance or lease automobiles." Canada has no clause that names a test, but PIPEDA, the Alberta and British Columbia privacy acts and Quebec Law 25 all require security safeguards that a penetration test directly evidences.
Where Stingrai fits: Stingrai is a CREST-accredited penetration testing service provider at firm level, founded in Toronto in 2021 with a London office, testing for clients across the United States and Canada remotely and on site where scoped. Two named penetration testers from a team holding OSCE³, OSWE, OSEP, CREST CRT and CISSP certifications staff each human-led engagement, reviewed by the team lead and an engagement partner, with 18 published CVEs across the team. For a dealership that means the store network tested for segmentation between guest Wi-Fi, the service lane and the systems that reach the DMS, Active Directory and Microsoft 365 tested from a single phished workstation, credit application and F&I web applications tested across every role, and vishing aimed at the help desk. Findings post to the PTaaS portal as they are confirmed, retesting and an attestation letter are included, and engagements run as a one-time annual test on the Safeguards Rule calendar or as a continuous program. Published pricing covers one web application and its APIs (pricing); store-wide and group-wide scopes are quoted.
This guide is for dealer principals, dealer group CIOs, CISOs and controllers, and the Qualified Individuals who sign the Safeguards Rule report, at franchised and independent dealers in the United States and Canada. Every vendor entry was checked on its own site on 1 October 2026.
Quick answer: who are the best penetration testing companies for auto dealerships in 2026?
The best penetration testing companies for auto dealerships in 2026 are Stingrai, Plante Moran, Compass IT Compliance, CLA (CliftonLarsonAllen), MNP, Forvis Mazars, Rehmann, LBMC, Cherry Bekaert, BDO USA and Raxis. Stingrai ranks first: a CREST-accredited penetration testing service provider at firm level whose two named penetration testers cover store networks and Wi-Fi segmentation, Active Directory, Microsoft 365, credit application and F&I web applications, and help desk vishing, with retesting and an attestation letter included on one-time annual and continuous engagements. Plante Moran, Compass IT Compliance and CLA follow for a CREST-accredited testing team beside a dealership practice of more than 250 retail dealership clients, a dedicated dealership security program, and a dealership practice that briefed dealers on the CDK outage within days and offers penetration tests the client's IT team can follow along with.

What auto dealerships are actually required to test
Two instruments name the test: the FTC Safeguards Rule for US dealers that finance or lease, and PCI DSS for the card environment. The Canadian privacy laws require reasonable safeguards and breach reporting and leave the method to the dealer. The FTC Safeguards Rule requirements guide covers the rule clause by clause; this section covers how it lands on a dealership.
Does the FTC Safeguards Rule apply to my dealership?
Almost certainly, if the store arranges financing or leases. The FTC's dealer FAQ says the rule "applies to financial institutions subject to the FTC's authority. That includes most automobile dealers who finance or lease automobiles." A dealer that finances or arranges financing is a financial institution because lending is a financial activity under 12 U.S.C. 1843(k) (16 CFR 314.2(h)(1)), and 314.2(h)(2)(ii) names leasing directly. Arranging the credit also creates a customer relationship under 314.2(e)(2)(i)(E) ("credit to purchase a vehicle"), which is what makes the deal file customer information.
The rule protects customer information. The FAQ says approved financing and lease applications, lists of customers who financed or leased, and those customers' financial information always count, while names and addresses collected from every buyer, aggregate sales reports and service records do not unless combined with it. Customer information also stays covered after the deal is done: it "remains customer information even after the end of the customer relationship (e.g., if you no longer hold the note)." The same rule reaches tax preparers, as the accounting and CPA firm ranking shows.
Does the Safeguards Rule require dealers to run penetration tests?
Yes, unless the dealer runs effective continuous monitoring or maintains customer information on fewer than 5,000 consumers (see the exemption below). 16 CFR 314.4(d)(2) says the monitoring and testing "shall include continuous monitoring or periodic penetration testing and vulnerability assessments." Absent effective continuous monitoring, a dealer must conduct "Annual penetration testing of your information systems determined each given year based on relevant identified risks in accordance with the risk assessment," plus vulnerability assessments "at least every six months," whenever operations or business arrangements change materially, and "whenever there are circumstances you know or have reason to know may have a material impact on your information security program." The clause has applied since 9 June 2023, after the Commission moved the original 9 December 2022 date (87 FR 71509).
The rule defines the test at 314.2(n): assessors "attempt to circumvent or defeat the security features of an information system by attempting penetration of databases or controls from outside or inside your information systems." When it adopted the rule, the Commission rejected a commenter's argument that the definition would exclude "potential human vulnerabilities": "Attempted social engineering and phishing are important parts of testing the security of information systems and would not be excluded by this definition" (86 FR 70277). It also explained the annual cadence: although penetration testing "can be a somewhat lengthy and costly process for large or complex systems," a longer gap between tests "will leave information systems vulnerable to attacks that exploit weaknesses normally revealed by penetration testing" (86 FR 70293).
Scope follows the network, not the deal file. The rule's definition of an information system takes in systems "connected to a system containing customer information" (314.2(j)), and the dealer FAQ spells out the consequence: "unless you maintain two separate networks that are not connected, the protections that you need to provide for customer information on your network will also protect other information on your network." A showroom kiosk, a service-lane tablet or a guest Wi-Fi network that can reach the DMS segment belongs in the test.
Three other clauses shape the scope. Section 314.4(c)(5) requires multi-factor authentication "for any individual accessing any information system" unless the Qualified Individual approves an equivalent in writing. Section 314.4(c)(4) requires procedures for "evaluating, assessing, or testing the security of externally developed applications" used to transmit, access or store customer information, which covers a hosted credit application or digital retailing tool. And 314.4(i) puts "results of testing" in the Qualified Individual's annual written report to the board.
Which dealerships are exempt from the annual penetration test?
16 CFR 314.6 says sections 314.4(b)(1), (d)(2), (h) and (i) "do not apply to financial institutions that maintain customer information concerning fewer than five thousand consumers." An exempt dealer skips the written risk assessment, the annual penetration test and six-monthly vulnerability assessments, the written incident response plan and the board report. It does not skip multi-factor authentication, encryption, access controls, service provider oversight, training or the FTC breach notice, and the general duty in 314.4(d)(1) to "Regularly test or otherwise monitor the effectiveness of the safeguards' key controls, systems, and procedures" still applies. Former customers count: the Commission said it understands the provision to "count all individual consumers about which a financial institution maintains customer information, including both current and former customers" (86 FR 70301, note 344), so older deal files count for as long as the store keeps them. It added that a financial institution "may choose to dispose of information so it holds information on few enough consumers to qualify for exemption."
What does the rule say about the DMS, the CRM and other vendors?
Section 314.4(f) requires a dealer to select service providers "capable of maintaining appropriate safeguards," to require those safeguards by contract, and to assess providers periodically "based on the risk they present and the continued adequacy of their safeguards." The dealer FAQ is concrete about direct access: oversight "would include addressing the risk that the service provider's direct access to your information system would pose," and a vendor given direct access to the dealer's network "should be required to use multi-factor authentication for that access because they are individuals accessing your information systems." It also says an OEM does not become a service provider just because a dealer shares information with it.
The FTC has already brought a Safeguards Rule case in this channel. In LightYear Dealer Technologies, against the DMS vendor doing business as DealerBuilt, the Commission's complaint alleged that a storage device left an open port on the backup network for about 18 months, during which the company did not "perform any vulnerability scanning, penetration testing, or other diagnostics to detect the open port." An intruder reached the unencrypted personal information of approximately 12.5 million consumers stored by 130 of its dealership customers and downloaded the records of 69,283, and the company learned of it only when a dealership customer called to ask why customer data was publicly accessible. The order, made final in September 2019, requires penetration testing of its network at least every 12 months, vulnerability testing every four months, and independent assessments every two years for 20 years.
What does a dealer have to tell the FTC after a breach?
Since 13 May 2024, 314.4(j) has required notice to the FTC "as soon as possible, and no later than 30 days after discovery" of a notification event involving the information of at least 500 consumers. A notification event is unauthorized acquisition of unencrypted customer information, and unauthorized access is presumed to be acquisition unless the dealer has "reliable evidence" otherwise (314.2(m)). That presumption is why logging belongs in the test: a compromised F&I mailbox holding 500 deal files can become reportable unless the logs show nothing left.
Does PCI DSS apply to a dealership?
Card payments in service, parts and deposits bring a second testing clause. PCI DSS v4.0.1, published in June 2024 and listed in the PCI Security Standards Council document library, requires internal and external penetration testing "at least once every 12 months" and "after any significant infrastructure or application upgrade or change," by a qualified internal resource or qualified external third party with organizational independence (requirements 11.4.2 and 11.4.3). How much of a dealership sits inside that scope depends on how cards are taken, which the PCI DSS ranking covers.
What do PIPEDA and the provincial privacy laws require of Canadian dealers?
Which statute applies depends on the province. Alberta, British Columbia and Quebec "have their own private-sector privacy laws that have been deemed substantially similar to PIPEDA," the Office of the Privacy Commissioner says, so dealers there generally answer to the provincial act inside the province, while PIPEDA covers the other provinces and information that crosses borders.
PIPEDA Principle 4.7 says personal information "shall be protected by security safeguards appropriate to the sensitivity of the information." Section 10.1 requires a report to the Privacy Commissioner of any breach that creates "a real risk of significant harm to an individual," and the Breach of Security Safeguards Regulations require a record of every breach for 24 months. Alberta's Personal Information Protection Act, section 34, requires "reasonable security arrangements," and section 34.1 requires notice to the Commissioner "without unreasonable delay" where a reasonable person would consider that there is a real risk of significant harm. British Columbia's Personal Information Protection Act, section 34, also requires reasonable security arrangements. None of these texts names penetration testing.
Quebec Law 25
Quebec dealers answer to the Act respecting the protection of personal information in the private sector, as amended by Law 25. Section 10 requires "the security measures necessary to ensure the protection of the personal information" that are "reasonable given the sensitivity of the information, the purposes for which it is to be used, the quantity and distribution of the information and the medium on which it is stored." Section 3.5 requires prompt notice to the Commission d'accès à l'information when a confidentiality incident presents a risk of serious injury, and section 3.8 requires a register of incidents. Failing section 10 can draw an administrative monetary penalty of up to C$10 million or 2% of worldwide turnover (section 90.12) and penal fines of up to C$25 million or 4% (section 91). The Act does not mention penetration testing; the Law 25 guide sets out where a test fits.
Rule | Names penetration testing? | Cadence | What the evidence has to show |
|---|---|---|---|
FTC Safeguards Rule, 16 CFR 314.4(d)(2) | Yes | Annual, plus vulnerability assessments every six months, after material changes and when circumstances may materially affect the security program, unless effectively continuously monitored | Testing from outside and inside, scoped by the written risk assessment, including connected systems |
Small-dealer exemption, 16 CFR 314.6 | Removes (d)(2) below 5,000 consumers | 314.4(d)(1) still requires regular testing or monitoring | MFA, encryption, vendor oversight and breach notice still apply |
Service providers, 16 CFR 314.4(f) | No | Periodic assessment | Vendor access controlled, MFA on direct network access, safeguards in the contract |
FTC breach notice, 16 CFR 314.4(j) | No | 30 days from discovery, 500 or more consumers | Logs showing what was, or was not, acquired |
PCI DSS v4.0.1, requirements 11.4.2 and 11.4.3 | Yes, for the card environment in scope | At least every 12 months and after significant change | Internal and external tests by a qualified, organizationally independent tester |
PIPEDA, Alberta PIPA and BC PIPA | No | None | Safeguards appropriate to sensitivity; breach reports, and 24 months of breach records under PIPEDA |
Quebec Law 25, sections 10, 3.5 and 3.8 | No | None | Reasonable security measures, prompt notice of serious incidents and an incident register |
What the CDK outage showed dealers
CDK's systems went down for every dealer on them at once, and the dealer groups' own securities filings record what that meant.

Filer | Filing | What it disclosed |
|---|---|---|
AutoNation | Form 8-K, 24 June 2024 | The DMS supporting "sales, service, inventory, customer relationship management, and accounting functions" was out; all locations stayed open through manual and alternative processes. Its 31 July results put the second-quarter EPS hit at an estimated US$1.55. |
Lithia Motors | Form 8-K, 24 June 2024 | Took containment steps that included "severing business service connections between the Company's systems and CDK's," and had not identified any compromise of its own systems. |
Group 1 Automotive | Form 8-K, 24 June 2024 | US dealerships on alternative processes; its UK dealerships do not use CDK's dealer systems and were not affected. |
Sonic Automotive | Form 8-K, 5 July 2024 | Filed under Item 1.05, material cybersecurity incidents, after concluding the disruption to its DMS and CRM was reasonably likely to materially affect second-quarter results. |
Asbury Automotive Group | Form 8-K, 24 June 2024 | Sales, service, inventory, CRM and accounting affected; its Koons stores, which do not use CDK's DMS or CRM, ran with minimal interruption. |
Penske Automotive Group | Form 8-K, 21 June 2024 | Its auto dealerships do not use CDK's DMS; its Premier Truck Group, with locations in Ontario and Manitoba, was disrupted. |
AutoCanada | Q2 2024 results, 13 August 2024 | Outage from 19 June to 1 July 2024, cleanup to the end of July, and a credit facility covenant amended on 28 June because of it. |
Brookfield Business Partners, which acquired CDK in July 2022, said in its 2024 annual report on Form 20-F that the business "detected and promptly responded to unauthorized cyber activity on its network," shut down its systems while notifying law enforcement, gave customers one-time billing credits, and has since faced several class action lawsuits. In a notice of data breach dated 20 September 2024, CDK said "a third party gained unauthorized access to CDK's systems" and obtained files with information about vendors of CDK and its corporate predecessor. Separately, on 11 August 2024, AutoCanada identified a cybersecurity incident of its own, affecting its internal IT systems.
None of that is a failed test at a dealership. The useful questions for a dealer's own test are narrower: what the DMS connection, integration accounts and remote support tools can reach on the store network, whether the store can cut those connections cleanly, as Lithia did, and whether staff can tell a real vendor support call from a pretext. CDK's own State of Dealership Cybersecurity 2025 survey, published in November 2025, found that one in five dealerships reported being targeted in 2025 and that fewer than half of dealership leaders feel confident in their systems' ability to protect against attacks.
What the largest dealer groups disclose about security testing
Public dealer groups now describe their testing in the cybersecurity section of their annual reports, and the fiscal 2025 filings, made in February 2026, set a reference point for everyone else:
Asbury: "Internally, among other things, we perform two penetration tests per year, internal tests/code reviews, and simulations using cybersecurity professionals" (10-K).
Penske: engages third-party providers "to assist us with annual security assessments, penetration and vulnerability testing" (10-K).
Group 1: "Regular assessments and testing of our cybersecurity safeguards are conducted by independent third-party cybersecurity experts" (10-K).
AutoNation: examines its defenses through "internal audits, targeted testing, incident response exercises, maturity assessments, and industry benchmarking" (10-K).
The dealership attack surface: what a good scope covers
A dealership is a retail floor, a finance office and a repair shop on one network, with vendors connected to almost every part of it. A test scoped to the external IP addresses misses most of it.

DMS connections and integrations. The DMS provider hosts the core, but the store owns the connections: integration and API accounts for third-party tools, remote support software, VPNs, local servers and backups. Test what each connection can reach and whether it uses MFA, as the FTC's dealer FAQ expects for vendor access to the network. Hosted DMS and lender platforms need the provider's written permission before anyone tests them directly.
Credit applications, F&I and e-contracting. Online credit applications, F&I menus, document uploads for pay stubs and licences, and e-signature flows. Authenticated testing across customer, salesperson, F&I manager and administrator roles finds the authorization flaw that shows one customer's deal jacket to another.
Dealer website, chat and digital retail. Website platforms, chat and text widgets, trade-in and payment tools and digital retailing checkouts that collect personal and financial information, often run by several vendors under the dealer's domain. Section 314.4(c)(4) asks for procedures to test externally developed applications like these.
CRM and lead routing. Shared logins, bulk exports and API keys held by marketing vendors and the business development center.
Microsoft 365 and email. MFA on every sign-in path, legacy protocols, mailbox forwarding rules and OAuth consent grants. MNP's dealership guidance describes a common version of the fraud: an attacker posing as a regular supplier or contractor who alters payment information to redirect funds.
Store networks and Active Directory. Flat networks across showroom, service, parts and back office, and Kerberos, delegation and ACL paths that turn one phished workstation into domain admin.
Wi-Fi, kiosks and devices. Guest and service-lane Wi-Fi, check-in kiosks, cameras and public network jacks. MNP's guidance says "publicly accessible network jacks, public Wi-Fi systems, and office Wi-Fi networks, systems and applications should be segmented from each other," and the WiFi penetration testing guide covers how that is tested on site.
People and premises. Phishing and vishing aimed at the help desk, F&I and accounting, pretext calls posing as DMS or OEM support, and physical access to F&I offices and server closets. The Commission put social engineering inside the rule's definition of penetration testing; physical checks fall under the general testing duty in 314.4(d)(1), since the Commission said (d)(2) "is not relevant to information in physical form." The social engineering testing guide compares the formats.
How we ranked them
Eleven vendors were scored against ten criteria specific to dealerships and dealer groups. Every accreditation was checked on the CREST Marketplace, and every other claim traces to a page the vendor publishes, read on 1 October 2026.
Published dealership-sector security work on the vendor's own site.
Firm-level accreditation on the CREST Marketplace, distinct from individual certifications.
Coverage of the dealership attack surface: store networks and Wi-Fi, Active Directory, Microsoft 365, web applications and APIs, and social engineering.
Named testers, identified before signing.
Retest policy stated in writing.
Delivery: a findings portal, and both one-time annual and continuous options.
Evidence for the Safeguards Rule file: results the Qualified Individual can put in the annual board report.
Independence from the dealer's managed IT provider, DMS vendor and auditor.
North American delivery in the United States, Canada or both.
Pricing transparency before a sales call.
The 11 companies at a glance
# | Company | HQ | CREST (firm level) | Dealership evidence on its own site | Named testers | Retest | Published pricing | Best for |
|---|---|---|---|---|---|---|---|---|
1 | Stingrai | Toronto, ON (London, UK office) | Penetration Testing | Automotive aftermarket case study, Quebec group with 2,000+ locations | Yes, two per human-led engagement | Included | Yes, US$3,000 and US$6,800 | Safeguards Rule testing across store networks, applications and people |
2 | Plante Moran | Southfield, MI | Penetration Testing | Dealership practice of 250+ retail dealership clients; 2024 dealer cybersecurity article | Not stated | Not stated | No | Groups that want a CREST team beside their dealership advisors |
3 | Compass IT Compliance | North Providence, RI | Not listed | Auto dealership security page; dealer group CIO testimonial | Not stated | Not stated | No | Safeguards program support and testing from one firm |
4 | CLA (CliftonLarsonAllen) | Virtual headquarters (US) | Not listed | Auto dealer services list cybersecurity; June 2024 CDK webinar for dealers | Not stated | Not stated | No | Dealers whose IT staff want to observe the test |
5 | MNP | Canada (national firm since 1958) | Not listed | Dealership cyber assessment guidance by its offensive security leader | Not stated | Not stated | No | Canadian dealers and dealer groups |
6 | Forvis Mazars | US (national firm) | UK listing only | Dealer Safeguards article; July 2024 CDK return checklist | Not stated | Not stated | No | Physical and social engineering beside network tests |
7 | Rehmann | Michigan (offices in MI, OH and FL) | Not listed | Dealership practice; June 2024 dealer cybersecurity article | Not stated | Not stated | No | Dealers in Michigan, Ohio and Florida |
8 | LBMC | Brentwood, TN | Not listed | Dealer Safeguards article and auto dealer webinar | Not stated | Not stated | No | A first Safeguards file built with a risk assessment |
9 | Cherry Bekaert | Raleigh, NC | Not listed | August 2024 Safeguards Rule article for auto dealers | Not stated | Not stated | No | Compliance-shaped testing evidence |
10 | BDO USA | US (85+ offices) | Not listed | Auto Dealerships practice; 2023 Safeguards Rule article | Not stated | Not stated | No | Groups already using BDO's dealership practice |
11 | Raxis | Atlanta, GA | Not listed | June 2024 post on the CDK attack for car dealerships; GLBA page naming auto dealers | Scoping engineer does the test (stated) | Standard | No | The same tester from scoping through retest |
"Not stated" means the vendor's own site does not say. Ask for it in writing.
1. Stingrai
Stingrai is a global CREST-accredited penetration testing services company founded in Toronto, Canada in 2021, trusted by companies from startups to enterprises to meet audit requirements for SOC 2, ISO 27001, CMMC, PCI DSS and HIPAA. OSCE³, OSWE, OSEP, CREST CRT certified pentesters, who are also world-class security researchers and bug bounty hunters. Choose from fully human-led or hybrid (AI agents plus human penetration testers) engagements across web, API, mobile, AI and LLM, cloud, network, Active Directory and social engineering penetration tests and red team engagements.
What a dealer group's security committee can check. The firm-level accreditation is on the CREST Marketplace supplier page for Stingrai Inc, separate from the CREST CRT certifications individual testers hold, and Stingrai is rated 5.0 out of 5 on Clutch. The team has published 18 CVEs, including CVE-2025-50674, a privilege escalation to root in OpenMediaVault, and CVE-2024-32136, an SQL injection in a WordPress plugin, and its testers hold bug bounty Hall of Fame listings at Apple, Google, the US Department of Defense and the US Federal Reserve. Two named penetration testers run each human-led engagement, reviewed by the team lead and an engagement partner, under founder Arafat Afzalzada, who has 11 years in offensive security. In late 2025 Stingrai tested multiple scopes for an automotive aftermarket services group based in Quebec, whose collision, glass and mechanical repair network spans more than 2,000 locations, with weekly updates on the vulnerabilities found in each section of the scope.
How a dealership engagement is tested. Internal and external network testing covers the perimeter and remote access, lateral movement from a showroom or service workstation, and segmentation testing between guest Wi-Fi, the service lane and the segments that reach the DMS. The Wi-Fi security assessment runs on site or remotely with a Wi-Fi Pineapple. The Active Directory assessment follows ACL abuse and Kerberos and delegation paths to domain admin, and cloud testing treats Microsoft 365 and Entra ID as an attack path: app registrations, service principals, consent grants, Conditional Access gaps and hybrid-join trust. Web application testing of credit applications, F&I tools and customer portals runs black, grey or white box, authenticated across every role, for broken authorization, IDOR and business logic under OWASP Top 10 and ASVS. Phishing and vishing campaigns target the help desk, F&I and accounting, and physical security assessments test facility entry on site.
Evidence and delivery. Findings post to the PTaaS portal as they are confirmed, each with a working proof of concept and remediation guidance, with live chat to the assigned testers and Jira and Slack integration. Reports are redactable, executives get a unified dashboard, retesting is included, and every human-led and hybrid report ships with an attestation letter and a verified badge. Stingrai's penetration testing supports your Safeguards Rule program with what the Qualified Individual's annual report needs: scope, methods, findings with proof, retest results and the letter. Stingrai runs both one-time annual engagements timed to the Safeguards Rule calendar and continuous programs that test through the year.
Where Snipe fits. Snipe, Stingrai's autonomous AI penetration testing agent for web applications and their APIs, covers the dealer website, the credit application and customer portals in scope. It hunts broken authorization, IDOR and business logic flaws, reviews code, and opens AutoFix pull requests. The Autonomous tier is Snipe alone, with no penetration testers; in a Hybrid engagement Snipe and the penetration testers test together throughout, with the testers directing its focus. Store networks, Wi-Fi, Active Directory, Microsoft 365 and social engineering are tested by penetration testers.
Pricing: US$3,000 for an Autonomous Pentest and US$6,800 for a Hybrid Pentest per assessment of one web application and its APIs, or US$650 and US$1,275 per month on 12-month continuous plans, on the pricing page. The No High or Critical Finding = Don't Pay guarantee applies to the Autonomous Pentest only. Every other scope is quoted through get a quote.
Strength: one team covers the store network, identity, the customer-facing applications and the people who answer the phone, and every credential a dealer group's board might question has a public source. Limitation: a deliberately small team, which the CREST listing reflects, so on-site Wi-Fi and physical work across many rooftops needs scheduling lead time, and the fixed-price packages cover web applications and their APIs only. Best for: franchised and independent dealers and dealer groups in the US and Canada that need an annual Safeguards Rule test or continuous coverage from named, certified penetration testers.
2. Plante Moran
Plante Moran, which moved its corporate headquarters to the Southfield Town Center in Southfield, Michigan in 2021, runs a national dealership practice that its dealerships page says "serves more than 250 retail dealership clients, including automobile, commercial truck dealers, RV, motorcycle, power sports, heavy equipment dealers, and rental and fleet operators," with cybersecurity among the services listed. Its July 2024 article, Cybersecurity for auto dealers: Beware third-party risk, tells dealers "You can't outsource governance" and recommends independent risk and resilience assessments of vendors. Testing is done by what its penetration testing page calls "credentialed penetration testers": external and internal network tests, red and purple team exercises, social engineering by email, phone and text, social engineering exercises that "Simulate AI-powered voice and video impersonation and deception tactics," wireless assessments, Microsoft 365 configuration assessments and ransomware simulation. CREST lists Plante Moran for Penetration Testing with two years of membership. Named testers, retest terms, a findings portal and pricing are not stated.
Strength: a CREST-accredited testing team inside a firm that already works with hundreds of dealerships. Limitation: the dealership practice leads with accounting and advisory, so ask which offensive security staff will test, and document independence if Plante Moran also audits the group. Best for: dealer groups that want a CREST-accredited team testing under the same relationship as their dealership advisors.
3. Compass IT Compliance
Compass IT Compliance, at 2 Asylum Road in North Providence, Rhode Island, publishes the most dealer-specific security page in this ranking. Its auto dealership page names the systems a dealer test has to cover, "Dealer management systems, customer relationship management platforms, online credit application portals, F&I software, service scheduling tools, and connected vehicle technologies," running "across networks that are frequently flat, loosely segmented, and administered by small or outsourced IT teams," and quotes the chief information officer of Village Automotive Group on its "expertise in penetration testing and vulnerability assessments." A virtual CISO on its team advises independent and franchise dealers on the Safeguards Rule, and its FTC Safeguards Rule service covers the program "From the F&I office to the back-end deal jacket." The penetration testing page lists network, web application, wireless, mobile, cloud, social engineering and red team testing. Compass is not on the CREST Marketplace, and named testers, retest terms and pricing are not stated.
Strength: dealer-specific scoping language, and a dealer group CIO on the record about its testing. Limitation: it also sells virtual CISO and Safeguards program work, so a dealer that uses Compass for its Qualified Individual should separate the people who design the controls from the people who test them. Best for: independent and franchise dealers that want Safeguards program support and testing from one firm.
4. CLA (CliftonLarsonAllen)
CLA, which describes itself as operating "With a virtual headquarters" and employs nearly 9,000 people, lists cybersecurity among its services for auto dealers. In June 2024 it ran The CDK Cyber Incident and How Dealers Should Respond, a webinar covering the security issues facing dealers, the IT security processes to discuss with their teams, manual accounting during the outage and cyber insurance claims. Its penetration testing service looks for "ways to chain multiple vulnerabilities together to identify high risks and potential exposure," and offers a format few firms publish: the client's IT team can follow along while the planned attacks run, with guidance on how to stop them. CLA is also a PCI Qualified Security Assessor. It is not on the CREST Marketplace, and named testers, retest terms, a findings portal and pricing are not stated.
Strength: a dealership practice that responded to the CDK outage within days, and an observed test that trains the store's IT staff. Limitation: the dealer material is advisory rather than a published dealer testing method, and CLA may also be the group's auditor. Best for: single-point and mid-size dealers whose IT staff want to learn from the test.
5. MNP
MNP, a Canadian professional services firm since 1958, publishes the most Canadian-specific dealership security guidance in this ranking, written by Seyed Hejazi, MNP Digital Partner and National Offensive Security Leader. It tells dealers that "publicly accessible network jacks, public Wi-Fi systems, and office Wi-Fi networks, systems and applications should be segmented from each other," warns about supplier impersonation used to redirect payments, and says the dealership sector "is far less regulated around IT and cyber security requirements compared to other industries." MNP Digital's offensive security service assesses "systems, networks (internal, external, and wireless), mobile and web applications, and even people," beside 24x7 incident management. MNP is not on the CREST Marketplace, and named testers, retest terms, a findings portal and pricing are not stated.
Strength: Canadian delivery, with segmentation and fraud guidance written for dealerships by its offensive security leader. Limitation: thin published testing method, and if MNP is also the group's accountant, independence needs documenting. Best for: Canadian dealers and dealer groups that want testing and incident response from a domestic firm.
6. Forvis Mazars
Forvis Mazars, LLP, the US member of Forvis Mazars Global with about 7,000 team members, publishes dealer-specific security work: a Safeguards Rule article for dealerships dated July 2025 that summarizes the FTC's renewed guidance to auto dealers, and a July 2024 alert, Returning to the CDK Environment, whose network and security checklist begins "We believe it is safe to assume the worst from an overall network and security standpoint." Its cybersecurity practice lists "internal and external penetration testing, static and dynamic web application testing, social engineering, physical intrusion, IR tabletop, and DR/BCP tabletop testing," plus red team work and a 24/7 managed security service. The CREST Marketplace listing for Forvis Mazars is a UK listing, not the US firm. Named testers, retest terms and pricing are not stated.
Strength: physical intrusion and social engineering in the same catalogue as network and web application testing, with CDK-era guidance for dealers. Limitation: the testing practice serves many industries, so confirm which testers have dealership experience, and document independence if Forvis Mazars audits the group. Best for: dealer groups that want physical and social engineering testing alongside the network test.
7. Rehmann
Rehmann, founded in Saginaw, Michigan in 1941 and now with offices in Michigan, Ohio and Florida, has a dealership industry practice and published 10 ways car dealerships can safeguard their business two days after the CDK outage began, recommending a "Security Audit, Vulnerability Assessment & Pen Test" and MFA on "ALL methods of remote access to sensitive corporate data." Its cybersecurity solutions include reconnaissance, scanning and simulated attacks "through external, internal, and wireless vulnerability, penetration, and web application tests," alongside virtual CISO work and a managed security service. Rehmann is not on the CREST Marketplace, and named testers, retest terms, a findings portal and pricing are not stated.
Strength: dealership advisory, testing and managed security from one firm in the dealer's market. Limitation: if Rehmann is also the dealer's managed security provider, it should not test the controls it runs. Best for: dealers in Michigan, Ohio and Florida that want testing from a firm already in their region.
8. LBMC
LBMC, headquartered at 201 Franklin Road in Brentwood, Tennessee, publishes FTC Safeguards for Dealerships After CDK Cyberattack, first posted in July 2024 and updated in September 2026, which says "LBMC Cybersecurity specializes in helping companies become compliant with the FTC's Safeguards Rule" and performs "risk assessments and penetration tests." A September 2024 webinar for auto dealers with two LBMC shareholders covers controlling access, employee training, patching and incident response planning. Its technical security services include "Penetration testing and adversary simulation" and "Identity and Active Directory security testing," with digital forensics, incident response and ransomware readiness assessments. LBMC is not on the CREST Marketplace, and named testers, retest terms, a findings portal and pricing are not stated.
Strength: a risk assessment and a penetration test from one team, in the order the rule sets, since the written risk assessment decides what the annual test covers. Limitation: the dealer material is compliance-led rather than a published dealer testing method. Best for: dealers building their Safeguards Rule program and first annual test at the same time.
9. Cherry Bekaert
Cherry Bekaert, whose site lists its address as 3800 Glenwood Avenue in Raleigh, North Carolina, published FTC Safeguards Rule: What Auto Dealers Need to Know in August 2024, listing "Perform annual penetration testing and twice-annual VAs" among the steps dealers must take and pointing to dealers' "use of open wireless networks for customer convenience." Its compliance penetration testing service runs "targeted penetration testing to simulate real world attack paths against in scope environments" and promises reporting that "stands up to regulator and auditor scrutiny." Cherry Bekaert is not on the CREST Marketplace, and named testers, retest terms, a findings portal and pricing are not stated.
Strength: testing framed around what an auditor or regulator will ask to see. Limitation: no dealership practice page; the dealer material is a single article. Best for: dealers that want compliance-shaped testing evidence for the Safeguards file.
10. BDO USA
BDO USA, with more than 85 US offices and 14,600 professionals, runs an Auto Dealerships practice and published A New Challenge for Dealerships Across the US: The FTC Safeguard Rule in June 2023, which tells dealers they "should regularly monitor and test their security systems." Its Cybersecurity Assurance service offers "Continual assessment and penetration testing" and states that "Offensive security services and active penetration testing provide early detection and management of vulnerabilities." BDO USA is not on the CREST Marketplace; the BDO listing there is a UK firm. Named testers, retest terms, a findings portal and pricing are not stated.
Strength: a national dealership practice with testing in the same firm. Limitation: the dealer article summarizes requirements, and the testing page publishes no method detail. Best for: dealer groups already working with BDO's dealership practice.
11. Raxis
Raxis, at 2870 Peachtree Road in Atlanta, published "Ongoing Cyber Attack Disrupts Car Dealerships" on 21 June 2024, written by its CTO, Brian Tant, and updated in August 2025. The post says "Raxis recommends that car dealerships consider the following steps when designing a robust security program," among them "Use multi-factor authentication for identity verification." Its GLBA Safeguards Rule page lists auto dealers among the businesses GLBA covers, and its penetration testing page describes testing "by senior U.S. engineers who publish CVEs" and says "The pentester on your scope call is the one breaking in. And the one retesting your fix," under the heading "Retesting Comes Standard." Raxis Strike is a point-in-time test, and Raxis Attack is a PTaaS service with unlimited, continuous testing and findings in the Raxis One portal. Raxis is not on the CREST Marketplace, and pricing is not published.
Strength: the engineer who scopes the test runs it and retests the fixes. Limitation: no dealership practice page; the dealer material is a single 2024 post on the CDK attack. Best for: dealers that want the same tester from scoping through retest.
Firms considered and not ranked
Crowe and Wipfli both market to dealerships and sell penetration testing, but their dealership pages could not be verified for this guide on 1 October 2026, and the CREST listing under the Crowe name belongs to an Indonesian member firm. Eide Bailly serves more than 1,000 dealership clients and lists network penetration tests, but sells them inside its outsourced managed IT and security services. That raises the independence question every dealer should ask: whoever runs the network should not be the one testing it, and the same goes for a DMS vendor selling security products, as CDK does with CDK Network Protect, testing the controls around its own platform.
How much does dealership penetration testing cost in 2026?
Price follows rooftops, networks and applications. A single-point store with a hosted website and one DMS connection buys a different test from a 40-rooftop group with its own data center, a digital retailing platform and a captive finance arm. Stingrai publishes its package prices: US$3,000 for an Autonomous Pentest, which is Snipe alone with no penetration testers, and US$6,800 for a Hybrid Pentest, where penetration testers and Snipe test together, each per assessment of one web application and its APIs, which for a dealer is usually the credit application or customer portal. The same tiers run at US$650 and US$1,275 per month on 12-month continuous plans, and the No High or Critical Finding = Don't Pay guarantee applies to the Autonomous Pentest only. Store networks, Active Directory, Microsoft 365, Wi-Fi, social engineering and multi-rooftop programs are quoted through get a quote, with current figures on the pricing page.
The bands below are indicative, taken from our penetration testing cost guide for US dollars and the Canadian cost guide for standard Canadian scopes.
Dealership scope | Indicative US band | Indicative Canadian band (standard scope) |
|---|---|---|
Credit application, F&I tool or customer portal (web application) | US$5,000 to US$30,000 | C$12,000 to C$25,000 |
External network and remote access | US$5,000 to US$40,000 (network) | C$15,000 to C$35,000 |
Store network and Active Directory | US$5,000 to US$40,000 (network) | C$20,000 to C$35,000 internal; C$25,000 to C$35,000 Active Directory |
Microsoft 365, Entra ID and cloud | US$10,000 to US$50,000 (cloud) | C$25,000 to C$40,000 (cloud) |
Combined scope, single store or small group (up to 150 employees) | US$8,000 to US$20,000 | Quoted per scope |
Combined scope, mid-size group (150 to 500 employees) | US$20,000 to US$50,000 | Quoted per scope |
Annual program for a large group | US$50,000 to US$150,000 or more | C$60,000 to C$90,000 (PTaaS subscription) |
For scale, the FTC's 2021 final rule cites a NADA cost study, presented at the Commission's July 2020 workshop, that estimated the proposed amendments would cost an average franchised dealership US$293,975 up front and US$276,925 a year for the whole program, not just the test (86 FR 70279). The Commission adopted the rule anyway, saying properly securing information systems "can be an expensive and technically difficult task" but that the costs "are justified in order to protect customer information."
Three things move a dealership quote most: the number of rooftops and networks in scope, whether Wi-Fi and physical testing need someone on site at each store, and how many customer-facing applications need authenticated testing across roles. The cost calculator gives a starting figure.
Buyer checklist: ten questions to put to every vendor
The RFP template turns these into procurement language.
Which clause are you testing against? Expect 16 CFR 314.4(d)(2), tied to our written risk assessment, not a generic "GLBA scan."
Who exactly will test, and what do they hold? Names and certifications belong in the statement of work.
Where is your firm-level accreditation listed, and which legal entity will sign?
How will you test what connects to the DMS? Integration accounts, remote support tools and VPNs, with the DMS provider's written permission for anything it hosts.
Will you test segmentation between guest Wi-Fi, the service lane, kiosks and the networks that reach customer information? The FTC treats connected systems as in scope.
How will you test the credit application and F&I tools? Expect authenticated testing across customer, salesperson, F&I and administrator roles.
Do you run vishing against the help desk and the F&I office, including pretext calls posing as DMS or OEM support, and how do you handle call recording consent in each state and province?
Is retesting included, and what goes into the Qualified Individual's report? The board report has to cover results of testing.
Can you cover every rooftop, in both countries, on one schedule? Ask how on-site Wi-Fi and physical work is staffed.
Are you independent of our managed IT provider, DMS vendor and auditor?
Frequently Asked Questions
Who are the best penetration testing companies for auto dealerships in 2026?
The best penetration testing companies for auto dealerships in 2026 are Stingrai, Plante Moran, Compass IT Compliance, CLA (CliftonLarsonAllen), MNP, Forvis Mazars, Rehmann, LBMC, Cherry Bekaert, BDO USA and Raxis. Stingrai ranks first: a CREST-accredited penetration testing service provider at firm level whose two named penetration testers, from a team holding OSCE³, OSWE, OSEP, CREST CRT and CISSP certifications, cover store networks and Wi-Fi segmentation, Active Directory, Microsoft 365, credit application and F&I web applications, and help desk vishing, with retesting and an attestation letter included on one-time annual and continuous engagements. Plante Moran, Compass IT Compliance and CLA follow.
Does the FTC Safeguards Rule require auto dealers to do penetration testing?
Yes, for dealers that finance or lease and maintain customer information on 5,000 or more consumers, unless they run effective continuous monitoring. The FTC says the rule covers most automobile dealers who finance or lease automobiles, and 16 CFR 314.4(d)(2) requires annual penetration testing of information systems, plus vulnerability assessments at least every six months, after material changes to operations or business arrangements, and whenever circumstances may materially affect the information security program. The clause has applied since 9 June 2023, and the Commission said social engineering and phishing are part of a penetration test as the rule defines it.
Which dealerships are exempt from the annual penetration test?
Dealers that maintain customer information concerning fewer than 5,000 consumers are exempt under 16 CFR 314.6 from the annual penetration test and six-monthly vulnerability assessments, the written risk assessment, the written incident response plan and the annual board report. Multi-factor authentication, encryption, service provider oversight, training, the general duty to regularly test or monitor key controls and the 30-day FTC breach notice still apply. The FTC's dealer FAQ says customer information stays covered even after the dealer no longer holds the note.
Can continuous monitoring replace the annual penetration test?
The rule allows it. 16 CFR 314.4(d)(2) requires annual penetration testing and six-monthly vulnerability assessments only absent effective continuous monitoring or other systems to detect, on an ongoing basis, changes in information systems that may create vulnerabilities. When it adopted the rule, the Commission said the rule "requires one, not both," while noting that many financial institutions may choose to use both. In practice, monitoring flags changes and a test shows what an attacker can actually reach.
Does a dealership need to test its DMS provider?
A dealer cannot test its DMS provider's own platform, whether CDK, Reynolds and Reynolds or another, without the provider's written permission, but it can test everything on its own side: integration and API accounts, remote support tools, VPNs and what each can reach on the store network. Under 16 CFR 314.4(f) the dealer must select capable service providers, require safeguards by contract and assess them periodically, and the FTC's dealer FAQ says a vendor with direct access to the dealer's network should be required to use multi-factor authentication.
What happened in the June 2024 CDK Global outage?
On 19 June 2024 CDK Global shut down the systems behind its dealer management software after detecting unauthorized activity on its network. AutoNation, Lithia, Group 1, Sonic, Asbury and Penske filed Form 8-K reports on the disruption within five days, AutoNation estimated it cut second-quarter 2024 earnings by US$1.55 a share, and AutoCanada reported that the outage ran from 19 June to 1 July 2024. CDK later said a third party had gained unauthorized access to its systems.
Do Canadian dealerships need a penetration test?
No Canadian law names one for dealers. PIPEDA requires security safeguards appropriate to the sensitivity of the information and reports of breaches creating a real risk of significant harm; the Alberta and British Columbia Personal Information Protection Acts require reasonable security arrangements; and Quebec Law 25 requires reasonable security measures, with administrative penalties of up to C$10 million or 2% of worldwide turnover. A penetration test is the most direct evidence that those safeguards work.
How much does dealership penetration testing cost in 2026?
Stingrai publishes US$3,000 for an Autonomous Pentest (Snipe alone, no penetration testers) and US$6,800 for a Hybrid Pentest, each a one-time assessment of one web application and its APIs, or US$650 and US$1,275 per month on 12-month continuous plans; every other scope is quoted. Indicative bands from our cost guides put a US network test at US$5,000 to US$40,000, a mid-size dealer group's combined scope at US$20,000 to US$50,000, and a standard Canadian internal network test at C$20,000 to C$35,000.
Related reading
Best Penetration Testing Companies for Mortgage Lenders and Servicers (2026)
Best Penetration Testing Companies for Accounting and CPA Firms (2026)
Ready to scope a dealership penetration test?
The breach that ends in an FTC notice rarely starts at the firewall. It starts with a vendor remote access tool nobody revisited, a guest network that can see the DMS segment, or a help desk that resets a password for a caller who sounds like support. Stingrai is a CREST-accredited penetration testing service provider whose testing supports the evidence the FTC Safeguards Rule, PCI DSS and Canadian privacy programs ask for, delivered as a one-time annual engagement or as continuous coverage, with named penetration testers, retesting and an attestation letter. Book a free scoping call, get a quote for a store or group-wide scope, or see the published package prices on the pricing page.



