Fannie Mae now requires every single-family seller and servicer to commission "an independent third-party penetration test that is conducted at least annually" on the systems that store, access, process or transmit its confidential information, under the Information Security and Business Resiliency Supplement that took effect for lenders on 12 August 2025. Freddie Mac has required its Seller/Servicers to use a qualified independent third party for annual penetration testing since July 2023. The incidents behind the pressure are on the public record: Mr. Cooper Group told the SEC that personal information relating to "substantially all of our current and former customers" was taken in its October 2023 intrusion, and loanDepot said it would notify "up to approximately 16.9 million individuals" after its January 2024 incident (loanDepot 8-K/A).
Where Stingrai fits: Stingrai is a CREST-accredited penetration testing service provider at firm level, headquartered in Toronto with a London office and founded in 2021, serving clients in the United States and Canada. Two named penetration testers, from a team holding OSCE³, OSWE, OSEP, CREST CRT and CISSP, staff every human-led engagement, reviewed by the team lead and an engagement partner, with 18 published CVEs across the team. For a mortgage company that means the loan origination system and borrower portal tested for authorization across every role from borrower to underwriter, document upload and e-sign flows tested for IDOR, Microsoft 365 and Entra ID tested for the mailbox rules and consent grants behind wire-instruction fraud, Active Directory tested from a phished workstation toward the servicing platform, and vishing aimed at the help desk and closing team. It is delivered as a one-time annual engagement timed to the Safeguards Rule, NYDFS or GSE calendar, or as a continuous program through the PTaaS portal, with retesting and an attestation letter included. Published pricing is US$3,000 for an Autonomous Pentest and US$6,800 for a Hybrid Pentest covering one web application and its APIs (pricing); lender-wide scopes are quoted.
Quick answer: who are the best penetration testing companies for mortgage lenders and servicers in 2026?
The best penetration testing companies for mortgage lenders and servicers in 2026 are Stingrai, Richey May, Plante Moran, Baker Tilly, CLA, Raxis, Wolf & Company, SBS CyberSecurity, CoNetrix and High Bit Security. Stingrai ranks first for named, certified penetration testers across the LOS, borrower portals, Microsoft 365 and wire-instruction controls, with retesting and an attestation letter included, one-time or continuous. Richey May, Plante Moran and Baker Tilly follow for the most mortgage-specific security practice, a CREST-accredited test inside a firm that serves mortgage banks, and testing next to a mortgage compliance center of excellence.

What mortgage lenders, brokers and servicers are actually required to test
Four sets of US rules name the penetration test for mortgage companies: the FTC Safeguards Rule and the state laws built on it, NYDFS Part 500, Fannie Mae's Supplement and Freddie Mac's Guide. A fifth layer, the incident notice clocks at Fannie Mae, Freddie Mac, FHA and Ginnie Mae, sets how quickly an exploited weakness must be reported. Canada names the test only for federally regulated lenders.
Does the FTC Safeguards Rule apply to mortgage lenders, brokers and servicers?
Yes, by name. The scope section, 16 CFR 314.1(b), lists "mortgage lenders," "mortgage brokers" and "account servicers" among the financial institutions under FTC jurisdiction, and 314.2(h)(2)(xi) adds that "a mortgage broker is a financial institution because brokering loans is a financial activity." The customer relationship definition at 314.2(e) covers a consumer who "has a loan for which you own the servicing rights" and one for whom you "arrange or broker a home mortgage loan," so servicers and brokers hold customer information even when they never fund a loan. Real estate settlement services are listed as well.
The rule reaches institutions not subject to another regulator's GLBA enforcement under section 505, which is why it lists non-federally insured credit unions. Insured banks and federally insured credit unions that originate mortgages follow the interagency safeguards guidelines instead, as the banking and credit union ranking explains.
Does the Safeguards Rule require penetration testing?
Yes, unless the lender runs effective continuous monitoring. 16 CFR 314.4(d)(2) says monitoring and testing "shall include continuous monitoring or periodic penetration testing and vulnerability assessments," and absent effective continuous monitoring requires "Annual penetration testing of your information systems determined each given year based on relevant identified risks in accordance with the risk assessment," plus vulnerability assessments "at least every six months" and after material changes. Section 314.2(n) defines the test as one in which "assessors attempt to circumvent or defeat the security features of an information system by attempting penetration of databases or controls from outside or inside your information systems." The clause has applied since 9 June 2023, after the Commission delayed the original December 2022 date (87 FR 71509).
Four other clauses shape a mortgage scope. Section 314.4(c)(4) requires procedures for "evaluating, assessing, or testing the security of externally developed applications," which reaches a licensed LOS or point-of-sale platform. Section 314.4(c)(5) requires multi-factor authentication "for any individual accessing any information system" unless the Qualified Individual approves an equivalent in writing. Section 314.4(f)(3) requires "periodically assessing your service providers based on the risk they present." And 314.4(i) puts "results of testing" in the Qualified Individual's written report to the board, at least annually. The Safeguards Rule testing guide works through each clause.
Who is exempt, and when does the FTC need to hear about a breach?
Section 314.6 exempts institutions that "maintain customer information concerning fewer than five thousand consumers" from the annual test, the written risk assessment, the incident response plan and the board report. A small brokerage may fall under that threshold. Since 13 May 2024, 314.4(j) has required notice to the FTC "as soon as possible, and no later than 30 days after discovery" of a notification event involving the information of at least 500 consumers, and unauthorized access to unencrypted customer information is presumed to be acquisition unless the institution has reliable evidence otherwise.
The FTC has applied the rule to the mortgage supply chain. In December 2020 it announced a settlement with Texas-based Ascension Data & Analytics, a mortgage industry analytics company whose vendor stored mortgage documents "on a cloud-based server in plain text, without any protections to block unauthorized access," exposing data on tens of thousands of mortgage holders, including Social Security numbers and credit files (FTC). The settlement requires a comprehensive data security program and biennial assessments by an independent organization. Vendor oversight belongs in the test scope.
Which state regulators write the test into state law?
The Conference of State Bank Supervisors published a Nonbank Model Data Security Law in July 2023 that is "largely based on the FTC Safeguards Rule," with alternative language that requires licensees to conform to the federal rule. The CSBS adopting-states list names 13 states when checked on 1 October 2026, among them the full-language adopters Arkansas, whose Act 262 covers mortgage licensees, Minnesota, Nevada, New York, North Dakota and Rhode Island. NYDFS itself says Part 500 "has served as a model" for the CSBS law (DFS, August 2026).
Minnesota shows what the full version does. Chapter 46A applies to "a residential mortgage originator or servicer under chapter 58," and section 46A.03, subdivision 5, requires "annual penetration testing of the financial institution's information systems" absent continuous monitoring, with the same exemption below 5,000 consumers. A state examiner, not only the FTC, can now ask for the report.
Does NYDFS Part 500 apply to mortgage bankers, brokers and servicers?
Yes. A covered entity under 23 NYCRR 500.1(e) is any person operating under "a license, registration, charter, certificate, permit, accreditation or similar authorization under the Banking Law," and the Department of Financial Services supervises mortgage bankers, mortgage brokers and mortgage loan servicers under that law. Section 500.5(a)(1) requires "penetration testing of their information systems from both inside and outside the information systems' boundaries by a qualified internal or external party at least annually," and 500.5(a)(2) adds automated scans plus manual review of systems the scans do not cover.
Two exemptions matter in mortgage. Under 500.19(a), an entity with fewer than 20 employees and independent contractors, less than US$7.5 million in gross annual revenue in each of the last three fiscal years, or less than US$15 million in year-end total assets is exempt from 500.5, which can cover a small brokerage. Under 500.19(b), an employee or agent who is itself a covered entity, which can include an individually licensed mortgage loan originator, is exempt to the extent the employer's program covers it. The 500.19(a) exemption is partial: a small broker still files a Notice of Exemption within 30 days under 500.19(f), certifies compliance (or acknowledges noncompliance) by 15 April each year under 500.17(b), keeps five years of supporting records, and reports cybersecurity incidents within 72 hours under 500.17(a). Among mortgage licensees, only a 500.19(b) employee or agent covered by its employer's program, or an individual originator whose license is inactive under Banking Law section 599-i (500.19(g)), is exempt from the whole Part. The NYDFS guide covers each clause.
What do Fannie Mae and Freddie Mac require?
Both require an independent penetration test every year, which rules out a lender grading its own work.
Fannie Mae's Supplement, first published 5 February 2025 and reissued 2 September 2025 (effective 22 September 2025 under Bulletin 25-01), binds single-family sellers and servicers and multifamily lenders from 12 August 2025, technology service providers from 31 December 2025 and document custodians from 1 April 2026. Section 3.4 requires "an independent third-party penetration test that is conducted at least annually on systems or system components used to store, access, process or transmit Confidential Information or connect to a Fannie Mae system," plus vulnerability scanning "on a regular basis." Section 3.3 adds an independent security assessment of the control environment at least annually and after any Cybersecurity Incident, by "a qualified independent auditor"; the September reissue removed the requirement that the assessor be unaffiliated with the lender. The program must align with, or exceed, a standard such as the NIST framework or ISO 27001, a corporate officer attests to it annually (single-family lenders can do so through the Form 582 process), and the lender answers for vendor failures "to the same extent as if such failure were committed by the Company."
Freddie Mac's Guide Section 1302.2(b)(xi) reads: "Not less than annually, employ a qualified and independent third party to conduct penetration testing on systems or system components used to store, access, process and/or transmit Freddie Mac confidential information or Protected Information or connect to System(s). At a minimum, the executive summary of the penetration report on Freddie Mac-related services and data should be made available to Freddie Mac for review." The annual third-party test dates from Guide Bulletin 2023-6, effective 3 July 2023, according to Freddie Mac's own summary, and Freddie Mac revised its "vulnerability management and penetration testing" requirements from 11 March 2025 (Bulletin 2024-17) and its rules on "managing system vulnerabilities" from 1 January 2026 (Bulletin 2025-13). The same October 2025 bulletin requires a SOC 2 Type 2 examination from 1 January 2027 for Seller/Servicers whose servicing portfolio is US$150 billion or more, covering "all systems and networks that store, process or transmit Freddie Mac data."
How fast must a mortgage company report a cyber incident?
Faster than most firms can scope a test. Fannie Mae requires notice "without undue delay and no later than 36 hours after identification." Freddie Mac's Section 1302.5(a) requires notice no later than 36 hours after discovering an Incident, a window in force since 1 January 2025, and immediate notice when an incident forces a Seller/Servicer to shut down, disable or disconnect systems used for Freddie Mac originations or servicing (Bulletin 2024-17). HUD's Mortgagee Letter 2024-23 gives FHA-approved mortgagees "no later than 36 hours" after determining that a Reportable Cyber Incident occurred, replacing the 12-hour standard of ML 2024-10, and cites "an unprecedented influx of Cyber Incidents impacting FHA Mortgagees, beginning in Fiscal Year 2023." Ginnie Mae's APM 24-02 requires issuers, including those that subservice, to notify it "within 48 hours of detection that a Cyber Incident may have occurred." NYDFS allows 72 hours, and the FTC 30 days for events involving 500 or more consumers.

Canada: FSRA, the MBRCC principles and OSFI B-13
No Canadian mortgage brokering rule names penetration testing. In Ontario, FSRA's Information Guidance MB0048INF, effective 18 August 2022 and last updated 12 April 2024, adopts the Mortgage Broker Regulators' Council of Canada's Principles for Cybersecurity Preparedness for mortgage agents, brokers, brokerages and administrators, and asks brokerages and administrators to notify FSRA "as soon as a licensee determines a cybersecurity incident could have a material impact on clients." The four MBRCC principles cover responsibility and resourcing, identification and prevention of risks, incident monitoring and response, and third-party management, and the document states that it "does not create new obligations." It also says brokerages that serve financial institutions should take reasonable steps to understand and comply with those institutions' cybersecurity expectations, which is one route by which a lender's security requirements reach its broker network.
FSRA's broader IT Risk Management Guidance GR0016INT, effective 1 April 2024, applies to the same licensees. It expects notice of a material IT risk incident "as soon as is reasonable, which normally falls within 72 hours or sooner," lists regular testing of data management controls among effective practices, and warns that failing to follow those practices "may impact the suitability for both licence issuance and licence renewal."
Federally regulated lenders are different. OSFI Guideline B-13, effective 1 January 2024 for every federally regulated financial institution, including the banks and trust and loan companies that lend on mortgages, asks institutions to "regularly perform tests and exercises, to identify vulnerabilities or control gaps in its cyber security programs (e.g., penetration testing and red teaming) using an intelligence-led approach," and to set "defined triggers, and minimum frequencies" themselves. OSFI's incident reporting advisory requires a report "within 24 hours, or sooner if possible." The OSFI B-13 guide covers the detail. Private-sector privacy law adds safeguards without naming a test: PIPEDA Principle 4.7 requires "security safeguards appropriate to the sensitivity of the information," section 10.1 requires breach reports where there is "a real risk of significant harm," and Quebec's private sector act, as amended by Law 25, requires reasonable security measures at section 10 and prompt notice of incidents presenting a risk of serious injury at section 3.5.
Rule | Who it covers | Names penetration testing? | Cadence | What the evidence has to show |
|---|---|---|---|---|
FTC Safeguards Rule, 16 CFR 314.4(d)(2) | Non-bank lenders, brokers and servicers | Yes | Annual, plus vulnerability assessments every six months, unless continuously monitored | Testing from outside and inside, tied to the written risk assessment |
State laws on the CSBS model, such as Minn. Stat. 46A.03 | State-licensed originators and servicers in adopting states | Yes, where the full model is enacted | Annual, unless continuously monitored | The Safeguards Rule test, enforceable by the state regulator |
NYDFS 23 NYCRR 500.5(a)(1) | New York mortgage bankers, brokers and servicers above the 500.19(a) thresholds | Yes | At least annually | Inside and outside the boundaries, by a qualified party; five years of records |
Fannie Mae Supplement, section 3.4 | Sellers and servicers, technology service providers, document custodians | Yes | At least annually | Independent third party; systems touching Fannie Mae data or systems |
Freddie Mac Guide Section 1302.2(b)(xi) | Seller/Servicers | Yes | Not less than annually | Qualified and independent third party; executive summary available to Freddie Mac |
HUD ML 2024-23 and Ginnie Mae APM 24-02 | FHA mortgagees; Ginnie Mae issuers and subservicers | No | Incident notice in 36 and 48 hours | Detection fast enough to report on time |
FSRA MB0048INF and GR0016INT | Ontario brokerages, agents, brokers and administrators | No | Incident notice normally within 72 hours | Regular testing of data management controls; MBRCC principles |
OSFI Guideline B-13, section 3.1.2 | Banks and trust and loan companies | Yes, as an example | Set by the institution | Intelligence-led tests with defined triggers and minimum frequencies |
PIPEDA and Quebec Law 25 | Private-sector lenders and brokers | No | None | Safeguards matched to sensitivity; breach reports |
What the Mr. Cooper and loanDepot filings show
Two large US mortgage companies disclosed incidents within ten weeks of each other, and their SEC filings show what a mortgage breach costs.
Mr. Cooper Group, October 2023. The Coppell, Texas servicer determined on 31 October 2023 that an unauthorized third party had gained access to certain technology systems (8-K). Its systems "were not accessible from November 1 through November 4," so many customers could not make payments or reach their accounts (8-K/A, 9 November 2023). On 15 December it reported that personal information "relating to substantially all of our current and former customers was obtained" (8-K/A). Its 2023 10-K reports US$27 million of cybersecurity incident related costs in 2023 and 26 putative class actions in the Northern District of Texas: 20 consolidated on 9 January 2024 and six more filed after that order. At the end of 2023 it served 4.6 million customers with US$992 billion of unpaid principal balance.
loanDepot, January 2024. The lender reported unauthorized access to certain systems "and the encryption of data," and shut systems down (8-K). It later said it would notify up to approximately 16.9 million individuals, and in the first quarter of 2024 it recorded about US$14.7 million of incident expenses, net of expected insurance recovery, in addition to lost revenue (10-Q).
Both companies describe penetration testing in their own annual reports. Mr. Cooper's 2023 10-K says it undergoes "external annual penetration assessments to evaluate susceptibility to attack, for example, through social engineering, application websites and system/network vulnerabilities," and loanDepot's 2024 10-K says it conducts "penetration and vulnerability testing." Neither filing says how the attackers got in, so no conclusion about either test follows. The narrower lesson holds: a test covers its scope on its date, which is why the GSE rules now ask for independence, an annual cadence and remediation of what the test finds.
The mortgage attack surface: what a good scope covers
A perimeter test misses most of the places where borrower data and closing funds move.

Loan origination system. Encompass and similar platforms hold every application. Test role boundaries between loan officers, processors, underwriters, closers and brokers, the admin console, custom plug-ins, and where integration API keys are stored.
Borrower and broker portals. One borrower must never see another borrower's loan file. That takes an authorization test across every role and loan, plus document upload handling, account recovery and multi-factor authentication, the failures API scanners miss.
Closing, e-sign and wire instructions. The FBI's 2025 Internet Crime Report, published April 2026, counts US$3.05 billion in business email compromise losses across 24,768 complaints, and describes buyers closing on a home who wired more than US$449,000 after an email impersonating their attorneys. Test who can change payee or wire details, the out-of-band callback, lookalike domains and the closing team's phone process. The BEC statistics cover the trend.
Microsoft 365 and Entra ID. Mailbox forwarding and inbox rules, OAuth consent grants, legacy authentication and Conditional Access exceptions are how a fake instruction lands inside a real email thread. Each exception to the 314.4(c)(5) multi-factor requirement needs the Qualified Individual's written approval, so the exception list is worth testing.
Active Directory and the internal network. Kerberos and delegation paths, ACL abuse and flat networks turn one phished processor into access to LOS and servicing servers. When servicing systems go offline, payments stop: many Mr. Cooper customers could not make payments for four days.
Servicing and payment platforms. Payment portals, IVR and call-center account changes, payoff requests and escrow disbursement need the same authorization testing as origination.
Credit bureau, GSE and vendor APIs. Credentials for credit, income and asset verification, pricing engines and GSE connections should be scoped, stored and rotated properly. Fannie Mae's section 3.4 reaches any system that connects to a Fannie Mae system.
Vendors, subservicers and third-party originators. Ascension's exposure began at a vendor's unprotected cloud server, and 314.4(f) expects service providers to be assessed periodically, so test vendor remote access, correspondent and broker portals and subservicer integrations.
How we ranked them
Ten vendors were scored against ten criteria. Every accreditation was checked on the CREST Marketplace, and every vendor entry links to a page on the vendor's own site, verified on 1 October 2026.
Published mortgage-sector security work on the vendor's own site.
Firm-level accreditation on the CREST Marketplace, plus the company certifications listed there.
Coverage of the mortgage attack surface described above.
Named testers, identified with their certifications before signing.
Retest policy stated in writing.
Delivery: a portal for findings, and both one-time and continuous options.
Evidence for GSE, NYDFS and state files, such as a report, attestation letter and a statement of tester independence.
Pricing transparency.
North American delivery in the United States, Canada or both.
Independence from the lender's IT, managed security and audit providers, which the GSE third-party wording makes concrete.
The 10 companies at a glance
# | Company | Based (own site) | Accreditations (CREST Marketplace) | Delivery model | Named testers | Retest | Published pricing | Best for |
|---|---|---|---|---|---|---|---|---|
1 | Stingrai | Toronto, ON (London, UK office) | Penetration Testing, firm level | Human-led, hybrid or autonomous; one-time or continuous; PTaaS portal | Yes, two per human-led engagement | Included | Yes, US$3,000 and US$6,800 | Named testers, retest and an attestation letter for GSE and NYDFS files |
2 | Richey May | Englewood, CO | Not listed | Advisory-led testing beside vCISO, managed services and IT audit | Not stated | Not stated | No | A mortgage-specialist adviser fluent in GSE requirements |
3 | Plante Moran | Southfield, MI | Penetration Testing; US SOC 2 Type 2 | Consulting-led, project or managed service | Not stated | Not stated | No | A CREST-accredited test from a firm serving mortgage banks |
4 | Baker Tilly | US offices nationwide | Not listed | Testing beside a mortgage compliance and QC practice | Not stated | Not stated | No | Lenders buying compliance reviews and testing together |
5 | CLA | Minneapolis, MN | Not listed | Advisory-led testing, red and purple team, payment fraud assessments | Not stated | Not stated | No | Wire-fraud controls reviewed beside the test |
6 | Raxis | Atlanta, GA | Not listed | Point-in-time or PTaaS (Raxis Attack) | A senior US engineer does the work | Yes, on PTaaS | No | Safeguards Rule testing of MFA, access control and encryption |
7 | Wolf & Company | Boston, MA | Not listed | DenSecure testing team inside an accounting and advisory firm | Not stated | Not stated | No | Financial-institution specialists with red teaming |
8 | SBS CyberSecurity | Madison, SD | Not listed | Testing plus a Safeguards Rule program and GRC software | Not stated | Not stated | No | Smaller lenders building a Safeguards Rule program |
9 | CoNetrix | Lubbock, TX | Not listed | Testing beside managed IT and the Tandem GRC platform | Not stated | Not stated | No | Lenders already documenting GSE rules in Tandem |
10 | High Bit Security | Port Sanilac, MI | Not listed | Testing-only boutique; PTaaS option | Not stated | Remediation validated in its mortgage case | Yes, published rate card | A defined external or internal test at a published price |
"Not stated" means the vendor's own site does not say. Ask for it in writing.
1. Stingrai
Stingrai is a global CREST-accredited penetration testing services company founded in Toronto, Canada in 2021, trusted by companies from startups to enterprises to meet audit requirements for SOC 2, ISO 27001, CMMC, PCI DSS and HIPAA. OSCE³, OSWE, OSEP, CREST CRT certified pentesters, who are also world-class security researchers and bug bounty hunters. Choose from fully human-led or hybrid (AI agents plus human penetration testers) engagements across web, API, mobile, AI and LLM, cloud, network, Active Directory and social engineering penetration tests and red team engagements.
What a lender's risk committee can check. The firm-level accreditation is on the CREST Marketplace supplier page for Stingrai Inc, separate from the CREST CRT certifications individual testers hold. The Clutch profile shows 5.0 out of 5 across 20 reviews when checked on 1 October 2026. The team has published 18 CVEs, including CVE-2025-50674, a local privilege escalation in OpenMediaVault, and CVE-2024-32136, an SQL injection in a WordPress plugin. Two named penetration testers, from a team holding OSCE³, OSWE, OSEP, CREST CRT and CISSP, run each human-led engagement, reviewed by the team lead and an engagement partner, under founder Arafat Afzalzada, who has 11 years in offensive security. A published case study covers penetration testing of a Toronto credit management platform whose report went to its SOC 2 program and its vendors.
How a mortgage engagement is tested. Web application testing covers the borrower portal, point-of-sale and broker portals, LOS customizations and their APIs, black, grey or white box, authenticated across every role from borrower and co-borrower to loan officer, processor, underwriter and closer, for broken authorization, IDOR and business logic under OWASP Top 10 and ASVS. Cloud testing treats Microsoft 365 and Entra ID as an attack path: app registrations, service principals, consent grants, Conditional Access gaps and hybrid-join trust. The Active Directory assessment follows ACL abuse and Kerberos and delegation paths to domain admin, and network testing covers the perimeter, vendor remote access and segmentation between corporate and servicing networks. Phishing and vishing campaigns test the help desk, the closing team and the payment instruction change process, and red teaming runs assumed-breach scenarios when a board wants to see the whole chain.
Evidence and delivery. Findings post to the PTaaS portal as they are confirmed, each with a working proof of concept and remediation guidance, with live chat to the assigned testers and Jira and Slack integration. Reports are redactable, which helps when a warehouse lender, investor or GSE reviewer asks for evidence. Retesting is included, and every human-led and hybrid report ships with an attestation letter and a verified badge. Stingrai's penetration testing supports your Safeguards Rule, NYDFS Part 500, Fannie Mae and Freddie Mac information security programs, as a one-time annual engagement timed to the 15 April NYDFS certification or the GSE review cycle, or as a continuous program that tests every release. Stingrai works in offensive security only, which keeps the testers independent of the teams that build and run the lender's systems.
Where Snipe fits. Snipe, Stingrai's autonomous AI penetration testing agent for web applications and their APIs, covers borrower portals, broker portals and point-of-sale apps. It hunts broken authorization, IDOR and business logic flaws, reviews code, and opens AutoFix pull requests. The Autonomous tier is Snipe alone, with no penetration testers, and carries the No High or Critical Finding = Don't Pay guarantee; in a Hybrid engagement Snipe and the penetration testers test together throughout, with the testers directing its focus. Microsoft 365, Active Directory, network, LOS integration and social engineering scopes are tested by penetration testers.
Pricing: US$3,000 for an Autonomous Pentest and US$6,800 for a Hybrid Pentest per assessment of one web application and its APIs, or US$650 and US$1,275 per month on 12-month continuous plans, on the pricing page. Every other scope is quoted through get a quote.
Strength: every claim a GSE reviewer or state examiner will ask about has a public source, from the CREST listing to the CVE records and review profile. Limitation: a deliberately small team, which the CREST listing reflects at 6 to 10 technical people, so multi-branch physical and social engineering programs need scheduling lead time, and the fixed-price packages cover one web application and its APIs only. Best for: independent mortgage banks, servicers and broker networks in the US and Canada that need named, certified penetration testers and an attestation letter for GSE, NYDFS and state files, one-time or continuous.
2. Richey May
Richey May, an accounting and advisory firm with its corporate headquarters in Englewood, Colorado, runs a mortgage banking practice and a cybersecurity division, RM Cyber. Its August 2025 article A Hose by Any Other Name explains what a penetration test must be to satisfy section 3.4 of Fannie Mae's Supplement, and RM Cyber publishes guidance on Freddie Mac's January 2026 changes, Ginnie Mae's notification mandate, FHA reporting and 23 NYCRR 500. Its threat management service covers external and internal network penetration testing, which starts with network scanners but whose "specialty lies within our skilled consultants," plus web application assessments, physical testing and targeted phishing. A 2020 case study describes Richey May supplying security leadership to CrossCountry Mortgage after its CIO, who was also acting CISO, left. Richey May is not on the CREST Marketplace, and named testers, retest terms and pricing are not stated.
Strength: the most mortgage-specific security practice in this ranking, written in the GSEs' own vocabulary. Limitation: RM Cyber also sells vCISO and managed services, so if it runs part of your program, confirm the testers are separate from that team, and ask how much of the network test is manual exploitation. Best for: independent mortgage banks and servicers that want an adviser who reads Fannie Mae, Freddie Mac, Ginnie Mae and FHA requirements alongside the test.
3. Plante Moran
Plante Moran, headquartered in Southfield, Michigan, serves "more than 600 banks, credit unions, insurance companies, investment funds, broker-dealers, mortgage banks, and other leasing and specialty finance companies," and its mortgage banking, consumer and specialty finance practice covers "questions of cybersecurity, data analytics, and the crucial role of IT." Its cybersecurity practice says its experts "achieved CREST certification for penetration testing in December 2024," and the CREST Marketplace lists Penetration Testing and US SOC 2 Type 2, with 11 to 25 technical people and both project-based and managed-service engagement models. Named testers, retest terms and pricing are not stated.
Strength: firm-level CREST accreditation inside a firm that already serves mortgage banks. Limitation: the mortgage practice page leads with accounting for servicing rights and derivatives, so ask for testing references from mortgage clients, and if the firm also audits your financial statements or SOC reports, confirm how the test team is separated. Best for: mortgage banks that want a CREST-accredited test from a large advisory firm with a mortgage practice.
4. Baker Tilly
Baker Tilly built a Mortgage Center of Excellence around The Compliance Group, which joined in December 2021 to strengthen "regulatory compliance and risk management services for the mortgage lending and servicing markets." Its mortgage compliance reviews cover technology management, including "Network security, external threat assessment, access to consumer information," and the practice publishes a case study of a mortgage company that achieved Fannie Mae approval with its advisers. Its penetration testing and vulnerability assessment service covers external penetration testing, internal vulnerability scanning, wireless and web application security testing and social engineering. Baker Tilly is not on the CREST Marketplace, and named testers, retest terms and pricing are not stated.
Strength: mortgage compliance, quality control and security testing from one firm with US offices nationwide. Limitation: the internal service is described as vulnerability scanning, so write an internal penetration test and Active Directory testing into the statement of work. Best for: lenders and servicers that already buy mortgage compliance or QC reviews from Baker Tilly.
5. CLA
CLA (CliftonLarsonAllen LLP), whose press releases are datelined Minneapolis, lists mortgage advisory services covering mortgage compliance, HMDA-LAR assessments, MERS annual reports and mortgage quality control alongside network and penetration testing. Its cybersecurity services include external network and application testing, internal network testing, red team and purple team penetration testing, social engineering, wireless testing and payment fraud assessments, which map onto closing-wire risk. Its Safeguards Rule article names mortgage brokers among covered institutions and lists "engaging third-party penetration testing and vulnerability assessments" among the requirements. CLA is not on the CREST Marketplace, and named testers, retest terms and pricing are not stated.
Strength: payment fraud assessments and red teaming from a firm with a mortgage compliance practice. Limitation: the mortgage advisory menu sits on CLA's credit union page, so confirm testing experience with independent mortgage banks. Best for: credit union mortgage operations and mid-size lenders that want wire-fraud controls reviewed beside the test.
6. Raxis
Raxis lists 2870 Peachtree Road in Atlanta and describes its work as manual penetration testing "by senior U.S. engineers since 2011." Its GLBA Safeguards Rule page says "Mortgage lenders, auto dealers, insurers, tax preparers, financial advisors, and credit unions all fall under GLBA," warns that many face mandatory testing for the first time "and grab the cheapest option," and tests the rule's controls directly: whether MFA can be bypassed, whether encrypted data is exposed and whether access controls enforce least privilege. Its financial services page maps testing to the Safeguards Rule, NYDFS 500.5 and PCI DSS, and its PTaaS option, Raxis Attack, includes "retesting of every fix." Raxis is not on the CREST Marketplace, and pricing is not published.
Strength: Safeguards Rule testing from a testing-focused firm, point-in-time or continuous. Limitation: no mortgage case study is published; the mortgage reference is a GLBA page rather than a sector practice. Best for: non-bank lenders and brokers that want a test written against the controls in 314.4.
7. Wolf & Company
Wolf & Company lists its Boston office at 255 State Street, with offices in Springfield, Massachusetts, Princeton, New Jersey and Miami. Its cybersecurity team, branded DenSecure in June 2022, runs penetration testing, cloud penetration testing, social engineering, red and purple teaming, Active Directory security and LLM assessments, and its cybersecurity page cites "18 Certifications Across the Team" and "150+ Assessments a Year." Its December 2021 alert on the amended Safeguards Rule singled out "mortgage brokers and agents who connect consumers with lenders" and predicted "significant gaps in the information security practices" of newly covered firms. Wolf is not on the CREST Marketplace, and named testers, retest terms and pricing are not stated.
Strength: a dedicated testing team inside a firm built around financial institutions. Limitation: its mortgage-specific material dates from 2021. Best for: Northeast lenders and servicers that want a financial-institution specialist with red and purple teaming.
8. SBS CyberSecurity
SBS CyberSecurity, at 700 S Washington Ave in Madison, South Dakota, sells an FTC Safeguards Rule service beside penetration testing of external and internal networks, web applications and wireless networks, red and purple teaming and Microsoft 365 security assessments. Its August 2025 Safeguards Rule guide lists mortgage brokers first among the nonbank businesses the rule covers and spells out "ongoing monitoring, annual penetration testing, and vulnerability scans twice a year." SBS also sells the TRAC risk management platform. It is not on the CREST Marketplace, and named testers, retest terms and pricing are not stated.
Strength: a Safeguards Rule program and the test from one vendor that serves examined banks and credit unions. Limitation: its industry menu lists banks and credit unions rather than mortgage companies, so ask for non-bank lender references. Best for: smaller lenders and bank-affiliated mortgage operations building a Safeguards Rule program.
9. CoNetrix
CoNetrix, founded in Lubbock, Texas in 1977 and still based there, is a family of companies that includes CoNetrix Security and Tandem. Tandem sells information security GRC software for mortgage companies that "stays up to date with Freddie Mac, Fannie Mae, FTC, CFPB, and other information security regulations," and CoNetrix sells network, external and internal penetration testing and IT audit. CoNetrix also provides managed IT services. It is not on the CREST Marketplace, and named testers, retest terms and pricing are not stated.
Strength: mortgage-specific policy and risk documentation from the same group as the tester. Limitation: the mortgage page sells software rather than testing, and if CoNetrix manages your network, choose a different tester to keep the test independent. Best for: mortgage companies already documenting Fannie Mae and Freddie Mac requirements in Tandem.
10. High Bit Security
High Bit Security lists a mailing address in Port Sanilac, Michigan and an operations center in Sandusky, under the line "Penetration Testing. It's Everything We Do." Its mortgage company case study describes an external penetration test for a full-service mortgage bank "licensed to lend across most of the United States with over 100 locations" that produced a 55-page report, found unsupported operating systems and an internal database server exposed directly to the internet, and ended with High Bit validating that the vulnerabilities were remediated. It publishes an itemized rate card, with standard packages listed between US$4,650 and US$13,300 when checked on 1 October 2026. It is not on the CREST Marketplace, and named testers are not stated.
Strength: published pricing and a mortgage-bank case study from a testing-only firm. Limitation: a small firm, and its mortgage case covers an external test only. Best for: brokers and smaller lenders that need a defined external or internal test at a published price.
Firms considered and not ranked
Some capable testers were left out because their own sites publish no mortgage-sector testing work. Coalfire holds firm-level CREST accreditation and appears in our USA ranking, but its 2020 case study for Blend, described as "a leader in the financial services space," covers coordinated PCI DSS, ISO 27001 and SOC 2 audits and never mentions mortgage. NetSPI, GuidePoint Security and TrustedSec, also in our USA ranking, and Optiv, in our banking ranking, publish no mortgage testing work. RSM US offers penetration testing and red teaming, but its only mortgage-related security material is a Safeguards Rule explainer. Pivot Point Security's GLBA page mentions mortgage only through lead-generation finders. Managed IT providers with mortgage pages were left out on independence: whoever runs the network should not test it. In Canada, the mortgage-industry pages at MNP and BDO Canada cover anti-money laundering and accounting rather than security testing, and the Canadian testing firms we checked list no mortgage pages; our Canada ranking covers the national market.
How much does mortgage penetration testing cost in 2026?
Mortgage scopes usually combine the borrower portal and LOS integrations, Microsoft 365, Active Directory, the external perimeter and a social engineering campaign aimed at wire instructions. Stingrai publishes its package prices: US$3,000 for an Autonomous Pentest, which is Snipe alone with no penetration testers, and US$6,800 for a Hybrid Pentest, where penetration testers and Snipe test together, each per assessment of one web application and its APIs. The same tiers run at US$650 and US$1,275 per month on 12-month continuous plans. Every other scope is quoted through get a quote, with current figures on the pricing page.
The bands below are indicative, taken from our penetration testing cost guide for US dollars and the Canadian cost guide for standard Canadian scopes.
Mortgage scope | Indicative US band | Indicative Canadian band (standard scope) |
|---|---|---|
Borrower, point-of-sale or broker portal (web application) | US$5,000 to US$30,000 | C$12,000 to C$25,000 |
LOS, pricing and credit bureau integrations (API) | US$6,000 to US$30,000 | C$15,000 to C$25,000 |
External perimeter and vendor remote access | US$5,000 to US$40,000 (network) | C$15,000 to C$35,000 |
Internal network and Active Directory | US$5,000 to US$40,000 (network) | C$20,000 to C$35,000 internal; C$25,000 to C$35,000 Active Directory |
Microsoft 365, Entra ID and cloud | US$10,000 to US$50,000 (cloud) | C$25,000 to C$40,000 (cloud) |
Lender-wide testing, mid-market organization | US$20,000 to US$50,000 | Quoted per scope |
Annual program | US$50,000 to US$150,000 or more (enterprise) | C$60,000 to C$90,000 (PTaaS) |
Three things move a mortgage quote most: how many borrower and partner portals need authenticated testing across roles, how many branches and domains are in scope, and whether social engineering includes vishing of the closing and help desk teams. The cost calculator gives a starting figure.
Buyer checklist: questions to put to every vendor
The RFP template turns these into procurement language.
Who exactly will test, and can we see their names and certifications before we sign?
How will the report show independence for Fannie Mae section 3.4 and Freddie Mac Section 1302.2(b)(xi)? Ask for a statement that the testers are separate from your IT, managed security and audit providers.
Which of our systems connect to a Fannie Mae system, and are all of them in scope?
Will you test authorization across every role in the LOS and borrower portal: borrower, co-borrower, loan officer, processor, underwriter, closer and broker?
Will you test Microsoft 365 and Entra ID as a wire-fraud path, including mailbox rules, OAuth consent grants and Conditional Access exceptions?
Do you run vishing against our help desk and closing team, and test the process for changing payment instructions?
How do you test credit bureau, verification and GSE integration credentials without touching production consumer data?
Is retesting included, and within what window? NYDFS 500.17(b) expects five years of supporting records, and Fannie Mae expects findings remediated within a commercially reasonable timeframe.
What can we hand Fannie Mae, Freddie Mac, a warehouse lender or a state examiner? Ask for the attestation letter, an executive summary Freddie Mac can review, and a redacted report.
Can you run the annual test as a one-time engagement and keep borrower-facing applications under continuous testing between annual tests?
Frequently Asked Questions
Who are the best penetration testing companies for mortgage lenders and servicers in 2026?
The best penetration testing companies for mortgage lenders and servicers in 2026 are Stingrai, Richey May, Plante Moran, Baker Tilly, CLA, Raxis, Wolf & Company, SBS CyberSecurity, CoNetrix and High Bit Security. Stingrai ranks first: a CREST-accredited penetration testing service provider at firm level whose two named penetration testers, drawn from a team holding OSCE³, OSWE, OSEP, CREST CRT and CISSP, test the LOS, borrower portals, Microsoft 365, Active Directory and wire-instruction controls, with retesting and an attestation letter included on one-time or continuous terms. Richey May, Plante Moran and Baker Tilly follow.
Does the FTC Safeguards Rule require mortgage lenders and brokers to run penetration tests?
Yes, unless they run effective continuous monitoring. 16 CFR 314.1(b) names mortgage lenders, mortgage brokers and account servicers, and 314.4(d)(2) requires annual penetration testing based on the written risk assessment, plus vulnerability assessments at least every six months and after material changes. The requirement has applied since 9 June 2023. Institutions holding customer information on fewer than 5,000 consumers are exempt from the annual test under 314.6, but not from multi-factor authentication or the 30-day FTC notice for events involving 500 or more consumers.
Do Fannie Mae and Freddie Mac require an independent penetration test?
Yes. Section 3.4 of Fannie Mae's Information Security and Business Resiliency Supplement, binding single-family sellers and servicers since 12 August 2025, requires an independent third-party penetration test at least annually on systems that store, access, process or transmit Fannie Mae confidential information or connect to a Fannie Mae system. Freddie Mac's Guide Section 1302.2(b)(xi) requires Seller/Servicers, not less than annually, to employ a qualified and independent third party to conduct penetration testing on systems that handle Freddie Mac confidential information or connect to its systems, and says at least the executive summary of the report should be made available to Freddie Mac for review; the annual third-party test dates from 3 July 2023.
Does NYDFS Part 500 require penetration testing for mortgage bankers, brokers and servicers?
Yes, for those above the small-entity thresholds. Mortgage companies operating under a Banking Law licence or registration are covered entities under 23 NYCRR 500.1(e), and 500.5(a)(1) requires penetration testing from inside and outside the information systems' boundaries by a qualified internal or external party at least annually. Section 500.19(a) exempts from 500.5 any entity with fewer than 20 employees and contractors, under US$7.5 million in gross annual revenue in each of the last three fiscal years, or under US$15 million in year-end total assets, but the exemption is partial: the entity still files a Notice of Exemption within 30 days, certifies compliance or acknowledges noncompliance by 15 April each year, and reports cybersecurity incidents within 72 hours.
How quickly must a mortgage company report a cyber incident?
Fannie Mae requires notice no later than 36 hours after identifying a Cybersecurity Incident, and Freddie Mac no later than 36 hours after discovery, or immediately if systems used for Freddie Mac business are shut down or disconnected. HUD Mortgagee Letter 2024-23 gives FHA-approved mortgagees 36 hours after determining that a Reportable Cyber Incident occurred, and Ginnie Mae APM 24-02 gives issuers 48 hours from detection. NYDFS allows 72 hours, OSFI 24 hours for federally regulated institutions, and the FTC 30 days for events involving 500 or more consumers.
Do Canadian mortgage brokerages and lenders have to run penetration tests?
No Canadian mortgage brokering rule names one. FSRA in Ontario adopted the MBRCC Principles for Cybersecurity Preparedness through Information Guidance MB0048INF and expects licensees to notify it of incidents that could materially affect clients, and its IT Risk Management Guidance lists regular testing of data management controls. Federally regulated banks and trust and loan companies follow OSFI Guideline B-13, which names penetration testing and red teaming as examples of intelligence-led testing and leaves the frequency to the institution.
What should a mortgage penetration test cover?
A mortgage scope should cover the loan origination system and its integrations, borrower and broker portals including document upload and e-sign, Microsoft 365 and Entra ID, Active Directory and the internal network, servicing and payment platforms, credit bureau and GSE connections, vendor and subservicer access, and social engineering aimed at wire instructions. Fannie Mae's Supplement scopes the annual test to systems that store, access, process or transmit its confidential information or connect to a Fannie Mae system.
How much does mortgage penetration testing cost in 2026?
Stingrai publishes US$3,000 for an Autonomous Pentest (Snipe alone, no penetration testers) and US$6,800 for a Hybrid Pentest per assessment of one web application and its APIs, or US$650 and US$1,275 per month on 12-month continuous plans; every other scope is quoted. Indicative bands from our cost guides put a US network test at US$5,000 to US$40,000, a US cloud test at US$10,000 to US$50,000 and a standard Canadian internal network test at C$20,000 to C$35,000.
Related reading
Best Banking and Credit Union Penetration Testing Companies (2026)
Best Penetration Testing Companies for Auto Dealerships (2026)
Ready to scope a mortgage penetration test?
The breach that ends in a GSE notice rarely starts at the firewall. It starts with a portal that shows one borrower another borrower's file, a mailbox rule nobody reviewed, or a call to the help desk that resets the wrong password before a closing. Stingrai is a CREST-accredited penetration testing service provider whose testing supports the evidence the Safeguards Rule, NYDFS Part 500, Fannie Mae and Freddie Mac ask for, delivered as a one-time annual engagement or as continuous coverage, with named penetration testers, retesting and an attestation letter. Book a free scoping call, get a quote for a lender-wide scope, or see the published package prices on the pricing page.



