main logo icon

Published on

September 25, 2026

|

24 min read

Best Penetration Testing Companies for Telecommunications (2026): Carriers, ISPs and UCaaS Providers

Ranked guide to the best penetration testing companies for carriers, ISPs, cable operators, MVNOs and UCaaS providers in 2026, with what Bill C-8, the CRTC, FCC CPNI rules and the Salt Typhoon guidance require, verified 25 September 2026.

Arafat Afzalzada

Arafat Afzalzada

Founder

Network SecuritySocial EngineeringWeb App Security

Summarize with AI

ChatGPTPerplexityGeminiGrokClaude

TL;DR

No telecom regime in Canada or the United States names penetration testing. Canada's Bill C-8 received royal assent on 15 June 2026 as S.C. 2026, c. 9. Its Telecommunications Act amendments took effect that day and let the Minister of Industry order a provider to have assessments conducted to identify any vulnerability in its networks, while the Critical Cyber Systems Protection Act it enacts is not yet in force. The CRTC regulates outages and network abuse rather than testing. In the United States, the FCC's CPNI rules require reasonable measures against unauthorized access, the 2023 breach amendments to 47 CFR 64.2011 are still delayed, and the January 2025 CALEA cybersecurity ruling was rescinded on 20 November 2025. The evidence that should drive a telecom test is the Salt Typhoon record: the FCC counts at least eight US communications companies infiltrated through publicly known vulnerabilities, and the Canadian Centre for Cyber Security records three compromised network devices at a Canadian telecom in February 2025. The best telecom penetration testing companies in 2026 are Stingrai, NCC Group, P1 Security, IOActive, Mandiant, Kroll, LevelBlue, Enea, Bishop Fox, Rapid7, Optiv and TrustedSec, each verified on its own site on 25 September 2026.

Salt Typhoon "had infiltrated at least eight U.S. communications companies," the Federal Communications Commission recorded in its November 2025 order, and the intrusions "exploited publicly known common vulnerabilities and exposures (CVEs) and other avoidable weaknesses to compromise networks, rather than zero-day" flaws (FCC 25-81, 90 FR 58006). In mid-February 2025 the same actors compromised three network devices registered to a Canadian telecommunications company, pulled their running configurations and modified at least one to build a GRE tunnel for traffic collection, according to the Canadian Centre for Cyber Security. Both records describe known, patchable weaknesses in exposed infrastructure. Finding them before an adversary does is the job of a telecom penetration test.

Regulators moved in opposite directions. Canada enacted Bill C-8 and gave the Minister of Industry power to order vulnerability assessments. The FCC adopted a network security ruling in January 2025 and rescinded it in November. Neither names penetration testing.

Where Stingrai fits: Stingrai is a CREST-accredited penetration testing service provider at firm level, founded in Toronto in 2021 with a London office. Two named penetration testers holding OSCE³, OSWE, OSEP, CREST CRT and CISSP staff every engagement, reviewed by the team lead and an engagement partner, with 18 published CVEs across the team. For a carrier, ISP, MVNO or UCaaS provider they test the edge, Active Directory paths toward management systems, customer portals, cloud and the care staff SIM swap fraud targets, with red team work of the kind in Stingrai's published telecom case study, one-time or continuously, with retesting and an attestation letter included. Published pricing is US$3,000 for an Autonomous Pentest and US$6,800 for a Hybrid Pentest covering one web application and its APIs (pricing); every other scope is quoted.

This guide is for mid-market and enterprise carriers, ISPs, cable operators, MVNOs, UCaaS and CPaaS providers and telecom SaaS in Canada and the United States. Every vendor entry was verified on its own site on 25 September 2026.

Quick answer: who are the best penetration testing companies for telecommunications in 2026?

The best penetration testing companies for telecommunications in 2026 are Stingrai, NCC Group, P1 Security, IOActive, Mandiant, Kroll, LevelBlue, Enea, Bishop Fox, Rapid7, Optiv and TrustedSec. Stingrai ranks first for firm-level CREST accreditation and named penetration testers across the edge, identity, cloud, customer portals and support channels, one-time or continuous. NCC Group, P1 Security and IOActive follow for a published 5G and OpenRAN practice, signalling and 5G core depth, and telecom hardware research.

Chart of what each telecom regime in Canada and the United States asks of a penetration test in 2026

What telecom buyers are actually required to test

Seven instruments get cited in telecom procurement, and not one names penetration testing. Some bind today, one is not yet in force, one was rescinded, and the rest are guidance.

Does Bill C-8 require penetration testing?

Not by name. Bill C-8 was introduced on 18 June 2025, passed the House on 26 March 2026 and the Senate on 4 June 2026, and received royal assent on 15 June 2026 as Statutes of Canada 2026, chapter 9 (LEGISinfo). Public Safety Canada's release is direct: "Amendments to the Telecommunications Act take immediate effect upon Royal Assent" (Public Safety Canada).

Part 1 adds a policy objective to section 7 of the Telecommunications Act, "to promote the security of the Canadian telecommunications system", and two order-making powers. Section 15.1 lets the Governor in Council bar a provider from using a specified supplier's products and services. Section 15.2 lets the Minister of Industry order a provider to develop a security plan, to mitigate vulnerabilities, and to:

(j) require that assessments be conducted to identify any vulnerability in a telecommunications service provider's telecommunications services, telecommunications networks or telecommunications facilities or its security plan referred to in paragraph (i);

Contravening an order carries administrative monetary penalties of up to C$10 million for a company, or C$15 million for a subsequent contravention, with each day a separate violation. The word "penetration" appears nowhere in chapter 9. The Act creates a power to compel vulnerability assessments and mitigation by order, and a provider with independent testing and a documented remediation trail is best placed to answer one.

When does the Critical Cyber Systems Protection Act apply?

Not yet. Part 2 enacts the Critical Cyber Systems Protection Act, whose provisions "come into force on a day or days to be fixed by order of the Governor in Council." The Justice Laws consolidation current to 3 September 2026 still marks it "not in force" (Justice Laws), and Public Safety Canada says it "will be implemented gradually, with certain provisions coming into force through a phased approach."

Telecommunications services are item 1 of the six vital services in Schedule 1, and Schedule 2, which will name the classes of designated operators, is empty. Once designated, an operator has 90 days under section 9 to establish a cyber security program with steps to manage cyber security risks, including supply chain and third-party risks, and to "protect its critical cyber systems from being compromised". Section 13 requires an annual review, and section 17 requires incident reports to the Communications Security Establishment "within a period prescribed by the regulations, not to exceed 72 hours". The Act never names penetration testing, but an operator will have to show its protections work, and an independent test with a retest is the most direct evidence.

What does the CRTC expect from carriers on security?

Less than most vendors imply. The Commission says that under the Telecommunications Act it "plays a narrow role by regulating telecommunications service providers (TSPs)" (Decision 2025-142). Its instruments cover resilience and network abuse:

  • Outage reporting. Telecom Decision 2025-225, effective 4 November 2025, requires facilities-based providers to report a major outage to the CRTC, ISED and emergency management organizations within two hours, and to file a post-outage report within 30 days of restoring service, whatever the cause.

  • Network abuse. Decision 2025-142 set terms for carriers that opt into network-level botnet blocking, Decision 2026-140 expanded that framework, and Decision 2026-52 made call traceback participation mandatory for all providers of voice telecommunications services, which matters to VoIP and UCaaS providers that carry voice (CRTC decisions, 2026).

  • Resilience rules in development. Notice of Consultation 2025-226 asks whether providers should be required to implement the CSTAC Security Incident Response Standard and Vendor Management Standard.

The CSTAC standards come closest to naming testing. Their Critical Infrastructure Protection Standard, version 1.1 of January 2020, asks providers to "Test devices against the hardening security standards adopted" and to "Perform security testing prior to systems being granted approval to move into production" (CSTAC, hosted by ISED). It is voluntary, and it does not say penetration testing.

What does the Canadian Centre for Cyber Security say about telecom threats?

The Cyber Centre publishes threat reporting and guidance, not rules. Its June 2025 bulletin with the FBI reports that "Three network devices registered to a Canadian telecommunications company were compromised by likely Salt Typhoon actors in mid-February 2025," through CVE-2023-20198, and assesses that PRC actors "will almost certainly continue to target Canadian organizations as part of this espionage campaign, including telecommunications service providers and their clients, over the next two years." An April 2025 advisory reports "repeated compromises of misconfigured and unpatched routing devices." The Cyber Centre co-sealed the December 2024 hardening guide described below, and its Cyber Security Readiness Goals, effective 29 October 2024, include a goal titled "Third-Party validation of cyber security control effectiveness" and name telecommunications among the sectors slated for sector-specific goals. None of these documents uses the phrase penetration testing.

Do the FCC's CPNI rules require penetration testing?

No. The safeguard that binds today is 47 CFR 64.2010(a): "Telecommunications carriers must take reasonable measures to discover and protect against attempts to gain unauthorized access to CPNI." The FCC's 2023 SIM swap order added paragraph (h): wireless providers and resellers must authenticate SIM change requests without relying on biographical, account, recent payment or call detail information, review those methods at least annually and train staff on fraudulent SIM changes. As printed in the eCFR on 1 September 2026, paragraph (h) still notes that compliance is not required until a compliance date is added.

The 2023 rewrite of the breach rule at 47 CFR 64.2011 is not in effect either. The Data Breach Reporting Requirements order (FCC 23-111, adopted 13 December 2023) would extend the rule to "covered data" that includes personally identifiable information, drop the requirement that access be intentional, and require notice to the Commission, the Secret Service and the FBI within seven business days, including "The method of compromise". It took effect on 13 March 2024 "except for the amendments codified at 47 CFR 64.2011 and 64.5111", which are "delayed indefinitely" pending an effective-date notice (Federal Register, 89 FR 9968), so the eCFR still prints the earlier text. Neither version mentions testing, yet both assume the carrier can reconstruct how an attacker got in, which a penetration test report answers in advance.

Is the FCC's January 2025 CALEA cybersecurity ruling still in force?

No. On 15 January 2025 the outgoing Commission adopted a Declaratory Ruling concluding "that section 105 of CALEA affirmatively requires telecommunications carriers ... to secure their networks from unlawful access to or interception of communications", with an NPRM that would have required "Covered Providers", including broadband providers, cable systems, interconnected VoIP providers, wireless resellers and MVNOs, to "create, update, and implement cybersecurity and supply chain risk management plans". On 20 November 2025 the FCC rescinded the ruling and withdrew the NPRM in FCC 25-81, published at 90 FR 58006. It pointed instead to carrier commitments made during 2025: "accelerated patching of outdated or vulnerable equipment, updating and reviewing access controls, disabling unnecessary outbound connections, and improving their threat-hunting efforts." Nothing from the episode binds a carrier today, but each commitment is a control a penetration test can verify.

What does the CISA and NSA hardening guidance ask for?

The joint Enhanced Visibility and Hardening Guidance for Communications Infrastructure, published 4 December 2024 by CISA, NSA, the FBI and partners including the Cyber Centre, is best practice rather than regulation, and it does not use the phrase penetration test. It is still the most specific public checklist for a telecom test, asking engineers to "Use an out-of-band management network that is physically separate from the operational data flow network", to confirm that network "does not allow lateral management connections between devices", to use SNMPv3 only, to disable Cisco Smart Install, and to "Conduct port-scanning and scanning of known internet-facing infrastructure" for exposed services. The agencies noted that the compromises "align with existing weaknesses associated with victim infrastructure; no novel activity has been observed."

The FBI and CISA had stated on 13 November 2024 that PRC-affiliated actors "compromised networks at multiple telecommunications companies to enable the theft of customer call records data" and more (CISA). Joint advisory AA25-239A, co-sealed in August 2025 by the Cyber Centre and CSIS among others, describes actors working "large backbone routers of major telecommunications providers, as well as provider edge (PE) and customer edge (CE) routers" through known flaws including CVE-2023-20198 in Cisco IOS XE, CVE-2024-21887 in Ivanti Connect Secure and CVE-2024-3400 in Palo Alto Networks PAN-OS.

Where SOC 2, PCI DSS and FedRAMP fit

UCaaS, CPaaS and telecom SaaS usually get their testing requirement from customers and certifications: a third-party report for SOC 2 reviews, PCI DSS 4.0.1 requirement 11.4 for any provider handling card data, and FedRAMP for cloud communications sold to federal agencies. Scope the test once against the real attack surface, then present the same report into each file.

The telecom attack surface: what a good scope covers

A telecom scope is not a web application with a network attached. It is eight surfaces, and the advisories above show which ones attackers are working.

Scope map of the eight telecom attack surfaces a penetration test should cover, with the public signal behind each
  • Edge and perimeter network devices. Routers, VPN concentrators, firewalls and their management interfaces, tested for exposure and for the CVEs named in AA25-239A. The advisories place both the US and the Canadian intrusions here, and an external network penetration test is the floor.

  • Privileged management and lawful intercept networks. The highest-value targets in a carrier. The test proves they are reachable only from where they should be and that one compromised device cannot reach the next, the move AA25-239A describes with harvested TACACS+ and RADIUS traffic. Specifics belong in rules of engagement agreed with legal leadership.

  • OSS and BSS platforms. Provisioning, activation, billing and customer care systems. CSTAC places communications with "back-end billing and customer care systems" on the management plane, so service accounts and integration trust are in scope.

  • Customer self-service portals and mobile apps. Account-scoped authorization across line, billing, number and device records, and the APIs behind the app. Broken object level authorization here exposes CPNI at scale.

  • SIM swap and account takeover through support channels. Care desks, retail stores and chat agents route around every technical control. A social engineering test should vish SIM change, port-out and account reset flows against the rules in 47 CFR 64.2010, and our SIM swap statistics cover the losses.

  • Cloud-native 5G core and Kubernetes. Rapid7's March 2026 research notes that core functions such as the AMF, SMF and UDM "run as cloud native network functions inside Kubernetes pods" (Rapid7). Cluster RBAC, network policy, secrets and the service interfaces between functions are in scope, next to SS7, Diameter and GTP signalling; the cloud penetration testing ranking covers the cluster side.

  • SIP and VoIP infrastructure. Session border controllers, SIP trunk authentication, toll fraud paths, caller ID handling, and UCaaS and CPaaS admin consoles and APIs.

  • Active Directory and Entra ID. The bridge from a phished workstation to network management and support tooling. AA25-239A records the actors targeting "internal enterprise environments" as well as customer-facing systems.

Covering all eight is a program, not one engagement: edge and management networks first, then identity and support channels, then portals and the core, with a red team exercise to test detection across all of them.

How we ranked them

Twelve vendors were scored against ten criteria, each traced to the vendor's own pages or an independent register.

  1. A published telecom practice or telecom research on the vendor's own site.

  2. Telecom surfaces: signalling, 5G core, edge devices, OSS and BSS.

  3. Enterprise surfaces: Active Directory, Entra ID, cloud and customer portals.

  4. Support-channel testing: vishing and SIM change pretexting.

  5. Adversary simulation: red team scenarios built on the actors in the advisories.

  6. Accreditation. Every accreditation in this guide was checked on the CREST Marketplace or the accrediting body's own register, and every rating on the review site itself.

  7. Named testers before signature.

  8. Retest and delivery: retest terms, portal and ticketing.

  9. Pricing transparency.

  10. North American presence.

Integrators and product vendors without an offensive testing service were not ranked; two are noted after the ranking.

The 12 companies at a glance

#

Company

HQ

Accreditations

Delivery model

Named testers

Retest

Published pricing

Best for

1

Stingrai

Toronto, ON

CREST Penetration Testing, firm level

Human-led or hybrid; one-time or continuous; PTaaS portal

Yes, two per engagement

Included

Yes, from US$3,000

Full carrier scope plus red team

2

NCC Group

Manchester, UK

CREST Penetration Testing, Threat Led and eight more

Consultant-led; continuous option; portal

Not stated

Continuous testing

No

5G, OpenRAN and interconnect

3

P1 Security

Paris, France

None listed

Telecom-only consultancy

Consulting lead named

Not stated

No

Signalling and 5G core interfaces

4

IOActive

Seattle, WA

CREST Penetration Testing

Consultant-led; hardware labs

Not stated

Not stated

No

CPE, base station and satellite hardware

5

Mandiant

Mountain View, CA

CREST Penetration Testing and Threat Led, Europe and Middle East

Consultant-led; red and purple team

Not stated

Not stated

No

Intelligence-led red team

6

Kroll

New York, NY

CREST Penetration Testing, Incident Response, SOC

Consultant-led; agile option

Not stated

Not stated

No

High-volume application testing

7

LevelBlue

Plano, TX

CREST Penetration Testing and Threat Led, UK entity

Consultants plus PTaaS; Fusion platform

Not stated

Included, no extra cost

No

Testing with managed security

8

Enea

Solna, Sweden

None listed

Remote signalling tests

Not stated

Not stated

No

Signalling firewall validation

9

Bishop Fox

Tempe, AZ

CREST Penetration Testing

Consultant-led plus continuous; portal

Service leads named

Application testing

No

UCaaS and CPaaS platforms

10

Rapid7

Boston, MA

None stated

Consulting; continuous red team

Not stated

Not stated

No

Rapid7 platform customers

11

Optiv

Leawood, KS

CREST Penetration Testing

Consultant-led; red and purple team

Not stated

Not stated

No

Consolidating with an integrator

12

TrustedSec

Fairlawn, OH

CREST Penetration Testing; PCI QSA

Consultant-led; red team

Bios published

Validation testing

No

Identity and vishing scopes

"Not stated" means the vendor does not publish the detail on its own site, not that it lacks the capability. Ask for it in writing.


1. Stingrai (top rated for telecommunications)

Stingrai is a global CREST-accredited penetration testing services company founded in Toronto, Canada in 2021, trusted by companies from startups to enterprises to meet audit requirements for SOC 2, ISO 27001, CMMC, PCI DSS and HIPAA. OSCE³, OSWE, OSEP, CREST CRT certified pentesters, who are also world-class security researchers and bug bounty hunters. Choose from fully human-led or hybrid (AI agents plus human penetration testers) engagements across web, API, mobile, AI and LLM, cloud, network, Active Directory and social engineering penetration tests and red team engagements.

The firm-level accreditation is listed on the CREST Marketplace under Penetration Testing, one of a handful held by firms headquartered in Canada. Ratings are 5.0 out of 5 from 19 reviews on Clutch and 4.9 out of 5 on G2. Two named penetration testers run every engagement, reviewed by the team lead and an engagement partner. The team has published 18 CVEs, including CVE-2025-50674 in OpenMediaVault and CVE-2024-32136 in a WordPress plugin, and holds bug bounty Hall of Fame listings at Apple, Google, the US Department of Defense and the US Federal Reserve. Founder Arafat Afzalzada has 11 years in offensive security.

For a telecom provider, network testing covers the perimeter, edge devices and segmentation between corporate, customer and management networks. The Active Directory assessment follows ACL abuse and Kerberos and delegation paths to domain admin, and cloud testing runs from control plane to workload across AWS, Azure with Entra ID and Google Cloud. Portals and APIs are tested across every account role, apps against OWASP MASVS and MASTG, and vishing targets care, retail and NOC staff. Red teaming runs assumed breach and threat intelligence-led scenarios, with purple teaming alongside the SOC. The telecom case study shows the work: signalling attacks against SS7, Diameter and GTP, phishing aimed at NOC staff, and lateral movement toward core infrastructure.

Findings post to the PTaaS portal as they are confirmed, each with a working proof of concept, with live chat to the testers and Jira and Slack integration. Retesting is included, and every report ships with an attestation letter and a verified badge, the assessment and mitigation record a section 15.2 order could require a provider to show. Stingrai delivers both one-time annual penetration tests and continuous programs.

Where a customer portal, UCaaS admin console or CPaaS API is in scope, Snipe, Stingrai's autonomous agent for web applications and their APIs, hunts broken authorization, IDOR and business logic flaws in account, porting and billing flows. The Autonomous tier is Snipe alone, with no penetration testers. On Hybrid, Snipe and the penetration testers test together throughout, with the testers directing its focus. Network, Active Directory, cloud, mobile, social engineering and red team work is human-led.

  • HQ: Toronto, Ontario, with a London, UK office.

  • Delivery model: fully human-led or hybrid, one-time or continuous, through the PTaaS portal. Named testers: yes, two per engagement. Retest: included.

  • Pricing: published at US$3,000 (Autonomous) and US$6,800 (Hybrid) per assessment for one web application and its APIs; other scopes quoted. Accreditations: CREST Penetration Testing, firm level.

  • Services: web and API, mobile, cloud, network, Active Directory, phishing, red teaming, purple teaming and adversary simulation.

  • Best for: carriers, ISPs, MVNOs and UCaaS providers in Canada and the US that want named, credentialed penetration testers across edge, identity, cloud, portal and support-channel surfaces, with red team on top.

Strength: every checkable claim has a public source, from the CREST listing to the CVE records and review profiles. Limitation: a smaller bench than the global consultancies here, so estate-wide programs with many concurrent scopes should be scheduled early, and engagements needing security-cleared testers should say so in scoping.

2. NCC Group

NCC Group's telecommunications practice covers legacy networks through 5G and OpenRAN, delivering "penetration testing, red teaming, and compliance consulting aligned to the Telecommunications (Security) Act, GSMA FS.31, SAS and NESAS frameworks." Its researchers built an in-house tool for testing SS7, Diameter and GTP interconnect signalling (NCC Group, March 2024), and it publishes a 5G standalone case study covering a UK operator's cloud-native core and OpenRAN components.

  • HQ: Manchester, UK, with a North American regional headquarters in Chicago and an office in Waterloo, Ontario.

  • Delivery model: consultant-led, with continuous testing and the Cyber Services Portal. Named testers: not stated. Retest: stated for continuous testing. Pricing: not published.

  • Accreditations: CREST Penetration Testing, Threat Led Penetration Testing, Cyber Threat Intelligence, Incident Response, Security Operations Centre and Vulnerability Assessment, among ten CREST listings, with ISO 27001.

  • Best for: operators with 5G standalone, OpenRAN and interconnect scopes.

Strength: the most complete published telecom practice among the generalists. Limitation: the practice is framed around UK regulation, so Canadian and US mapping comes from your side, and testers are not named.

3. P1 Security

P1 Security is a telecom-only firm that has worked on operator and national mobile infrastructure since 2011. Its audit and red team page says it "delivers telecom focused vulnerability assessments, penetration testing, red team engagements, and security architecture reviews" across SS7, SIGTRAN, Diameter, GTP-C, IMS, roaming, RAN and O-RAN, NFVI, OSS and OAM, and fixed broadband and FTTH. Its 5G core assessment tests cores interface by interface, up to N32 at the SEPP roaming edge, and it cites 500 security missions.

  • HQ: Paris, France (registered office).

  • Delivery model: consultant-led missions alongside its own telecom scanning products. Named testers: the head of consulting, an OSWE holder, is named. Retest: not stated. Pricing: not published.

  • Accreditations: no CREST listing.

  • Best for: mobile operators and MVNOs that need signalling, roaming and 5G core interfaces tested by specialists.

Strength: telecom-only depth down to individual 5G core interfaces. Limitation: no North American office, no CREST listing and no stated retest service, so pair it with a generalist for enterprise IT and support channels.

4. IOActive

IOActive's telecommunications page addresses mobile network operators and describes work from satellite terminals and base stations to handsets, the public switched telephone network, silicon and cloud applications. Its research includes satellite communications security, and its Seattle headquarters houses a hardware lab.

  • HQ: Seattle, Washington, with a London office.

  • Delivery model: consultant-led assessments supported by hardware labs, plus red and purple team. Named testers: not stated. Retest: not stated. Pricing: not published.

  • Accreditations: CREST Penetration Testing, listed for Europe, the Middle East and North America, with ISO 27001.

  • Best for: operators and equipment vendors that need CPE, base station, satellite terminal or chip-level testing.

Strength: hardware and silicon depth that few testing firms match. Limitation: the telecom page is broad rather than specific on the 5G core or signalling, and retest terms are not published.

5. Mandiant (Google Cloud)

Mandiant's red team service lists telecommunications among the sectors its consultants have worked in, and its threat intelligence is why telecom buyers call. Mandiant documented APT41's MESSAGETAP malware on a telecom provider's SMS servers in 2019 and China-nexus actor UNC3886 deploying backdoors on Juniper routers in March 2025.

  • HQ: Mountain View, California, as part of Google; the Mandiant pages state no separate headquarters.

  • Delivery model: consultant-led penetration testing, red team and purple team. Named testers: not stated. Retest: not stated. Pricing: not published.

  • Accreditations: CREST Penetration Testing and Threat Led Penetration Testing, listed through its Irish entity for Europe and the Middle East.

  • Best for: carriers that want red team scenarios built on frontline intelligence about router-focused actors.

Strength: direct incident and intelligence exposure to the actors targeting carrier routing gear. Limitation: the CREST listing does not cover North America, and retest and portal terms are not published.

6. Kroll

Kroll's penetration testing practice is consultant-led, with agile and threat-led options and a separate red team service. Its telecom evidence is a case study in which a top-50 global telecommunications company assigned roughly 200 web applications for testing at about 25 a month, later extended to networking, IoT and 5G mobile devices.

  • HQ: New York, New York.

  • Delivery model: consultant-led, with agile and threat-led testing and red team. Named testers: not stated. Retest: not stated. Pricing: not published.

  • Accreditations: CREST Penetration Testing, Incident Response and Security Operations Centre, with ISO 27001.

  • Best for: operators with large web application estates that need testing throughput.

Strength: proven volume inside a telecom application program. Limitation: its telecom industry page covers financial advisory, so testing depth rests on one case study.

7. LevelBlue

LevelBlue was formed in May 2024 as a joint venture of WillJam Ventures and AT&T around AT&T's managed cybersecurity business, and tests through its SpiderLabs team. It says it "safeguards technology businesses like SaaS, ISPs, and Telcos", published a Salt Typhoon analysis in December 2024, and its penetration testing page offers "retesting services at no additional cost."

  • HQ: Plano, Texas.

  • Delivery model: SpiderLabs consultants plus tiered PTaaS on its Fusion platform. Named testers: not stated. Retest: included at no additional cost. Pricing: not published.

  • Accreditations: CREST Penetration Testing, Threat Led Penetration Testing and Vulnerability Assessment through LevelBlue Cyber Solutions Ltd, a UK entity, with ISO 27001.

  • Best for: ISPs and telecom-adjacent SaaS buying testing and managed security from one provider.

Strength: retesting at no additional cost, stated in writing. Limitation: no dedicated telecom testing page, so telecom credibility rests on heritage and research.

8. Enea

Enea, which acquired AdaptiveMobile Security in 2021, sells signalling penetration testing across SS7, Diameter and GTP-C, run remotely "without installing equipment or software at the operator sites," as a rapid test, a full test or repeat auditing at regular intervals.

  • HQ: Solna, Sweden, with a US office in Redwood City, California.

  • Delivery model: remote signalling tests plus a recurring audit tier. Named testers: not stated. Retest: not stated. Pricing: not published.

  • Accreditations: no CREST listing; ISO 27001 and ISO 9001 certificates.

  • Best for: operators validating signalling firewalls and interconnect exposure.

Strength: interconnect testing from the outside, the way a rogue roaming partner would attack. Limitation: signalling only, from a company that is a product vendor first.

9. Bishop Fox

Bishop Fox runs consultant-led testing alongside its continuous Cosmos platform, with findings delivered through the Bishop Fox portal. Its application penetration testing includes "retesting to confirm that remediation efforts are effective and complete," its social engineering service covers vishing, and its consultants published research on the 5G registration protocol in September 2025.

  • HQ: Tempe, Arizona.

  • Delivery model: consultant-led plus continuous testing, through its portal. Named testers: service leads are named. Retest: stated for application testing. Pricing: not published.

  • Accreditations: CREST Penetration Testing, with ISO 27001.

  • Best for: UCaaS, CPaaS and telecom software platforms with continuous releases.

Strength: portal delivery and continuous testing for product platforms. Limitation: no telecom industry page, so operator network context comes from your side.

10. Rapid7

Rapid7 sells consultant-led penetration testing and Vector Command, a continuous red team service with same-day reporting. Its telecom credential is research: the March 2026 BPFdoor report, which traces implants disguised as container services inside telecom cores.

  • HQ: Boston, Massachusetts.

  • Delivery model: point-in-time consulting plus continuous red team on its Command platform. Named testers: not stated. Retest: not stated. Pricing: not published.

  • Accreditations: none stated on its current pages.

  • Best for: operators on Rapid7 tooling who want testing and continuous red team in one relationship.

Strength: current, telecom-specific research on core-network implants. Limitation: no accreditation stated and no published retest terms.

11. Optiv

Optiv's attack and penetration practice is consultant-led, with red and purple team services and a separate remediation service. It announced CREST accreditation for penetration testing on 2 October 2025, and it publishes no telecom page.

  • HQ: Leawood, Kansas, with an office in Mississauga, Ontario.

  • Delivery model: consultant-led testing plus red and purple teams. Named testers: not stated. Retest: not stated. Pricing: not published.

  • Accreditations: CREST Penetration Testing.

  • Best for: large enterprises consolidating testing with an integrator.

Strength: integrator breadth across the US and Canada. Limitation: no telecom practice is published.

12. TrustedSec

TrustedSec runs a consultant-led penetration testing practice that ends in validation testing: "After you've addressed identified vulnerabilities, we retest to confirm they've been successfully mitigated." Its red team uses phishing, vishing, SMS and physical techniques, which fits the identity and support-channel side of a carrier scope.

  • HQ: Fairlawn, Ohio.

  • Delivery model: consultant-led engagements and red team. Named testers: consultant bios are published. Retest: stated, as validation testing. Pricing: not published.

  • Accreditations: CREST Penetration Testing; PCI QSA.

  • Best for: corporate identity and support-channel scopes, including vishing.

Strength: voice and SMS pretexting inside a red team scenario. Limitation: no telecom page, so network context comes from your scoping brief.


Two firms worth knowing that are not ranked here

CGI, headquartered in Montréal, runs a communications practice built on IT solutions for telecom clients, including BSS and OSS integration. Its Canadian offensive offer is a continuous validation service built around autonomous testing, and its CREST accreditations sit with its UK entity. Bell Cyber, the security arm of Bell Canada, headquartered in Verdun, Québec, publishes offensive security services from vulnerability scans to network penetration tests and red and purple team exercises. Canadian enterprises should know both. Competing carriers may prefer an independent tester to a rival's security arm.

How much does telecom penetration testing cost in 2026?

Telecom scopes combine the perimeter, Active Directory, multi-role portals, cloud and often social engineering, so they price above a single application test. The bands below are indicative, not quotes: US dollar figures come from our penetration testing cost guide, and Canadian dollar figures are the standard-scope column of our Canadian cost analysis.

Scope

Indicative US band

Indicative Canadian band

Web application or customer portal

US$5,000 to US$30,000

C$12,000 to C$25,000

API

US$6,000 to US$30,000

C$15,000 to C$25,000

Mobile application, per platform

US$7,000 to US$35,000

C$18,000 to C$30,000

External network

US$5,000 to US$40,000

C$15,000 to C$35,000

Internal network and Active Directory

US$5,000 to US$40,000

C$20,000 to C$35,000

Cloud (IaaS or PaaS)

US$10,000 to US$50,000

C$25,000 to C$40,000

Red team or adversary simulation

Quoted on tester-days

C$45,000 to C$65,000

Annual program

US$50,000 to US$150,000 or more

C$60,000 to C$90,000 for PTaaS

Signalling and 5G core assessments from specialists are quoted individually, and our red team cost guide covers red team budgeting.

Only Stingrai's own figures are firm prices. An Autonomous Pentest runs Snipe alone, with no penetration testers, at US$3,000 per assessment, and a Hybrid Pentest, where Snipe and penetration testers test together throughout, is US$6,800, each for one web application and its APIs, such as a customer portal. The same tiers run as 12-month continuous plans at US$650 and US$1,275 per month. Every other scope, including networks, Active Directory, cloud, social engineering and red team, is quoted through Get a Quote. Current figures are on the pricing page.

Buyer checklist: 10 questions to put to a telecom testing vendor

  1. Who exactly will test our network, and what do they hold? Names and certifications, written into the statement of work.

  2. Which telecom surfaces have you tested? Anonymized examples across edge, OSS and BSS, signalling and SIP.

  3. Which entity and region does your accreditation cover? Several firms here hold CREST through a subsidiary in another country.

  4. How will you protect live service? Change windows, stop conditions and rollback, given the CRTC's two-hour outage notice.

  5. Can you test our support channels? Vishing against SIM change, port-out and reset flows, with written authorization and legal review.

  6. How will you handle management and lawful intercept networks? Who may touch them, what is excluded, and who signs off.

  7. Is retesting included, and in what window? In writing, for all severities.

  8. How do findings reach our engineers? Portal, Jira and Slack, with a working proof of concept per finding.

  9. Will the report stand up to an order or a program review? Scope, methods, findings, remediation and retest evidence.

  10. Can you run both the annual test and continuous coverage? Weekly changes should not wait eleven months for a look.

The statement of work template turns these answers into contract language.

Frequently Asked Questions

Who are the best penetration testing companies for telecommunications in 2026?

The best penetration testing companies for telecommunications in 2026 are Stingrai, NCC Group, P1 Security, IOActive, Mandiant, Kroll, LevelBlue, Enea, Bishop Fox, Rapid7, Optiv and TrustedSec. Stingrai ranks first as a CREST-accredited penetration testing service provider at firm level with two named penetration testers on every engagement, testing the edge, identity, cloud, customer portals and the support channels SIM swap fraud runs through, one-time or continuously, with retesting and an attestation letter included. NCC Group, P1 Security and IOActive follow for a published telecom practice spanning 5G and OpenRAN, signalling and 5G core depth, and telecom hardware and satellite research.

Does Bill C-8 require penetration testing?

Not by name. Bill C-8 received royal assent on 15 June 2026 as S.C. 2026, c. 9, and its Telecommunications Act amendments took effect that day. Section 15.2 lets the Minister of Industry order a provider to develop a security plan, to have assessments conducted to identify any vulnerability in its networks, and to mitigate them, with penalties of up to C$10 million, or C$15 million for a subsequent contravention. The word penetration does not appear in the Act, but an independent test with a remediation trail is the evidence a provider would need if such an order arrives.

When does the Critical Cyber Systems Protection Act come into force?

On a day or days to be fixed by order of the Governor in Council. The Justice Laws consolidation current to 3 September 2026 marks it not in force, and no class of operators has been designated. Once designated, a telecommunications operator has 90 days to establish a cyber security program, must review it annually, and must report incidents to the Communications Security Establishment within a prescribed period of no more than 72 hours.

Do the FCC's CPNI rules require penetration testing?

No. 47 CFR 64.2010(a) requires carriers to take reasonable measures to discover and protect against attempts to gain unauthorized access to CPNI. The FCC rewrote the breach rule at 47 CFR 64.2011 in December 2023 to cover personally identifiable information and to require notice to the Commission within seven business days, but those amendments are delayed indefinitely pending an effective-date notice, and the eCFR still printed the earlier text on 1 September 2026. Neither version mentions testing.

Is the FCC's January 2025 CALEA cybersecurity ruling still in force?

No. The Commission adopted a Declaratory Ruling on 15 January 2025 reading section 105 of CALEA as a duty for carriers to secure their networks, with an NPRM proposing risk management plans for carriers, cable systems, interconnected VoIP providers and MVNOs. On 20 November 2025 the FCC rescinded the ruling and withdrew the NPRM in FCC 25-81, citing carrier commitments to faster patching, access control reviews, fewer outbound connections and better threat hunting.

What should a telecom penetration test cover?

Eight surfaces: edge and perimeter network devices, privileged management and lawful intercept networks, OSS and BSS platforms, customer portals and mobile apps, the support channels where SIM swap happens, cloud-native 5G core and Kubernetes, SIP and VoIP infrastructure, and Active Directory and Entra ID. Signalling interfaces such as SS7, Diameter and GTP need a specialist, and a red team exercise tests detection across all of them.

Can a penetration test include SIM swap and vishing scenarios?

Yes, and for a mobile provider it should. A social engineering engagement can call care desks and visit retail stores with pretexts requesting SIM changes, port-outs and account resets, then measure the results against 47 CFR 64.2010 and the provider's own scripts. It needs written authorization, legal review, test accounts and an agreed stop procedure.

How much does telecom penetration testing cost in 2026?

It depends on scope. Indicative bands from our cost research run from US$5,000 to US$30,000 for a customer portal and US$5,000 to US$40,000 for a network test in the United States, and C$15,000 to C$35,000 for an external network test in Canada. Stingrai publishes firm prices for one web application and its APIs: US$3,000 for an Autonomous Pentest and US$6,800 for a Hybrid Pentest, or US$650 and US$1,275 per month on 12-month continuous plans. Every other scope is quoted.


0 views

0

X

Related reading

Best Penetration Testing Companies for Government and the Public Sector (2026): State, Local, Provincial and Municipal
Network SecurityWeb App Security

Best Penetration Testing Companies for Government and the Public Sector (2026): State, Local, Provincial and Municipal

Best penetration testing companies for state, local, provincial and municipal government in 2026, ranked, with what CJIS, IRS 1075 and GovRAMP require.

25 min read

Best Penetration Testing Companies for iGaming, Sportsbooks and Casinos (2026)
Web App SecurityNetwork Security

Best Penetration Testing Companies for iGaming, Sportsbooks and Casinos (2026)

The best penetration testing companies for iGaming, sportsbooks and casinos in 2026, ranked, with what AGCO, New Jersey, Michigan and GLI rules require.

24 min read

Best Penetration Testing Companies for Accounting and CPA Firms (2026): FTC Safeguards Rule Ready
Network SecuritySocial Engineering

Best Penetration Testing Companies for Accounting and CPA Firms (2026): FTC Safeguards Rule Ready

Best penetration testing companies for accounting and CPA firms in 2026, ranked, with what the FTC Safeguards Rule and IRS guidance actually require.

24 min read

Contents

X