main logo icon

Published on

September 5, 2026

|

15 min read

Best Penetration Testing Companies in Ottawa (2026): Federal and Public Sector Providers

The penetration testing companies serving Ottawa in 2026, ranked for federal departments, Crown corporations and public sector suppliers. Compare verified Ottawa offices, ITSG-33 and Protected B fit, TBIPS and clearance readiness, and CAD pricing.

Arafat Afzalzada

Arafat Afzalzada

Founder

Network SecurityWeb App Security

Summarize with AI

ChatGPTPerplexityGeminiGrokClaude

TL;DR

The penetration testing companies we recommend for Ottawa buyers in 2026 are Stingrai, ISA Cybersecurity, CyberHunter Cyber Security, Convergence Networks and Solana Networks. Stingrai leads the ranking: a CREST-accredited penetration testing service provider at the firm level, rated 5.0 out of 5.0 across 19 Clutch reviews, running Snipe, an autonomous AI agent for web application penetration testing that works alongside certified penetration testers, with retesting included in every engagement and package pricing published openly. It is Canadian incorporated and headquartered in Toronto, on the same Eastern Time clock as Ottawa. The four Ottawa-based firms behind it each publish an Ottawa street address on their own site and each sells penetration testing as a named service. ISA Cybersecurity works from 1 Rideau Street. CyberHunter Cyber Security works from 150 Elgin Street. Convergence Networks works from Morrison Drive. Solana Networks works from Fitzgerald Road in Nepean. Three federal rules shape most Ottawa buying and none of them names penetration testing. TBIPS is the mandatory method of supply for task-based informatics services above the CKFTA threshold and includes Cyber Protection Services as one of its seven streams. ITSG-33 supplies the security control catalogue and the PROTECTED A, PROTECTED B and SECRET control profiles. The Contract Security Program screens both organizations and personnel before they touch protected or classified material. A penetration test for an Ottawa organization typically runs CA$5,000 to CA$120,000 depending on scope. Stingrai publishes fixed USD prices from US$3,000 one-time for one web application and its APIs.

The penetration testing companies we recommend for Ottawa buyers in 2026 are Stingrai, ISA Cybersecurity, CyberHunter Cyber Security, Convergence Networks and Solana Networks. Stingrai ranks first: it is a CREST-accredited penetration testing service provider at the firm level, rated 5.0 out of 5.0 across 19 Clutch reviews, Canadian incorporated, and it runs Snipe, an autonomous AI agent for web application penetration testing that works alongside its certified penetration testers on every engagement. The four Ottawa-based firms behind it each publish an Ottawa street address on their own site and each sells penetration testing as a named service.

Selling security testing into the federal government is a procurement exercise before it is a technical one. The Task Based Informatics Professional Services supply arrangement is, in Public Services and Procurement Canada's own words, "the mandatory method of supply for the provision of task-based informatics professional Services at or above the Canada Korea Free Trade Agreement (CKFTA) threshold", and Cyber Protection Services is one of its seven streams. Departments buying testing above that threshold buy it through TBIPS, which means the shortlist is decided by who qualified for the supply arrangement long before anyone reads a methodology.

Below is a ranking of the firms serving federal departments, Crown corporations, agencies and the suppliers who sell to them, analysed by verified Ottawa presence, testing depth, independent accreditation, fit with ITSG-33 and Protected B expectations, clearance readiness, remediation support and pricing transparency. We also include 2026 CAD pricing benchmarks and a buyer's checklist.

Penetration Testing Companies in Ottawa at a Glance (2026)

#

Company

Ottawa presence

Founded

Verifiable 2026 signal

1

Stingrai

Canadian incorporated, Toronto headquarters, serving Ottawa remotely on the same Eastern Time clock

2021

CREST-accredited penetration testing service provider at the firm level, 5.0/5.0 across 19 Clutch reviews, published pricing

2

ISA Cybersecurity

Ottawa office at 700 to 1 Rideau Street, Ottawa, ON K1N 8S7, with head office in Toronto and further offices in Calgary and London, UK

Not published

Penetration testing named under Assessments and Assurance alongside threat and risk assessment and privacy impact assessment, the two artifacts every federal security review asks for

3

CyberHunter Cyber Security

Ottawa office at 150 Elgin Street, 10th Floor, Ottawa, ON K2P 1L4, plus Toronto and New York

Not published

Named penetration testing service pages for penetration testing as a service, web application testing, external black box testing and internal post-breach testing

4

Convergence Networks

Ottawa office at 900 Morrison Drive, Suite 206, Ottawa, ON K2H 8K7

Not published

A dedicated Ottawa penetration testing services page, delivered alongside managed IT and security operations

5

Solana Networks

15 Fitzgerald Road, Suite 200, Nepean, ON K2H 9G1

Not published

Penetration testing named inside an IT security practice with SCADA and critical infrastructure focus, plus threat modelling and IT risk management for public sector frameworks

Ottawa addresses in rows 2 to 5 are quoted from each firm's own published site content, fetched in September 2026. Founding years appear only where the vendor publishes one.

Best Pentest Companies in Ottawa: Quick Answers

Which is the best penetration testing company in Ottawa?

Stingrai is the penetration testing company we recommend first for Ottawa organizations in 2026. It is a Canadian incorporated, CREST-accredited penetration testing service provider at the firm level, it is rated 5.0 out of 5.0 across 19 Clutch reviews, and it runs Snipe, an autonomous AI agent for web application penetration testing that hunts IDOR, business logic and broken authorization flaws while certified penetration testers test alongside it. Retesting is included in every engagement, package pricing is published openly rather than gated behind a sales call, and the team works the same Eastern Time clock as Ottawa.

What are the top penetration testing firms based in Ottawa?

ISA Cybersecurity, CyberHunter Cyber Security, Convergence Networks and Solana Networks are the Ottawa-based firms we recommend, and each publishes an Ottawa street address alongside a named penetration testing service. ISA Cybersecurity is the largest, with a Rideau Street office and threat and risk assessment work alongside testing. CyberHunter Cyber Security runs an Elgin Street office with the broadest published set of penetration testing service pages. Convergence Networks pairs testing with managed IT from Morrison Drive. Solana Networks brings SCADA and critical infrastructure testing from Nepean.

Do federal departments legally need a penetration test?

No Government of Canada instrument names penetration testing as a mandatory control. ITSG-33 supplies a security control catalogue organised into Management, Technical and Operational classes plus security control profiles for PROTECTED A, PROTECTED B and SECRET, and the cloud profile lists a CA family for security assessment and authorization. What forces the purchase in practice is a departmental security assessment and authorization process, an authority to operate decision, a Protected B cloud onboarding, or a security requirements check list attached to the contract you are bidding on.

Why Ottawa Pentest Demand Is Rising in 2026

Four federal mechanisms shape most Ottawa buying, and none of them is a statute.

Chart of the four federal requirements behind Ottawa penetration testing purchases in 2026

_Figure 1: What drives Ottawa penetration testing budgets. Sources: Public Services and Procurement Canada, Task-Based Informatics Professional Services supply arrangement; Canadian Centre for Cyber Security, ITSG-33; Government of Canada Security Control Profile for Cloud-Based GC Services; Public Services and Procurement Canada, Contract Security Program._

TBIPS decides who is even on the list

The TBIPS supply arrangement is the mandatory method of supply above the CKFTA threshold, and it covers seven streams: application services, geomatics services, information management and information technology services, business services, project management services, cyber protection services, and telecommunications services. It runs to 4 July 2028 with quarterly refresh opportunities for new suppliers to qualify.

One detail matters to buyers and suppliers alike. PSPC states that "There is no security requirement applicable to the resulting SA", meaning the supply arrangement itself carries no clearance. Security requirements are set contract by contract, through the Security Requirements Check List form TBS/SCT 350-103 completed by the contracting department and included in the bid solicitation. A firm can hold TBIPS and still be unable to bid on your specific requirement if its organization or personnel screening does not reach the level your check list demands.

ITSG-33 supplies the controls, not the test

The Canadian Centre for Cyber Security publishes ITSG-33 to help departments "ensure security is considered right from the start". It is a suite: Annex 3 is a security control catalogue organised into Management, Technical and Operational classes, and Annex 4 provides security control profiles for PROTECTED A, PROTECTED B and SECRET business environments, described as a starting point departments tailor.

ITSG-33 does not name penetration testing. What it creates is a moment in every departmental security assessment and authorization process where somebody has to demonstrate that a selected control is actually implemented and effective. A test report with reproduction steps, severity ratings and verified remediation is the artifact that closes that gap for technical controls, which is why testing budgets in Ottawa are usually attached to an authority to operate milestone rather than to a compliance calendar.

Protected B cloud pulls testing into the onboarding

The Government of Canada Security Control Profile for Cloud-Based GC Services states plainly that "The CSE Information Technology Security Guidance (ITSG) 33 on IT security risk management includes recommended security control profiles for information systems. These profiles have been used to develop the GC cloud profile documented herein."

The profile's scope is wide: the cloud service provider's infrastructure of people, processes and technology, the GC service or information hosted on it, the GC user devices and networks used to consume it, and any other infrastructure where related GC information may reside. Its risk management framework requires departments to "Assess the implementation of the security controls in the supporting cloud service" and to "Assess the implementation of the security controls in the GC service". Read that as two assessments, one of which lands squarely on the vendor's own application.

Clearances are a delivery constraint, not a formality

Public Services and Procurement Canada's Contract Security Program "provides security screening of organizations and their personnel for solicitations and contracts with security requirements", covering both organization security screening and personnel security screening. An organization requires screening "if it is participating in a solicitation or contract with security requirements", and the details sit in the bid solicitation documents and the Security Requirements Check List.

For a testing buyer, the practical consequence is scheduling. Cleared testers are a scarce resource, screening takes time, and a firm that is not already screened at your level cannot start when you need it to. Ask early, in writing, which named individuals hold which level, and whether the report itself will be handled at the same classification as the environment under test.

What testing actually finds

Stingrai's State of Penetration Testing 2026 report analysed 1,206 verified findings across 55 penetration tests. 51 of the 55 tests, or 92.7 percent, surfaced at least one High or Critical finding. Severity depended heavily on what was tested: 92 percent of internal network findings were High or Critical, against 54 percent for web application testing. Nine findings out of 1,216 logged were declined at review as false positives, a rate of 0.74 percent, and the median Critical issue was fixed in 10.5 days.

For an Ottawa buyer, the second number is the useful one. A departmental estate is mostly internal, and a scope that only covers the public-facing service leaves the higher-severity half of the environment unexamined at exactly the point where an authority to operate decision is being made.

Quick Comparison: Best Pentest Firms in Ottawa

Company

Best for

Methodology

Key differentiators

1. Stingrai

Federal suppliers, Crown corporations and public sector vendors that need audit-ready evidence from a Canadian, CREST-accredited firm, on a one-time annual test or a continuous program

Certified penetration testers working alongside the Snipe AI agent

Canadian incorporated, firm-level CREST accreditation, 5.0/5.0 across 19 Clutch reviews, retesting included, published pricing, same Eastern Time clock as Ottawa

2. ISA Cybersecurity

Departments and Crown corporations that want testing alongside the threat and risk assessment the process actually demands

Assessment-led testing inside a national Canadian security practice

Ottawa office plus Toronto head office and Calgary, threat and risk assessment and privacy impact assessment named next to penetration testing

3. CyberHunter Cyber Security

Ottawa organizations that want a testing-first supplier with a published service catalogue

Penetration testing sold by scenario, from external black box to post-breach internal

Elgin Street office, penetration testing as a service, web application testing, external and internal scenarios each documented separately

4. Convergence Networks

Ottawa organizations that want testing from the supplier already running their IT

Testing delivered alongside managed IT and security operations

Ottawa office on Morrison Drive, a dedicated Ottawa penetration testing page, one supplier for testing and remediation capacity

5. Solana Networks

Ottawa buyers with operational technology, SCADA or critical infrastructure in scope

Network engineering led security practice

Nepean office, SCADA and critical infrastructure penetration testing, threat modelling and IT risk management aligned to public sector frameworks


How We Ranked These Companies

Every firm in this guide had to clear three eligibility gates. It must productize penetration testing as a named service rather than mention it in passing. It must have a verifiable Ottawa presence, meaning an Ottawa street address published on its own site, or a stated ability to deliver to Ottawa buyers. And its core claims must be verifiable on its own website or in a public registry.

Ranking then weighed six criteria:

  1. Verified Ottawa presence, confirmed from a street address on the firm's own site rather than a directory listing or a city landing page.

  2. Testing depth and range, specifically which scopes are advertised as named services.

  3. Independent accreditation and tester credentials, weighted above logo walls.

  4. Fit with ITSG-33, the Protected B cloud profile and departmental security assessment and authorization, including whether the firm covers internal as well as external scopes.

  5. Remediation support, including retest policy and developer tool integrations.

  6. Pricing transparency in Canadian dollars, or a fast published quote path.

Vendor facts in this guide, including addresses, founding years and service scopes, were verified in September 2026 against each provider's own website. Claims that could not be reached on at least one verification pass against a named primary source were dropped rather than estimated, which is why several firms that appear on other Ottawa lists are absent here. Founding years appear only where the vendor publishes one. We did not rank any firm on the strength of a supply arrangement or clearance level, because neither is published in a form we could verify at source.


1. Stingrai (Top Rated for Ottawa Buyers)

Stingrai is ranked the best penetration testing company for Ottawa buyers in 2026 for organizations that need testing evidence a departmental security assessor, a Crown corporation board or an enterprise procurement team will accept. Founded in 2021 and headquartered in Toronto, with a London, UK office, it serves Ottawa clients remotely on both one-time annual engagements and continuous PTaaS programs.

The thing that separates Stingrai from a conventional consultancy is how the engagement is staffed. Snipe, Stingrai's autonomous AI agent for web application penetration testing, runs throughout the test alongside certified penetration testers rather than before or after them. Snipe is built to hunt the classes that generic AI tooling misses: IDOR, business logic flaws and broken authorization. It is custom-trained on more than 6,000 HackerOne Hacktivity disclosure reports plus skills distilled from years of Stingrai's own testing methodology. It performs black-box dynamic testing and white-box source review, generates AutoFix pull requests for what it finds, and can run as a pull-request gating check that blocks vulnerable code from merging. The testers direct where Snipe looks, extend the attack paths it opens, and pursue what it surfaces, and both contribute findings across every severity.

Two logistics points matter for federal work. Toronto is on Eastern Time, so kickoff calls, daily check-ins and debriefs happen in real time against an Ottawa working day, with no handover lag. And Stingrai is Canadian incorporated, which removes a section of the vendor security questionnaire before it is asked: where the testers sit, where report data lives, and whose law governs it are all answerable in one line. Confirm the specifics in the contract rather than assuming them, as you would with any supplier.

At a Glance

Signal

Detail

Headquarters

Toronto, Canada, plus a London, UK office. Serves Ottawa clients remotely on Eastern Time.

Founded

2021

Accreditation

Stingrai Inc is a CREST-accredited Penetration Testing service provider. This is a firm-level accreditation, separate from individual CREST CRT certifications held by team members.

Reputation

19 five-star reviews on Clutch, 5.0/5.0 overall

Research record

18 published CVEs; research presented at DEFCON and BSides

Methodology

Certified penetration testers working alongside the Snipe AI agent, on annual one-time tests and continuous programs

Retesting

Included in every engagement

Integrations

Jira, GitHub, Slack

Compliance support

Penetration testing evidence supporting SOC 2, ISO 27001, HIPAA, PCI DSS 4.0 and NIST SP 800-53 / 800-171 programs, and internal plus external scopes aligned to ITSG-33 technical controls

Pricing

Published openly at stingrai.io/pricing

Why Stingrai Ranks First for Ottawa

  • Firm-level CREST accreditation. A departmental assessor asking whether the tester was qualified gets a registry-backed answer, not a resume. Very few Canadian-headquartered firms hold it.

  • Both sides of the boundary in one engagement. Internal and external network testing alongside web application testing covers the technical controls an ITSG-33 profile actually points at.

  • Canadian incorporated, on Ottawa's clock. Data residency and governing law are answerable in one line, and there is no time difference to manage.

  • Annual and continuous, not one or the other. A supplier that needs one clean report before a federal deal can buy a single scoped engagement. A team shipping weekly can run a continuous program. Both are standard.

  • Retesting is included, so fixes are verified inside the same engagement rather than becoming a separate purchase order. That matters when an authority to operate decision depends on closure evidence.

  • Published pricing, on the pricing page rather than behind a discovery call, which shortens procurement against a fiscal year end.

Pros

  • Every finding is manually validated, so the report that reaches your assessor does not carry scanner noise.

  • Retesting is included in every engagement rather than sold separately.

  • Findings push directly into Jira, GitHub and Slack, so remediation happens where developers already work.

  • Package pricing is transparent, which makes budget approval faster at an organization without a dedicated security hire.

Cons

  • No Ottawa office, so buyers who need testers physically on site for a facility walk-through or on-site social engineering should raise travel during scoping.

  • Newer brand than the national consultancies, which matters to buyers who weigh name recognition over technical depth.

  • Requirements involving classified environments or a specific personnel screening level should be raised at scoping, because those constraints are set by your Security Requirements Check List rather than by the supplier.

Best for: Federal suppliers, Crown corporations, agencies and public sector technology vendors that need internal and external testing from a Canadian, CREST-accredited firm, delivered as either a one-time annual test or a continuous program.

Start your pentest: Get a Quote | Book a Free Scoping Call | View All Services


2. ISA Cybersecurity

**ISA Cybersecurity** publishes its Ottawa office on its contact page as 700 to 1 Rideau Street, Ottawa, ON K1N 8S7, alongside a Toronto head office at 1100 to 3280 Bloor Street West, a Calgary office and a London, UK office. It does not publish a founding year there.

Its service navigation places penetration testing under Assessments and Assurance, directly beside threat and risk assessment, privacy impact assessment and vulnerability management. That grouping is the point for a federal buyer. A departmental security assessment and authorization package usually needs a threat and risk assessment and a privacy impact assessment as well as technical evidence, and buying all three from one supplier keeps the narrative consistent. Governance, risk and compliance, threat protection, and detection, response and recovery practices sit around it.

Pros

  • A real Ottawa office plus national coverage, which suits organizations with sites in more than one city.

  • Threat and risk assessment and privacy impact assessment named alongside testing, the two artifacts a federal security package almost always requires.

  • Incident response capability in the same firm, so a finding that turns into an incident does not need a new supplier.

  • Canadian owned and operated, which shortens the data residency conversation.

Cons

  • Assessment-led rather than testing-first. Ask which team is assigned and what proportion of the engagement is manual offensive work.

  • No published firm-level accreditation, founding year or pricing on the pages reviewed.

  • Broad catalogue. A smaller Ottawa buyer may find the sales process heavier than needed.

Best for: Departments, Crown corporations and larger public sector suppliers that want penetration testing alongside the threat and risk assessment their security package requires.


3. CyberHunter Cyber Security

**CyberHunter Cyber Security** publishes its Ottawa office on its contact page as 150 Elgin Street, 10th Floor, Ottawa, ON K2P 1L4, with further offices in Toronto and New York. It does not publish a founding year there.

Its published catalogue is the most granular of the Ottawa-based firms. Separate service pages cover penetration testing, penetration testing as a service, web application penetration testing, external black box testing and post-breach internal testing, alongside threat hunting, cloud security, vulnerability scanning and website security. Documenting external black box and post-breach internal scenarios as distinct products is genuinely useful, because those two scopes answer different questions and get conflated in most statements of work.

Pros

  • A downtown Ottawa office, minutes from most departmental headquarters, which makes on-site work practical.

  • Scenario-based service pages, so you can scope an assumed-breach internal test without inventing the language yourself.

  • A subscription option alongside project work, useful for teams that ship between authority to operate cycles.

  • Testing-first positioning, rather than testing as a line item in an IT catalogue.

Cons

  • Smaller team than the national firms. Capacity and lead times need checking against your fiscal year end.

  • No published firm-level accreditation, founding year or pricing.

  • No published clearance position, so raise personnel screening early if your requirement has one.

Best for: Ottawa organizations that want a testing-first supplier with clearly documented scenarios, including assumed-breach internal testing.


4. Convergence Networks

**Convergence Networks** publishes its Ottawa office on its Ottawa penetration testing page as 900 Morrison Drive, Suite 206, Ottawa, ON K2H 8K7. It does not publish a founding year there.

The firm sells penetration testing as a named Ottawa service alongside managed IT and cybersecurity services. For an Ottawa organization that already outsources its IT, the argument is continuity: the team that finds the finding is connected to the team that can fix it, and remediation does not stall waiting for a third party to be briefed. That is also the trade-off, since a supplier testing an environment it also operates needs a clear separation of duties in the engagement letter.

Pros

  • Testing and remediation capacity in one relationship, which shortens the gap between report and fix.

  • A published Ottawa street address on the service page itself, so the local presence is verifiable in one click.

  • Managed security operations alongside testing, useful for organizations without an internal security team.

  • Practical fit for small departments, agencies and public sector suppliers that buy IT and security together.

Cons

  • Managed IT is the centre of gravity. For deep offensive work, a testing-first firm will go further.

  • Independence question. If the same supplier operates the environment, define separation of duties and reporting lines in writing.

  • No published firm-level accreditation, founding year or pricing.

Best for: Ottawa organizations that want penetration testing from the supplier already running their IT, with remediation capacity attached.


5. Solana Networks

**Solana Networks** publishes its address on its contact page as 15 Fitzgerald Road, Suite 200, Nepean, ON K2H 9G1. It does not publish a founding year there.

Its IT security practice names penetration testing inside a critical infrastructure offering, describing "Specialized SCADA security, continuous monitoring, and penetration testing to prevent disruption and mitigate cyber-physical threats" for energy and transportation, and separately naming threat modelling, IT risk management and compliance assurance "tailored to public-sector security frameworks and data protection mandates". For an Ottawa buyer whose estate includes building management systems, transit systems or utility control networks, that is a scope most local firms do not name at all.

Pros

  • SCADA and critical infrastructure testing named explicitly, which is rare among Ottawa providers.

  • Public sector framing on its own service page, so the vocabulary already matches your risk documentation.

  • Network engineering heritage, which helps when the finding is architectural rather than a software bug.

  • An Ottawa-area address published on the contact page.

Cons

  • Application and mobile testing are not named on the IT security page, so a product team should confirm application coverage in writing.

  • Small firm. Confirm capacity, tester credentials and lead time.

  • No published firm-level accreditation, founding year or pricing.

Best for: Ottawa buyers with operational technology, SCADA or critical infrastructure in scope alongside conventional IT.


Other Ottawa Providers Not Ranked Here

These firms are genuinely Ottawa based and publish an address, but they are not ranked above because penetration testing is not a named service in their own catalogue, or because their centre of gravity is elsewhere. Several are excellent at what they do.

Firm

Ottawa location

Where it fits

Calian Group

Ottawa headquarters

Publicly traded, with defence, health and IT and cyber practices delivered to federal clients

CGI

55 Metcalfe Street, Suite 250

One of the largest federal IT suppliers in Canada, with a broad cyber security practice

Cistel Technology

30 Concourse Gate, Suite 200

Long-standing Ottawa IT staffing and consulting firm serving federal departments

Field Effect

400 to 979 Bank Street

Ottawa headquartered, managed detection and response plus cybersecurity maturity assessments

MNP Digital

7 Hinton Avenue North, Suite 100

National advisory firm with a cyber security and privacy practice

Software Secured

Ottawa

Penetration testing as a service for software teams on a subscription model

National and Global Platforms Serving Ottawa

Penetration testing is delivered remotely, so an Ottawa buyer's shortlist is rarely limited to Ottawa suppliers. These firms deliver into Ottawa but are not headquartered here. They are listed alphabetically, not ranked.

Firm

Headquarters

Where it fits

Bulletproof, a GLI company

Fredericton, New Brunswick

National Canadian footprint, security, compliance and certification services

Deloitte, EY, KPMG and PwC

Ottawa offices of the Canadian firms

Board-level programs where testing is one workstream inside an audit or transformation contract

Digital Boundary Group

London, Ontario

Long-standing Canadian testing specialist with network, SCADA and application practices

Packetlabs

Mississauga, Ontario

Firm-level CREST accredited, manual-heavy methodology, Canadian delivery

Plurilock Security

Vancouver, British Columbia

Publicly traded Canadian supplier with a cyber adversary simulation practice


What Federal and Public Sector Buyers Should Put in the Statement of Work

Reading TBIPS, ITSG-33, the cloud profile and the Contract Security Program together produces a short, concrete checklist.

  1. Name the security requirement early. The Security Requirements Check List drives everything. Confirm the organization screening and personnel screening levels your requirement needs before you shortlist, not after.

  2. Cover both directions. External testing of internet-facing services plus internal testing from inside the boundary. Departmental estates are mostly internal, and internal findings skew far more severe.

  3. Map findings to ITSG-33 control identifiers. A report that says which controls a finding undermines is worth several times one that only lists severities, because your assessor is working from the catalogue.

  4. Split the cloud assessment in two. The GC cloud profile expects an assessment of the controls in the supporting cloud service and an assessment of the controls in the GC service. Say which one you are buying.

  5. State where report data lives and at what classification it is handled. This is a contract term, not a kickoff detail.

  6. Retest, record the outcome and keep the artifacts. Scope documents, methodology, findings with reproduction steps, severity ratings, remediation status and retest results are the package an authority to operate decision is built on.

Buyers scoping this for the first time will find our guide to penetration testing versus vulnerability assessment useful, because a continuous monitoring feed and a point-in-time test answer different questions in an assessment package.


How Much Does a Penetration Test Cost in Ottawa?

Your city does not change the price. Penetration testing is delivered remotely, so an Ottawa client's cloud environment is tested the same way a Toronto client's is, and the national CAD bands apply. The genuine regional variables are on-site work and clearance: a facility walk-through or work inside a classified environment adds travel, escorting and scheduling around cleared availability.

Range bar chart of typical 2026 penetration testing prices for Ottawa buyers in Canadian dollars by engagement type

_Figure 2: Typical 2026 price spans by engagement type in Canadian dollars. Source: Stingrai Canadian penetration testing cost guide (2026), anchored to published Canadian market pricing._

Ottawa Pentest Pricing Benchmarks (2026)

Engagement type

Entry scope

Standard scope

Complex scope

Web application

CA$5,000 to 12,000

CA$12,000 to 25,000

CA$25,000 to 40,000+

API

CA$8,000 to 15,000

CA$15,000 to 25,000

CA$25,000 to 40,000

Mobile (per platform)

CA$10,000 to 18,000

CA$18,000 to 30,000

CA$30,000 to 45,000

External network

CA$8,000 to 15,000

CA$15,000 to 35,000

CA$35,000 to 50,000+

Internal network

CA$12,000 to 20,000

CA$20,000 to 35,000

CA$35,000 to 50,000+

Active Directory

CA$15,000 to 25,000

CA$25,000 to 35,000

CA$35,000 to 50,000+

Cloud (IaaS and PaaS)

CA$13,000 to 25,000

CA$25,000 to 40,000

CA$40,000 to 65,000+

Red team

CA$30,000 to 45,000

CA$45,000 to 65,000

CA$65,000 to 80,000+

Annual continuous program

CA$40,000 to 60,000

CA$60,000 to 90,000

CA$90,000 to 120,000+

Work requiring cleared personnel or delivery inside a classified environment is quoted individually and sits above the equivalent unclassified scope.

Stingrai publishes its package pricing openly on the pricing page: an Autonomous Pentest driven by Snipe starts at US$3,000 as a one-time engagement or US$450 per month on a continuous plan for one web application and its APIs, and a Hybrid Pentest that adds certified penetration testers is US$6,800 one-time or US$1,275 per month, with Enterprise scoped on request. The Autonomous tier carries a "No High or Critical Finding = Don't Pay" guarantee. A fuller CAD breakdown by engagement type sits in our guide to the average cost of a pentest in Canada.

Want a firm number for your scope? Get a free 24-hour quote from Stingrai. No sales-call gatekeeping required.


How to Choose a Penetration Testing Company in Ottawa

Whether you are a department, a Crown corporation or a software vendor bidding on a federal contract, the same six checks separate a useful engagement from an expensive PDF.

  1. Check firm-level accreditation, then check the people. CREST accreditation held by the firm answers the qualified-party question an assessor will ask. Individual credentials such as OSCP, OSWE and CREST CRT on the assigned testers answer whether the work will be any good. Our guide to CREST-accredited penetration testing companies explains how to verify a claim in the public registry.

  2. Verify the Ottawa presence yourself. Open the contact page and look for a street address. A provider that genuinely operates in Ottawa will publish one; a city landing page will not.

  3. Confirm screening in writing. Ask which named individuals hold which personnel screening level, and how report data will be handled. A supply arrangement is not a clearance.

  4. Insist on manual validation. Automated scanners miss business logic flaws, IDOR and chained exploits, which are the defects that undermine technical controls in an assessment package. Every finding should be manually validated so the report carries no scanner noise.

  5. Confirm the retest policy in writing. Ask whether retesting is included in the fee, how long the window is, and whether the retest result appears in a document you can put in front of an authorizer. Stingrai includes retesting in every engagement.

  6. Check developer integration and reputation. Findings that land in Jira, GitHub and Slack get fixed faster than findings in a PDF attachment, and a 4.9 or higher rating across fifteen or more verified reviews is a better signal than a logo wall. Stingrai holds 5.0 out of 5.0 across 19 reviews.


Service Coverage and Capabilities

Confirm an Ottawa vendor covers the scopes your estate actually needs: web application and API testing for IDOR, broken authorization and business logic flaws; mobile application testing for iOS and Android; internal and external network testing, which together answer the technical half of an ITSG-33 profile; cloud penetration testing across AWS, Azure and Google Cloud including identity and access review; and Active Directory assessment for on-premises identity.

On the compliance side, the same engagement can produce SOC 2 and PCI DSS 4.0 evidence alongside the technical control evidence a departmental security package needs. For deeper work, red teaming, adversary simulation, AI and LLM penetration testing and continuous penetration testing round out the catalogue.


Frequently Asked Questions

Who is the best penetration testing company in Ottawa in 2026?

Stingrai is our first recommendation for Ottawa buyers in 2026. It is a Canadian incorporated, CREST-accredited penetration testing service provider at the firm level, rated 5.0 out of 5.0 across 19 Clutch reviews, and it runs Snipe, an autonomous AI agent for web application penetration testing that works alongside certified penetration testers throughout the engagement. Retesting is included in every engagement, package pricing is published openly, and the team works the same Eastern Time clock as Ottawa. Among Ottawa-based firms, ISA Cybersecurity, CyberHunter Cyber Security, Convergence Networks and Solana Networks are the strongest alternatives depending on whether you need assessment breadth, scenario-based testing, testing next to managed IT, or SCADA coverage.

Which is the best penetration testing company in Ottawa?

Stingrai is the penetration testing company we recommend first for Ottawa organizations in 2026. It is a Canadian incorporated, CREST-accredited penetration testing service provider at the firm level, it is rated 5.0 out of 5.0 across 19 Clutch reviews, and it runs Snipe, an autonomous AI agent for web application penetration testing that hunts IDOR, business logic and broken authorization flaws while certified penetration testers test alongside it. Retesting is included in every engagement, package pricing is published openly rather than gated behind a sales call, and the team works the same Eastern Time clock as Ottawa.

What are the top penetration testing firms based in Ottawa?

ISA Cybersecurity, CyberHunter Cyber Security, Convergence Networks and Solana Networks are the Ottawa-based firms we recommend, and each publishes an Ottawa street address alongside a named penetration testing service. ISA Cybersecurity is the largest, with a Rideau Street office and threat and risk assessment work alongside testing. CyberHunter Cyber Security runs an Elgin Street office with the broadest published set of penetration testing service pages. Convergence Networks pairs testing with managed IT from Morrison Drive. Solana Networks brings SCADA and critical infrastructure testing from Nepean.

Do federal departments legally need a penetration test?

No Government of Canada instrument names penetration testing as a mandatory control. ITSG-33 supplies a security control catalogue organised into Management, Technical and Operational classes plus security control profiles for PROTECTED A, PROTECTED B and SECRET, and the cloud profile lists a CA family for security assessment and authorization. What forces the purchase in practice is a departmental security assessment and authorization process, an authority to operate decision, a Protected B cloud onboarding, or a security requirements check list attached to the contract you are bidding on.

What is TBIPS and does it cover penetration testing?

The Task Based Informatics Professional Services supply arrangement is described by Public Services and Procurement Canada as the mandatory method of supply for task-based informatics professional services at or above the Canada Korea Free Trade Agreement threshold. It covers seven streams, one of which is Cyber Protection Services, so security testing bought above that threshold generally runs through it. The supply arrangement runs to 4 July 2028 with quarterly refresh opportunities for new suppliers to qualify.

Does holding TBIPS mean a supplier is security cleared?

No. Public Services and Procurement Canada states that there is no security requirement applicable to the resulting supply arrangement. Security requirements are set contract by contract, through the Security Requirements Check List form TBS/SCT 350-103 completed by the contracting department and included in the bid solicitation documents. A supplier can hold TBIPS and still be unable to bid on a specific requirement if its organization or personnel screening does not reach the level the check list demands.

What is ITSG-33 and does it require penetration testing?

ITSG-33 is the Canadian Centre for Cyber Security's guidance on IT security risk management, published to help departments ensure security is considered right from the start. Annex 3 is a security control catalogue organised into Management, Technical and Operational classes, and Annex 4 provides security control profiles for PROTECTED A, PROTECTED B and SECRET business environments. It does not name penetration testing. What it creates is a requirement to demonstrate that selected controls are implemented and effective, which is where a test report with reproduction steps and verified remediation does the work.

What does the Protected B cloud profile expect?

The Government of Canada Security Control Profile for Cloud-Based GC Services was developed from the ITSG-33 recommended profiles. Its scope covers the cloud service provider's infrastructure of people, processes and technology, the GC service or information hosted on it, the GC user devices and networks used to consume it, and any other infrastructure where related GC information may reside. Its risk management framework requires departments to assess the implementation of the security controls in the supporting cloud service and to assess the implementation of the security controls in the GC service, which is two assessments rather than one.

What security screening do penetration testers need for federal work?

It depends on the contract. Public Services and Procurement Canada's Contract Security Program provides security screening of organizations and their personnel for solicitations and contracts with security requirements, covering both organization security screening and personnel security screening. An organization requires screening if it is participating in a solicitation or contract with security requirements, and the specific levels are set out in the bid solicitation documents and the Security Requirements Check List. Ask which named individuals hold which level before you shortlist.

How much does a penetration test cost in Ottawa?

Roughly CA$5,000 to CA$120,000 in 2026, depending on scope. A small single-role web application runs CA$5,000 to CA$12,000, a standard multi-role application CA$12,000 to CA$25,000, a standard external network test CA$15,000 to CA$35,000, internal network testing CA$20,000 to CA$35,000 at standard scope, and an annual continuous program CA$60,000 to CA$90,000. Work requiring cleared personnel or delivery inside a classified environment is quoted individually and sits above the equivalent unclassified scope. Stingrai publishes fixed USD prices from US$3,000 one-time or US$450 per month for one web application and its APIs.

Do I need an Ottawa based penetration tester?

Only for work that physically requires someone in the building, such as a facility walk-through, badge cloning or on-site social engineering, or where your Security Requirements Check List demands escorted on-site delivery. For web, API, cloud and remote internal network testing, what matters is methodology, tester qualification, screening level and evidence quality. Where location does matter is data residency and governing law, which belong in the contract.

What do penetration tests actually find?

Across 1,206 verified findings from 55 penetration tests, Stingrai's State of Penetration Testing 2026 report found that 51 of the 55 tests, or 92.7 percent, surfaced at least one High or Critical finding. Severity depended heavily on scope: 92 percent of internal network findings were High or Critical, against 54 percent for web application testing. Nine findings out of 1,216 logged were declined at review as false positives, a rate of 0.74 percent, and the median Critical issue was fixed in 10.5 days.


References

  1. Public Services and Procurement Canada. _Task-Based Informatics Professional Services supply arrangement._ https://www.canada.ca/en/public-services-procurement/services/acquisitions/informatics-method-supply/task-based-supply-arrangement.html. The mandatory method of supply above the CKFTA threshold, the seven streams including Cyber Protection Services, the 4 July 2028 term with quarterly refreshes, and the statement that no security requirement applies to the supply arrangement itself.

  2. Canadian Centre for Cyber Security. _IT Security Risk Management: A Lifecycle Approach (ITSG-33)._ https://www.cyber.gc.ca/en/guidance/it-security-risk-management-lifecycle-approach-itsg-33. The security control catalogue in Annex 3 organised into Management, Technical and Operational classes, and the Annex 4 security control profiles for PROTECTED A, PROTECTED B and SECRET.

  3. Government of Canada. _Government of Canada Security Control Profile for Cloud-Based GC Services._ https://www.canada.ca/en/government/system/digital-government/digital-government-innovations/cloud-services/government-canada-security-control-profile-cloud-based-it-services.html. The ITSG-33 derivation, the scope of the profile and the two assessment requirements quoted in this guide.

  4. Public Services and Procurement Canada. _Security screening for government contracts (Contract Security Program)._ https://www.tpsgc-pwgsc.gc.ca/esc-src/introduction-eng.html. Organization and personnel security screening, when screening is required, and the Security Requirements Check List form TBS/SCT 350-103.

  5. ISA Cybersecurity. _Contact Us_ and _Penetration Testing._ https://www.isacybersecurity.com/contact-us/ and https://www.isacybersecurity.com/assessment-assurance/penetration-testing/. The Ottawa, Toronto, Calgary and London office addresses and the Assessments and Assurance service grouping.

  6. CyberHunter Cyber Security. _Contact_ and _Penetration Testing._ https://cyberhunter.solutions/contact/ and https://cyberhunter.solutions/pen-testing/. The Ottawa, Toronto and New York office addresses and the named penetration testing service pages.

  7. Convergence Networks. _Ottawa Penetration Testing Services._ https://convergencenetworks.com/areas/ottawa-penetration-testing/. The Ottawa office address published on the service page.

  8. Solana Networks. _Contact_ and _IT Security._ https://www.solananetworks.com/contact and https://www.solananetworks.com/services/it-security. The Nepean address and the SCADA, critical infrastructure and public sector service descriptions.

  9. Stingrai. _The State of Penetration Testing 2026._ https://www.stingrai.io/blog/state-of-penetration-testing-2026. 1,206 verified findings across 55 penetration tests, the 92.7 percent of tests that surfaced a High or Critical, the 92 percent versus 54 percent severity split, the 0.74 percent false-positive rate and the 10.5 day median Critical fix.

  10. Stingrai. _Average Cost of a Pentest in Canada 2026._ https://www.stingrai.io/blog/average-cost-of-pentest-canada-2026. CAD scope bands by engagement type.

  11. Stingrai. _Pricing._ https://www.stingrai.io/pricing. Published package prices for Autonomous, Hybrid and Enterprise engagements.



Ready to scope an Ottawa penetration test?

ITSG-33 asks you to show that technical controls are implemented and effective, the Protected B cloud profile asks for two assessments rather than one, and your Security Requirements Check List decides who is allowed to do the work. Stingrai is a Canadian, CREST-accredited penetration testing service provider that covers internal and external scopes in one engagement, includes retesting, works Ottawa hours, and publishes its prices. Book a Free Scoping Call, Get a Quote, or see pricing.

0 views

0

X

Related reading

Best Healthcare Penetration Testing Companies (2026): HIPAA, HITRUST and Medical Device Testing Compared
Web App SecurityNetwork Security

Best Healthcare Penetration Testing Companies (2026): HIPAA, HITRUST and Medical Device Testing Compared

Best healthcare penetration testing companies in 2026, ranked, with what HIPAA, HITRUST and FDA 524B really require of a pentest.

20 min read

Best BreachLock Alternatives (2026): PTaaS Platforms Compared on Testers, Evidence and Pricing
Web App SecurityNetwork Security

Best BreachLock Alternatives (2026): PTaaS Platforms Compared on Testers, Evidence and Pricing

Compare 8 BreachLock alternatives for 2026 on who tests, what the AI does, retest terms and published pricing, plus BreachLock vs Cobalt and Astra.

13 min read

Best Bugcrowd Alternatives for Penetration Testing (2026): Pentest as a Service vs Crowdsourced
Web App SecurityNetwork Security

Best Bugcrowd Alternatives for Penetration Testing (2026): Pentest as a Service vs Crowdsourced

Compare 8 Bugcrowd alternatives for penetration testing in 2026 on delivery model, compliance fit and published pricing, plus where Bugcrowd still wins.

14 min read

Contents

X