main logo icon

Published on

September 5, 2026

|

18 min read

Top Penetration Testing Companies in Vancouver (2026)

The penetration testing companies serving Vancouver and British Columbia in 2026, ranked for SaaS, public sector and credit union buyers. Compare verified BC presence, BC PIPA and FIPPA fit, BCFSA expectations and CAD pricing from CA$5,000.

Arafat Afzalzada

Arafat Afzalzada

Founder

Web App SecurityNetwork Security

Summarize with AI

ChatGPTPerplexityGeminiGrokClaude

TL;DR

The penetration testing companies we recommend for Vancouver buyers in 2026 are Stingrai, Forward Security, Mirai Security, Kobalt.io, Plurilock Security and Brockton Point Solutions. Stingrai leads the ranking: a CREST-accredited penetration testing service provider at the firm level, rated 5.0 out of 5.0 across 19 Clutch reviews, running Snipe, an autonomous AI agent for web application penetration testing that works alongside human penetration testers, with retesting included in every engagement and package pricing published openly. It serves British Columbia clients remotely from its Toronto headquarters, on both one-time annual tests and continuous programs. The five BC-based firms below all appear in the Province of British Columbia's 2025 cybersecurity company directory with penetration testing among their listed services. Forward Security (Vancouver, 2018) is the application and cloud security specialist. Mirai Security (Vancouver, 2017) covers web, mobile, network and physical testing alongside compliance work. Kobalt.io (Vancouver, 2018) runs whole security programs for cloud-native companies. Plurilock Security (Vancouver, 2016) is a publicly traded firm with an offensive security services arm. Brockton Point Solutions (Langley, 2022) adds Web3 and smart contract review. Three local rules drive most BC buying. BC PIPA section 34 requires reasonable security arrangements for personal information. FIPPA has required public bodies to run a privacy management program and report significant-harm breaches since February 1, 2023. BCFSA's Information Security Guideline, in effect July 1, 2025, sets testing expectations for BC credit unions, insurance companies and trust companies. A penetration test in BC typically runs CA$5,000 to CA$120,000 depending on scope. Stingrai publishes fixed USD prices from US$3,000 one-time or US$450 per month for one web application and its APIs.

The penetration testing companies we recommend for Vancouver buyers in 2026 are Stingrai, Forward Security, Mirai Security, Kobalt.io, Plurilock Security and Brockton Point Solutions. Stingrai ranks first: it is a CREST-accredited penetration testing service provider at the firm level, rated 5.0 out of 5.0 across 19 Clutch reviews, and it runs Snipe, an autonomous AI agent for web application penetration testing that works alongside its certified human penetration testers on every engagement. The five BC-based firms behind it all carry penetration testing in the Province of British Columbia's own 2025 cybersecurity company directory, which is the cleanest way to verify that a Vancouver provider is real before you shortlist it.

The average Canadian data breach reached CA$6.98 million in 2025, up 10.4 percent from CA$6.32 million the year before, even as the global average fell, according to IBM's Cost of a Data Breach Report, Canada release. Canada is the exception to the global cost decline, and British Columbia buys testing into that headwind with three provincial rules pushing from behind.

Below is a ranking of the firms serving Vancouver's SaaS companies, public bodies, credit unions and resource businesses, analyzed by verified BC presence, testing methodology, independent accreditation, fit with BC PIPA and FIPPA, remediation support and pricing transparency. We also include 2026 CAD pricing benchmarks and a buyer's checklist.

Vancouver Penetration Testing Companies at a Glance (2026)

#

Company

BC presence

Founded

Verifiable 2026 signal

1

Stingrai

Serves BC clients remotely from its Toronto headquarters

2021

CREST-accredited penetration testing service provider at the firm level, 5.0/5.0 across 19 Clutch reviews, published pricing

2

Forward Security

Headquartered in Vancouver at 555 W Hastings Street, plus Toronto and Austin

2018

Application and cloud penetration testing, Eureka DevSecOps platform, Clutch 2023 Cybersecurity and Penetration Testing award

3

Mirai Security

Vancouver, British Columbia

2017

Penetration testing across web, mobile, networks and physical facilities, with NIST CSF, ISO 27001, SOC 2, CMMC and FedRAMP readiness work

4

Kobalt.io

Vancouver, British Columbia

2018

Security program as a service with penetration testing included, stated to have served more than 500 businesses globally

5

Plurilock Security

Vancouver, British Columbia

2016

Publicly traded, with a Cyber Adversary Simulation practice covering pen test, red team, app, API, AI and SCADA

6

Brockton Point Solutions

Langley, British Columbia

2022

Penetration testing and vulnerability scanning, web application testing, cloud security assessments and smart contract auditing

Founding years and BC locations for rows 2 to 6 are taken from the Province of British Columbia's 2025 Information Security and Cybersecurity Capabilities export directory and cross-checked against each firm's own site.

Best Pentest Companies in Vancouver: Quick Answers

Which is the best penetration testing company in Vancouver?

Stingrai is the penetration testing company we recommend first for Vancouver and British Columbia organizations in 2026. It is a CREST-accredited penetration testing service provider at the firm level, it is rated 5.0 out of 5.0 across 19 Clutch reviews, and it runs Snipe, an autonomous AI agent for web application penetration testing that hunts IDOR, business logic and broken authorization flaws while certified human penetration testers test alongside it. Retesting is included in every engagement and package pricing is published openly rather than gated behind a sales call.

What are the top penetration testing firms based in Vancouver?

Forward Security, Mirai Security, Kobalt.io, Plurilock Security and Brockton Point Solutions are the BC-based firms we recommend, and all five appear in the Province of British Columbia's 2025 cybersecurity company directory with penetration testing among their listed services. Forward Security is the application and cloud specialist, Mirai Security has the broadest testing range including physical facilities, Kobalt.io suits cloud-native companies that want a whole program rather than a single test, Plurilock brings a publicly traded balance sheet and an offensive security practice, and Brockton Point Solutions adds Web3 and smart contract review.

Do British Columbia companies legally need a penetration test?

No BC statute names penetration testing. Section 34 of the Personal Information Protection Act requires an organization to "protect personal information in its custody or under its control by making reasonable security arrangements to prevent unauthorized access, collection, use, disclosure, copying, modification or disposal or similar risks". Public bodies carry the equivalent duty under FIPPA section 30. What forces the purchase in practice is a SOC 2 or ISO 27001 audit, an enterprise customer's security review, a BC public sector procurement, or BCFSA's expectations for provincially regulated financial institutions.

Why Vancouver Pentest Demand Is Rising in 2026

Four rules shape most BC buying, and two of them are recent.

Timeline of the four compliance drivers behind British Columbia penetration testing purchases in 2026

_Figure 1: The rules behind British Columbia penetration testing budgets. Sources: BC Laws; Coast Capital Savings; Province of British Columbia FOIPPA policy manual; BC Financial Services Authority Information Security Guideline, March 2025._

BC PIPA sets the private sector floor

British Columbia is one of three provinces with private sector privacy legislation deemed substantially similar to PIPEDA, so most BC companies answer to PIPA rather than to the federal statute. PIPA was assented to on October 23, 2003 and has been in force since January 1, 2004. Section 34 is the operative security duty, and it is short: reasonable security arrangements, proportionate to the information.

"Reasonable" is doing the work in that sentence. The Office of the Information and Privacy Commissioner for BC assesses it after the fact, against what a comparable organization would have done. A documented penetration test, with reproduction steps, severity ratings and evidence that findings were fixed and verified, is the standard way an organization shows the arrangements were more than a policy document.

FIPPA changed what public bodies have to do

BC's public sector statute moved first. Since February 1, 2023, the head of a public body must maintain a privacy management program in line with the Minister's direction, and must notify both the affected individual and the Information and Privacy Commissioner, without unreasonable delay, of any privacy breach that could reasonably be expected to result in significant harm.

The underlying security duty sits in section 30. The Province's own FOIPPA policy manual states it plainly: "A public body must protect personal information in its custody or under its control by making reasonable security arrangements against such risks as unauthorized access, collection, use, disclosure or disposal."

This matters far beyond government offices. FIPPA covers health authorities, school districts, post-secondary institutions, municipalities, Crown corporations and the vendors that hold their data. If you sell software to any of them, their obligation becomes a clause in your contract.

Selling to the BC public sector means an STRA

The Province requires a Security Threat and Risk Assessment for information systems, and its STRA standard applies to "all government organizations (ministries, public agencies, boards, and commissions), service providers, and any other entity managing the Government of British Columbia's information". An STRA must be conducted during planning, development and implementation, and refreshed for significant changes.

The standard does not name penetration testing. What it does is create a moment in every BC public sector procurement where somebody has to document the technical risk in your system and propose a treatment for each item. A current third-party test report is the fastest way to answer that, and the absence of one is the most common reason a BC public sector deal stalls in security review.

BCFSA raised the bar for BC financial institutions

British Columbia supervises its own credit unions, insurance companies and trust companies through the BC Financial Services Authority. BCFSA published a new Information Security Guideline in March 2025, which replaced the October 2021 version and came into effect on July 1, 2025. It applies to provincially regulated financial institutions, which the guideline defines as BC incorporated credit unions, insurance companies and trust companies.

The guideline does not name penetration testing either. It sets an expectation one level up, requiring PRFIs to "establish and implement a testing process that validates the robustness and effectiveness of the security measures and ensures that the testing framework is adapted to consider new threats and vulnerabilities identified through risk-monitoring activities", and to ensure "that tests are conducted in the event of changes to infrastructure, processes, or procedures and if changes are made in response to material security incidents". Read that as a purchasing specification and it describes an annual test plus a change-triggered one.

Not every BC credit union answers to BCFSA. Coast Capital Savings, the largest credit union in Canada by membership, continued federally on November 1, 2018 and is now supervised by the Office of the Superintendent of Financial Institutions under the Bank Act, where Guideline B-13 sets expectations that include penetration testing and red teaming. Which regulator you answer to changes the evidence you need, so confirm it before you scope.

What testing actually finds

Stingrai's State of Penetration Testing 2026 report analyzed 1,206 verified findings across 55 penetration tests. 51 of the 55 tests, or 92.7%, surfaced at least one High or Critical finding. Severity depended heavily on what was tested: 92% of internal network findings were High or Critical, against 54% for web application testing. Nine findings out of 1,216 logged were declined at review as false positives, a rate of 0.74%.

For a BC buyer, the second number is the useful one. Organizations that only ever test the public web application are leaving the higher-severity half of the estate unexamined, and internal network testing is exactly the scope that a credit union's or a health authority's risk assessment will point at.

Quick Comparison: Best Pentest Firms in Vancouver

Company

Best for

Methodology

Key differentiators

1. Stingrai

BC SaaS, health technology and financial buyers who need audit-ready evidence from a CREST-accredited firm, on a one-time annual test or a continuous program

Human penetration testers working alongside the Snipe AI agent

Firm-level CREST accreditation, 5.0/5.0 across 19 Clutch reviews, retesting included in every engagement, published pricing, Jira, GitHub and Slack integrations

2. Forward Security

Application and cloud security for midsized BC technology, finance and health companies

Application security assessment, code security and DevSecOps tooling

Vancouver headquarters, Eureka DevSecOps platform, blockchain and IoT practices, Clutch 2023 Cybersecurity and Penetration Testing award

3. Mirai Security

BC organizations that need testing and compliance readiness from one advisor

Business-first assessment across web, mobile, network and physical scopes

Broadest testing range of the BC-based firms, plus NIST CSF, ISO 27001, SOC 2, CMMC and FedRAMP readiness

4. Kobalt.io

Cloud-native BC scale-ups that want a security program, not a single test

Named security program lead backed by a shared expert team

Security program as a service, vCISO and data protection officer support, penetration testing included in the catalogue

5. Plurilock Security

BC public sector and enterprise buyers who want a publicly traded supplier

Cyber adversary simulation delivered by a dedicated services team

Pen test, red team, tabletop, social engineering, and app, API, AI and SCADA coverage; broad Canadian delivery footprint

6. Brockton Point Solutions

Metro Vancouver companies pairing compliance readiness with Web3 exposure

Assessment and testing alongside governance and vCISO work

Web application penetration testing, cloud security assessments, smart contract and DApp auditing, CrowdStrike partnership


How We Ranked These Companies

Every firm in this guide had to clear three eligibility gates. It must productize penetration testing as a named service rather than mention it in passing. It must have a verifiable British Columbia presence, meaning a BC headquarters, a published BC office, or a stated ability to deliver to BC buyers. And its core claims must be verifiable on its own website or in a public registry.

Ranking then weighed six criteria:

  1. Verified BC presence, confirmed from the firm's own site and the Province of British Columbia's own 2025 cybersecurity company directory rather than a marketing listing.

  2. Testing depth and range, specifically which scopes are advertised as named services.

  3. Independent accreditation and tester credentials on the people who run the engagement, weighted above logo walls.

  4. Fit with BC PIPA, FIPPA and BCFSA expectations, including whether the firm covers internal as well as external scopes.

  5. Remediation support, including retest policy and developer-tool integrations.

  6. Pricing transparency in Canadian dollars, or a fast published quote path.

Vendor facts in this guide, including locations, founding years and service scopes, were verified in September 2026 against each provider's own website or the provincial directory. Claims that could not be reached on at least one verification pass against a named primary source were dropped rather than estimated.

Several firms that appear on other Vancouver lists are not ranked here. Some are headquartered elsewhere and are listed separately below. Others are BC-based but do not productize penetration testing as a named service, which the category test does not allow, however good the firm is at what it does do.


1. Stingrai (Top Rated for BC Buyers)

Stingrai is ranked the best penetration testing company for Vancouver and British Columbia buyers in 2026 for organizations that need testing evidence a SOC 2 auditor, a BC public sector security reviewer or a BCFSA-supervised board will accept. Founded in 2021 and headquartered in Toronto, with a London, UK office, it serves BC clients remotely on both one-time annual engagements and continuous PTaaS programs.

The thing that separates Stingrai from a conventional consultancy is how the engagement is staffed. Snipe, Stingrai's autonomous AI agent for web application penetration testing, runs throughout the test alongside certified human penetration testers rather than before or after them. Snipe is built to hunt the classes that generic AI tooling misses: IDOR, business logic flaws and broken authorization. It is custom-trained on more than 6,000 HackerOne Hacktivity disclosure reports plus skills distilled from years of Stingrai's own testers' methodology. It performs black-box dynamic testing and white-box source review, generates AutoFix pull requests for what it finds, and can run as a pull-request gating check that blocks vulnerable code from merging. The human testers direct where Snipe looks, extend the attack paths it opens, and pursue what it surfaces, and both contribute findings across every severity.

The three-hour time difference from Toronto is worth naming. Stingrai's team overlaps with a Vancouver working day from roughly mid-morning Pacific onward, and kickoff calls, daily check-ins and debriefs are scheduled around that rather than assuming Eastern hours.

At a Glance

Signal

Detail

Headquarters

Toronto, Canada, plus a London, UK office. Serves British Columbia clients remotely.

Founded

2021

Accreditation

Stingrai Inc is a CREST-accredited Penetration Testing service provider. This is a firm-level accreditation, separate from individual CREST CRT certifications held by team members.

Reputation

19 five-star reviews on Clutch, 5.0/5.0 overall

Research record

18 published CVEs; research presented at DEFCON and BSides

Methodology

Certified human penetration testers working alongside the Snipe AI agent, on annual one-time tests and continuous programs

Retesting

Included in every engagement

Integrations

Jira, GitHub, Slack

Compliance support

Penetration testing evidence supporting SOC 2, ISO 27001, HIPAA, PCI DSS 4.0 and NIST SP 800-53 / 800-171 programs, and internal plus external testing scoped for BC PIPA and FIPPA reasonable-security expectations

Pricing

Published openly at stingrai.io/pricing

Why Stingrai Ranks First for Vancouver

  • Data stays in Canada, and the tester is Canadian. For a BC public body or a health authority vendor, a Canadian-incorporated provider removes a whole section of the security questionnaire before it is asked.

  • Both sides of the boundary in one engagement. Internal and external network testing alongside web application testing means one report covers the scope that a BCFSA-supervised risk assessment or a FIPPA privacy management program will point at.

  • Firm-level CREST accreditation. An auditor asking whether the tester was qualified gets a registry-backed answer, not a resume. Very few Canadian-headquartered firms hold it.

  • Snipe hunts the bugs that leak BC personal information. Broken authorization, IDOR and business logic flaws in customer-facing applications are the defects behind most reportable privacy breaches, and they are what Snipe was purpose-built to find.

  • Annual and continuous, not one or the other. A BC scale-up that needs one clean report before an enterprise deal can buy a single scoped engagement. A company shipping weekly can run a continuous program. Both are standard.

  • Retesting is included. Fixes get verified inside the same engagement rather than becoming a separate purchase order, which matters when a privacy commissioner or an auditor wants remediation evidence and not just a finding list.

  • Published pricing. Package prices sit on the pricing page instead of behind a discovery call, which shortens procurement against an audit date.

Pros

  • Every finding is manually validated, so the report that reaches your auditor does not carry scanner noise.

  • Retesting is included in every engagement rather than sold separately.

  • Findings push directly into Jira, GitHub and Slack, so remediation happens where developers already work.

  • Package pricing is transparent, which makes budget approval faster at an organization without a dedicated security hire.

Cons

  • No Vancouver office, so buyers who need testers physically on site for a facility walk-through or on-site social engineering should raise travel during scoping.

  • Newer brand than the national accounting firms, which matters to buyers who weigh name recognition over technical depth.

  • Package prices are published in US dollars, so a CAD budget needs a conversion at the current rate.

Best for: British Columbia SaaS, health technology, credit union and public sector supplier organizations that need internal and external testing from a CREST-accredited Canadian firm, delivered as either a one-time annual test or a continuous program.

Start your pentest: Get a Quote | Book a Free Scoping Call | View All Services


2. Forward Security

**Forward Security Inc.** states on its contact page that it is "headquartered in beautiful Vancouver, Canada with reach across North America", at 555 W Hastings Street, Suite 1200, with additional offices in Toronto and Austin. The Province of British Columbia's directory records the company as Vancouver based and established in 2018.

It is the closest thing Vancouver has to a dedicated application security practice. Named services include penetration testing for application and cloud, application security risk assessment, code security and vulnerable dependency analysis, security design review and threat modelling, AI security services, blockchain and smart contract security, and IoT security risk assessment. It also sells Eureka, its own DevSecOps platform, which is listed separately in the provincial directory as a product.

The provincial directory records that the firm won a Clutch 2023 Cybersecurity and Penetration Testing award, was accepted into the Microsoft for Startups Founders Hub in 2023, and was named Most Promising Canada Tech Services Company in 2022. Its leadership team includes the lead of OWASP's Vancouver chapter.

Pros

  • Genuine Vancouver headquarters. Not a satellite office, which matters for on-site work and for buyers who want a local supplier on the invoice.

  • Application security depth. Threat modelling, design review and dependency analysis alongside testing means the engagement can reach design defects, not just implementation bugs.

  • A published AI security practice. Relevant for the BC companies wiring language models into product workflows.

  • DevSecOps tooling of its own. Eureka gives development teams somewhere for findings to live after the report.

Cons

  • Application and cloud focus. Internal network, Active Directory and physical scopes are not the practice's centre of gravity, so a BCFSA-driven full-estate scope will need a conversation.

  • No published firm-level accreditation. Credentials sit with individuals rather than in a public registry such as the CREST Marketplace.

  • No published pricing. Expect a scoping call before a number.

Best for: Vancouver technology, finance and health companies that want deep application and cloud security work from a locally headquartered specialist.


3. Mirai Security

**Mirai Security Inc.** is a Vancouver cybersecurity services company recorded in the provincial directory as established in 2017. It describes a business-first approach that aligns security work to business objectives, and its published service list is the broadest of the BC-based firms in this ranking.

Testing covers web, mobile, networks and physical facilities, which is unusual among Vancouver providers; physical facility testing in particular is scarce locally. Around it sit compliance support and readiness for NIST CSF, ISO 27001, SOC 2, CMMC and FedRAMP, cybersecurity strategy and architecture, cloud and application security, security awareness and human risk management, incident response and continuity planning, executive tabletop exercises, vendor risk management and vulnerability management. Published case studies include PayByPhone, the Vancouver-founded parking payments company.

The firm's stated industry focus tracks the BC economy rather than a generic technology list: healthcare, mining and manufacturing, logistics, technology, retail and hospitality, and finance and insurance.

Pros

  • The broadest local testing range. Web, mobile, network and physical facility testing under one supplier is rare in BC.

  • Compliance and testing in one relationship. Useful when the same project has to satisfy an auditor and a board.

  • Sector fit for BC. Mining, logistics and healthcare experience is directly relevant to the provincial economy.

  • Named executive leadership. The leadership page is public, which makes diligence straightforward.

Cons

  • Advisory-led delivery. The practice spans strategy, GRC and awareness, so tester seniority on any given engagement varies more than at a testing-only shop. Ask for tester bios.

  • No published firm-level accreditation. Credentials are not held in a public testing registry.

  • No published pricing. Scoping runs through a consulting motion.

Best for: BC organizations, particularly in healthcare, mining, logistics and financial services, that want testing and compliance readiness from a single Vancouver advisor.


4. Kobalt.io

**Kobalt.io** describes itself as "created in Vancouver, available worldwide" and is recorded in the provincial directory as Vancouver based and established in 2018. Its model is different from the others here: rather than selling assessments, it manages whole cybersecurity programs for small and medium cloud-native businesses, assigning a named security program lead backed by a shared team of specialists.

Penetration testing is one named service inside that catalogue, alongside security gap assessment, managed threat detection, vulnerability scanning and management, vCISO and data protection officer support, incident response planning and tabletop exercises, security awareness training with phishing simulations, and compliance and audit support across SOC 2, ISO 27001, CMMC, NIST, FedRAMP, GDPR, CCPA and CPRA, PIPEDA, HIPAA, HITRUST, PCI DSS and Quebec's Law 25. The provincial directory states the firm has served more than 500 businesses globally and that it is trusted by the National Research Council of Canada's Industrial Research Assistance Program to provide cybersecurity consultation to high-technology businesses.

Pros

  • Program, not project. A BC scale-up without a security hire gets an owner, not a PDF.

  • Compliance breadth in one place. The framework list covers almost every certification a BC SaaS company will be asked for, including Law 25 for Quebec customers.

  • Named program lead. Continuity across engagements is contractual rather than accidental.

  • Strong local track record. The NRC-IRAP relationship and the volume of served businesses are both recorded in the provincial directory.

Cons

  • Testing is one line in a broad catalogue. If you want deep offensive work rather than a well-run program, a specialist will go further.

  • Subscription-shaped commercial model. Buyers who only need one annual test may find the program framing heavier than necessary.

  • No published firm-level testing accreditation.

Best for: Cloud-native BC companies that need a managed security and compliance program with penetration testing built into it, rather than a standalone assessment.


5. Plurilock Security

**Plurilock Security Inc.** is recorded in the provincial directory as Vancouver based and established in 2016, and it is the only publicly traded company in this ranking. Its services navigation leads with Cyber Adversary Simulation Services, listing pen test, red team, tabletop, ransomware and social engineering, and application, API, AI and SCADA coverage. The provincial directory records penetration testing and offensive security among its products and services, delivered through what the company calls Plurilock Critical Services.

Around the offensive practice sit zero trust, data protection, identity and access management, public key infrastructure, cloud transformation, managed services, enterprise networking and technology risk management, plus a solution sales arm for both Canada and the United States. The company lists coverage across most Canadian metropolitan areas, including Vancouver and Victoria.

For BC public sector and larger enterprise buyers, the argument is procedural rather than technical: a listed company files public financials, which some procurement processes require, and the breadth of the catalogue means testing can be bought on the same paper as the rest of the security stack.

Pros

  • Public company disclosure. Financial statements are public, which satisfies supplier-viability checks in public sector procurement.

  • SCADA and OT in the advertised scope. Directly relevant to BC's utilities, ports and resource operators.

  • AI and API testing named explicitly. The scope list has kept pace with what BC products actually look like.

  • Broad Canadian coverage. Useful for organizations with sites outside the Lower Mainland.

Cons

  • Testing sits inside a much larger solutions business. The company also resells and integrates third-party security products, so confirm you are buying the services team and not a product bundle.

  • No published firm-level testing accreditation.

  • No published pricing. Engagements are quoted.

Best for: BC public sector, utility and enterprise buyers who want adversary simulation from a publicly traded Canadian supplier with a broad security catalogue.


6. Brockton Point Solutions

**Brockton Point Solutions** is recorded in the provincial directory as based in Langley, British Columbia and established in 2022, and the directory describes it as a Vancouver-based cybersecurity firm with over thirty years of combined expertise across the team. Its own site states experience "in governance, compliance, penetration testing, and strategic security leadership".

Named services include penetration testing and vulnerability scanning, web application penetration testing, cloud security assessments across AWS, Azure, GCP and SaaS, readiness assessments, governance and compliance, vCISO leadership, policy development, and security awareness training. The distinctive line is Web3: smart contract auditing and decentralized application protection sit in the published service list, which is rare for a Metro Vancouver firm and relevant given the region's blockchain company population. The firm is also a CrowdStrike partner.

Pros

  • Web3 and smart contract review. A named practice, not an afterthought, and locally available.

  • Compliance readiness alongside testing. Useful for a small BC company facing its first SOC 2 or customer security review.

  • Metro Vancouver base. Langley is inside the region, so on-site work does not carry travel.

Cons

  • The youngest firm in this ranking. Established in 2022, with a correspondingly short public track record.

  • Small team. Capacity and lead times need checking against your audit date.

  • No published firm-level accreditation or pricing.

Best for: Metro Vancouver small and mid-sized companies, especially those with Web3 exposure, that want testing and compliance readiness from a local firm.


Other BC-Based Providers

These firms are British Columbia based and appear in the provincial directory or publish from a BC address, but they are not ranked above, either because penetration testing is not a named service in their primary catalogue or because their centre of gravity is elsewhere. Several are excellent at what they do.

Firm

BC location

Founded

Where it fits

CyberClan

Vancouver, plus Victoria and Montreal

2006

Incident response and managed security led. Penetration testing is offered but sits outside the main service navigation

Safe Harbour Informatics

Vancouver

2008

First Nations owned. Managed security, vCISO and AI automation, with penetration testing and vulnerability assessments listed

Securicom Solutions

Vancouver

2001

Industrial and operational technology security, intrusion detection and secure remote access for critical infrastructure

Carmel Info-Risk Consulting Group

Vancouver

2013

Security threat and risk assessments, strategy and governance for small and medium enterprises

PrecisionSec

Victoria

2020

Threat intelligence feeds and enrichment for MSSPs and financial services, not assessment work

National and Global Firms Vancouver Buyers Shortlist

Penetration testing is delivered remotely, so a BC buyer's shortlist is rarely limited to BC suppliers. These firms are credible on the right scope and deliver into Vancouver, though none is headquartered in British Columbia. They are listed alphabetically, not ranked.

Firm

Headquarters

Where it fits

Bulletproof, a GLI company

Fredericton, NB, with a Vancouver office

Gaming and lottery compliance heritage, national footprint, infrastructure and application testing

Cycura (WELL Health)

Toronto, ON

Offensive security inside a health technology parent, relevant to BC health data workloads

Deloitte, EY, KPMG and PwC

Vancouver offices of the Canadian firms

Board-level programs where testing is one workstream in an audit or transformation contract

ISA Cybersecurity

Toronto, ON

Internal, external, wireless, mobile and web application testing plus red and purple teaming

Kroll

New York, NY

Acquired Security Compass Advisory in December 2021; pairs testing with incident response and forensics

Packetlabs

Mississauga, ON

Firm-level CREST accredited, manual-heavy methodology, Canadian delivery

Software Secured

Ottawa, ON

Penetration testing as a service for SaaS companies on a subscription model

Vumetric

Quebec City, QC

Independent Canadian testing specialist with published methodology


What BC Public Sector and Regulated Buyers Should Put in the Statement of Work

Reading BC PIPA, FIPPA and the BCFSA guideline together produces a short, concrete checklist.

  1. Cover both directions. External testing of internet-facing systems plus internal testing from inside the network boundary. A perimeter-only scope leaves the higher-severity half of the estate unexamined.

  2. Document tester qualification. Firm-level accreditation such as CREST, plus named individual certifications such as OSCP, OSWE and CREST CRT on the assigned testers, is the cleanest way to evidence competence to a commissioner or an examiner.

  3. State where data lives. For FIPPA-covered work, the location of report data, findings and any exported evidence is a contract term, not a detail. Ask before kickoff.

  4. Run it at least annually, and again after material change. The BCFSA guideline specifically expects tests when infrastructure, processes or procedures change, or after a material incident.

  5. Prioritize and remediate on a documented timeline. Severity ratings without owners and dates do not survive a privacy review.

  6. Retest and record the outcome. A commissioner asking about last year's Critical finding wants evidence it was fixed and verified.

  7. Keep the artifacts. Scope documents, methodology, findings with reproduction steps, severity ratings, remediation status and retest results are the package that answers a BC question, and the package an STRA needs.

Buyers scoping this for the first time will find our guide to penetration testing versus vulnerability assessment useful, because BC's reasonable-security standard is satisfied by neither one alone.


How Much Does a Penetration Test Cost in Vancouver?

Your city does not change the price. Penetration testing is delivered remotely, so a Vancouver client's cloud environment is tested the same way a Toronto client's is, and the national CAD bands apply. The one genuine regional variable is on-site work: physical security assessments, on-site social engineering and internal network tests that require someone on the premises add travel and per diem, and that cost is a function of distance from the provider rather than of Vancouver's cost of living.

Range bar chart of typical 2026 penetration testing prices for Vancouver buyers in Canadian dollars by engagement type

_Figure 2: Typical 2026 price spans by engagement type in Canadian dollars. Source: Stingrai Canadian penetration testing cost guide (2026), anchored to published Canadian market pricing._

Vancouver Pentest Pricing Benchmarks (2026)

Engagement type

Entry scope

Standard scope

Complex scope

Web application

CA$5,000 to 12,000

CA$12,000 to 25,000

CA$25,000 to 40,000+

API

CA$8,000 to 15,000

CA$15,000 to 25,000

CA$25,000 to 40,000

Mobile (per platform)

CA$10,000 to 18,000

CA$18,000 to 30,000

CA$30,000 to 45,000

External network

CA$8,000 to 15,000

CA$15,000 to 35,000

CA$35,000 to 50,000+

Internal network

CA$12,000 to 20,000

CA$20,000 to 35,000

CA$35,000 to 50,000+

Active Directory

CA$15,000 to 25,000

CA$25,000 to 35,000

CA$35,000 to 50,000+

Cloud (IaaS and PaaS)

CA$13,000 to 25,000

CA$25,000 to 40,000

CA$40,000 to 65,000+

Red team

CA$30,000 to 45,000

CA$45,000 to 65,000

CA$65,000 to 80,000+

Annual continuous program

CA$40,000 to 60,000

CA$60,000 to 90,000

CA$90,000 to 120,000+

Stingrai publishes its package pricing openly on the pricing page: an Autonomous Pentest driven by Snipe starts at US$3,000 as a one-time engagement or US$450 per month on a continuous plan for one web application and its APIs, and a Hybrid Pentest that adds certified human penetration testers is US$6,800 one-time or US$1,275 per month, with Enterprise scoped on request. A fuller CAD breakdown by engagement type and scope driver sits in our guide to the average cost of a pentest in Canada, and current market rates by scope are tracked in the penetration testing price index.

Want a firm number for your scope? Get a free 24-hour quote from Stingrai. No sales-call gatekeeping required.


How to Choose a Penetration Testing Company in Vancouver

Whether you are a Yaletown SaaS company, a Fraser Valley manufacturer or a Lower Mainland health authority supplier, the same seven checks separate a useful engagement from an expensive PDF.

  1. Check firm-level accreditation, then check the people. CREST accreditation held by the firm answers the qualified-party question an auditor will ask. Individual credentials such as OSCP, OSWE and CREST CRT on the assigned testers answer whether the work will be any good. Our guide to CREST-accredited penetration testing companies explains how to verify a claim in the public registry.

  2. Verify the BC presence yourself. The Province publishes a cybersecurity company directory with locations and founding years. A provider that is genuinely BC based will be easy to confirm; one that only runs a "Vancouver" landing page will not.

  3. Scope both sides of the boundary. If your risk assessment covers an internal network, an external-only test will not answer it, and internal findings skew far more severe.

  4. Insist on manual validation. Automated scanners miss business logic flaws, IDOR and chained exploits, which are the defects behind most reportable privacy breaches. Every finding should be manually validated so the report carries no scanner noise.

  5. Confirm the retest policy in writing. Ask whether retesting is included in the fee, how long the window is, and whether the retest result appears in a document you can hand a commissioner or an auditor. Stingrai includes retesting in every engagement.

  6. Check developer integration. Findings that land in Jira, GitHub and Slack get fixed faster than findings that live in a PDF attachment.

  7. Verify reputation independently. Look for a 4.9 or higher rating across fifteen or more reviews on a platform that verifies the reviewer, such as Clutch. Stingrai holds 5.0 out of 5.0 across 19 reviews.


Service Coverage and Capabilities

When evaluating a Vancouver vendor, confirm they cover the specific testing services your estate requires.

Core penetration testing services

Compliance-driven assessments

  • **SOC 2 Penetration Testing**: the standard evidence North American auditors expect for SOC 2 Type II.

  • **PCI DSS 4.0 Penetration Testing**: required under Requirement 11.4 for merchants and service providers.

  • BC PIPA and FIPPA support: internal and external testing with reproduction steps and retest evidence, scoped to reasonable-security expectations.

Advanced offensive security


More provider guides

Frequently Asked Questions

Who is the best penetration testing company in Vancouver in 2026?

Stingrai is our first recommendation for Vancouver and British Columbia buyers in 2026. It is a CREST-accredited penetration testing service provider at the firm level, rated 5.0 out of 5.0 across 19 Clutch reviews, and it runs Snipe, an autonomous AI agent for web application penetration testing that works alongside certified human penetration testers throughout the engagement. Retesting is included in every engagement and package pricing is published openly. Among BC-based firms, Forward Security, Mirai Security, Kobalt.io, Plurilock Security and Brockton Point Solutions are the strongest alternatives depending on whether you need application depth, testing range, a managed program, a publicly traded supplier or Web3 coverage.

Which penetration testing companies are actually headquartered in Vancouver?

Forward Security, Mirai Security, Kobalt.io, Plurilock Security, CyberClan and Safe Harbour Informatics are all recorded as Vancouver based in the Province of British Columbia's 2025 cybersecurity company directory, and Brockton Point Solutions is recorded in Langley. Of those, Forward Security, Mirai Security, Kobalt.io, Plurilock Security and Brockton Point Solutions carry penetration testing as a named service. Many firms that rank for "penetration testing Vancouver" are headquartered elsewhere and run a location landing page, so verify against the provincial directory or the firm's own contact page.

Does BC PIPA require a penetration test?

Not by name. Section 34 of the Personal Information Protection Act requires an organization to protect personal information in its custody or under its control by making reasonable security arrangements to prevent unauthorized access, collection, use, disclosure, copying, modification or disposal or similar risks. It is a reasonableness standard, assessed after the fact by the Office of the Information and Privacy Commissioner for BC. A documented penetration test with reproduction steps, severity ratings and verified remediation is the standard way an organization shows those arrangements were real.

What does FIPPA require of BC public bodies?

Section 30 of FIPPA requires a public body to protect personal information in its custody or under its control by making reasonable security arrangements against risks such as unauthorized access, collection, use, disclosure or disposal. Since February 1, 2023, the head of a public body must also maintain a privacy management program in line with the Minister's direction and must notify both the affected individual and the Information and Privacy Commissioner, without unreasonable delay, of a privacy breach that could reasonably be expected to result in significant harm. Vendors holding a public body's data inherit those expectations through contract.

Do BC credit unions have to run penetration tests?

BCFSA's Information Security Guideline, in effect since July 1, 2025, does not name penetration testing. It expects provincially regulated financial institutions, meaning BC incorporated credit unions, insurance companies and trust companies, to establish and implement a testing process that validates the robustness and effectiveness of security measures, adapted to new threats, and to run tests when infrastructure, processes or procedures change or after a material security incident. Federally continued credit unions are different: Coast Capital Savings became a federal credit union on November 1, 2018 and is supervised by OSFI, where Guideline B-13 sets expectations that include penetration testing and red teaming.

How much does a penetration test cost in Vancouver?

Roughly CA$5,000 to CA$120,000 in 2026, depending on scope. A small single-role web application runs CA$5,000 to CA$12,000, a standard multi-role SaaS application CA$12,000 to CA$25,000, a standard external network test CA$15,000 to CA$35,000, internal network testing CA$20,000 to CA$35,000 at standard scope, and an annual continuous program CA$60,000 to CA$90,000. Stingrai publishes fixed USD prices from US$3,000 one-time or US$450 per month for one web application and its APIs on its pricing page.

Is a penetration test more expensive in Vancouver than in Toronto?

Usually not. Testing is delivered remotely, so the same national bands apply across Toronto, Vancouver and Montreal. The genuine regional variable is on-site work: physical security assessments, on-site social engineering and internal network tests that require presence on the premises add travel and per diem, and that is a function of how far the provider has to come rather than of your city's cost of living.

Do I need a Vancouver based penetration tester?

Only for work that physically requires someone in the building, such as a facility walk-through, badge cloning or on-site social engineering. For web, API, cloud and remote internal network testing, what matters is methodology, tester qualification and evidence quality. Where location does matter for BC buyers is data residency: if you are a public body or a public body's vendor, ask where report data and exported evidence will be stored and get the answer in the contract.

How often should a BC company run a penetration test?

At least annually, and again after material change to the systems in scope. That cadence lines up with what a SOC 2 or ISO 27001 auditor expects, with BCFSA's change-triggered testing expectation, and with what an enterprise customer's security review will ask for. Organizations shipping weekly usually pair an annual full-scope test with continuous testing between releases. Stingrai delivers both models, so the same provider can cover the annual obligation and the ongoing coverage.

What do penetration tests actually find?

Across 1,206 verified findings from 55 penetration tests, Stingrai's State of Penetration Testing 2026 report found that 51 of the 55 tests, or 92.7%, surfaced at least one High or Critical finding. Severity depended heavily on scope: 92% of internal network findings were High or Critical, against 54% for web application testing. Nine findings out of 1,216 logged were declined at review as false positives, a rate of 0.74%.

What is the difference between a vulnerability scan and a penetration test?

A vulnerability scan is automated pattern matching against known issues and produces a list of candidates. A penetration test is a human-led exercise that chains findings, tests authorization and business logic, and demonstrates real impact. BC's reasonable-security standard is satisfied by neither alone: a scan without validation produces noise, and a test without ongoing scanning leaves a coverage gap between engagements.


References

  1. BC Laws. _Personal Information Protection Act, SBC 2003, c. 63._ https://www.bclaws.gov.bc.ca/civix/document/id/lc/statreg/03063_01. Section 34, the reasonable security arrangements duty, and the October 23, 2003 assent date.

  2. Province of British Columbia. _FOIPPA Policy and Procedures Manual, Protection of Personal Information._ https://www2.gov.bc.ca/gov/content/governments/services-for-government/policies-procedures/foippa-manual/protection-personal-information. Section 30 of FIPPA quoted in full.

  3. Province of British Columbia. _Guidance on Mandatory Privacy Breach Notifications._ https://www2.gov.bc.ca/gov/content/governments/services-for-government/information-management-technology/privacy/guidance-on-mandatory-privacy-breach-notifications. The February 1, 2023 privacy management program and breach notification obligations.

  4. Province of British Columbia. _6.11 Security Threat Risk Assessment Standard._ https://www2.gov.bc.ca/assets/gov/government/services-for-government-and-broader-public-sector/information-technology-services/standards-files/imit_611_security_threat_risk_assessment_standard.pdf. Scope covering government organizations, service providers and other entities managing BC government information.

  5. BC Financial Services Authority. _Information Security Guideline, March 2025._ https://www.bcfsa.ca/media/4042/download. In effect July 1, 2025, replacing the October 2021 version. Testing process and change-triggered testing expectations for provincially regulated financial institutions.

  6. Coast Capital Savings. _Coast Capital is the largest credit union in Canada to become a federal credit union._ October 30, 2018. https://www.coastcapitalsavings.com/about-us/press-room/news-releases/2018/20181030. Federal continuance effective November 1, 2018 and OSFI supervision under the Bank Act.

  7. Province of British Columbia. _Information Security and Cybersecurity Capabilities Export Directory, 2025._ https://www.britishcolumbia.ca/wp-content/uploads/RS3551_BC-2025Cybersecurity-CompanyDirectory-Web.pdf. Locations, founding years and service lists for Forward Security, Mirai Security, Kobalt.io, Plurilock Security, Brockton Point Solutions, CyberClan, Safe Harbour Informatics, Securicom Solutions, Carmel Info-Risk Consulting Group and PrecisionSec.

  8. IBM. _Cost of a Data Breach Report, Canada release._ July 30, 2025. https://canada.newsroom.ibm.com/2025-07-30-IBM-Report-Canadians-Data-Security-Under-Increased-Threat,-While-Breach-Costs-Surge. Average Canadian breach cost of CA$6.98 million, up 10.4 percent year over year.

  9. Forward Security. _Contact Us._ https://www.forwardsecurity.com/contact-us/. Vancouver headquarters at 555 W Hastings Street, Suite 1200, plus Toronto and Austin offices.

  10. Mirai Security. _Cybersecurity Services._ https://www.miraisecurity.com/services. Penetration testing among the published service lines.

  11. Kobalt.io. _Company website._ https://kobalt.io/. Penetration testing in the service catalogue and the "created in Vancouver" statement.

  12. Plurilock Security. _Services and Solutions._ https://plurilock.com/services/. Cyber Adversary Simulation Services covering pen test, red team, tabletop, social engineering and application, API, AI and SCADA scopes.

  13. Brockton Point Solutions. _Company website._ https://www.brocktonpointsolutions.com/. Stated experience in governance, compliance, penetration testing and strategic security leadership.

  14. Stingrai. _The State of Penetration Testing 2026._ https://www.stingrai.io/blog/state-of-penetration-testing-2026. Analysis of 1,206 verified findings across 55 penetration tests, including the 92.7% of tests that surfaced a High or Critical, the 92% versus 54% severity split by test type, and the 0.74% false-positive rate.

  15. Stingrai. _Average Cost of a Pentest in Canada 2026._ https://www.stingrai.io/blog/average-cost-of-pentest-canada-2026. CAD scope bands by engagement type and the regional pricing analysis.

  16. Stingrai. _Pricing._ https://www.stingrai.io/pricing. Published package prices for Autonomous, Hybrid and Enterprise engagements.



Ready to scope a Vancouver penetration test?

BC PIPA and FIPPA both ask for reasonable security arrangements, BCFSA expects a testing process that keeps pace with change, and your enterprise customers were already asking. Stingrai is a CREST-accredited Canadian penetration testing service provider that covers internal and external scopes in one engagement, includes retesting, and publishes its prices. Book a Free Scoping Call or Get a Quote.

0 views

0

X

Related reading

Best Healthcare Penetration Testing Companies (2026): HIPAA, HITRUST and Medical Device Testing Compared
Web App SecurityNetwork Security

Best Healthcare Penetration Testing Companies (2026): HIPAA, HITRUST and Medical Device Testing Compared

Best healthcare penetration testing companies in 2026, ranked, with what HIPAA, HITRUST and FDA 524B really require of a pentest.

20 min read

Best BreachLock Alternatives (2026): PTaaS Platforms Compared on Testers, Evidence and Pricing
Web App SecurityNetwork Security

Best BreachLock Alternatives (2026): PTaaS Platforms Compared on Testers, Evidence and Pricing

Compare 8 BreachLock alternatives for 2026 on who tests, what the AI does, retest terms and published pricing, plus BreachLock vs Cobalt and Astra.

13 min read

Best Bugcrowd Alternatives for Penetration Testing (2026): Pentest as a Service vs Crowdsourced
Web App SecurityNetwork Security

Best Bugcrowd Alternatives for Penetration Testing (2026): Pentest as a Service vs Crowdsourced

Compare 8 Bugcrowd alternatives for penetration testing in 2026 on delivery model, compliance fit and published pricing, plus where Bugcrowd still wins.

14 min read

Contents

X