Penetration testing firms in Canada
Firms in the HireACISO directory that do penetration testing work, ordered by tier and then alphabetically.
18 firms.
Penetration testing firms in Canada
TrazTech Inc. VerifiedOperates this site
The security and compliance practice that operates this directory. SOC 2 and ISO 27001 readiness, penetration testing, and fractional security leadership for Canadian companies selling into the United States.
3Tenets Consulting Unclaimed
Greater Toronto Area security and privacy consultancy offering governance and virtual CISO work, penetration testing and privacy assessments, aligning clients to frameworks including SOC 2. Not a CPA firm.
Cognisys Unclaimed
UK consultancy offering SOC 2 consulting to get clients audit ready in about four weeks, plus ISO 27001, ISO 42001, vCISO and penetration testing; it prepares clients for an independent auditor rather than signing the opinion.
Compass IT Compliance Unclaimed
Firm selling virtual CISO engagements staffed by veteran security professionals on a full or part-time basis, alongside compliance and testing services.
Digital Fort Unclaimed
Consultancy offering SOC 2, ISO 27001 and PCI DSS compliance readiness, fractional CISO services and penetration testing, and does not issue certificates.
GuardsArm Unclaimed
Security firm offering compliance readiness consulting for ISO 27001, SOC 2, HIPAA and PCI DSS alongside vCISO and monitoring services, and does not issue certificates.
IRM Consulting & Advisory Unclaimed
Consultancy offering ISO 27001 and ISO 42001 gap assessments and readiness work, fractional vCISO services and penetration testing, and does not issue certificates.
IS Partners Unclaimed
Describes itself as a CPA firm specializing in IT compliance that performs SOC 1, SOC 2 and SOC 3 audits, with ISO 27001, ISO 42001, penetration testing and virtual CISO services. Now part of Axiom GRC.
Kobalt.io Unclaimed
Vancouver security services firm combining penetration testing with SOC 2 and ISO 27001 readiness and virtual CISO support for growing technology companies.
Mirai Security Unclaimed
Vancouver consultancy offering a SOC 2 gap assessment against the Trust Services Criteria plus a virtual security office and other GRC work. Not a CPA firm and does not sign SOC 2 opinions.
Neotrust Unclaimed
French firm with a Montreal office listing CISO as a service within its security transformation practice, alongside testing and compliance work.
OmniCyber Security Unclaimed
Vancouver and Birmingham firm listing virtual CISO under its GRC practice, oriented to compliance program delivery alongside ISO 27001, ISO 42001 and testing work.
Sedara Security Unclaimed
US provider offering a virtual CISO service for security leadership and program resilience planning, alongside penetration testing.
Systemes Securitech Systems inc. Unclaimed
Montreal firm naming vCISO in its consulting services, delivered alongside SOC monitoring, penetration testing and incident response.
Tevora Unclaimed
Firm listing vCISO under resource augmentation, providing executive-level CISO assistance alongside compliance and testing work.
Truvo Cyber Unclaimed
Security consulting firm that builds ISO 27001 and SOC 2 programs and performs internal audits for clients ahead of third party certification, and does not issue certificates.
Uzado Inc. Unclaimed
Ontario provider offering a fractional vCISO covering security strategy, board reporting and audit ownership, alongside compliance and testing work.
Workstreet Unclaimed
Security and compliance services firm that prepares clients for the SOC 2 audit through gap analysis, implementation planning and observation period support, and guides them through the external audit rather than signing the opinion.
Get quotes instead of browsing
Describe what you need once and it reaches the firms on this page that match it.
Get quotesOther ways to narrow the list
Same directory, cut a different way.
- AI security firms in Canada, 5 firms
- Cloud compliance firms in Canada, 7 firms
- Compliance advisory firms in Canada, 54 firms
- ISO 27001 firms in Canada, 18 firms
- ISO 42001 firms in Canada, 9 firms
- Security questionnaires firms in Canada, 6 firms
- SOC 2 readiness firms in Canada, 17 firms
- Trust center firms in Canada, 6 firms
- vCISO firms in Canada, 60 firms
- Fractional CISO firms in British Columbia, 7 firms
- Fractional CISO firms in Ontario, 15 firms
- Fractional CISO firms in Quebec, 9 firms
How do I know I can trust one of these firms?
Judge the website the way you would judge a report they wrote for you, because it is the only sample of their work you get free. Look for past work in specifics, an address in every country they claim, writing that could only be about them, and named people doing the work. None is proof alone; two together is a reason to ask direct questions. The four checks in full.
How were these firms chosen?
They were listed from public information or added by the firm itself. Being listed is not a recommendation, and HireACISO does not rank firms by quality. Verified listings sit above free ones and the order inside each band is fixed.
Does it cost anything to get quotes?
No. Buyers are never charged. Firms can pay for a Verified listing, and higher-intent enquiries are offered to free listings for a fee, which is how the site is funded.
How many firms should I approach?
Three is the number that makes a quote comparable. One quote tells you a price, and two tell you which is cheaper. Three tells you what the work actually costs and which firm understood your scope.