Cybersecurity Services Pricing
Published starting prices across every penetration testing and compliance readiness engagement. Delivered by certified Canadian specialists with fixed scoping and complimentary retesting.
Engagement Starting Rates
Select between Penetration Testing and Compliance Readiness to view deliverables, timelines, and starting investments.
Under AICPA independence rules, the licensed CPA firm that issues your official SOC 2 attestation report cannot design, build, or implement your internal controls. Engaging an audit firm before your controls and evidence are in place simply risks audit failure or costly scope extensions. Lorikeet Security Canada operates as your dedicated readiness team: we scope your criteria, write the policies, coordinate evidence collection, and sit in on auditor fieldwork calls alongside your team. When you are audit-ready, we introduce you to trusted Canadian and US CPA audit firms (such as Prescient Assurance and MHM) for a seamless, predictable audit.
SOC 2 Readiness
Know exactly where you stand before your auditor walks in - control by control, with the evidence your CPA firm will ask for already filed.
- Gap Assessment Report mapped to Trust Services Criteria
- Control Mapping Spreadsheet with Owner and Status
- Evidence Collection Guide by Criterion
- Prioritised Remediation Roadmap
PIPEDA Readiness
A defensible privacy programme mapped to the ten Fair Information Principles, with a breach response process that actually meets the 24-month record-keeping requirement.
- PIPEDA Gap Assessment Mapped to the Ten Fair Information Principles
- Privacy Policy and Public-Facing Notice Review
- Breach Response Plan Aligned to the Breach of Security Safeguards Regulations
- Personal Information Inventory and Retention Schedule
HIPAA Readiness
Audit-ready compliance for Canadian digital health companies, SaaS vendors, and service providers handling protected health information.
- HIPAA Security & Privacy Gap Assessment Report
- Technical Safeguard Evaluation & Architecture Review
- Comprehensive Risk Analysis Document (NIST SP 800-30 aligned)
- Business Associate Agreement (BAA) Readiness Review
ISO 27001 Readiness
Build an ISMS that operates rather than a binder that satisfies - and arrive at Stage 1 with a real management system, not a document project.
- ISMS Scope Statement and Boundary Documentation
- Information Security Risk Assessment and Risk Register
- Statement of Applicability (all Annex A controls)
- Gap Assessment Report Mapped to ISO 27002:2022
GDPR Readiness
Lawful bases, a Record of Processing Activities, working data subject rights, and a 72-hour breach process - built before a regulator or customer asks for them.
- Data Mapping and Record of Processing Activities (RoPA)
- Lawful Basis Register for All Processing Activities
- Gap Assessment Report Mapped to GDPR Articles
- Transfer Impact Assessment and SCC Review
Quebec Law 25 Readiness Assessment
Achieve full compliance with Quebec's modernized private-sector privacy regime before CAI regulatory audits and severe statutory penalties.
- Law 25 Statutory Compliance Gap Assessment Report
- Privacy Impact Assessment (EFVP) Policy and Working Templates
- Cross-Border and Inter-Provincial Transfer Risk Assessment Matrix
- CAI-Compliant Confidentiality Incident Registry and Playbook
Alberta PIPA Readiness Assessment
Navigate Alberta's Personal Information Protection Act with practical compliance controls built for Alberta's enterprise, energy, and tech sectors.
- Alberta PIPA Statutory Gap Assessment Report
- OIPC Mandatory Breach Notification Protocol and RROSH Calculator
- Employee Personal Information (EPI) Workplace Governance Policy
- Cloud Service Provider and Out-of-Country Processing Notice Templates
| Readiness Framework | Starting At | Duration | Canadian Relevance | Action |
|---|---|---|---|---|
| $3,500 | 2-4 weeks | Many Canadian technology companies serving US enterprise customers are required to demonstrate ... | Scope → | |
| $6,500 | 1-3 weeks | PIPEDA is the federal private-sector privacy law and applies to virtually every Canadian busine... | Scope → | |
| $8,500 | 2-3 weeks | For Canadian health innovators based in Calgary, Toronto, or anywhere in Canada, handling US el... | Scope → | |
| $4,500 | 3-6 weeks | ISO 27001 is an international standard, and its geographic reach makes it the most common certi... | Scope → | |
| $7,500 | 2-4 weeks | Canadian companies with customers, employees, or partners in the EU or UK are subject to GDPR r... | Scope → | |
| $4,500 | 2-3 weeks | Law 25 carries Canada's highest statutory privacy penalties: administrative monetary penalties ... | Scope → | |
| $4,000 | 2-3 weeks | Alberta was the pioneer of mandatory privacy breach reporting in Canada. Under PIPA Section 34.... | Scope → |
How We Scope Your Engagement
No opaque estimates or multi-week discovery traps. We get you a confirmed flat-rate proposal in 3 simple steps.
Target Definition
We review your target assets (domains, IPs, cloud subscriptions, API specs, and roles) on a focused 20-minute scoping call.
Guaranteed Flat Rate
Within 24 to 48 hours, you receive a formal Statement of Work with a locked flat-rate quote, verified start date, and clear deliverables.
Execution & Free Retest
Testing is carried out by senior Canadian specialists. After remediation, your free retest validates the fixes for your audit.
Trusted by Fast-Growing Companies
Hear directly from organizations that rely on Lorikeet Security for rigorous testing and clear ROI.
We came to Lorikeet Security with not so small task of tracking down the source of a cyber incident. Lorikeet Security looked at attack vectors and they set up a full test environment and really showed they knew what they were doing. With amazing analytics reports on down to the minute of login attempts. The level of detail that Cyber Insurance Companies wish they had in house - Those reports are an invaluable tool and give confidence and value add to the executive level for pre or post ransomware attacks.
We used Lorikeet Security for a PTaaS pentest and briefly tried their ASM tool - both were amazing. Fast tests, accurate findings, and everything handled through a modern interface. The report summary, live chat, asset management, and live quoting features of the portal really stand out. Their 'white glove' touch contributed to a 10/10 experience. They're truly changing the pentest game with the new portal clients can use.
Pricing & Engagement Questions
Clear answers regarding payment, scoping, and Canadian tax handling.
Under AICPA professional standards and Canadian CPA independence rules, an accounting firm that issues an official SOC 2 attestation report is legally barred from designing, building, or implementing the internal controls it examines. The firm that builds your controls cannot audit them. Lorikeet Security Canada acts as your specialized readiness team - writing policies, implementing controls, and organizing evidence - before introducing you to independent accredited CPA audit firms (such as Prescient Assurance or MHM) to conduct the official audit.
The $3,500 CAD Gap Assessment is a rapid 1 to 2 week evaluation of your real environment against the Trust Services Criteria, delivering a detailed gap matrix and remediation roadmap. The $9,500 CAD Full Sprint includes end-to-end control design, custom policy writing, vendor risk reviews, evidence collection setup, and direct auditor coordination through fieldwork. Best of all, 100% of your Gap Assessment fee is credited toward the Full Sprint if you upgrade.
All engagements are billed as flat-rate contracts with transparent scoping in Canadian Dollars. Invoicing is handled locally with applicable provincial GST/HST, and your proposal is locked before work begins with zero unexpected hourly overages.
Yes. Every penetration test includes one complimentary retest round of all critical and high findings within 48 hours of your patch notification. Retesting validates that your fixes effectively resolve the vulnerabilities before we issue your final report and formal Letter of Attestation for auditors and enterprise buyers.
Most engagements start within 5 to 10 business days of proposal execution. For urgent compliance deadlines, audit filings, or procurement blocks, expedited scheduling is available.
Yes. Our most popular package is the SOC 2 All-In-One Audit Pass Package at $13,800 CAD (saving $2,200 CAD), combining full SOC 2 readiness with the required technical penetration test and letter of attestation.
Get a Guaranteed Scoping Proposal
Every environment is unique. Schedule a 20-minute scoping discussion with a senior Canadian security consultant and receive a flat-rate proposal within 24 hours.