Skip to main content
Home/Pricing
Fixed-Rate Transparent Pricing

Cybersecurity Services Pricing

Published starting prices across every penetration testing and compliance readiness engagement. Delivered by certified Canadian specialists with fixed scoping and complimentary retesting.

48-Hour Free Retesting Complimentary retesting of critical and high findings within 48 hours so client deals never stall.
Letter of Attestation Executive-ready attestation letters to satisfy enterprise procurement, cyber insurers, and CPA auditors.
Guaranteed Flat Rates in CAD Fixed price agreed upon upfront in Canadian Dollars. No surprise hourly rates or unapproved change orders.
Canadian Sovereign Team 100% certified North American specialists (OSCP, CISSP), PIPEDA & Law 25 compliant, zero offshore outsourcing.
Service Catalog

Engagement Starting Rates

Select between Penetration Testing and Compliance Readiness to view deliverables, timelines, and starting investments.

Featured Turnkey Bundle · Flat-Rate CAD
The SOC 2 All-In-One Audit Pass Package - $13,800 CAD (Save $2,200 CAD)
Everything Canadian SaaS and tech firms need to clear their SOC 2 Type I or Type II audit: Complete Readiness Sprint + Mandatory Technical Penetration Test (CC7.1) + 48-Hour Free Retesting + Formal Letter of Attestation + CPA Auditor Introduction and fieldwork defense.
Get Bundled Proposal
Why You Need a Readiness Consultant Before Engaging a CPA Auditor

Under AICPA independence rules, the licensed CPA firm that issues your official SOC 2 attestation report cannot design, build, or implement your internal controls. Engaging an audit firm before your controls and evidence are in place simply risks audit failure or costly scope extensions. Lorikeet Security Canada operates as your dedicated readiness team: we scope your criteria, write the policies, coordinate evidence collection, and sit in on auditor fieldwork calls alongside your team. When you are audit-ready, we introduce you to trusted Canadian and US CPA audit firms (such as Prescient Assurance and MHM) for a seamless, predictable audit.

SOC 2

SOC 2 Readiness

Starting at
$3,500
Typical duration: 2-4 weeks

Know exactly where you stand before your auditor walks in - control by control, with the evidence your CPA firm will ask for already filed.

  • Gap Assessment Report mapped to Trust Services Criteria
  • Control Mapping Spreadsheet with Owner and Status
  • Evidence Collection Guide by Criterion
  • Prioritised Remediation Roadmap
PIPEDA

PIPEDA Readiness

Starting at
$6,500
Typical duration: 1-3 weeks

A defensible privacy programme mapped to the ten Fair Information Principles, with a breach response process that actually meets the 24-month record-keeping requirement.

  • PIPEDA Gap Assessment Mapped to the Ten Fair Information Principles
  • Privacy Policy and Public-Facing Notice Review
  • Breach Response Plan Aligned to the Breach of Security Safeguards Regulations
  • Personal Information Inventory and Retention Schedule
HIPAA

HIPAA Readiness

Starting at
$8,500
Typical duration: 2-3 weeks

Audit-ready compliance for Canadian digital health companies, SaaS vendors, and service providers handling protected health information.

  • HIPAA Security & Privacy Gap Assessment Report
  • Technical Safeguard Evaluation & Architecture Review
  • Comprehensive Risk Analysis Document (NIST SP 800-30 aligned)
  • Business Associate Agreement (BAA) Readiness Review
ISO 27001

ISO 27001 Readiness

Starting at
$4,500
Typical duration: 3-6 weeks

Build an ISMS that operates rather than a binder that satisfies - and arrive at Stage 1 with a real management system, not a document project.

  • ISMS Scope Statement and Boundary Documentation
  • Information Security Risk Assessment and Risk Register
  • Statement of Applicability (all Annex A controls)
  • Gap Assessment Report Mapped to ISO 27002:2022
GDPR

GDPR Readiness

Starting at
$7,500
Typical duration: 2-4 weeks

Lawful bases, a Record of Processing Activities, working data subject rights, and a 72-hour breach process - built before a regulator or customer asks for them.

  • Data Mapping and Record of Processing Activities (RoPA)
  • Lawful Basis Register for All Processing Activities
  • Gap Assessment Report Mapped to GDPR Articles
  • Transfer Impact Assessment and SCC Review
Law 25 (Loi 25)

Quebec Law 25 Readiness Assessment

Starting at
$4,500
Typical duration: 2-3 weeks

Achieve full compliance with Quebec's modernized private-sector privacy regime before CAI regulatory audits and severe statutory penalties.

  • Law 25 Statutory Compliance Gap Assessment Report
  • Privacy Impact Assessment (EFVP) Policy and Working Templates
  • Cross-Border and Inter-Provincial Transfer Risk Assessment Matrix
  • CAI-Compliant Confidentiality Incident Registry and Playbook
Alberta PIPA

Alberta PIPA Readiness Assessment

Starting at
$4,000
Typical duration: 2-3 weeks

Navigate Alberta's Personal Information Protection Act with practical compliance controls built for Alberta's enterprise, energy, and tech sectors.

  • Alberta PIPA Statutory Gap Assessment Report
  • OIPC Mandatory Breach Notification Protocol and RROSH Calculator
  • Employee Personal Information (EPI) Workplace Governance Policy
  • Cloud Service Provider and Out-of-Country Processing Notice Templates
Readiness Framework Starting At Duration Canadian Relevance Action
$3,500 2-4 weeks Many Canadian technology companies serving US enterprise customers are required to demonstrate ... Scope →
$6,500 1-3 weeks PIPEDA is the federal private-sector privacy law and applies to virtually every Canadian busine... Scope →
$8,500 2-3 weeks For Canadian health innovators based in Calgary, Toronto, or anywhere in Canada, handling US el... Scope →
$4,500 3-6 weeks ISO 27001 is an international standard, and its geographic reach makes it the most common certi... Scope →
$7,500 2-4 weeks Canadian companies with customers, employees, or partners in the EU or UK are subject to GDPR r... Scope →
$4,500 2-3 weeks Law 25 carries Canada's highest statutory privacy penalties: administrative monetary penalties ... Scope →
$4,000 2-3 weeks Alberta was the pioneer of mandatory privacy breach reporting in Canada. Under PIPA Section 34.... Scope →
Transparent Process

How We Scope Your Engagement

No opaque estimates or multi-week discovery traps. We get you a confirmed flat-rate proposal in 3 simple steps.

01 / DISCOVERY

Target Definition

We review your target assets (domains, IPs, cloud subscriptions, API specs, and roles) on a focused 20-minute scoping call.

02 / PROPOSAL

Guaranteed Flat Rate

Within 24 to 48 hours, you receive a formal Statement of Work with a locked flat-rate quote, verified start date, and clear deliverables.

03 / TESTING & RETEST

Execution & Free Retest

Testing is carried out by senior Canadian specialists. After remediation, your free retest validates the fixes for your audit.

Client Stories

Trusted by Fast-Growing Companies

Hear directly from organizations that rely on Lorikeet Security for rigorous testing and clear ROI.

JBWeb

Digital Agency

“From Pentest to malware analysis these guys know what they're doing.”

We came to Lorikeet Security with not so small task of tracking down the source of a cyber incident. Lorikeet Security looked at attack vectors and they set up a full test environment and really showed they knew what they were doing. With amazing analytics reports on down to the minute of login attempts. The level of detail that Cyber Insurance Companies wish they had in house - Those reports are an invaluable tool and give confidence and value add to the executive level for pre or post ransomware attacks.

SOCaaS Incident Response
Flowtriq

SaaS Platform

“Streamlined Security Testing with White Glove Service”

We used Lorikeet Security for a PTaaS pentest and briefly tried their ASM tool - both were amazing. Fast tests, accurate findings, and everything handled through a modern interface. The report summary, live chat, asset management, and live quoting features of the portal really stand out. Their 'white glove' touch contributed to a 10/10 experience. They're truly changing the pentest game with the new portal clients can use.

Penetration Testing Continuous Assessments
FAQ

Pricing & Engagement Questions

Clear answers regarding payment, scoping, and Canadian tax handling.

Why can't our CPA audit firm also handle our readiness prep? +

Under AICPA professional standards and Canadian CPA independence rules, an accounting firm that issues an official SOC 2 attestation report is legally barred from designing, building, or implementing the internal controls it examines. The firm that builds your controls cannot audit them. Lorikeet Security Canada acts as your specialized readiness team - writing policies, implementing controls, and organizing evidence - before introducing you to independent accredited CPA audit firms (such as Prescient Assurance or MHM) to conduct the official audit.

What is the difference between the $3,500 Gap Assessment and the $9,500 Full Sprint? +

The $3,500 CAD Gap Assessment is a rapid 1 to 2 week evaluation of your real environment against the Trust Services Criteria, delivering a detailed gap matrix and remediation roadmap. The $9,500 CAD Full Sprint includes end-to-end control design, custom policy writing, vendor risk reviews, evidence collection setup, and direct auditor coordination through fieldwork. Best of all, 100% of your Gap Assessment fee is credited toward the Full Sprint if you upgrade.

How does billing and invoicing work? +

All engagements are billed as flat-rate contracts with transparent scoping in Canadian Dollars. Invoicing is handled locally with applicable provincial GST/HST, and your proposal is locked before work begins with zero unexpected hourly overages.

Is retesting really complimentary? +

Yes. Every penetration test includes one complimentary retest round of all critical and high findings within 48 hours of your patch notification. Retesting validates that your fixes effectively resolve the vulnerabilities before we issue your final report and formal Letter of Attestation for auditors and enterprise buyers.

How quickly can our assessment begin? +

Most engagements start within 5 to 10 business days of proposal execution. For urgent compliance deadlines, audit filings, or procurement blocks, expedited scheduling is available.

Do you offer multi-service or bundle discounts? +

Yes. Our most popular package is the SOC 2 All-In-One Audit Pass Package at $13,800 CAD (saving $2,200 CAD), combining full SOC 2 readiness with the required technical penetration test and letter of attestation.

Start Today

Get a Guaranteed Scoping Proposal

Every environment is unique. Schedule a 20-minute scoping discussion with a senior Canadian security consultant and receive a flat-rate proposal within 24 hours.