Business IT projects · Across Québec Request a quoteFrançais

Guide

Cybersecurity quote request: what to specify

Short answer

A cybersecurity quote request should specify the scope, the data to protect, the controls already in place, the type of mandate you want and the expected deliverables. The Canadian Centre for Cyber Security's baseline controls are a useful reference to describe what the business already has in place.

This guide is for information only and is not legal advice.

This guide covers only what is specific to cybersecurity. The general method for writing a request (context, objectives, timeline, budget, acceptance criteria) is described in the guide IT requirements document. Each type of mandate also has its own service page, listed below.

1. Scope: which systems are covered

In cybersecurity, the scope describes the systems the mandate will cover. In its Baseline cyber security controls for small and medium organizations, the Canadian Centre for Cyber Security recommends listing which information systems and assets are in scope, providing the rationale for excluding any of them and recognizing the acceptance of risk in doing so. It also recommends considering all systems, whether owned, contracted or otherwise used.

In the request, list what is in scope and what is excluded, for example:

  • workstations and mobile devices;
  • servers, on site or hosted;
  • cloud services and email;
  • the network, Wi-Fi and remote access;
  • the website, an online store or an application.

Also state which systems are managed by a third party, such as a hosting provider or software vendor, since their agreement may be needed depending on the mandate.

2. The data to protect

The Cyber Centre recommends understanding the value of information systems and assets, for example sensitive information about customers or proprietary intellectual property, and assessing the potential injury to confidentiality, integrity and availability.

For the request, it is enough to state which types of data are involved and where they are: personal information about customers or employees, financial data, client files, plans or intellectual property. Also state which systems cannot be interrupted. Obligations related to personal information in an IT project are explained in the guide IT requirements document and in the guide Quebec Law 25 for SMBs.

3. Controls already in place

Describing what already exists keeps the quote from proposing what you already have. The Cyber Centre's baseline controls are a practical list for this. For each one, state whether it is in place, partly in place or missing:

  1. incident response plan;
  2. automatic patching of operating systems and applications;
  3. security software enabled;
  4. secure device configuration;
  5. strong user authentication;
  6. employee awareness training;
  7. data backup and encryption;
  8. secure mobility;
  9. basic perimeter defences;
  10. secure cloud and outsourced IT services;
  11. secure websites;
  12. access control and authorization;
  13. secure portable media.

If you cannot answer for some controls, say so: an assessment can serve precisely to take stock.

4. Type of mandate

A clear request names the type of mandate you want. Each service page describes what the mandate can cover:

A single request can combine several parts. If so, state which one is the priority and why: a requirement from a client, an insurer or a contract, a new system, a past incident.

5. Rules for a penetration test

If the request covers a penetration test, the Cyber Centre's ITSP.10.033 control catalogue states that all parties agree to the rules of engagement before penetration testing scenarios begin. Points to specify in the request:

  • who in the business authorizes the test, and in what form;
  • the agreement of third parties that host or manage systems in scope;
  • the permitted time windows and the systems that must not be disrupted;
  • the person to contact during the test.

The Penetration testing page details how this type of mandate unfolds and its pitfalls.

6. Deliverables and confidentiality of results

State what you expect at the end of the mandate, for example:

  • a report, with an executive summary and the details of each finding;
  • a list of fixes ranked by priority;
  • a presentation of the results;
  • a retest after fixes, for a penetration test;
  • documentation of what was configured, for a rollout.

A cybersecurity report describes the weaknesses of your systems: state who receives it, how it is sent and how it is stored. The Cyber Centre also notes that penetration testing may expose information protected by laws or regulations to the people conducting the testing, and that rules of engagement, contracts or other appropriate mechanisms can set out how to protect it.

Frequently asked questions

Do we need a full requirements document for a cybersecurity quote?

Not necessarily. The IT requirements document guide describes the general method. For cybersecurity, the specific items to state are the scope, the data to protect, the controls already in place, the type of mandate and the expected deliverables.

What are the Canadian Centre for Cyber Security's baseline controls?

They are a Canadian Centre for Cyber Security publication that groups controls intended for small and medium organizations, such as an incident response plan, automatic patching, strong user authentication, employee awareness training and data backup. It is a reference to describe what is already in place.

How do we describe the scope of a cybersecurity mandate?

List the systems in scope and those excluded: workstations, servers, cloud services, email, network, Wi-Fi, remote access, website or application. Also state which systems are managed by a third party.

What should we specify for a penetration test?

The systems in scope, who authorizes the test and in what form, the agreement of third parties involved, the time windows and the person to contact. According to the Canadian Centre for Cyber Security, all parties agree to the rules of engagement before testing begins.

Which deliverables should we ask for?

Depending on the mandate: a report with an executive summary, a list of fixes ranked by priority, a presentation of the results, a retest after fixes or documentation of what was configured.

Is this guide legal advice?

No. This guide is for information only and is not legal advice.

Sources

  1. Canadian Centre for Cyber Security, Baseline cyber security controls for small and medium organizations, read on October 9, 2026
  2. Canadian Centre for Cyber Security, Assessment, authorization, and monitoring (ITSP.10.033), read on October 9, 2026

Have an IT project in mind?

Describe your project in a few lines: the team will contact you to clarify your needs and send you a quote.

Get a quote