Cybersecurity work spans a wider range of engagement shapes than most IT contracting: a two-week penetration test with a fixed deliverable, a compliance audit against a defined framework, and an open-ended incident-response retainer can all be billed through the same corporation to different clients in the same year, and each carries a different personal services business risk profile. The general PSB test does not change for cybersecurity consultants, but the facts that feed into it look different depending on which kind of engagement is being assessed.
The Same Four Factors, Different Facts
CRA’s personal services business test still runs on control, tools and equipment, chance of profit and risk of loss, and integration into the client’s operations, the same factors covered generally in the PSB risk guide. What changes across engagement types is how each factor actually plays out on the ground.
Control. A penetration test with a fixed rules-of-engagement document, a defined testing window, and a deliverable report has a natural, contract-defined boundary around when and how the work happens. An incident-response retainer, by contrast, often has the client setting priorities in real time as an incident unfolds, which looks closer to direction than a scoped project does.
Tools and equipment. A consultant running scans and tests from their own lab environment, licensed tooling, and testing infrastructure, the kind of setup covered in security lab environments and defensible records, supports the independent-business side of this factor. A consultant working exclusively inside the client’s SIEM, ticketing system, and provided endpoint, with no independent infrastructure of their own, does not.
Chance of profit and risk of loss. A fixed-price penetration test carries real project risk: if the engagement takes longer than scoped, the consultancy absorbs the cost. An hourly incident-response retainer with guaranteed monthly payment regardless of hours worked carries closer to zero downside risk, which reads more like compensation than business income.
Integration. A specialized penetration test or compliance audit engaged for a defined period is more clearly a discrete service than an incident-response function that, in practice, has become the client’s ongoing security operations coverage, filling a role that would otherwise sit with an in-house security employee.
Engagement Types and Where They Tend to Sit
None of the following determines PSB status on its own. They describe where each engagement type tends to land relative to the four-factor test before other facts, client concentration, contract terms, and actual working patterns, are layered in.
Project-based penetration testing and audits. Fixed scope, fixed timeline, a defined deliverable, and typically a fixed or capped price. This structure most naturally produces the independent contractor profile: real project risk, a bounded engagement, and a deliverable rather than ongoing presence.
Standby incident-response retainers, covered from the revenue side in incident-response retainers, deposits, and revenue recognition, sit closer to the employment end of the spectrum the longer they run with a single client, the more the client directs day-to-day priorities, and the less the consultant retains other clients alongside the retainer.
Governance and compliance advisory, ongoing reviews against a framework such as SOC 2 or ISO 27001, falls somewhere between the two depending on whether the engagement is structured as periodic scoped reviews or as continuous embedded advisory presence.
Fractional or virtual CISO arrangements, where a consultant effectively runs security strategy for a client on an ongoing basis, carry meaningfully elevated PSB risk regardless of title, since the role is frequently indistinguishable in practice from an internal security leadership position, just paid through a corporation instead of payroll.
Single-Client Concentration in Security Practices
Cybersecurity consultancies are more prone than some IT contracting fields to a specific concentration pattern: a consultant lands one large enterprise or government retainer client that fills most of their billable capacity, and the relationship extends year over year through renewal rather than competitive rebid. That pattern, a long single-client relationship renewed repeatedly with no real gap or competitive process, is one of the risk factors the general PSB guide flags, and it shows up often in security retainer work specifically because incident-response and ongoing advisory relationships are naturally sticky once established.
Maintaining even a modest second client relationship, structuring the primary retainer around defined deliverables rather than open-ended availability, and supplying the consultancy’s own tooling and lab environment where practical are the levers most available to a security consultant managing this risk, the same categories of adjustment covered generally in the PSB guide, applied to the specific shape of security engagements.
Contracting Through an Agency or MSSP
Security consultants frequently contract through a staffing agency or a managed security service provider rather than directly with the end client whose environment they are testing or defending. That structure changes who the paying party is but does not change the underlying test. If the agency or MSSP is effectively a billing pass-through, and the end client sets hours, supplies equipment, and directs the work day to day, the working relationship being assessed is still the one with the end client in substance, whatever the invoicing chain looks like on paper.
Reviewing Risk Per Engagement, Not Per Corporation
A cybersecurity consultancy’s overall PSB exposure is rarely a single answer. A corporation billing a mix of fixed-scope penetration tests to several clients and a long-running incident-response retainer to one client should have each relationship assessed on its own facts, since a clearly independent project-based relationship does not offset the risk sitting inside a single-client retainer that looks more like ongoing employment. Reviewing the engagement mix annually, before renewal decisions are made rather than after a filing is done, keeps the analysis current with how the practice’s client base is actually shaped.
Related Guides
- Personal services business risk for incorporated IT contractors covers the general four-factor test this guide applies to security-specific engagement types.
- Incident-response retainers, deposits, and revenue recognition covers the revenue side of the standby retainer structures referenced here.
- Security lab environments, home-office costs, and defensible records covers the tools-and-equipment documentation that supports the independent-business side of the PSB test.
- Ottawa federal government IT contractors covers the same PSB analysis for the federal contracting market specifically, where single-client concentration is common.
Scope of This Guide
This guide covers how engagement structure affects personal services business risk for Canadian cybersecurity consultants operating through a corporation. It does not cover:
- Employment status questions for consultants operating as sole proprietors, where PSB rules do not apply
- Contract drafting for statements of work or master services agreements, which should be reviewed with a lawyer
- Provincial labour or employment standards classification questions, which are separate from the federal PSB tax analysis
This is general information, not advice for a specific engagement. A CPA reviewing your actual client mix and contract terms can assess where your practice’s PSB risk sits.