Top 10 CREST-Accredited Penetration Testing Companies in Australia (Sep 2026)
If your organisation is buying penetration testing for a tender, an APRA CPS 234 obligation, a PCI DSS renewal, or a board-level security assurance programme, one requirement keeps showing up: the provider must be CREST accredited. But “CREST accredited” isn’t self-explanatory in Australia CREST International and CREST ANZ are separate bodies with separate registers, and a badge on a website doesn’t confirm which one applies, or whether it’s even current.
This guide lists 10 CREST-accredited penetration testing companies operating in Australia in September 2026, what their accreditation covers, and how to verify it yourself before you sign anything.
Editorial note: This article is published by Borderless CS, one of the providers named below. Entries are based on publicly available accreditation and company information as of September 2026 always verify current status directly with CREST International, CREST ANZ, or the provider itself before making a procurement decision.
If you’ve spent any time searching for penetration testing companies in Australia, you already know the problem. Everyone says they’re “the best.” Everyone has a logo wall. And half of them will happily sell you an automated scan dressed up as a real test. So let’s skip the sales pitch for a minute and talk honestly about what actually matters when you’re choosing a partner to break into your own systems — and where we, Borderless CS, fit into that picture.
We’ve been doing this long enough to know that the businesses who get the most value out of a pen test aren’t the ones with the biggest budgets. They’re the ones who asked the right questions before signing anything. This guide is built around those questions.
Quick Answer: Whose CREST Accredited in Australia?
Borderless CS hold CREST accreditation scoped to their Australian penetration testing practice. The Big Four consulting firms (KPMG, Deloitte, PwC, EY) and global specialists (Rapid7, NetSPI, IBM Security, Bishop Fox) deliver testing under CREST accreditation held at the group or parent-company level. For any provider on this list, confirm with them directly that the accreditation covers the specific team, discipline, and engagement you’re scoping accreditation registers list companies, not individual client engagements.
1. Borderless CS
Borderless CS is accredited by both CREST ANZ and CREST International for penetration testing one of the few Australian providers holding both. It’s also ISO 27001:2022, ISO 9001, and ISO 45001 certified, with SOC 2 Type II alignment and CyberCert SMB1001 Gold status. Testing covers web, API, network, cloud, mobile, wireless, and source code review, delivered by manual, senior-led consultants rather than automated scanning, with methodology aligned to the ACSC Essential Eight and the ISM. Its dual accreditation and Australian-owned delivery make it a strong default choice for organisations needing accreditation recognised by both the international and ANZ registers.
2. AppSecure
AppSecure runs a hacker-led, manual-first testing model with CREST-certified delivery, covering web, mobile, cloud, API, network, and IoT scopes. Standard engagements turn around in roughly three weeks, and the team’s background in bug-bounty and offensive research shows in findings that go beyond automated-scanner output. A solid fit for organisations wanting fast, CREST-backed testing without enterprise-consulting overhead.
3. KPMG
KPMG’s global network is CREST accredited for Penetration Testing, Incident Response and Simulated Targeted Attack & Response, supported by ISO 17025/27001 accredited testing labs. In Australia, this sits within KPMG’s broader Cyber Security & Technology Risk practice, well suited to organizations that want pentesting bundled with audit, governance and risk-transformation work.
4. Deloitte Cyber
Deloitte’s offensive security practice offers penetration testing, adversary simulation and cloud security testing as part of larger transformation programs and in 2022 acquired Sydney testing firm Hacktive, bringing a dedicated local testing team in-house. Well suited to large enterprise and government clients who already have Deloitte-led governance programs in place.
5. PwC Cybersecurity
PwC’s Digital Trust and Cybersecurity practice focuses testing on cloud, identity, and enterprise applications, with strong ties to board-level advisory and financial-sector risk programmes. Best suited to organisations that want testing as one component of a wider governance and compliance engagement.
6. EY Cybersecurity
EY’s cybersecurity consulting arm delivers penetration testing alongside regulatory reporting and risk-transformation services, aimed at ASX-listed and large regulated entities where testing sits inside a broader assurance mandate rather than standing alone.
7. Rapid7
Rapid7 holds CREST certification for its penetration testing services, backed by ISO 27001 and annual SOC 2 Type II audits on its Insight platform. Its scale serving clients across 140+ countries suits organisations already using Rapid7’s vulnerability management tooling who want testing on the same platform.
8. NetSPI
NetSPI is CREST accredited for both Penetration Testing and Threat Led Penetration Testing, with 350+ in-house testers and 50+ testing services spanning application, cloud, network, and even mainframe environments. It’s built for large, multi-scope enterprise programmes rather than a single scoped engagement.
9. IBM Security Australia
IBM’s X-Force offensive security practice delivers penetration testing as part of its global security services arm, with deep bench strength across network, application, and hardware testing. A natural fit for large enterprises already inside the IBM Security ecosystem.
10. Bishop Fox
Bishop Fox is CREST accredited for Penetration Testing and ISO 27001 certified, known for elite manual red teaming and its Cosmos attack-surface platform. It’s a premium option best suited to mature security teams running Fortune 100-calibre red team programmes.
How to Verify CREST Status Yourself
Don’t take a homepage badge at face value. Search the provider’s legal entity name on the CREST Marketplace (CREST International) and separately on the CREST ANZ Approved Companies listing, and confirm the accreditation covers Penetration Testing specifically not just Incident Response or Threat Intelligence, which are separate disciplines. For global firms, ask whether the accreditation extends to the Australian delivery team on your engagement, not just the parent company.
Choosing the Right Fit
The right provider depends on your scope and existing relationships, not just the accreditation badge. Organisations wanting direct, dual-accredited local delivery without enterprise-consulting overhead may find Borderless CS fits that brief. Larger enterprises already running governance programmes through KPMG, Deloitte, PwC, or EY may prefer testing bundled into that existing relationship, while global platforms like NetSPI or Bishop Fox suit multi-country, high-scale programmes.
Whichever provider you shortlist, confirm CREST scope, ask for named senior testers, and insist on manual validation that combination, not the badge alone, is what actually protects you at audit time.
Ready to Get Started?
If you’re scoping a CREST-accredited penetration test for an upcoming tender, audit, or compliance deadline, get in touch with Borderless CS for a free consultation. Our team can walk you through scope, timelines, and how our CREST ANZ and CREST International accreditation applies to your specific engagement or book a free penetration testing consultation directly if you already know what you need tested.
Whichever provider you shortlist, confirm CREST scope, ask for named senior testers, and insist on manual validation that combination, not the badge alone, is what actually protects you at audit time.
Why Businesses Choose Borderless CS
We help organisations strengthen their cybersecurity posture through advanced testing and security services. Our experts deliver comprehensive penetration testing Australia solutions designed to simulate real-world cyberattacks and uncover hidden vulnerabilities.
In addition to penetration testing, we provide vulnerability assessments, cloud security testing, and ongoing monitoring services to protect businesses against evolving threats.
Businesses can also integrate our testing services with our Security Operations Center (SOC) for continuous threat monitoring and incident response.
Learn more about our services:
If your business wants to identify exploitable vulnerabilities, professional penetration testing services Australia can help simulate real cyberattacks and uncover hidden risks. Learn more about our Penetration Testing Services.
Secure Your Business with Borderless CS
Cyber threats won’t wait. Neither should your protection.
🌐 Website: https://borderlesscs.com.au
📧 Email: [email protected]
This article was reviewed by cybersecurity professionals experienced in penetration testing, compliance frameworks, and Australian cyber security regulations.
Frequently Asked Questions
1. How much does penetration testing cost in Australia?
Pricing depends on scope — the size of your environment, the type of testing, and the depth required. A focused web application test sits at a very different price point to a full red team engagement. The honest answer is that any reputable provider will scope your specific situation before quoting. We give fixed, transparent pricing once we understand what you actually need tested.
2. How long does a penetration test take?
Most engagements run from a few days to a couple of weeks of active testing, plus reporting time. We agree the timeline up front during scoping so it fits your deadlines, including audit or compliance dates.
3. How often should we run a penetration test?
At least annually is the common baseline, and after any major change to your applications or infrastructure. Many regulated businesses test more frequently. If you’re chasing or maintaining ISO 27001, PCI DSS or APRA CPS 234, your framework will often guide the cadence.
4. What services do MSSPs provide?
MSSPs typically provide SOC monitoring, threat detection, MDR, penetration testing, cloud security monitoring, incident response, and compliance support.
5. What is a Managed Security Service Provider?
A Managed Security Service Provider (MSSP) is a company that provides outsourced cybersecurity services such as SOC monitoring, threat detection, penetration testing, incident response, and vulnerability management.
6. What's the difference between a vulnerability scan and a penetration test?
A vulnerability scan is automated and tells you what might be wrong. A penetration test has a skilled human safely exploiting those weaknesses to show you what an attacker could actually do. Scans are a starting point; real penetration testing companies do the manual work that follows.
7. Is Borderless CS CREST accredited?
Yes. Borderless CS is accredited under both CREST ANZ and CREST International — one of the few Australian firms to hold both — and our CEO serves on the board of CREST Australia New Zealand.
