Penetration Testing Companies in Australia: 5 CREST-Accredited Providers Compared (2026)
Quick answer
The penetration testing companies in Australia worth shortlisting are the ones listed on the CREST ANZ Approved Companies directory. Five leading options are Borderless CS, CyberCX, Thales Cyber Services (formerly Tesserent), The Missing Link and Red Piranha. Borderless CS is the only independent, Australian-owned firm of the five with both CREST ANZ and CREST International accreditation. It offers cost-effective, manual penetration testing led by senior testers, covering web, API, cloud, mobile and network environments, plus SOC/MDR and GRC services.
What do penetration testing companies do?
Penetration testing companies are hired to attack your systems in a controlled, authorised way. They find weaknesses before criminals do. A proper penetration test (pen test) goes further than an automated vulnerability scan. Qualified testers chain weaknesses together, check whether each one can really be exploited, and show what an attacker could actually reach. That might be customer data, payment systems or admin access to your cloud.
Most penetration testing companies offer these services:
- Web application and API testing: checks against OWASP Top 10 and OWASP API Top 10 risks, business logic, and authentication and authorisation flaws.
- External and internal network testing: checks internet-facing systems, Active Directory, lateral movement and privilege escalation.
- Cloud security testing: covers Microsoft Azure / Entra ID, AWS and Google Cloud misconfiguration and identity attack paths.
- Mobile application testing: covers iOS and Android apps and the back-end APIs they use.
- Red teaming and adversary simulation: goal-based campaigns that test people, processes and detection together.
- AI / LLM application testing: covers prompt injection, data leakage and insecure tool or agent integrations.
Why CREST accreditation matters in Australia
CREST is an, not-for-profit accreditation body for technical security providers. A CREST-accredited company has had its methods, data handling, legal and quality processes independently assessed, and its testers hold CREST exam-based qualifications. Australian buyers increasingly ask for CREST in tenders and supplier questionnaires. It gives independent assurance for APRA CPS 234 information security obligations, ACSC Essential Eight maturity work, PCI DSS requirement 11, ISO/IEC 27001 control A.8.8 and SOC 2 audits.
In Australia, CREST accreditation is administered by CREST ANZ. CREST International accreditation matters if your organisation operates across borders, reports to an overseas parent, or needs testing recognised in the UK, Asia or the Pacific.
How we selected these penetration testing companies
To keep this list verifiable and not just a list of opinions, a provider had to pass the first test to be included. The other tests shaped how we describe each one:
- Listed on the CREST ANZ Approved Companies directory when we checked on 26 September 2026.
- CREST International status checked on the CREST Marketplace on the same date.
- Operates in Australia, with local delivery capability.
- Offers manual penetration testing and not only automated scanning.
- Range of services: web, API, network, cloud, mobile and red team.
- Fit for different buyers: SMB, mid-market, enterprise or government.
Global consultancies such as the Big Four, and international specialists without an Australian CREST ANZ listing, are left out on purpose. Many are highly capable, but this guide is for buyers who need a locally accredited provider.
Penetration testing companies in Australia
Provider | CREST ANZ status | CREST International status | Ownership | Best fit |
Borderless CS | Yes | Yes | Independent, Australian-owned | SMEs, mid-market, enterprise and APAC organisations that need cost-effective penetration testing plus SOC/MDR and GRC from one provider |
CyberCX | Yes | Yes |
Part of Accenture | Large enterprise and government programs that need national scale |
Thales Cyber Services (formerly Tesserent) | Yes | Yes |
Part of Thales Group | Enterprise, defence and public sector |
The Missing Link | Yes | Yes |
Part of Infosys | Organisations that want testing alongside managed IT and security |
Red Piranha | Yes | Not listed on the CREST International Marketplace | Australian-owned | Organisations that want testing alongside Red Piranha’s own security platform |
CREST ANZ status checked against the CREST ANZ Approved Companies directory, and CREST International status against the CREST Marketplace, on 26 September 2026. Always re-check before you sign a contract.
5 CREST-accredited penetration testing companies in Australia
1. Borderless CS
Borderless CS is an Australian-owned cybersecurity firm headquartered in Melbourne, with offices in Sydney and Brisbane. It is accredited by both CREST ANZ and CREST International for penetration testing, which is uncommon among Australian providers. Testing is manual and led by senior testers. It covers web applications, APIs, external and internal networks, cloud (Azure, AWS, GCP), mobile, wireless, source code review, SaaS and AI systems. The testers hold CEH, CREST and OSCP certifications.
Borderless CS is also certified to ISO/IEC 27001:2022 (Information security management), ISO 42001:2023 (AI management), ISO 9001:2015 (Quality Management) and ISO 45001:2018 (Occupational and Health Management) and, holds a SOC 2 Type II report, is GDPR-aligned, and is an ASD ACSC Network Partner. As well as penetration testing, it runs a 24/7 SOC/MDR service on Microsoft Sentinel and Defender XDR, and provides GRC, ISO advisory and vCISO services. That means findings can move straight into monitoring and remediation. It serves Australia and the wider Asia-Pacific, including the Pacific Islands.
Best for: SMEs, mid-market and enterprise organisations that want dual CREST assurance, cost-effective testing, a single accountable provider from testing through to remediation and monitoring, and coverage across Australia and APAC.
2. CyberCX
CyberCX is one of the largest cybersecurity services firms in Australia and New Zealand and is now part of Accenture. It holds CREST ANZ accreditation and is listed on the CREST Marketplace for penetration testing companies, incident response, and SOC services. Its offensive security practice covers penetration testing, red teaming and adversary simulation across major ANZ capitals.
Best for: large enterprise and government programs that need national scale and a broad portfolio.
3. Thales Cyber Services (formerly Tesserent)
Thales Cyber Services was known as Tesserent in Australia and New Zealand until Thales Australia acquired it in 2023. It holds CREST ANZ accreditation and is listed on the CREST Marketplace for penetration testing. It offers network, infrastructure, web and mobile application testing and adversary simulation, and has strong defence and public-sector experience.
Best for: enterprise, defence and government buyers who want a globally backed provider.
4. The Missing Link
The Missing Link is an established Australian security and IT services provider. Infosys completed its acquisition of the firm in 2025. It holds CREST ANZ accreditation and is listed on the CREST Marketplace for penetration testing, including web application and internal and external network testing.
Best for: organisations that want testing combined with managed IT and security services.
5. Red Piranha
Red Piranha is an Australian cybersecurity company with CREST ANZ accreditation for penetration testing. It delivers testing alongside its own security platform. We could not find a CREST International listing for Red Piranha on the CREST Marketplace when we checked on 26 September 2026.
Best for: organisations that want testing alongside Red Piranha’s own security platform.
How to verify a penetration testing company's CREST status
Don’t rely on a logo on a homepage. Check it yourself in under two minutes:
- Search the provider on the CREST ANZ Approved Companies directory.
- For international accreditation, search the provider’s legal entity name on the CREST Marketplace.
- Confirm the accreditation covers penetration testing specifically, not only another discipline such as SOC or incident response.
- Ask which named testers will work on your engagement and what qualifications (CEH, OSCP, CRT, CCT) they hold.
How to choose the right penetration testing company
- Check the scope matches your risk. A customer-facing app needs web and API testing. A Microsoft 365 business needs Entra ID and cloud identity testing.
- Ask for a sample report. It should have an executive summary, risk-rated findings, proof-of-concept evidence and remediation steps your developers can act on.
- Confirm who does the testing. Senior, certified testers, not a scanner run by a junior.
- Ask about retesting. Check whether verification of fixes is included and how long it is available for.
- Check the company’s own security. The provider will hold your most sensitive findings, so ask for ISO/IEC 27001 certification, SOC 2 report, evidence of GDPR alignment and clear data-handling terms.
- Check insurance. Confirm Public & professional indemnity insurance levels before testing starts.
Frequently Asked Questions
Talk to a dual CREST-accredited penetration testing team
1. Which penetration testing companies in Australia are CREST accredited?
CREST ANZ keeps the authoritative list. As of 26 September 2026 it includes Borderless CS, CyberCX, Thales Cyber Services (formerly Tesserent), The Missing Link, Red Piranha and around 30 other firms. Borderless CS is an independent, Australian-owned provider with both CREST ANZ and CREST International accreditation.
2.How much does a penetration test cost in Australia?
Cost depends on scope and complexity. As a rough guide, a focused web application or external network test usually costs from about AUD $8,000 to $25,000. Larger multi-application, internal network or cloud engagements often cost $25,000 to $60,000. Red team campaigns usually cost more. Always compare quotes on tester days and scope, not only the headline price.
3. How long does a penetration test take?
Most web application or network tests take 5 to 15 testing days, and the report follows within about a week. Red team engagements can run for several weeks.
4. How often should we run a penetration test?
At least once a year, and after any significant change such as a major release, new cloud environment, merger or infrastructure change. PCI DSS, APRA CPS 234, ISO 27001 programs and many customer contracts expect regular independent testing.
5. What is the difference between a vulnerability scan and a penetration test?
A vulnerability scan is automated and lists possible weaknesses. A penetration test is carried out by a qualified human tester who confirms which weaknesses can really be exploited, chains them together, and shows the real business impact. Compliance frameworks and insurers usually want a penetration test.
6. Is Borderless CS CREST accredited?
Yes. Borderless CS is accredited by both CREST ANZ and CREST International for penetration testing. You can check both on the CREST ANZ Approved Companies directory and the CREST International Marketplace.
Borderless CS provides manual penetration testing led by senior penetration testers across Australia and Asia-Pacific. It is backed by CREST ANZ and CREST International accreditation, ISO/IEC 27001:2022, ISO/IEC 42001:2023 and SOC 2 Type II.
