Top 5 APRA CPS 234 Penetration Testing Companies in Australia (2026)
Choosing an APRA CPS 234 penetration testing provider is one of those decisions that looks simple on a procurement form and turns out not to be. Every firm you approach will say they’re CREST accredited, every proposal will mention manual testing, and the quotes will come back anywhere from eight thousand dollars to eighty. Somewhere in that spread is a provider whose report will hold up when internal audit picks it apart. The rest will sell you a document.
We put this comparison together because APRA CPS 234 penetration testing sits in an awkward spot. The standard never actually says “penetration testing.” What paragraph 27 says is that you have to test the effectiveness of your information security controls through a systematic testing program, and paragraph 29 says whoever does that testing needs to be appropriately skilled and functionally independent of the controls they’re assessing. Paragraph 30 then asks you to look at the whole program at least once a year and decide whether it’s still adequate. Penetration testing is simply how most regulated entities answer all three, and it’s what auditors have come to expect to see.
Since CPS 230 came into force in July 2025, the questions have got harder. It’s no longer enough to show a board that testing happened. You’re being asked which critical operations were in scope, why those and not others, what was found, what was fixed, and who verified the fix. Material incidents go to APRA inside 72 hours. Material control weaknesses inside ten business days. The penetration test report is one of the few documents in your security program that a regulator, an auditor and a risk committee will all read, usually looking for different things.
So the provider matters. Not because the good ones find more bugs (though they do), but because the evidence they produce either stands up to scrutiny or creates more work than it saves.
Here are five firms Australian regulated entities are shortlisting in 2026.
How We Assessed These Companies
Eight criteria, weighted towards what an APRA-regulated entity actually has to prove rather than what makes for good marketing copy:
- CREST accreditation, at company level. Plenty of providers advertise CREST when what they mean is that one consultant holds a certification. Company accreditation means the methodology, scoping and reporting have been independently assessed. Check the registry, not the website.
- Manual, exploitation-led testing. Scanners find known vulnerabilities. People find broken authorisation, business logic flaws and the chains that turn two minor issues into one serious one. CPS 234 asks about control effectiveness, and you can only demonstrate that by hand.
- Reporting quality. Can internal audit use the report as it stands? Is there evidence, business impact, a remediation path and a clear risk rating, or is it scanner output with a cover page?
- Retesting. A finding closed without verification is an open finding with better paperwork.
- Financial services experience. CPS 234, CPS 230, PCI DSS, ISO 27001 and APP 11 overlap heavily. A provider who has mapped a test to those before will save you weeks of back and forth.
- Australian presence and data jurisdiction. Where does the test data sit, who can reach it, and how long is it kept? For regulated entities that’s a governance question, not a preference.
- Turnaround and engagement fit. A six-week lead time on a pre-release test has a real cost attached to it.
- Independence. If the firm designed, built or runs the control, they shouldn’t be the one testing it. This catches more organisations than you’d expect, particularly where an MSP has expanded into testing.
Weight these differently if your situation calls for it. A major bank with an internal red team wants something very different from a mutual ADI running its first structured program.
Top 5 CPS 234 Penetration Testing Companies
| Rank | Provider | Headquarters | Australian Owned | Primary Focus | Best For |
|---|---|---|---|---|---|
| 1 | Borderless CS | Melbourne, VIC (also Sydney, Brisbane) | Yes | Dual CREST-accredited penetration testing, SOC and MDR, GRC | Regulated entities wanting senior manual testing and regulator-ready evidence without Big 4 pricing |
| 2 | NetSPI | Minneapolis, USA | No | Penetration Testing as a Service, attack surface management | Large enterprises wanting continuous testing through a platform |
| 3 | KPMG Australia | Sydney, NSW | No (global network) | Assurance-led cyber, regulatory advisory | Entities needing testing inside a broader APRA assurance program |
| 4 | PwC Australia | Sydney, NSW | No (global network) | Threat-led testing, cyber transformation | Board-level programs and intelligence-led scenarios |
| 5 | Deloitte Australia | Sydney, NSW | No (global network) | Red teaming, cyber risk advisory | Complex multi-entity groups running combined engagements |
1. Borderless CS
Headquarters: Melbourne, Victoria, with offices in Sydney and Brisbane Accreditations: Dual CREST accredited (CREST ANZ and CREST International), ISO/IEC 27001:2022, ISO 9001:2015, ISO 45001:2018, SOC 2 Type 2, Cybercert Gold, GDPR aligned Australian owned: Yes
Borderless CS is Australian owned, headquartered in Melbourne, with offices in Sydney and Brisbane and delivery reaching across Australia and into the Pacific. The client list covers financial services, government, healthcare and retail. For APRA work the thing worth knowing is that the firm runs both a CREST-accredited offensive security team and a 24/7 security operations capability, which is a combination you don’t see often and which changes what the testing team knows.
The accreditation is dual, and you can check it
A lot of Australian providers describe themselves as CREST accredited. Some hold a single accreditation. A fair number are talking about individual tester certifications and letting you assume it’s more. Borderless CS holds CREST ANZ and CREST International accreditation at company level, and both are listed publicly: CREST ANZ through the Approved Companies directory, CREST International on the CREST Marketplace.
That verifiability does real work in a CPS 234 program. When internal audit asks how you satisfied paragraph 29, a link to a public registry ends the conversation. Consultants hold CREST and OSCP certifications individually, so the accreditation holds at the practitioner level too, which is where it actually matters on the day.
The broader certification stack is relevant for a reason that’s easy to miss. ISO/IEC 27001:2022 and SOC 2 Type 2 mean the firm you’re handing your most sensitive test data to has had its own controls independently audited. Under paragraph 21 of CPS 234 that’s a third-party risk question, and procurement teams at regulated entities are asking it earlier in the process than they used to.
Testing that covers the whole estate
Scope runs across web applications, APIs, external and internal networks, mobile, cloud, wireless, SaaS platforms, source code review and AI penetration testing, with continuous monitoring available where a program needs ongoing coverage rather than an annual snapshot.
The AI testing capability deserves a mention on its own. Banks, insurers and super funds are rolling out LLM-based assistants, document processing and fraud models considerably faster than their testing programs have adapted to cover them. Prompt injection, output handling, and the authorisation boundaries around retrieval systems are live exposures that a conventional application test simply won’t reach, because they weren’t in scope when the scope template was written. Paragraph 27 ties testing frequency to the rate of change in threats and vulnerabilities, which makes a newly deployed AI system close to the textbook case for testing more often, not less.
Methodology is manual ethical hacking against recognised frameworks, aligned to the ASD Essential Eight, NIST and the Australian Government Information Security Manual. The stated position is that manual work exists to find the business logic flaws and chained exploits a scanner walks straight past, and in regulated environments those tend to be the findings that matter. A tool will tell you a security header is missing. A tester will find that one user role can pull another customer’s transaction history through an API parameter nobody documented.
Six stages, built around producing evidence
Engagements move through scoping and consultation, reconnaissance, manual testing, controlled exploitation, risk analysis and reporting, then remediation and retesting. Two of those are where regulated entities usually get let down by other providers.
Controlled exploitation is what turns a theoretical finding into a demonstrated control failure. This is the part that matters for CPS 234, because the standard asks about control effectiveness. A list of vulnerabilities doesn’t prove a control failed. A documented exploitation path does.
Remediation and retesting closes the loop. Once fixes go in, the findings are retested and the report is updated to show the verified position. It sounds procedural but it’s the difference between handing an auditor a list of things you intend to fix and handing them a record of things you fixed and confirmed.
Reports written for the people who have to read them
Each engagement produces an executive summary for management, a full technical report, risk-rated findings, evidence and screenshots, business impact analysis and prioritised remediation guidance, followed by a session walking the technical team through it all.
Borderless CS also issues a Letter of Attestation at completion, which for regulated entities is more useful than it first appears. It’s a single shareable document evidencing that independent testing took place, without circulating a technical report full of exploitation detail. It covers customer assurance requests, compliance and regulatory audits, cyber insurance renewals, and tender submissions. Most institutions field several of those a year, and the alternative is either redacting the report each time or handing over more than the requester should reasonably have.
For APRA clients, findings are mapped to the control obligations they touch, covering CPS 234 paragraphs 27 to 30 and, where it applies, CPS 230 critical operations. That mapping is what lets internal audit use the report directly rather than translating it first.
Why the SOC changes the risk ratings
Because Borderless CS also runs managed detection and response for regulated clients, the testing team rates findings against what a monitored environment actually does with them. A vulnerability that gets caught by a mature detection stack in seconds carries different business risk from one that would sit exploited and unnoticed for a month, even where a scanner scores the two identically.
Most providers can’t draw that distinction, because they never see the environment again after the report goes out. On paper it’s a small thing. In front of a risk committee it turns a severity score into a position you can defend.
Why Borderless CS stands out
- Dual CREST accreditation (ANZ and International) at company level, publicly verifiable, with CREST and OSCP certified consultants
- ISO/IEC 27001:2022, ISO 9001:2015, ISO 45001:2018, SOC 2 Type 2 and Cybercert Gold certified, so third-party risk on the tester is already answered
- Australian owned and operated, offices in Melbourne, Sydney and Brisbane, test data held onshore
- Manual exploitation-led testing aligned to Essential Eight, NIST and the ISM
- Coverage across web, API, mobile, internal and external infrastructure, cloud, wireless, SaaS, source code review and AI penetration testing
- Retesting and remediation verification included, with reporting updated to the verified position
- Letter of Attestation issued for audits, insurers, customers and tenders
- Findings mapped to CPS 234 and CPS 230 obligations rather than left as a generic vulnerability list
- In-house SOC and MDR, so risk ratings reflect actual detection capability
- Senior consultants on every engagement rather than a graduate pyramid
Best for: APRA-regulated entities, fintechs and Pacific financial institutions that need real CPS 234 control testing, evidence that satisfies both a regulator and an auditor, and a provider who stays involved through remediation instead of disappearing at delivery. Full scope is on the penetration testing service page, and the CREST-accredited testing methodology covers how engagements run.
2. NetSPI
Headquarters: Minneapolis, United States Accreditations: CREST accredited Australian owned: No
NetSPI is one of the larger dedicated offensive security firms globally, and its reputation rests largely on the Penetration Testing as a Service model. Instead of waiting for a PDF at the end, clients work through a platform where findings surface as they’re discovered, remediation gets tracked, and testing runs on a continuous cadence rather than annually. Attack surface management and adversary simulation sit alongside the core practice.
3. KPMG Australia
Headquarters: Sydney, New South Wales Accreditations: Vary by service line, confirm at engagement Australian owned: No, part of the global KPMG network
KPMG’s Australian cyber practice sits close to its assurance and regulatory advisory business, and that proximity is the point. If your CPS 234 problem is wider than testing, say a gap assessment, a control framework redesign, a board reporting uplift and a test all running at once, KPMG can wrap the lot into one engagement and speak the regulator’s language throughout.
4. PwC Australia
Headquarters: Sydney, New South Wales Accreditations: Vary by service line, confirm at engagement Australian owned: No, part of the global PwC network
PwC is strongest at the top of the house. Threat-led testing, scenario design informed by threat intelligence, and translating technical exposure into something a board can act on are all areas the firm does well. For institutions running intelligence-led red team exercises rather than scoped penetration tests, the methodology maturity and global threat research behind it are real assets.
5. Deloitte Australia
Headquarters: Sydney, New South Wales Accreditations: Vary by service line, confirm at engagement Australian owned: No, part of the global Deloitte network
Deloitte brings scale. The Australian cyber practice covers red teaming, adversary simulation, cyber risk advisory and incident response, with a large global network behind it. For complex corporate groups, an insurer with several regulated subsidiaries sharing a technology platform being the obvious example, Deloitte can staff a coordinated engagement across entities in a way smaller firms struggle to.
What About Firms Not on This List?
Plenty of capable providers aren’t here. CyberCX, Gridware, The Missing Link, InfoTrust, Content Security, IBM X-Force Red and NCC Group all do credible work in this market, and several hold CREST accreditation. The list is deliberately narrow: it covers the providers most often shortlisted specifically for APRA obligations, where the deliverable has to satisfy a prudential regulator rather than close out an internal security backlog.
If the firm you’re considering isn’t on it, run them through the eight criteria above. The framework is worth more than the ranking.
How to Choose a CPS 234 Penetration Testing Provider
Ask for a redacted sample report before you sign anything. This one request filters out more providers than everything else combined. You’re looking for reproduction steps, evidence, business impact and a remediation path. If what comes back reads like scanner output with commentary bolted on, keep looking.
Ask what proportion of testing hours are manual. Then ask what the tester actually does once the scan finishes. A vague answer is an answer.
Check independence properly. Paragraph 29 is explicit about it. If your provider designed, built or operates the control, they shouldn’t be testing it, and this trips up more organisations than you’d think, especially where an existing MSP has moved into testing services.
Find out who’s doing the work. Names, certifications, years of experience. Some firms sell with principals and deliver with graduates, and you generally find out after the engagement starts.
Get retesting in writing. Included, or quoted separately? Across a multi-year testing program that difference adds up.
Scope against critical operations. Under CPS 230 your testing scope should follow the operations that hurt most when they fail. A test covering the corporate website but not the core banking integration is a compliance artefact, not assurance.
Confirm data handling. Where test data is stored, how long it’s retained, who can access it, and how it’s destroyed when the engagement closes.
For how CPS 234 interacts with ISO 27001, PCI DSS, APP 11, the Essential Eight and the SOCI Act, our guide to penetration testing for compliance in Australia covers the overlap in detail.
This article was reviewed by cybersecurity professionals experienced in penetration testing, compliance frameworks, and Australian cyber security regulations.
Frequently Asked Questions
1. Does APRA CPS 234 specifically require penetration testing?
Not in those words. Paragraph 27 requires a systematic testing program to evaluate the effectiveness of information security controls, and paragraph 29 requires testers to be appropriately skilled and independent. Penetration testing is how regulated entities satisfy that for technical controls in practice, and it’s what APRA and internal audit expect to see as evidence.
2.How often should an APRA-regulated entity run penetration testing?
There’s no fixed interval in the standard. Paragraph 27 links frequency to how fast vulnerabilities and threats are changing, how critical and sensitive the asset is, and what happens if it’s compromised. Most regulated entities settle on annual testing for core systems with additional testing after material change, and more frequent coverage for internet-facing or high-criticality systems. Paragraph 30 then requires you to review whether that cadence is still sufficient at least once a year.
3. Does the tester have to be external?
No. CPS 234 requires independence from the design and implementation of the control, not external delivery. An internal team with genuine separation can meet it. Most entities use an external CREST-accredited provider anyway, because it’s cleaner to evidence and easier to defend when internal audit asks.
4. Why does CREST accreditation matter for CPS 234?
It independently validates a provider’s methodology, scoping, testing and reporting against a recognised benchmark. It isn’t a legal requirement under CPS 234, but it gives internal audit and APRA something concrete against the “appropriately skilled” test in paragraph 29. Defending a CREST-accredited provider is considerably easier than explaining why you picked an unaccredited one.
5. What should a CPS 234 penetration test report contain?
Scope and methodology, an executive summary a non-technical board member can follow, findings with risk ratings and business impact, reproduction steps and evidence, prioritised remediation guidance, and retest results. Mapping each finding to the control obligation it touches makes the audit conversation substantially shorter.
6. What is a penetration testing Letter of Attestation?
A short, shareable document confirming an independent test was performed, by whom, over what scope and when, without exposing the technical detail in the full report. Regulated entities use it for customer assurance requests, regulatory audits, cyber insurance applications and tender submissions. It doesn’t replace the report, which is what internal audit and APRA will want, but it saves redacting a technical document every time a counterparty asks for evidence. Not every provider issues one, so raise it during scoping rather than after.
7. How much does CPS 234 penetration testing cost in Australia?
Price follows scope, complexity and testing depth rather than the framework itself. A single web application test sits at the lower end. A multi-application, API, infrastructure and cloud engagement across a regulated entity sits well above it. Treat unusually low quotes with suspicion, since they generally indicate automated scanning rather than manual work. Ask for a day count and the seniority of the testers, not just a total.
8. Do the Big 4 have an advantage for APRA compliance work?
They have strong regulatory advisory depth and brand recognition at board level. For hands-on technical testing, specialist CREST-accredited firms frequently go deeper, turn around faster and cost less, because testing is the business rather than one line in a larger engagement. A fair number of regulated entities use both: Big 4 for program-level assurance, a specialist for the technical testing underneath it.
