
When an enterprise security questionnaire asks whether your penetration testing provider is CREST certified, most security leaders assume there is one answer. There are actually two possible answers in Australia, and they are not the same thing.
The formal relationship between CREST International and CREST ANZ ended at the end of April 2019. CREST ANZ has not adopted CREST International's accreditation standards, and CREST International does not recognise CREST ANZ membership alone as equivalent. Both bodies operate in Australia. Both issue credentials described as CREST accreditation. A procurement specification that says "CREST certified" without specifying which body could be satisfied by either, or neither, depending on the reading.
Understanding what each body actually validates, and how to verify a provider's current status, is the most practical thing an Australian buyer can do before selecting a penetration testing partner.
What CREST International Accreditation Validates

CREST International is the UK-founded global body. Exactly 510 companies worldwide hold CREST's firm-level Penetration Testing accreditation. Australia has 45 of those accredited firms, making it the fourth-largest CREST International market behind the UK with 202, the United States with 51, and Singapore with 50.
Firm-level CREST International accreditation means the company itself has been audited against CREST's standards, covering governance, methodology, quality assurance, and internal security practices. Individual CREST International certification, such as CREST Registered Tester (CRT) or Certified Penetration Testing Engineer, means specific testers within the firm have passed hands-on examinations. Unlike multiple-choice certifications, CREST exams require testers to identify and exploit real vulnerabilities, validating actual penetration testing competency rather than theoretical knowledge.
These two levels operate independently. A firm with firm-level accreditation may employ testers who have not individually passed CREST examinations. An individual tester with CREST certification may work for a firm that does not hold firm-level accreditation. When evaluating a provider, ask for both: company-level accreditation status and the individual certifications held by the testers who will actually conduct your engagement.
On 28 July 2026, CREST added Domain 7, Responsible AI Use, to its requirements for all accredited providers, plus an optional Annex B covering AI-enabled penetration testing. This update applies to all CREST International accredited firms and reflects the expanding role of AI tooling in security assessments.
What CREST ANZ Accreditation Validates
CREST ANZ is the leading sovereign not-for-profit body dedicated to certifying cybersecurity professionals and approving service providers across Australia and New Zealand. CREST ANZ accreditation validates that the company has the right governance, methodologies, and security practices to deliver quality services.
In 2020, CREST ANZ developed a multi-dimensional accreditation programme for individual penetration testers, called the ABPT programme, assessing Technical Competency, Professional Competency, and Trust Standards developed by CREST ANZ members. The ABPT programme is open to individual testers from both member and non-member companies.
CREST ANZ approved companies are listed on the CREST ANZ website. CREST International accredited companies in Australia and New Zealand are listed on the CREST Marketplace at crest-approved.org. These are two separate registries. Searching one does not verify status on the other.
When Each Accreditation Matters for Australian Buyers

For most Australian enterprise procurement and compliance purposes, the relevant question is which body the specific requirement references. The answer varies by framework.
APRA-regulated entities, government agencies operating under the Essential Eight framework, and enterprises in critical infrastructure sectors increasingly mandate CREST certification as a minimum provider qualification. Government procurement specifications and enterprise RFPs in Australia commonly reference CREST without specifying the body, which creates the ambiguity that buyers need to resolve before they can evaluate a quote.
For APRA CPS 234 compliance, the requirement is for independent systematic testing of security controls by a qualified provider. CREST International accreditation at the firm level is the strongest independent evidence of provider qualification that APRA supervisors recognise. For the broader compliance evidence chain that connects penetration testing to regulatory requirements, the guide to continuous penetration testing for SOC 2 and ISO 27001 compliance covers how testing evidence from a CREST-accredited provider connects to control documentation that auditors accept.
For SOC 2 and ISO 27001 purposes, both accreditations provide credible evidence that the provider meets recognised quality standards. SOC 2 auditors and ISO 27001 certification bodies primarily care that the testing was conducted by a provider with validated methodology and individual tester competency, rather than the specific CREST body. Either accreditation satisfies this requirement, provided the provider can show both firm-level and individual-level credentials.
For government or IRAP-adjacent procurement, different requirements apply entirely. IRAP assessors are endorsed by the ASD under the Australian Government Information Security Manual, which is a separate accreditation pathway from both CREST bodies.
How to Verify a Provider's CREST Status Before Signing

CREST accreditation is one of the most repeated and least verified claims in security procurement, and the gap between the firms that hold it and the firms that imply it is wide.
Verification takes two steps. For CREST International status, search the CREST Marketplace at crest-approved.org for the provider's exact company name. For CREST ANZ status, search the CREST ANZ Approved Companies directory at crestaustralia.org. Both are publicly searchable and current.
Ask the provider: which body accredited them, which service category the accreditation covers (penetration testing is specific, not all security services), and the individual CREST certification status of the testers conducting your engagement. A provider who cannot answer all three has not been asked them enough. Some providers hold dual accreditation from both bodies, removing the ambiguity entirely for organisations with both domestic and international requirements.
The guide to what happens after a penetration test covers the remediation and re-testing cycle that determines whether a CREST-accredited report actually improves your security posture. A CREST report that closes as a PDF is worth less than one that produces a confirmed remediation cycle.
Book a consultation with Capture The Bug to confirm CREST accreditation status and scope for your specific engagement requirements.
Book a ConsultationPlan Your Annual Pentesting Strategy the Right Way
Learn how modern SaaS companies structure pentesting across the year to reduce risk, stay compliant, and avoid last-minute panic before audits.
Your Last Pentest Is Already Out of Date
Every week you ship without continuous testing is a week a vulnerability goes unseen. See what Capture The Bug finds in your first engagement.
Frequently Asked Questions
Q1: Is CREST ANZ the same as CREST International in Australia?
A: No. CREST International and CREST ANZ are two separate bodies. Their formal relationship ended in April 2019. CREST International has explicitly stated that CREST ANZ membership alone is not recognised as equivalent to CREST International accreditation. Both bodies issue credentials described as CREST accreditation in Australia. When a procurement specification requires a CREST-certified provider, it is important to confirm which body the requirement references, as the two registries are separate and a firm listed on one does not automatically appear on the other.
Q2: How do I verify that a penetration testing provider is CREST accredited in Australia?
A: To verify CREST International status, search the CREST Marketplace at crest-approved.org for the provider's exact company name. To verify CREST ANZ status, search the CREST ANZ Approved Companies directory at crestaustralia.org. Both registries are publicly searchable. Also ask the provider which body accredited them, which service category the accreditation covers (penetration testing is a specific category), and the individual CREST certification status of the testers conducting your engagement.
Q3: Does APRA require CREST certified penetration testing in Australia?
A: APRA CPS 234 requires APRA-regulated entities to maintain information security capabilities commensurate with their threat exposure, including systematic testing of security controls. CREST International firm-level accreditation is the strongest independent evidence of provider qualification that APRA supervisors recognise. APRA does not mandate CREST accreditation by name, but APRA-regulated entities in banking, insurance, and superannuation that select non-CREST providers carry a higher evidential burden to demonstrate provider quality during supervisory review.
Q4: What did CREST add to its requirements in July 2026?
A: On 28 July 2026, CREST added Domain 7, Responsible AI Use, to its general requirements for all accredited providers. An optional Annex B covering AI-enabled penetration testing was also added. This update applies to all CREST International accredited firms and reflects the expanding use of AI tooling in security assessments. Providers accredited by CREST International now need to demonstrate responsible AI use practices as part of their accreditation, in addition to the existing six domains covering governance, methodology, quality assurance, and tester competency.
Q5: Does the Essential Eight require CREST penetration testing in Australia?
A: The ACSC Essential Eight does not explicitly mandate penetration testing as one of its eight mitigation strategies, and it does not specify CREST accreditation as a requirement. However, organisations demonstrating higher Essential Eight maturity levels and those in government or critical infrastructure sectors increasingly use CREST-accredited testing as evidence that security controls function as intended. Government procurement specifications and enterprise RFPs in regulated sectors commonly specify CREST certification as a minimum provider qualification, making it a practical requirement for providers serving these markets.





