
The AU penetration testing market changed in February 2026. Accenture completed its acquisition of CyberCX in a deal reported at more than A$1 billion, Accenture's largest cyber security acquisition to date. CyberCX now sits inside a global professional services firm. Tesserent trades as Cyber Solutions by Thales after Thales completed its acquisition in October 2023, and is the pick for sovereign, defence, and critical infrastructure scopes.
These ownership changes are not just corporate news. For AU organisations under APRA CPS 234 or the Security of Critical Infrastructure Act, who controls the provider and where sensitive findings are handled are material procurement questions. APRA CPS 234 paragraph 28 expects "appropriately skilled and functionally independent specialists," and CPS 230 on operational risk raises careful expectations about overseas handling of sensitive data. An entity testing inside a global parent's infrastructure may create data handling considerations that did not exist twelve months ago.
Understanding who owns whom in 2026 is the starting point for every AU organisation that last evaluated their testing provider more than two years ago.
The 2026 AU Provider Landscape

The AU penetration testing market in 2026 is large but uneven. The leaders for Australian buyers are CyberCX, Tesserent, elttam, Volkis, and Gridware. Each occupies a different position.
CyberCX is now the largest provider by team size, inside Accenture, running more than 3,000 penetration tests per year across every Australian state. It suits large enterprise and critical infrastructure organisations that need full-spectrum managed security alongside testing, and are comfortable with the data handling implications of a global parent.
Tesserent under Thales is the natural fit for defence, sovereign, and SOCI Act-regulated environments where ownership and data residency are contractual requirements, not preferences.
elttam is the Melbourne research house whose consultants publish genuine offensive research. It is the specialist option for organisations that need research-led application security depth rather than enterprise delivery scale.
Volkis and Gridware serve the mid-market with strong technical execution and transparent pricing, occupying the space between boutique and enterprise scale.
For SaaS teams prioritising continuous testing, real-time findings visibility, and compliance reporting aligned to Privacy Act 2020 NZ, Privacy Act 1988 AU, SOC 2, and ISO 27001, Capture The Bug delivers CREST-certified PTaaS with a live dashboard and AU and NZ regulatory experience across both markets.
Seven Criteria That Matter in the AU Market Specifically

Australian ownership and data jurisdiction is the first. For APRA-regulated entities, the strongest fit is an Australian-headquartered, CREST-certified provider with Australian-jurisdiction handling of sensitive findings. Post the CyberCX/Accenture acquisition, asking "where are your findings stored and who has access" is a standard APRA CPS 230 procurement question, not a niche concern.
CREST accreditation at both firm and individual level is the second. The AU CREST market has 45 internationally accredited firms. CREST International and CREST ANZ are separate bodies. Verify at crest-approved.org rather than relying on marketing. The guide to CREST penetration testing in Australia covers the International vs ANZ distinction and how to verify before signing.
SOCI Act and sector-specific compliance experience is the third. The Enhanced CIRMP Rules registered in June 2026 made SOCI Act requirements more prescriptive for operators in electricity, gas, water, ports, hospitals, and financial market infrastructure. Verify the provider has experience testing in your specific sector under the Enhanced CIRMP framework, not just the original 2022 Act requirements.
Manual testing depth versus automated scanning is the fourth. A CREST-accredited firm that relies primarily on automated tools is not delivering manual penetration testing in the way the CREST standard implies. Ask directly: what percentage of findings in your last five reports were manually validated versus automated tool output?
Compliance framework alignment is the fifth. APRA CPS 234, Essential Eight, PCI DSS, ISO 27001, IRAP, and SOC 2 each create different evidence requirements. For a single application test, a boutique is usually most cost-effective. For a multi-application continuous programme, a PTaaS platform is more efficient. Match the provider to the compliance requirement, not the brand.
Retesting and remediation evidence is the sixth. ISO 27001 and SOC 2 auditors specifically look for corrective-action evidence confirming findings were remediated and re-tested. A penetration test without a structured remediation cycle produces a finding list, not the evidence auditors check. The guide to what happens after a penetration test covers the confirmed closure evidence that compliance audits require.
Engagement fit and response time is the seventh. Australians reported 84,700 cybercrimes to the ASD in 2024-25, roughly one every six minutes, and the average cost for large organisations reached A$202,700, a 219% jump in one year. A provider that takes three weeks to start a scoped engagement cannot respond at the pace the threat environment moves. Ask for time from signed scope to first finding before committing.
Three Questions Before You Shortlist

Verify the ownership structure now. The AU market consolidation of 2025 and 2026 means a provider that was Australian-owned at your last review may not be. For APRA-regulated entities, data sovereignty is a material consideration under CPS 230. For SOCI Act responsible entities, supply chain security requirements add a further layer.
Confirm CREST accreditation is current and covers penetration testing specifically, not just cyber security services broadly. Accreditation is category-specific on the CREST Marketplace and can be verified in minutes.
Ask for a sample engagement timeline, from signed scope to first finding delivered, not just time to report delivery. For AU organisations under active compliance cycles, the testing speed that actually matters is the speed from contract to findings, not from findings to PDF.
Book a scoping consultation with Capture The Bug to discuss AU compliance requirements, data jurisdiction, and whether continuous PTaaS or a point-in-time engagement is the right fit for your environment.
Book a Scoping ConsultationPlan Your Annual Pentesting Strategy the Right Way
Learn how modern SaaS companies structure pentesting across the year to reduce risk, stay compliant, and avoid last-minute panic before audits.
Your Last Pentest Is Already Out of Date
Every week you ship without continuous testing is a week a vulnerability goes unseen. See what Capture The Bug finds in your first engagement.
Frequently Asked Questions
Q1: What happened to CyberCX in Australia in 2026?
A: Accenture completed its acquisition of CyberCX in February 2026 in a deal reported at more than A$1 billion, Accenture's largest cyber security acquisition to date. CyberCX now operates as part of Accenture's global security practice. For APRA-regulated entities under CPS 230, the change in ownership creates procurement questions about data handling, data residency, and functional independence from a global parent's infrastructure that did not exist when CyberCX was Australian-owned.
Q2: What does APRA CPS 234 require from a penetration testing provider?
A: APRA CPS 234 paragraph 28 requires that testing be conducted by "appropriately skilled and functionally independent specialists." CPS 230 on operational risk raises expectations about overseas handling of sensitive data. For APRA-regulated entities, the strongest fit is generally an Australian-headquartered, CREST-certified provider with Australian-jurisdiction handling of sensitive findings. APRA expects systematic testing calibrated to how fast threats change and how critical the assets are, which implies annual testing as a floor, not a ceiling.
Q3: Which Australian penetration testing companies are CREST certified?
A: Australia holds 45 of the 510 CREST International firm-level Penetration Testing accreditations globally as of August 2026, making it the fourth-largest CREST market. Providers with CREST International firm-level accreditation include Stingrai, CyberCX, Gridware, Amaru, and Capture The Bug, among others. Verify current status at crest-approved.org rather than relying on provider marketing. CREST International and CREST ANZ are separate bodies and their registries are separate.
Q4: What is the SOCI Act and how does it affect penetration testing provider selection in Australia?
A: The Security of Critical Infrastructure Act 2018 requires responsible entities in eleven critical infrastructure sectors including electricity, gas, water, ports, telecommunications, hospitals, and financial market infrastructure to maintain and implement risk management programmes. The Enhanced CIRMP Rules registered in June 2026 made these requirements more prescriptive. SOCI Act responsible entities should confirm that their penetration testing provider has experience testing in their specific sector under the Enhanced CIRMP framework, not just general cyber security experience.
Q5: How do I compare penetration testing companies in Australia for ISO 27001 and SOC 2?
A: Any CREST-certified firm producing manual penetration test reports will produce evidence accepted by ISO 27001 certification bodies and SOC 2 service auditors. The distinction between them for ISO 27001 and SOC 2 purposes is usually about scope, delivery model, and whether retesting is included. ISO 27001 and SOC 2 auditors specifically look for corrective-action evidence confirming findings were remediated and re-tested, not just identified. A penetration test without a structured remediation and re-testing cycle does not produce the evidence auditors actually check under either framework.





