
Choosing a penetration testing provider in New Zealand used to be a fairly straightforward decision. A company needed a report for a compliance requirement, called two or three firms, picked one based on price and availability, and filed the report away until the next cycle. That process still exists, but it describes a shrinking share of how serious security decisions actually get made in 2026.
The market has matured. More NZ companies are selling into Australia, the US, and enterprise buyers who ask harder questions about security than they did three years ago. The Privacy Act 2020 raised the floor for how organisations handle personal data. And a wave of high-profile incidents has made boards and investors less willing to accept an annual report as the full picture of a company's security posture. What buyers want from penetration testing services in New Zealand has genuinely shifted, and the guide for choosing a provider needs to reflect that.
What penetration testing in New Zealand looked like before 2024
For most of the decade before 2024, the dominant model for penetration testing New Zealand organisations used was a once-a-year, fixed-scope engagement. A firm would scope the test in a discovery call, run the engagement over a few weeks, and deliver a PDF report with a list of findings ranked by severity. The company would fix the critical items, file the report, and wait for the next cycle.
This model was not bad. It found real issues. For many companies, it still does. But it was designed for products and environments that changed slowly, and it was designed to satisfy a compliance requirement rather than to give a real-time picture of a company's actual exposure at any given moment.
What has changed heading into 2026

Three things have shifted the expectations of buyers comparing penetration testing services in New Zealand.
First, most serious SaaS and tech companies now ship far faster than once a year. A test that ran in March covers a product that no longer exists by September. Buyers who understand this are asking providers how they handle the gap between a fixed test date and the product that keeps evolving after it.
Second, the customers and partners those NZ companies serve are asking more specific questions. A US enterprise customer running a security questionnaire in 2026 is not just looking for a report on file. They are asking whether testing is ongoing, whether retests are documented, and whether findings are tracked through to verified remediation. A single annual PDF does not satisfy that level of scrutiny the way it once did.
Third, CREST certification has gone from a nice-to-have to a near-requirement for any engagement where the report is going to be used with an overseas customer, a financial institution, or a regulated buyer. The certification confirms that the testers have passed rigorous independent assessment and that the methodology meets a recognised global standard.
What a 2026 buyer should actually be evaluating

When comparing penetration testing New Zealand providers in 2026, these are the questions that actually change the outcome rather than just the paperwork.
- How quickly do findings get delivered? A finding that arrives in a PDF six weeks after testing ended is less useful than one that reaches the engineering team while the feature is still being worked on. Faster delivery means faster fixing, which means less time spent exposed.
- Is retesting included or billed separately? This single question separates a genuine service from a one-and-done engagement. A finding is not resolved until a retest confirms the fix worked. If that costs extra every time, the incentive to retest thoroughly is quietly reversed.
- What does the scope actually cover? For most NZ SaaS products, the highest-risk surface is the APIs that power the product and the access controls behind them. A penetration testing service that treats APIs as a core part of scope rather than an add-on is going to find materially different things from one that focuses primarily on web application front-ends.
- Can the report be used for compliance evidence? Different frameworks ask for different things. A buyer who needs evidence for SOC 2 and also wants to satisfy the NZ Privacy Act's accountability obligations needs a report structured to address both, not a generic findings list.
Your Last Pentest Is Already Out of Date
Every week you ship without continuous testing is a week a vulnerability goes unseen. See what Capture The Bug finds in your first engagement.
Book a demo
For any NZ company comparing providers or trying to work out whether a current engagement actually covers what matters most in 2026, a direct conversation is faster than another round of quotes. Book a demo with Capture The Bug and see exactly what scope, delivery format, and reporting structure fits the specific product and compliance picture.
What CREST certification actually means for NZ buyers

CREST membership is not a guarantee of a good test. It is a guarantee that the firm and its testers meet a minimum standard of demonstrated competence, ethical conduct, and methodology that has been independently verified. For buyers comparing penetration testing services in New Zealand, that baseline matters because the alternative is trusting a self-described expert with no external verification of their claims.
For any engagement whose report will be used with overseas customers, investors, or regulated buyers, CREST certification on the provider's side significantly reduces the risk that the evidence gets challenged on quality grounds. Capture The Bug holds CREST certification and applies that standard across every engagement, including the continuous penetration testing service model that an increasing number of NZ companies are moving toward as the annual snapshot approach becomes less adequate.
The Privacy Act angle most buyers overlook
The Privacy Act 2020 places a direct obligation on New Zealand organisations to take reasonable steps to protect personal information. A penetration test is one of the most direct forms of evidence that those reasonable steps are being taken, and regulators and courts have increasingly looked at whether security testing was conducted and how recent it was when assessing whether an organisation met its obligations following an incident.
For NZ companies with any volume of customer or employee personal data, this makes the frequency and quality of penetration testing a legal consideration, not just a commercial one. A once-a-year test may satisfy the minimum, but for a company shipping new data-handling features regularly, a continuous testing program produces a far stronger evidence trail.
Plan Your Annual Pentesting Strategy the Right Way
Learn how modern SaaS companies structure pentesting across the year to reduce risk, stay compliant, and avoid last-minute panic before audits.
FAQ
What should a NZ company look for in a penetration testing provider in 2026?
The most important factors are CREST certification from the provider, clear scope coverage that includes APIs and access controls, fast finding delivery rather than a single end-of-engagement report, included retesting rather than separately billed follow-up, and a report structured for the compliance frameworks the company actually needs to satisfy.
Is CREST certification required for penetration testing in New Zealand?
It is not legally required by default, but it is increasingly expected by overseas customers, financial institutions, and regulated buyers who use the report. It also provides independent assurance that the tester's methodology and competence meet a recognised global standard.
How does the Privacy Act 2020 affect penetration testing decisions for NZ organisations?
The Privacy Act places an obligation on organisations to take reasonable steps to protect personal information. Penetration testing is one of the most direct ways to demonstrate those steps are being taken, and regulators look at the frequency and quality of testing when assessing incidents.
How much does penetration testing cost in New Zealand?
Cost depends heavily on scope. A broad full-application engagement costs more than a focused test on specific APIs or high-risk workflows. For many growing companies, a continuous model spread across the year works out cheaper per unit of coverage than a single large annual engagement, once retesting and compliance evidence are factored in.
What is the difference between a traditional annual pentest and a continuous penetration testing service?
A traditional pentest tests a product on one specific date and produces a single report. A continuous service tests the product as it changes, delivers findings as they are confirmed, includes retesting, and produces a running evidence trail rather than a snapshot.





