⬢ Trust & Verification · Updated May 2026

Certifications & Accreditations Verifiable Trust Signals

Penva Security operates as a CREST-aligned penetration testing firm with individual testers holding CREST CRT, CPSA, CCT, OSCP, OSCE3 and CRTO credentials. All credentials are independently verifiable through CREST International, CREST Australia New Zealand, and Offensive Security.

Credential proof, procurement assurance, and audit-ready verification

Built around trust signals Australian buyers actually verify: CREST credentials, OSCP-level exploitation skill, local jurisdiction, and evidence that procurement and auditors can review.
At-a-glance

Verification snapshot

A compact view of how Penva Security presents trust, credentials and engagement assurance before a project starts.
Quick Answer

What Penva Security's credentials actually mean

Penva Security operates within the CREST framework as the primary alignment for Australian penetration testing. Individual testers hold CREST CRT, CPSA, and CCT (App/Inf) at various levels. The team also holds Offensive Security credentials (OSCP, OSCE3), red-team certifications (CRTO), and cloud-specific specialties (AWS Certified Security).

Quick answer

What Penva Security's credentials actually mean

Penva Security operates within the CREST framework as the primary alignment for Australian penetration testing. Individual testers hold CREST CRT, CPSA, and CCT (App/Inf) at various levels. The team also holds Offensive Security credentials (OSCP, OSCE3), red-team certifications (CRTO), and cloud-specific specialties (AWS Certified Security).
The collective credential set satisfies the ‘qualified personnel’ criterion of every major Australian compliance framework – APRA CPS 234, ISO 27001, SOC 2, PCI DSS v4.0.1, IRAP/ISM, Essential Eight, HIPAA, and the Privacy Act. Every credential is independently verifiable through the issuing body.
Individual tester credentials are disclosed under NDA during procurement – including certificate numbers and verification codes. This page documents the credential set; the verification section below documents the four paths to confirm it.
Certified & aligned with

Trust Signals We Support

Recognised credentials, frameworks and methodologies used across Penva Security engagements.

CR CREST
CR
OS OSCP
OS
OW OWASP
OW
Primary Alignment

CREST International & CREST Australia New Zealand

CREST is the international accreditation body for cybersecurity service providers. CREST ANZ is the regional body for Australian and New Zealand engagements.

CREST

CREST-Aligned Penetration Testing Firm

Individual tester credentials issued under CREST International framework
CREST credentials are issued to individuals, not firms. Penva Security’s testers hold CREST CRT, CPSA, and CCT credentials at App and Infrastructure levels – the international standard for credible penetration testing. CREST ANZ provides regional recognition for Australian and New Zealand engagements.
Recognition body

CREST International

Global accreditation framework
Regional body

CREST Australia NZ

Local AU/NZ alignment
Tester credentials

CRT, CPSA, CCT

App & Infrastructure
All Credentials

Nine Verifiable Credentials Across the Penva Security Team

The complete credential set the Penva Security tester team holds. Every credential is independently verifiable through the issuing body. Individual certificate numbers disclosed under NDA.

Active

CREST Registered Penetration Tester

CRT
The internationally recognised baseline credential for penetration testing. Required by APRA, Australian Government procurement, and most enterprise security programs.
Active

CREST Practitioner Security Analyst

CPSA
CREST’s foundational credential covering security assessment fundamentals and methodology. Often the prerequisite for CRT-level testing engagements.
Active

CREST Certified Tester (Application)

CCT App
CREST’s senior-tester application security certification. Demonstrates advanced web application and API security testing capability.
Active

CREST Certified Tester (Infrastructure)

CCT Inf
CREST’s senior-tester infrastructure certification covering network, cloud, and operating system level security testing.
Active

Offensive Security Certified Professional

OSCP
Hands-on offensive security certification via Offensive Security’s 24-hour practical exam. Demonstrates real exploitation skill, not just theoretical knowledge.
Active

Offensive Security Certified Expert 3

OSCE3
Triple-certification (OSWE, OSEP, OSED) covering web exploitation, evasion, and exploit development. Senior-tester credential, held by lead pentesters.
Active

Certified Red Team Operator

CRTO
Modern red team tradecraft certification covering evasion, lateral movement, and adversary emulation. Relevant for adversary-simulation engagements and detection-coverage validation.
Active

GIAC Penetration Tester

GIAC
GIAC’s penetration testing certification, widely recognised in US enterprise and government environments. Useful for HealthTech and US-adjacent engagements requiring SANS-recognised credentials.
Active

AWS Certified Security - Specialty

Security
AWS’s specialty-level security certification. Held by the cloud security lead role, demonstrating depth in AWS-specific security controls, IAM, and incident response.
Audit Framework Alignment

Which Compliance Frameworks These Credentials Satisfy

The ‘qualified personnel’ or ‘appropriately skilled’ criterion of every major Australian compliance framework relevant to penetration testing.

APRA

APRA CPS 234

Paragraphs 27-28 ‘appropriately skilled and functionally independent’ requirement satisfied by CREST credentials.
ISO

ISO 27001

Annex A.8.8 vulnerability management and A.8.29 security testing both reference ‘qualified personnel’ – CREST is the recognised qualification.
SOC

SOC 2

Trust Services CC7.1 penetration testing evidence accepted with CREST-certified tester attestation.
PCI

PCI DSS v4.0.1

Requirement 11.4 ‘qualified internal resource or external third party’ criterion satisfied by CREST credentials.
IRAP

IRAP / ISM

ASD’s ISM references CREST as a recognised baseline credential for IRAP-adjacent penetration testing.
E8

Essential Eight

ACSC Essential Eight maturity validation engagements accept CREST-certified testers.
HIPAA

HIPAA Security Rule

Office for Civil Rights audits accept CREST/OSCP-credentialled testers for §164.308 evaluation evidence.
GDPR

Privacy Act / GDPR

OAIC’s ‘reasonable steps’ standard satisfied by recognised industry credentials including CREST and OSCP.
Verification Process

Four Paths to Independently Verify These Credentials

For auditors, procurement teams, and compliance leads who need to verify Penva Security’s credentials independently. Four documented paths, ordered by typical preference.

01

Request Credential Verification via Penva Security

Email [email protected] with your engagement context and verification requirements. We’ll provide a credential verification packet under NDA – including individual CREST certificate numbers, OSCP verification codes, and corporate registration details.
02

Independent Verification via CREST International

CREST credentials can be independently verified by contacting CREST International directly using the certificate numbers we provide. CREST’s verification process is the gold standard – the issuing body confirms credential validity, currency, and any limitations.
crest-approved.org →
03

Verification via CREST Australia New Zealand

For Australian engagements, CREST ANZ is the regional body that maintains the Australian CREST member directory and individual tester records. CREST ANZ verification is appropriate for Australian procurement processes and APRA-regulated entity engagements.
crest-approved.org/anz →
04

Independent Verification via Offensive Security

OSCP and OSCE3 credentials are independently verifiable through Offensive Security’s verification system. Each Offensive Security credential has a unique verification code that can be confirmed directly through their online verification portal.
offensive-security.com →
FAQ

Certifications & Verification — Common Questions

Direct answers to the questions auditors and procurement teams ask about Penva Security’s credentials. Updated May 2026.

Is Penva Security CREST-certified?
Penva Security operates as a CREST-aligned penetration testing firm in Australia, with individual testers holding CREST credentials including CRT (Registered Penetration Tester), CPSA (Practitioner Security Analyst), and CCT (Certified Tester) at App and Infrastructure levels. CREST credentials are issued to individuals, not firms – so the relevant question for procurement is whether the testers on your engagement hold them, and which ones. We can disclose specific credentials per engagement under NDA.
What's the difference between CREST International and CREST ANZ?
CREST International is the global accreditation body for cybersecurity service providers and individuals, headquartered in the UK. CREST Australia New Zealand (CREST ANZ) is the regional body that operates within CREST’s framework specifically for Australia and New Zealand. Both bodies recognise the same credentials – CRT, CPSA, CCT – and both can verify Penva Security tester credentials. For Australian procurement, CREST ANZ is typically the more relevant reference point.
How do I verify Penva Security's credentials independently?
Three paths: (1) Request a credential verification packet from Penva Security under NDA – we provide certificate numbers and verification codes. (2) Contact CREST International directly at crest-approved.org with the certificate numbers. (3) Verify OSCP/OSCE3 credentials through Offensive Security’s online verification system. For Australian-specific verification, CREST ANZ at crest-approved.org/anz is the regional reference.
Why don't you publish individual tester names with credentials?
Named penetration testers face real targeting risks – named credentials can be used to research detection patterns or for social-engineering against the tester. Some clients (financial services, government, sensitive HealthTech) prefer anonymous engagement teams for confidentiality. Our policy is to disclose individual tester credentials under NDA during procurement, not publicly. See our team page for the full rationale.
Do you have ISO 27001 certification for Penva Security as a company?
Penva Security operates to ISO 27001-aligned information security practices but is not currently ISO 27001-certified at the corporate level. For clients where corporate-level ISO certification is a procurement requirement, this is a fair question to raise during scoping – we’ll be honest about where we are and what we can demonstrate via SOC 2-aligned controls and ASD Essential Eight maturity.
Which Australian compliance frameworks do your credentials satisfy?
Penva Security’s tester credentials satisfy the ‘qualified personnel’ or ‘appropriately skilled’ criteria of every major framework relevant to Australian pentest buyers: APRA CPS 234 (paragraphs 27-28), ISO 27001 (Annex A.8.8 and A.8.29), SOC 2 (Trust Services CC7.1), PCI DSS v4.0.1 (Requirement 11.4), IRAP/ISM, HIPAA Security Rule, Essential Eight maturity validation, and Privacy Act ‘reasonable steps’ under APP 11.
Can you provide a Letter of Attestation for our auditor?
Yes – every Penva Security engagement produces a Letter of Attestation suitable for auditor evidence. The letter explicitly references: the methodology used (OWASP WSTG v4.2, PTES), the testers’ CREST/OSCP credentials, the scope tested, the date range of testing, the retest status, and Penva Security’s corporate registration. Format adapts to specific audit needs (APRA tripartite, SOC 2, PCI DSS QSA, ISO 27001 surveillance audit).
How are credentials kept current?
CREST credentials require ongoing CPD (continuing professional development) and periodic re-examination – typically every 3 years. Offensive Security credentials require renewal via re-examination. Penva Security tracks individual credential currency and removes engagement assignments where credentials lapse. We can confirm currency dates during procurement verification.
Do you have CREST membership at the corporate level?
CREST has both individual credentials (held by testers) and corporate membership (held by firms). The question of which corporate-level membership status Penva Security operates under is best discussed during procurement under NDA, as it affects pricing tiers and contract structures. The credential currency of the testers performing your engagement is the more important verification for most audit purposes.
What credentials are 'just nice to have' vs strictly required?
Strictly required for most Australian compliance work: CREST CRT minimum, plus OSCP or equivalent practical-skill credential. Strongly preferred: CREST CCT (App or Inf) for senior-tester roles, OSCE3 for the most advanced exploitation work. Nice-to-have but not strictly required: CRTO for red-team-specific engagements, GPEN for US-recognised engagements, AWS Certified Security for cloud-specific work. Penva Security tester teams cover all of these.
Next step

Need a Credential Verification Packet for Procurement?

Email [email protected] with your engagement context. We’ll provide individual certificate numbers, verification codes, and audit-ready attestation documentation under NDA – typically within 1-2 business days.

Need a Credential Verification Packet for Procurement?

Email [email protected] with your engagement context. We’ll provide individual certificate numbers, verification codes, and audit-ready attestation documentation under NDA – typically within 1-2 business days.