HackLabs is an approved member of CREST Australia New Zealand — independently assessed against the highest standards in offensive security. When you work with HackLabs, you work with a firm that's been vetted, certified, and held accountable.
CREST is the globally recognised not-for-profit body that sets and enforces standards for the cyber security industry. CREST accreditation isn't self-declared — it requires companies and their testers to pass rigorous independent assessment covering technical competence, professional conduct, and service quality.
When you choose a CREST-accredited firm, you know the people testing your systems have the skills to do it properly — and the professional accountability to do it responsibly.
CREST approval requires passing independent technical and professional assessments — not just filling in a form.
All CREST members are bound by a strict disciplinary code. Professional accountability for every engagement.
Testers hold CREST certifications demonstrating real-world offensive security skills — not just vendor training.
Australian government agencies and regulators recognise CREST accreditation as the procurement benchmark for security testing.
All HackLabs penetration testing engagements are delivered by CREST-certified testers under our CREST-accredited quality framework.
Manual OWASP-aligned testing of web applications — auth flaws, injection, business logic, and beyond.
REST, GraphQL, and gRPC API assessment — OWASP API Top 10 and beyond.
Internet-facing attack surface assessment — from recon to full exploitation.
Active Directory attacks, lateral movement, and privilege escalation from inside your network.
iOS and Android security testing — binary analysis, runtime, API, and storage.
Full-scope adversarial engagements — physical, digital, and social engineering combined.
Many Australian government agencies, financial institutions, and regulated entities require their security testing providers to hold CREST accreditation. It's not just a quality signal — it's often a mandatory procurement requirement.
Choosing a CREST-accredited firm protects your organisation from liability risk, satisfies regulatory requirements, and ensures the firm you're trusting with your most sensitive systems is operating to a verified standard.
View HackLabs on CREST ANZ ↗Federal and state government agencies increasingly require CREST-accredited providers for security testing engagements.
APRA-regulated entities and ASX-listed companies often mandate CREST accreditation for penetration testing suppliers.
CREST-accredited testing satisfies the penetration testing controls in ISO 27001 and SOC 2 Type II audit requirements.
PCI DSS Requirement 11.4 mandates penetration testing by qualified personnel — CREST accreditation satisfies this requirement.
Approved member of CREST Australia New Zealand — independently assessed for technical competence and professional conduct.
Verify listing ↗Endorsed to deliver Essential Eight maturity assessments for Australian government agencies using ASD's official assessment guidance.
Learn more →ASD-endorsed IRAP assessors for federal and state government agencies handling PROTECTED and OFFICIAL:Sensitive data.
Learn more →Tell us about your security requirements and we'll respond within one business day.