Sooner or later most Australian businesses hear the same question from an auditor, an insurer or a big customer: “When was your last penetration test?” For a lot of business owners that question immediately raises another – do we actually need one, or is it just best practice?
The honest answer depends on which framework you’re being measured against. Some standards spell out penetration testing by name. Others describe it in different words, but still expect it as proof that your defences hold up under real pressure. At Ever Nimble, we spend a lot of time helping businesses make sense of this, so we thought it was worth setting the record straight on penetration testing compliance in Australia, framework by framework.
Let’s jump into it, so you can understand your requirements going forward and avoid over or under testing.
Why there’s confusion in the first place
Compliance frameworks weren’t written with a shared vocabulary. Some use the term penetration testing directly. Others talk about systematic testing, security testing or validating control effectiveness. Read five different frameworks trying to work out pentest compliance for your SMB in Australia, and it’s easy to come away with five different impressions.
So, let’s clear things up. Here’s what each one actually expects.
1. Does ISO 27001 require a penetration test?
Not by name. ISO 27001:2022 doesn’t use the words “penetration test” anywhere in the standard. What it does require, under Annex A 8.8 (Management of Technical Vulnerabilities) and A 8.29 (Security Testing in Development and Acceptance), is that organisations identify technical vulnerabilities and test that their controls actually work.
In practice, auditors treat penetration testing as the expected evidence for meeting these controls. If you turn up to a certification audit without any record of testing your systems the way an attacker would, It’s likely you’ll fail.
So, while the ISO 27001 penetration testing requirements aren’t spelled out word for word, a pentest is usually how businesses demonstrate they’ve genuinely met A 8.8 and A 8.29 – not just documented them.
2. Does PCI DSS require penetration testing?
Yes – and this is one of the few places where the standard is communicated clearly. Under PCI DSS Requirement 11.4, any business that stores, processes, or transmits cardholder data must carry out penetration testing at least annually, and again after any significant change to the network or application environment.
The PCI DSS penetration testing requirements call for testing of both the internal and external network, plus segmentation testing if you’re relying on network segmentation to reduce the scope of your cardholder data environment. If your business takes card payments in any capacity, this isn’t a “nice to have” – it’s a documented, recurring requirement.
3. Does APRA CPS 234 require penetration testing?
APRA CPS 234 also doesn’t use the words “penetration test” either, but it requires regulated entities to undertake “systematic testing” of their information security controls, at a frequency that matches the criticality and sensitivity of the information involved, how frequently systems change, and the speed at which vulnerabilities and threats evolve.
For most APRA-regulated entities and their third-party suppliers, penetration testing is simply the standard, accepted way of meeting that obligation. If you’re being asked about APRA CPS 234 penetration testing as part of a supplier assessment or an internal audit, this is why: a pentest is the practical evidence that your systematic testing obligation has actually been met, rather than just claimed.
4. Does the Essential Eight require penetration testing?
Again, not by name. The Essential Eight is a set of eight baseline mitigation strategies, and none of them are labelled “penetration testing.” What the framework does require is that businesses validate their maturity level, and that’s where Essential Eight penetration testing comes in.
Penetration testing is one of the most reliable ways to check whether controls like patching, application control, and restricting admin privileges are actually working the way they’re supposed to, rather than just being configured correctly on paper. Many businesses commission a pentest specifically to validate the maturity level they’re claiming, ahead of an assessment or a client due diligence request.
If you need support to meet Essential Eight compliance, see how we can help here.
5. What level of SMB1001 requires penetration testing?
SMB1001 is a tiered framework, running from Bronze through to Diamond, and penetration testing only becomes a formal requirement at the top tier. SMB1001 penetration testing sits at Diamond level, alongside independent, external verification of your controls. This is a tier enterprise customers increasingly ask suppliers to hold. If you’re currently navigating SMB1001 compliance or want to get started without the guesswork, we can help.
What this means for your business
Pull all five frameworks together and a clear pattern shows up. Some name penetration testing directly and set a hard requirement, like PCI DSS. Others treat it as the accepted way of proving a broader obligation, like APRA CPS 234, ISO 27001, and the Essential Eight. And some only require it once you’re chasing the highest level of certification, like SMB1001.
What none of them do is treat penetration testing as optional once you reach the risk profile. For most Australian SMBs, particularly those handling card payments, operating in a regulated industry, or working toward a higher-tier certification, the real question isn’t whether a pentest is required. It’s when, and how often.
This is exactly why pentest compliance for SMBs in Australia has become such a common conversation with our clients. Businesses aren’t confused about whether cyber security matters, they’re unsure which framework applies to them and what it actually expects. Getting clear on that early saves a lot of scrambling later, whether that’s ahead of a certification audit, a cyber insurance renewal, or a big customer’s due diligence questionnaire.
Remember, testing is a programme, not an event. It should be conducted annually (at a minimum), there should be retesting after fixes are implemented, and retesting after material change.
How can Ever Nimble help Australian businesses navigate pentesting requirements?
At Ever Nimble we help SMBs across Australia navigate pentesting for your framework, from whether it’s necessary to how often it should occur. Whether you need to understand where you sit against ISO 27001, PCI DSS, APRA CPS 234, the Essential Eight, or SMB1001, our team can walk you through what applies to your business and where penetration testing fits into the picture.
Why partner with us? We’re an MSP and MSSP that takes cyber security seriously. We were named MSP of the Year 2023 (Kaseya DattoCon), have ranked in the Channel Futures MSP 501 for five consecutive years, and our CEO Chris Morrissey was named WA Entrepreneur of the Year in 2025. If you’re ready for expert support that trades guesswork for peace of mind, get in touch with our team to talk through compliance obligations.
FAQs
What’s the difference between a vulnerability scan and a penetration test?
A scan finds known issues automatically; a pentest is human-led and actively tries to exploit them, which is what frameworks like PCI DSS and ISO 27001 expect as evidence.
How often do I actually need to test?
Annually at minimum under PCI DSS, APRA CPS 234 and ISO 27001 expectations, plus after any significant change to your systems.
Does Essential Eight require penetration testing?
Not by name, but ASD builds its own maturity guidance on pentesting experience, and it’s the standard way to prove your controls work in practice.
What level of SMB1001 requires penetration testing?
Diamond, the tier most often requested by enterprise customers doing supply-chain due diligence.
Do I need a penetration test if I’m not in finance or handling card payments?
Possibly yes: the Privacy Act’s “reasonable steps” obligation and client/insurer/tender requirements catch far more SMBs than people expect.
Can one test satisfy multiple frameworks?
Often yes, if scoped correctly – and this is exactly the kind of gap analysis Ever Nimble does before recommending a test.

