CyberCX Alternative: AU Pentest Options Compared 2026
Two Australian pentest delivery models, compared by one of the providers. Read it accordingly.
If you are searching for a CyberCX alternative, you are almost certainly not shopping for a security philosophy. You have a deadline, a scope you half understand, and a budget you cannot size because nobody publishes a number. This is a comparison of two Australian penetration testing delivery models, written by one of the providers, with the conflict of interest declared before the first claim rather than buried in a footer.
The Questionnaire Line That Starts This
It usually arrives on a Thursday. An enterprise prospect, or an insurer, or a customer's procurement team sends through a security questionnaire, and somewhere around question 40 sits the line that turns a good week into a project:
"Has an independent third-party penetration test been performed within the last 12 months? Please attach the report."
You are the CTO or the security lead at an Australian mid-market SaaS company. You have maybe three weeks before the deal review. You do not have a report. So you do what everyone does: you open a browser and start searching. What comes back is a page of vendor-written listicles, each ranking itself favourably, plus a handful of cost guides quoting a range so wide it cannot become a budget line. By the third one you have stopped reading and started scanning for the one thing none of them will tell you: what any of these firms actually charges.
That is the actual problem with this category. Not quality, and not credentials: the Australian market is well served by capable firms. The problem is that almost nothing about the purchase is visible until you have given a vendor your contact details and sat through a scoping call, by which point a week of your three is gone.
So before anything else, the disclosure:
We are one of the providers in this comparison. That should change how you read it, so here is how we have handled it: every claim we make about ourselves is one you can check on a page we publish, and every claim about CyberCX is limited to what it publishes. Where CyberCX is a better fit than us, we say so.
That last clause is not a rhetorical flourish. There is a section below on when CyberCX is the right call, including one case where we are categorically not eligible for the work. A comparison that concludes "buy from us in all circumstances" is not a comparison. It is an ad with a table in it.
The Two Models (Not the Two Companies)
The honest axis here is not brand against brand. It is delivery model, because these options are not two grades of the same purchase. They are different purchases that happen to produce a document with a similar name on the cover.
Say it plainly, because the rest of this post depends on it: a bespoke consulting engagement and a productised report are different things to buy. Comparing their prices without comparing their models is how buyers end up disappointed by a purchase that was never designed to do the thing they needed.
The difference shows up first in the calendar, before it ever shows up in the invoice:
What You Can Verify Before You Buy
Here is the part most comparison posts skip, and it is the only part that helps you in a three-week window. Forget rankings. Ask instead: what can I confirm about this vendor before I enter a sales process? Four questions do most of the work.
1. How is the price determined? This is the one that decides whether you can plan. We publish ours: AUD $7,999 ex GST for a single on-demand report, listed on /pricing alongside the larger on-demand tiers and the subscription plans, with the same endpoint bands and prices repeated on the request form. CyberCX's penetration testing guide says cost depends on scope and follows a consultation. That is a normal consulting model; it simply calls for a different buying process.
2. Can you estimate your own scope? Related but distinct. With a productised model you multiply targets by frequency and land on a tier: Standard covers up to 50 endpoints, Comprehensive covers 51 to 150, and beyond that the scope is custom. Those bands are published on /pricing and the request form, and the pentest cost calculator does the arithmetic for you, so you can size the purchase in a browser tab at 11pm without booking anything. For a consulting engagement, ask the firm to confirm how it will define the scope and whether that approach suits your environment.
3. Is the evidence standard published? This is the question sophisticated buyers ask and almost nobody else does, and it matters more every year as AI enters testing. We publish ours: every finding carries the actual HTTP request and response that produced it, step-by-step reproduction instructions, and a SHA-256 proof hash computed over that captured request and response, shown against the finding in the platform. The signed report itself carries a document-level content hash recorded at the moment of signing, alongside the signer's name, credential and signing date. Be precise about what each of those does. The proof hash lets you check a specific piece of evidence against the capture we retain; the document hash records the state of the report when it was signed. Neither is a third-party timestamping notarisation, and the assurance that the capture is genuine in the first place rests on the independence of the party who ran the test and put their name on it. Ask every provider for a representative evidence specification before you buy; the answer is more useful than an assumption about how a particular team works.
4. Is the report independently signed? Ask every provider whether the final report is signed by a named certified security professional outside your organisation. That is what a questionnaire asking for an independent third-party assessment is testing.
| What you can check before buying | CyberCX | CyberOrbit |
|---|---|---|
| Price approach | Its guide says pricing follows consultation and scope | Yes: AUD $7,999 ex GST on /pricing |
| Scope approach | Ask how the firm will define your scope | Yes: targets x frequency, published tiers |
| Per-finding evidence standard | Ask for a representative evidence specification | Yes: captured HTTP request/response, repro steps, SHA-256 proof hash |
| Independent third-party signed report | Confirm with the provider | Yes: a named certified security professional reviews and signs the report |
Three of those four rows are about visibility, not capability. That distinction is the whole point. You are not choosing between a good vendor and a bad one. You are choosing the purchase that fits what you are buying it for.
See what your external surface exposes, mapped to the controls it touches.
Run a free External Security Check →Where Each One Is the Right Answer
When CyberCX is the right call
Start with the clearest case, because it is not close.
If you need an IRAP assessment or government-grade work, that is a specialist engagement and a different purchase. We do not provide it. If your buyer requires assessment against the Information Security Manual by an endorsed assessor, you should be talking to an IRAP provider.
Beyond that, several situations call for a bespoke consulting engagement: novel or very large scopes, complex trust boundaries, systems that do not resemble anything a productised test was designed around, sovereign and defence scopes with clearance requirements, or a buyer who needs a preferred supplier or established vendor relationship.
What we publish tiers for is scoped, evidence-backed testing of systems: applications, APIs and the infrastructure behind them. A red-team exercise, social engineering or physical testing is not on our price list at all, and pretending otherwise would waste your three weeks. If that is the work, start with a scoping conversation rather than a form.
When CyberOrbit fits
Our case is narrower and more specific: the recurring, compliance-triggered test. You need a report because your SOC 2 or ISO 27001 auditor expects one as evidence, PCI DSS v4.0.1 requires one under Requirement 11.4, or an enterprise customer's questionnaire asks for one. The scope is a web application and its API. The environment is not exotic. What you want is a known price, a known date, and an independent signed report that survives an auditor reading it closely. That is the purchase we built for buyers who value published scope and pricing.
Set side by side, what the productised model gives you and what it asks you to give up:
- What the productised model (CyberOrbit) gives you: a published price and a self-estimable scope, so the purchase can be sized tonight without a call
- A 48-hour target from scope sign-off to a signed independent report, with no scoping stage in the critical path, and up to four business days where human sign-off queues
- A published per-finding evidence standard: captured HTTP request and response, reproduction steps, and a SHA-256 proof hash over that capture
- A retest included with every on-demand tier, so fixing what we found does not start a second quote
- A repeatable cadence for compliance-triggered testing, one-off or continuous, at the same known price each time
- What you give up with a productised service: a bespoke consulting engagement may suit novel architecture and complex business logic better
- IRAP and government-grade assessment, work we do not perform
- Expert scoping applied to complex, unusual or very large environments before any testing begins
- Preferred-supplier standing and brand recognition that answer board-level procurement questions price transparency does not
- Stated scale and specialist breadth for complex, bespoke assessments
What the Report Has to Contain
Whoever you pick, the deliverable is the thing you actually bought. Here is a vendor-neutral checklist you can send to every firm on your shortlist, including us. If a vendor cannot answer these nine, that is information.
We wrote more on why point 4 and point 6 are becoming the deciding questions in what auditors now ask about AI-assisted pentest reports. Send the list. Compare the answers side by side. It is a better filter than any listicle, ours included.
Compliance Mapping
Most mid-market buyers are not testing for its own sake. They are testing because a framework told them to, which means the report's cross-references determine whether it does its job.
Be specific about this, because "maps to every framework" is a claim buyers should refuse to accept without a control table behind it. The CyberOrbit signed report carries a compliance control appendix for the framework you select at scoping. The frameworks with a real control table today are SOC 2, ISO/IEC 27001:2022, PCI DSS v4.0.1, HIPAA, GDPR, Cyber Essentials and Cyber Essentials Plus, ISO/IEC 42001, BSI C5 and ENS. Independently of that selection, every finding carries its own CWE and OWASP Top 10 category. The practical effect is that one assessment feeds several audits rather than one, and your remediation backlog and your audit evidence come out of the same artefact instead of being reconciled by hand in audit week.
Three framework caveats, stated up front rather than discovered at delivery:
- NIS2 and DORA. The signed report does not carry a NIS2 or DORA control appendix. Testing evidence is still useful against both obligations, for the reasons set out below, but you will be mapping it to your own obligation register rather than reading a cross-reference off our document. If you need that appendix, say so at scoping and we will tell you honestly that it is not built yet.
- Essential Eight. The signed report does not carry an Essential Eight control appendix either. E8 output today lives in our free External Security Check, as a gap checklist. That checklist is deliberately conservative: six of the eight mitigation strategies (application control, Office macro configuration, restricting administrative privileges, patching operating systems, multi-factor authentication and regular backups) are endpoint, identity and backup controls that are structurally invisible to any external assessment, so the checklist marks them "cannot be checked from outside" rather than scoring them. Two produce a partial external signal: patching applications, where internet-facing software discloses a version with a known CVE, and user application hardening, via response security headers. Both are partial views of the control, not coverage of it.
- IRAP. None of the above is an IRAP assessment or government-grade assurance. We do not provide IRAP assessments or claim to.
If E8 is the specific reason you are here, read Essential Eight penetration testing for Australian businesses for the framework treatment, and hold any vendor, us included, to the control-table test above.
Framework by framework, here is what the mapping actually does for you:
How does the report map to SOC 2?
One honest note on how auditors use it. A penetration test is one input, not a control in itself, and your auditor will decide which criteria it supports in your environment. Many treat it as evidence toward CC4.1 as well, as a separate evaluation of control effectiveness. Our appendix does not assert CC4.1, so do not expect to read that cross-reference off the document. The parts that carry the most weight with an auditor are the independence statement, the named signer, and evidence they can trace back to a captured request and response rather than a claim. See what SOC 2 actually requires of a penetration test for the full treatment.
How does the report map to PCI DSS v4.0.1 Requirement 11.4?
Where we fit, precisely: an external web application and API assessment addresses 11.4.3, is documented against 11.4.1, and the included retest supports 11.4.4. It does not discharge 11.4.2 internal testing, and it does not perform segmentation testing under 11.4.5 or 11.4.6. Those are separate exercises, and any vendor implying one external test closes all of 11.4 is a vendor your QSA will correct. Our detailed walkthrough is in PCI DSS 4.0 penetration testing requirements.
How does the report map to ISO 27001 Annex A control A.8.29?
The cross-reference matters at surveillance audit time: a finding mapped to the control it affects lets you show the auditor the test, the result and the remediation from a single document rather than reconstructing the chain across three systems.
How does testing evidence support NIS2 if we sell into the EU?
NIS2 is a directive, so the obligations that actually bind you are the national laws transposing it, and those differ by member state. The directive itself places cybersecurity risk-management obligations on essential and important entities, including, at Article 21(2)(f), policies and procedures to assess the effectiveness of risk-management measures. Independent testing evidence is one of the standard ways organisations demonstrate that assessment. Article 20 puts approval and oversight of those measures on management bodies personally, which is why the report needs an executive summary legible to people who are not engineers. Note also that if you are a supplier rather than an in-scope entity, NIS2 tends to reach you through your customer's supply-chain security obligations at Article 21(2)(d) rather than directly. The details are in NIS2 penetration testing requirements.
How does testing evidence support DORA for financial entities?
DORA applies directly to EU financial entities. It sets up a digital operational resilience testing programme (Articles 24 and 25) covering regular testing of ICT tools and systems, and separately an advanced threat-led penetration testing regime (Articles 26 and 27, built on TIBER-EU) that applies only to entities identified for it by their competent authority. TLPT is a specialist exercise with its own provider requirements, and it is not what a productised web application assessment is.
If you are a mid-market SaaS company reading this, the likely position is that DORA does not apply to you directly at all. You are an ICT third-party service provider, and DORA reaches you through the contractual terms your financial-entity customer must impose under Article 30, which can include cooperating in their testing. Critical ICT third-party providers additionally fall under the EU Oversight Framework, which is a designation made by the European Supervisory Authorities rather than something you opt into. Getting this distinction right matters, because the obligation you are being asked to evidence is usually your customer's, pushed down a contract. See DORA penetration testing requirements for which obligations attach to whom.
What does CyberOrbit actually give me against the Essential Eight, and is it IRAP-grade?
The signed report does not carry an Essential Eight control appendix. What exists today is the Essential Eight gap checklist in our free External Security Check, and its honesty rule is the part worth reading. Six of the eight mitigation strategies (application control, macro configuration, restricting administrative privileges, patching operating systems, multi-factor authentication and regular backups) are endpoint, identity and backup controls that leave no trace in HTTP, TLS or DNS. No external assessment can see them, so the checklist marks them "cannot be checked from outside" rather than scoring them as gaps. Absence of an external signal is not evidence of a failure, and a tool that renders it as one is lying to you.
Two of the eight produce a partial external signal. Patching applications shows up where internet-facing software discloses a version with a known CVE, which is a real signal but covers only the software visible from outside. User application hardening shows up in response security headers, which tell you how the server hardens the content it serves, not how the endpoint browser, Office, PDF and PowerShell are configured. Treat both as partial views, not as coverage of the control.
Anyone claiming to determine your Essential Eight maturity level from an external assessment is overclaiming. Maturity is assessed across the whole organisation, mostly from evidence that is internal by definition. And none of this is an IRAP assessment or government-grade assurance. If your requirement is IRAP, use a specialist provider. For the framework treatment, see Essential Eight penetration testing for Australian businesses.
The Cost Question
Penetration-test pricing varies with scope, delivery model and the depth of human effort required. A published figure is useful only when it comes with the target, evidence and retest boundaries that it covers. Compare those boundaries before comparing any headline number. Our own breakdown is in how much a penetration test costs in 2026, and you can put your own numbers through the free pentest cost calculator before you compare any quote.
CyberOrbit's published tiers, all AUD ex GST, on /pricing, with the on-demand endpoint bands repeated on the request form:
- On-demand Standard, $7,999. One signed report, up to 50 endpoints, one free retest within 30 days.
- On-demand Comprehensive, $9,999. Up to 150 endpoints, two free retests within 60 days.
- On-demand Enterprise, $14,999. 150+ endpoints, custom scope, unlimited retests for 90 days.
- Subscription Pro, $1,499/mo. One signed report a year, plus scheduled testing against your declared scope across 11 monitored targets.
- Subscription Scale, $2,999/mo. Two signed reports a year, scheduled testing across 21 monitored targets, and API, webhook and CI/CD access.
The retest lines are worth pausing on, because point nine of the checklist above asks every vendor what happens after you fix things. Ours is a published inclusion, which is a small thing until the week your auditor asks for evidence that a critical finding was actually closed.
The obvious objection deserves a direct answer, and a flat "no, it is just as deep" would be the wrong one. A fixed $7,999 buys materially fewer hours than a multi-week consulting engagement. Is it a shallower test? In one specific dimension, yes, and you should hear that here rather than discover it at delivery. You are not buying senior consultant weeks spent reasoning about your architecture, chaining findings through bespoke business logic, or pursuing the creative attack path that only occurs to someone who has lived in your application for a fortnight. That is a real capability, it is what a day-rate engagement is for, and it is exactly what Where Each One Is the Right Answer said to buy from a consulting firm.
What the price is not is a proxy for corner-cutting on the systematic work or on the evidence. A day-rate engagement prices consultant time, so the number moves with how many days your scope consumes and a meaningful share of those days go to scoping, coordination and report production rather than testing. A productised engagement prices the report instead. The systematic 80% of the work, the part that looks broadly the same on every web application and API, is automated and run by us; the review of what came back and the sign-off on the document are done by a certified security professional. Every finding still carries its captured HTTP request and response, its reproduction steps and its proof hash, because that is the standard we publish and can be held to. The trade is narrower creative depth for a known price, a known date and a published evidence floor. If your risk lives in the creative depth, buy the consulting engagement.
If your testing need is recurring rather than annual, the subscription maths changes the comparison again, which we worked through in continuous versus annual penetration testing.
How to Run Your Own 30-Minute Shortlist
You do not need to trust this post. You can do the work yourself in about half an hour, tonight, without booking a single call.
Whoever comes back with specifics on evidence, signing and re-test is the vendor who has thought about the document you are actually buying. If that is us, our on-demand report is $7,999 AUD ex GST and we target delivery 48 hours after scope sign-off. If it is CyberCX, you reached that on better grounds than a listicle, which is the outcome worth having either way. And if you are still unsure whether an independent report is the right artefact at all, start with what SOC 2 actually requires of a penetration test.