Certifications, Accreditations & Memberships

Proof of capability matters.

Cybersecurity credentials should tell you something useful about the people and organisation you are trusting. Vectra combines independent company accreditations, ASD-endorsed assessors, PCI qualifications, vendor certifications and hands-on technical credentials across our Australian cyber team.

Company assuranceCREST-accredited penetration-testing capability and PCI DSS QSA services.
Government securityASD-endorsed IRAP Assessors with current ISM assessment capability.
Platform expertiseCrowdStrike-certified expertise across Falcon administration, response, SIEM engineering, cloud security and identity security.
Offensive securityOSCP, CEH, eCPPT, CRTP and CRTE qualifications across the testing team.
Governance & auditCISA, CISM, CISSP and PCI-QSA expertise across risk, assurance and compliance.
CRESTIndependent company accreditation for professional penetration testing
IRAPASD-endorsed information security assessors
PCI DSSQSA capability and supported ASV scanning services
CrowdStrikeCertified Falcon administration and response expertise
CREST Member Security TestingCREST-accredited testing
IRAPASD-endorsed assessors
PCI Qualified Security AssessorPCI QSA capability
CrowdStrike
5 Team Certifications
Falcon certified capability
Australian Information Security AssociationIndustry membership
ISACAProfessional community
What This Page Represents
Organisation.
People.
Practice.

Not every credential means the same thing. Some apply to Vectra as an organisation. Others belong to individual practitioners. Vendor certifications demonstrate platform knowledge, while professional qualifications demonstrate expertise in a specific security discipline.

This page separates those categories so customers can understand exactly what sits behind the Vectra capability they are buying.

The credential only matters if the right qualified people are actually involved in the work. That is why Vectra builds specialist practices around the people who hold and use these qualifications.

Company Accreditations & Assurance

Independent standards around how the work is delivered.

These credentials operate at an organisational or regulated-service level. They provide assurance around governance, methodology, quality and the organisation’s ability to deliver specific assessment services.

Company Accreditation

CREST Accredited Penetration Testing

Vectra delivers penetration testing as a CREST-accredited organisation. CREST accreditation assesses cybersecurity providers against organisational and service-specific requirements covering governance, service delivery, quality assurance and operational capability.

Applies to Vectra’s accredited penetration-testing practice. CREST company accreditation is distinct from individual practitioner certifications.
Government Assurance

ASD-Endorsed IRAP Assessors

Vectra has practitioners endorsed by the Australian Signals Directorate under the Infosec Registered Assessors Program. IRAP Assessors perform independent security assessments using the Australian Government Information Security Manual and related frameworks.

IRAP endorsement applies to individual assessors. An IRAP assessment does not itself constitute ASD certification or accreditation of the assessed system.
Payment Security

PCI DSS Qualified Security Assessor

Vectra provides PCI DSS assessment and advisory services through its QSA capability. Qualified Security Assessor companies and individual assessors are subject to PCI Security Standards Council qualification and ongoing programme requirements.

Used for formal PCI DSS assessments, Reports on Compliance, readiness, scoping and wider payment-security advisory work.
Payment Security

Approved Scanning Vendor Services

Vectra provides supported PCI DSS ASV vulnerability scanning for organisations requiring formal external scans, remediation support, rescanning and passing evidence under PCI DSS requirements.

ASV scanning is a specific PCI DSS compliance activity and does not by itself demonstrate full PCI DSS compliance.
CrowdStrike Certifications

Certified across the Falcon platform.

Vectra’s CrowdStrike Strike Team includes practitioners certified across administration, response, Next-Gen SIEM, cloud security and identity security. This gives the page a much more complete reflection of how Vectra now delivers CrowdStrike across the wider Falcon platform.

These certifications support architecture, deployment, policy, detection engineering, incident response, cloud protection and identity-security work across customer environments.

CrowdStrike Certified Falcon Administrator badgeCrowdStrike Certified Falcon AdministratorValidates practical knowledge of Falcon platform administration, including sensor deployment, policies, configuration and day-to-day platform management.
CrowdStrike Certified Falcon Responder badgeCrowdStrike Certified Falcon ResponderValidates front-line detection triage, investigation and response skills using CrowdStrike Falcon.
CrowdStrike Certified SIEM Engineer badgeCrowdStrike Certified SIEM EngineerValidates engineering skills for CrowdStrike Next-Gen SIEM, including data onboarding, parsing, search, detection content and platform configuration.
CrowdStrike Certified Cloud Specialist badgeCrowdStrike Certified Cloud SpecialistValidates specialist knowledge of CrowdStrike cloud-security capabilities and the protection of cloud workloads and environments.
CrowdStrike Certified Identity Specialist badge
CrowdStrike Certified Identity SpecialistValidates specialist knowledge of Falcon identity-security capabilities, including identity threat detection, protection and response use cases.
Vectra CrowdStrike capability: these five certifications are represented within the Vectra team today and support our broader Strike Team capability across endpoint, SIEM, cloud and identity security.
Practitioner Certifications

Specialist qualifications across the cyber lifecycle.

The certifications below are examples of recognised qualifications held across the Vectra team. They support different disciplines and are not intended to imply that every practitioner holds every certification.

Offensive Security

Hands-on attack and penetration testing

OSCPCertified Ethical Hacker

Practical qualifications used across penetration testing, adversary simulation and red-team work.

OSCPCEHeCPPTCRTPCRTE
Governance, Risk & Assurance

Security governance and independent assessment

CISACISMCISSP

Credentials supporting audit, information-security management, architecture, risk and regulated assessment work.

CISACISMCISSPPCI-QSAIRAP
Security Operations

Detection, investigation and platform operations

Certifications supporting SOC analysis, endpoint response and the operation of modern security platforms.

CCFACCFRCCSECCCSCCISMicrosoft Security Operations AnalystBlue Team Level 1IBM QRadar SOC Analyst
Partner Capability & Recognition

Technical accreditation is only part of the picture.

Vendor partnership status and industry recognition can provide additional evidence of investment, capability and customer scale. We keep this separate from professional certification because the two are not the same thing.

CrowdStrike Elite PartnerVectra operates as a CrowdStrike Elite Partner, supporting Falcon deployment, managed security and broader platform adoption in Australia.
Vectra Strike TeamA dedicated CrowdStrike practice combining certified Falcon administrators, responders, SIEM engineers, cloud specialists and identity specialists with SOC and deployment engineering capability.
Ensign InfoSecurityVectra is part of Ensign InfoSecurity, which was named CrowdStrike’s 2026 JAPAC Managed Security Services Partner of the Year.
Broader technology ecosystemVectra maintains specialist relationships across security operations, endpoint, identity, cloud, data, infrastructure, application security and compliance technologies.
Professional Memberships

Connected to the standards and communities shaping the industry.

Cybersecurity Community

Australian Information Security Association

Vectra supports AISA and the Australian cybersecurity community through industry participation, knowledge sharing and ongoing professional development.

Governance & Assurance

ISACA

ISACA develops globally recognised professional certifications and guidance across audit, governance, security, risk and assurance, including CISA and CISM.

Payment Security

PCI Security Standards Council Ecosystem

Vectra participates in the PCI security ecosystem through QSA capability, payment-security consulting and supported Approved Scanning Vendor services.

What This Means for Customers

Credentials should reduce uncertainty.

A certification is not a substitute for experience, but the right combination of accreditation, practitioner capability and operational track record gives customers a stronger basis for selecting a cybersecurity provider.

Independent assuranceCompany accreditation demonstrates that the provider itself has been assessed against recognised service-delivery standards.
Qualified practitionersIndividual certifications demonstrate that specific people have met the knowledge or practical requirements of recognised professional programmes.
Platform competenceVendor certifications provide evidence that engineers and analysts understand the security platforms they deploy and operate.
Regulated servicesIRAP and PCI qualifications matter where assessment work must be performed within formal government or industry programmes.
Ongoing developmentCertifications, endorsements and partner programmes require continued training, renewal or capability development as technologies and standards change.
A Note on Credentials

We keep the wording precise.

Company accreditations, individual certifications, government endorsements, vendor partner tiers and industry memberships are different forms of assurance. Vectra does not treat them as interchangeable.

Certification holdings can change as team members join, move roles or renew credentials. This page represents current and established capability across the Vectra organisation and should not be interpreted as a complete register of every certification held by every employee. Where a customer engagement requires a particular assessor, qualification or vendor certification, Vectra can confirm the assigned personnel during scoping.
Credentials FAQs

Common questions about Vectra’s qualifications.

Is Vectra CREST accredited?

Yes. Vectra delivers penetration-testing services through a CREST-accredited practice. CREST company accreditation assesses providers against requirements covering governance, quality, service delivery and operational capability.

Are Vectra IRAP Assessors certified by ASD?

The correct terminology is ASD-endorsed. IRAP Assessors are individual ICT professionals endorsed by the Australian Signals Directorate after meeting the programme’s experience, training, assessment, security-clearance and professional requirements.

Is Vectra a PCI DSS QSA?

Vectra provides PCI DSS assessment services through its QSA capability. PCI SSC qualifies QSA companies and individual assessors to conduct PCI DSS assessments and prepare applicable compliance reports.

Does Vectra have CrowdStrike-certified engineers?

Yes. Vectra’s CrowdStrike practice includes practitioners holding CCFA, CCFR, CCSE, CCCS and CCIS certifications across Falcon administration, response, SIEM engineering, cloud security and identity security.

What offensive-security certifications does Vectra hold?

Qualifications represented across Vectra’s offensive-security team include OSCP, CEH, eCPPT, CRTP and CRTE, alongside Vectra’s CREST-accredited penetration-testing practice.

Does every Vectra consultant hold all of these certifications?

No. Certifications are role-specific and held by different practitioners across Vectra. Engagements are assigned based on the skills, experience and formal qualifications relevant to the customer requirement.

Certified Expertise. Practical Delivery.

Put the right qualified people on the problem.

Talk to Vectra about a security assessment, penetration test, CrowdStrike deployment, PCI DSS programme, IRAP engagement or managed security requirement.

Talk to Vectra →
Professional certifications, partner status and individual credentials are subject to issuer requirements, renewal cycles and personnel changes. Specific qualification requirements can be confirmed during engagement scoping.