Cybersecurity credentials should tell you something useful about the people and organisation you are trusting. Vectra combines independent company accreditations, ASD-endorsed assessors, PCI qualifications, vendor certifications and hands-on technical credentials across our Australian cyber team.
Professional communityNot every credential means the same thing. Some apply to Vectra as an organisation. Others belong to individual practitioners. Vendor certifications demonstrate platform knowledge, while professional qualifications demonstrate expertise in a specific security discipline.
This page separates those categories so customers can understand exactly what sits behind the Vectra capability they are buying.
The credential only matters if the right qualified people are actually involved in the work. That is why Vectra builds specialist practices around the people who hold and use these qualifications.
These credentials operate at an organisational or regulated-service level. They provide assurance around governance, methodology, quality and the organisation’s ability to deliver specific assessment services.
Vectra delivers penetration testing as a CREST-accredited organisation. CREST accreditation assesses cybersecurity providers against organisational and service-specific requirements covering governance, service delivery, quality assurance and operational capability.
Applies to Vectra’s accredited penetration-testing practice. CREST company accreditation is distinct from individual practitioner certifications.Vectra has practitioners endorsed by the Australian Signals Directorate under the Infosec Registered Assessors Program. IRAP Assessors perform independent security assessments using the Australian Government Information Security Manual and related frameworks.
IRAP endorsement applies to individual assessors. An IRAP assessment does not itself constitute ASD certification or accreditation of the assessed system.Vectra provides PCI DSS assessment and advisory services through its QSA capability. Qualified Security Assessor companies and individual assessors are subject to PCI Security Standards Council qualification and ongoing programme requirements.
Used for formal PCI DSS assessments, Reports on Compliance, readiness, scoping and wider payment-security advisory work.Vectra provides supported PCI DSS ASV vulnerability scanning for organisations requiring formal external scans, remediation support, rescanning and passing evidence under PCI DSS requirements.
ASV scanning is a specific PCI DSS compliance activity and does not by itself demonstrate full PCI DSS compliance.Vectra’s CrowdStrike Strike Team includes practitioners certified across administration, response, Next-Gen SIEM, cloud security and identity security. This gives the page a much more complete reflection of how Vectra now delivers CrowdStrike across the wider Falcon platform.
These certifications support architecture, deployment, policy, detection engineering, incident response, cloud protection and identity-security work across customer environments.
The certifications below are examples of recognised qualifications held across the Vectra team. They support different disciplines and are not intended to imply that every practitioner holds every certification.
Practical qualifications used across penetration testing, adversary simulation and red-team work.
Credentials supporting audit, information-security management, architecture, risk and regulated assessment work.
Certifications supporting SOC analysis, endpoint response and the operation of modern security platforms.
Vendor partnership status and industry recognition can provide additional evidence of investment, capability and customer scale. We keep this separate from professional certification because the two are not the same thing.
Vectra supports AISA and the Australian cybersecurity community through industry participation, knowledge sharing and ongoing professional development.

ISACA develops globally recognised professional certifications and guidance across audit, governance, security, risk and assurance, including CISA and CISM.
Vectra participates in the PCI security ecosystem through QSA capability, payment-security consulting and supported Approved Scanning Vendor services.
A certification is not a substitute for experience, but the right combination of accreditation, practitioner capability and operational track record gives customers a stronger basis for selecting a cybersecurity provider.
Company accreditations, individual certifications, government endorsements, vendor partner tiers and industry memberships are different forms of assurance. Vectra does not treat them as interchangeable.
Yes. Vectra delivers penetration-testing services through a CREST-accredited practice. CREST company accreditation assesses providers against requirements covering governance, quality, service delivery and operational capability.
The correct terminology is ASD-endorsed. IRAP Assessors are individual ICT professionals endorsed by the Australian Signals Directorate after meeting the programme’s experience, training, assessment, security-clearance and professional requirements.
Vectra provides PCI DSS assessment services through its QSA capability. PCI SSC qualifies QSA companies and individual assessors to conduct PCI DSS assessments and prepare applicable compliance reports.
Yes. Vectra’s CrowdStrike practice includes practitioners holding CCFA, CCFR, CCSE, CCCS and CCIS certifications across Falcon administration, response, SIEM engineering, cloud security and identity security.
Qualifications represented across Vectra’s offensive-security team include OSCP, CEH, eCPPT, CRTP and CRTE, alongside Vectra’s CREST-accredited penetration-testing practice.
No. Certifications are role-specific and held by different practitioners across Vectra. Engagements are assigned based on the skills, experience and formal qualifications relevant to the customer requirement.
Talk to Vectra about a security assessment, penetration test, CrowdStrike deployment, PCI DSS programme, IRAP engagement or managed security requirement.