main logo icon

Published on

October 1, 2026

|

32 min read

Best Adversary Simulation and Red Teaming Services (2026): Ranked for Threat-Led Testing, Purple Teaming and Regulated Programs

Ranked guide to the best adversary simulation and red teaming services in 2026, with what OSFI B-13 and I-CRT, DORA TLPT, TIBER-EU, CBEST and CREST's simulated attack qualifications actually require, verified 1 October 2026.

Arafat Afzalzada

Arafat Afzalzada

Founder

Network SecuritySocial Engineering

Summarize with AI

ChatGPTPerplexityGeminiGrokClaude

TL;DR

Threat-led red teaming is written into financial supervision on both sides of the Atlantic. OSFI's Guideline B-13 says every federally regulated financial institution should regularly run tests such as penetration testing and red teaming using an intelligence-led approach, and OSFI's I-CRT framework recommends an intelligence-led assessment at least once in each three-year supervisory cycle for Canada's systemically important banks and internationally active insurance groups. DORA requires identified EU financial entities to run threat-led penetration testing at least every three years, with at least 12 weeks of active red team testing under Regulation (EU) 2025/1190, and the Bank of England's CBEST averages 9 to 12 months and uses only CBEST-accredited CREST members. Supply is thin: only 13 of the 32 firms CREST accredits for Threat Led Penetration Testing list North America among their regions, and only NetSPI is headquartered in the United States or Canada. The best adversary simulation and red teaming service providers in 2026 are Stingrai, NCC Group, Mandiant, NetSPI, IBM X-Force Red, LRQA, TrustedSec, SpecterOps, Praetorian, Bishop Fox, CrowdStrike and GuidePoint Security. Every vendor entry links to a page on the vendor's own site, checked on 1 October 2026.

Only 13 of the 32 firms that CREST accredits for Threat Led Penetration Testing list North America among the regions they operate in, and only one of them, NetSPI, is headquartered in the United States or Canada, according to the CREST Marketplace on 1 October 2026. Twenty-seven of the 32 are headquartered in the United Kingdom. By comparison, 516 firms hold CREST's penetration testing accreditation. The tests the smaller group is accredited for run on long clocks: the EU's DORA rules require at least 12 weeks of active red team testing under Regulation (EU) 2025/1190, the Bank of England puts the average CBEST project at 9 to 12 months, and OSFI recommends that Canada's systemically important banks and internationally active insurance groups complete an intelligence-led assessment at least once in each three-year supervisory cycle.

Where Stingrai fits: Stingrai is a CREST-accredited penetration testing service provider at firm level, headquartered in Toronto with a London, UK office and founded in 2021. Its red teaming runs in three modes: assumed breach from a compromised laptop or stolen credentials, black-box full chain from zero inside knowledge, and threat intelligence-led scenarios designed with threat intelligence partners for DORA and TIBER-style programs, on premises and in the cloud. Purple teaming runs MITRE ATT&CK techniques openly beside your SOC, tunes SIEM, EDR and firewall rules live and tests SOAR playbooks against the live techniques. Two named penetration testers from a team holding OSCE³, OSWE, OSEP, CREST CRT and CISSP run each human-led engagement, and the team's red team operations certifications include CRTL, CRTO and CRTE. Engagements run as a one-time annual exercise or a continuous program through the PTaaS portal, and every scope across its adversary simulation services, from red teaming to purple teaming, is quoted through get a quote.

Quick answer: who provides the best adversary simulation and red teaming services in 2026?

The best adversary simulation and red teaming service providers in 2026 are Stingrai, NCC Group, Mandiant, NetSPI, IBM X-Force Red, LRQA, TrustedSec, SpecterOps, Praetorian, Bishop Fox, CrowdStrike and GuidePoint Security. Stingrai ranks first for North American banks, insurers and critical infrastructure operators that need intelligence-led red teaming and purple teaming from named, certified operators, one-time or continuous. NCC Group, Mandiant and NetSPI follow: NCC Group for CREST threat-led accreditations matched among the ranked firms only by LRQA, backed by offices in Chicago and Waterloo; Mandiant for red teaming drawn from incident response casework; and NetSPI as the only CREST Threat Led Penetration Testing holder headquartered in the United States or Canada.

Two-column chart of what OSFI B-13, OSFI I-CRT, NYDFS 500.5, CISA red team assessments, DORA TLPT, TIBER-EU, CBEST and the CREST simulated attack qualifications ask of a red team in 2026

Red teaming, adversary simulation and purple teaming: what each one proves

Regulators draw the lines more sharply than most vendor pages. OSFI's I-CRT framework describes traditional penetration testing as "an attempt to 'exploit' an application or break into a network to identify as many vulnerabilities or design flaws as possible," and red teaming as "a war-gaming format that consists of two teams" that is "an effective way to test and evaluate an organization's ability to detect and respond to a cyber-attack." The EU's TLPT rules add that conventional penetration tests "do not assess the full scenario of a targeted attack against an entire entity, including the complete scope of its people, processes and technologies," and define purple teaming as "a collaborative testing activity that involves both the testers and the blue team." CREST notes that red team engagements are "often known as simulated attacks or adversary simulation."

Penetration test

Red team

Threat-led adversary simulation

Purple team

Question it answers

What is exploitable in this scope?

Would anyone notice an adversary reaching what matters?

Can the institution withstand the actors most likely to target it?

Does each technique trigger prevention or detection, and how do we close the gap?

Defenders told?

Yes

No, beyond a small control group

No, beyond a control group and, in regulated schemes, the regulator

Yes, working beside the testers

Unit of scope

Assets

Objectives and crown jewels

Critical or important functions

Techniques mapped to MITRE ATT&CK

Threat intelligence

Optional

Optional

Required, from a provider kept separate from the red team

Used to choose the techniques

Output

Findings with proof of exploitability

Attack narrative and detection timeline

Red and blue team reports, replay, remediation plan and, where a scheme applies, an attestation

Per-technique outcomes and tuned detections

The red team vs penetration test vs continuous validation guide covers the buying sequence, and the purple team scoping guide covers the statement of work for a purple team exercise.

What the threat-led frameworks actually require

The texts below decide what a regulated red team looks like for a North American bank, insurer or critical infrastructure operator. Each was read from its own primary source on 1 October 2026.

OSFI Guideline B-13: every federally regulated financial institution

Guideline B-13, published 31 July 2022 and effective 1 January 2024, applies to banks, foreign bank branches, insurers and trust and loan companies. Section 3.1.2, under Principle 14, reads: "FRFIs should set defined triggers, and minimum frequencies, for intelligence-led threat assessments to test cyber security processes and controls. FRFIs should also regularly perform tests and exercises, to identify vulnerabilities or control gaps in its cyber security programs (e.g., penetration testing and red teaming) using an intelligence-led approach." The verb is should, the method is intelligence-led, and the triggers and minimum frequencies are the institution's to set.

OSFI's I-CRT framework: systemically important banks and IAIGs

OSFI's Intelligence-led Cyber Resilience Testing framework, dated April 2023, calls itself a "how to" guide and says: "This document is not a policy instrument used to set regulatory expectations." Its current scope is "all Systemically Important Banks (SIBs) and Internationally Active Insurance Groups (IAIGs)," which in Canada means the six domestic systemically important banks and the IAIGs. OSFI's 21 April 2023 release recommends an assessment "at least once during each three-year supervisory cycle, beginning in 2023," and the framework adds that other FRFIs "may request an I-CRT assessment and OSFI will evaluate the request on a case-by-case basis."

Three provisions shape procurement. OSFI says "it is recommended to contract separate vendors for the threat intelligence and the red teaming," and requires due diligence that both "possess the requisite skills set, experience, and capability"; the framework names no accreditation scheme. Its indicative phases are 6 to 8 weeks of initiation, 6 to 10 weeks of threat intelligence, 8 to 12 weeks of execution and 4 to 6 weeks of closure. And the red team provider must "provide feedback on the FRFI incident detection and response capability," after which OSFI issues a supervisory letter in which it "may provide an 'I-CRT Label'." The I-CRT explainer walks through the scope decision.

DORA threat-led penetration testing and Regulation (EU) 2025/1190

North American groups with EU banking, insurance or investment entities answer to DORA, which has applied since 17 January 2025. Articles 26(1) and 26(2) say financial entities identified by their competent authorities "shall carry out at least every 3 years advanced testing by means of TLPT," covering critical or important functions on live production systems. Article 27 limits testers to those that "are of the highest suitability and reputability," demonstrate expertise in threat intelligence, penetration testing and red team testing, "are certified by an accreditation body in a Member State or adhere to formal codes of conduct or ethical frameworks," provide independent assurance or an audit report on how they manage TLPT risks, and carry professional indemnity insurance "including against risks of misconduct and negligence."

Commission Delegated Regulation (EU) 2025/1190, published in the Official Journal on 18 June 2025 and in force since 8 July 2025, "has been drafted in accordance with the TIBER-EU framework" and supplies the operating detail. The active red team testing phase "shall last for at least 12 weeks" (Article 11(5)). An external red team needs at least a manager with five years of penetration testing and red team testing experience and two further testers with at least two years each, plus "at least five references" (Article 7). Testers must run restoration procedures that include "command and control deactivation," "scope and date kill switches" and "removal of backdoors and other malware." And the closure phase requires the blue team and the testers to "replay the offensive and defensive actions performed during the TLPT," followed by "a purple teaming exercise" (Article 12(5)).

TIBER-EU: the voluntary framework DORA's rules mirror

The ECB's TIBER-EU framework, January 2025 edition, states that "the adoption of the TIBER-EU framework by authorities and jurisdictions is voluntary," and that "financial entities completing a test under a national or European-level implementation of the TIBER-EU framework will be DORA TLPT-compliant, assuming they fulfil the formal TLPT-related requirements set by the competent authorities." It sets "a minimum of 12 weeks" of active testing, describes "3 years intervals being the norm," and says that "where feasible, entities should ensure that the providers are accredited and certified by a recognised body as being able to conduct a TIBER-EU test." Its guidance for service provider procurement deliberately "does not provide a list of recommended certifications," tells buyers to check whether an exam is practical, proctored and renewed, and warns that "the entity should not rely on qualifications and certifications alone."

CBEST: the Bank of England's regulator-led test

The Bank of England's CBEST Implementation Guide, 2024 edition, describes "a regulator-led assessment" that has been part of the supervisory toolkit of the Bank, the PRA and the FCA since 2014. A firm enters when the regulator requests it as part of the supervisory cycle, when the firm asks and the regulator agrees, or after an incident. Providers are not optional: "Service providers must be accredited in order to conduct the threat intelligence, penetration testing and reporting elements of the CBEST," and "must also be members of the cyber security membership body CREST." The regulators find "the average CBEST project duration is around 9 to 12 months," with an indicative penetration testing phase of about 14 weeks, and the guide notes that "CBEST assessment is not a pass/fail test." One finding applies in any jurisdiction: CBEST "reveals the value of simulating highly privileged internal attackers, such as malicious insiders and/or supply chain attacks."

CREST's simulated attack qualifications: CCSAS, CCSAM and their successors

CBEST built its people requirement on CREST examinations. The CREST Certified Simulated Attack Manager (CCSAM) examination "tests candidates' knowledge and expertise in leading a team that specialises in Simulated Attacks," and CREST still lists it on its red teaming page. The specialist exam has a new name: CREST says the CREST Certified Red Team Specialist (CCRTS) "was previously known as the CREST Certified Simulated Attack Specialist (CCSAS)" and is "a critical requirement by the Bank of England as part of the CBEST accreditation process." The 2024 CBEST guide asks a penetration testing provider for a CREST Certified Red Team Manager (CCRTM), or The Cyber Scheme's CSRTM as an alternative, alongside CCRTS specialists, and asks a threat intelligence provider for a CREST Certified Threat Intelligence Manager (CCTIM). A CCRTM "remains valid for 3 years from the date you sat the exam," so ask for the date as well as the name.

These are individual qualifications. CREST's company-level equivalents on the CREST Marketplace are Threat Led Penetration Testing, formerly STAR ILPT, and its financial services variant, TLPT-FS.

United States: NYDFS Part 500 and CISA red team assessments

New York's 23 NYCRR 500.5, as amended effective 1 November 2023, requires covered entities to conduct "penetration testing of their information systems from both inside and outside the information systems' boundaries by a qualified internal or external party at least annually." That is a penetration testing requirement; a bank or insurer that wants evidence about detection and response commissions a red team on top of it. For critical infrastructure, CISA runs red team assessments on request. Its advisory AA24-326A, released 21 November 2024, describes one conducted "over approximately a three-month period" against a US critical infrastructure organization that "discovered evidence of the red team's initial activity but failed to act promptly," whose leadership "deprioritized the treatment of a vulnerability their own cybersecurity team identified," and which "relied too heavily on host-based endpoint detection and response (EDR) solutions and did not implement sufficient network layer protections."

Framework

Who it applies to

Cadence

Provider rules

Active red team window

How it closes

OSFI B-13, section 3.1.2

All FRFIs

Triggers and minimum frequencies set by the FRFI

Not specified

Not specified

Not specified

OSFI I-CRT

SIBs and IAIGs; other FRFIs on request

At least once per three-year supervisory cycle, plus event-driven

Separate threat intelligence and red team vendors recommended; no accreditation scheme named

Execution 8 to 12 weeks (indicative)

Debrief, remediation plan, OSFI supervisory letter, possible I-CRT Label

DORA TLPT, RTS (EU) 2025/1190

Financial entities identified by competent authorities

At least every 3 years

Article 27 plus RTS Article 7: experience, references, insurance, restoration

At least 12 weeks

Replay, purple teaming, summary to the authority, attestation

TIBER-EU, January 2025

Entities in jurisdictions that adopt it

3-year intervals the norm

Accredited and certified "where feasible"

Minimum 12 weeks

Replay, purple teaming, attestation

CBEST, 2024 guide

Firms and FMIs requested by the regulators

Supervisory cycle, request or incident

CBEST-accredited CREST members; CCRTM or CSRTM plus CCRTS

About 14 weeks (indicative)

Remediation plan reviewed by the regulator

NYDFS 23 NYCRR 500.5

New York covered entities

Penetration test at least annually

Qualified internal or external party

Not applicable

Not specified

Canadian operators of federally regulated critical infrastructure should also track Bill C-8 and its Critical Cyber Systems Protection Act, covered in our related reading below.

The red team scope: what a regulated program should cover

Regulators scope threat-led tests by function rather than by IP range: I-CRT by critical business functions, DORA by critical or important functions, CBEST by important business services. Mandiant's M-Trends 2026, published 23 March 2026 and based on more than 500,000 hours of incident investigations in 2025, shows where those functions are attacked across all industries and regions. It found that the high tech sector, at 17 percent of incidents, overtook the financial sector, at 14.6 percent, as the most frequently targeted industry, ending finance's run at the top in 2023 and 2024.

  • The help desk and identity. Across Mandiant's 2025 investigations, "highly interactive voice phishing" was the second most common initial infection vector at 11 percent, while email phishing fell to 6 percent. Scope voice social engineering against the help desk and the reset process, not only email.

  • Active Directory, Entra ID and recovery systems. M-Trends describes ransomware operators that "actively targeted backup infrastructure, identity services, and virtualization management planes." Paths from one workstation to Active Directory control, and from there to backups and hypervisors, decide the blast radius.

  • Edge devices. M-Trends describes espionage clusters that "deliberately target edge and core network devices, such as virtual private networks (VPNs) and routers, that typically lack standard endpoint detection and response (EDR) telemetry." A red team should show whether the SOC sees anything there at all.

  • Cloud control planes and SaaS. M-Trends recommends behavioral detection for "anomalous bulk API operations, or the suspicious use of SaaS integration tokens," which belong in cloud and identity provider scenarios.

  • Third parties. DORA lets ICT third-party service providers sit inside TLPT scope and allows pooled testing, the 2024 CBEST guide adds guidance on third parties behind important business services, and CISA's red team got in through a web shell left from a third party's previous security assessment.

  • People and premises. The EU rules expect an external red team to cover skills that include "physical penetration, social engineering," so on-site physical testing belongs in a full-scope scenario.

  • Insiders. CBEST's observation about "highly privileged internal attackers" is the case for at least one assumed breach scenario that starts from a privileged account.

ATT&CK mapping, assumed breach and rules of engagement

Three agreements decide whether a red team produces evidence a supervisor or a board can use.

MITRE ATT&CK mapping. The current release is ATT&CK v19.2, an August 2026 "Agile" release that added groups such as ShinyHunters (G1057), which MITRE describes as stealing "credentials and personally identifiable information for resale or extortion." Use ATT&CK to describe the chain the red team ran and the techniques the purple team validated, and ask which version the report maps to. A heatmap of covered techniques is not a measure of quality; how to read ATT&CK coverage in a red team proposal shows how to spot padding.

Assumed breach. An assumed breach scenario starts from a granted foothold, such as a compromised laptop or stolen credentials, and spends the budget on detection, lateral movement and containment. The regulated frameworks formalize the same idea for stalled scenarios: the EU rules define a "leg-up" as assistance "to enable the testers to continue the execution of an attack path where they are not able to advance on their own," and I-CRT calls it "de-chaining." Agree the starting points and leg-ups before day one; the assumed breach guide covers when to start inside.

Rules of engagement. The rules set the control group, the need-to-know list, deconfliction contacts, out-of-bounds systems and stop conditions. DORA's rules limit knowledge of a test to "the control team, the management body, the testers, the threat intelligence provider and the TLPT authority," and let the control team lead suspend testing when it threatens critical or important functions. The rules of engagement checklist turns this into contract language.

How we ranked them

This ranking is built for regulated programs, so it weights threat-led schemes, purple teaming and North American delivery more heavily than a general comparison of red team providers would. Twelve firms were scored against nine criteria. Every evidence page was read on the vendor's own site and every accreditation on the CREST Marketplace on 1 October 2026.

  1. A red team or adversary simulation service published on the firm's own site.

  2. Purple teaming offered as a named service or built into the red team method.

  3. Threat-led capability: CREST Threat Led Penetration Testing, partner-assured CBEST or TIBER-EU alignment on the CREST Marketplace, or published support for DORA TLPT and TIBER-EU.

  4. North American delivery: a US or Canadian headquarters or office, or North America among the firm's CREST regions.

  5. Firm-level accreditation on the CREST Marketplace.

  6. A published method: phases, ATT&CK mapping and detection measurement.

  7. Safety and governance: named roles, rules of engagement and debriefs.

  8. Delivery model: one-time and continuous options.

  9. Independence from the products being tested.

Bar chart of CREST Marketplace threat-led listings on 1 October 2026: 32 Threat Led Penetration Testing holders, 13 listing North America; 16 TLPT-FS, 8 listing North America; 15 CBEST, 8 listing North America; 22 TIBER-EU aligned, 10 listing North America

The 12 companies at a glance

#

Company

HQ

CREST Marketplace (1 Oct 2026)

Threat-led listings

Red team and purple team

Continuous option

Best for

1

Stingrai

Toronto, ON (London, UK office)

Penetration Testing, firm level

None; threat intelligence-led scenarios in DORA and TIBER style

Assumed breach, black-box full chain, threat intelligence-led; purple team

Yes, one-time or continuous

Named operators and purple teaming for North American regulated programs

2

NCC Group

Manchester, UK (Chicago regional HQ; Waterloo, ON)

Penetration Testing, Threat Led Penetration Testing, TLPT-FS and more

CBEST, STAR-FS, TIBER-EU, plus GBEST alignment

Red, black, purple and gold teams; regulatory simulated attack

Not stated

Groups needing CBEST or TIBER-EU plus North American offices

3

Mandiant

Part of Google Cloud, US (CREST entity: Ireland)

Penetration Testing, Threat Led Penetration Testing, TLPT-FS, Incident Response

CBEST, STAR-FS, TIBER-EU

Red team assessment; purple team assessment

Not stated

Red teaming drawn from incident response

4

NetSPI

Minneapolis, MN (Toronto, ON office)

Penetration Testing, Threat Led Penetration Testing

Threat Led Penetration Testing; CBEST claimed on its own page

Assumed breach, black box, threat intelligence-led

Annual baseline moving to continuous

A US-headquartered threat-led accreditation

5

IBM X-Force Red

Armonk, NY

Penetration Testing, Incident Response, Vulnerability Assessment

None listed; DORA TLPT and TIBER-EU support on its page

Red team, purple team, threat intelligence-based testing

Managed red team with monthly sprints

Red, purple and continuous red teaming on one contract

6

LRQA

UK (registered office Birmingham)

Penetration Testing, Threat Led Penetration Testing, TLPT-FS, Cyber Threat Intelligence and more

CBEST, STAR-FS, TIBER-EU, plus iCAST, AASE, CORIE, FEER and GBEST alignment

Red teaming with a technical lead, red team member and attack manager; purple teaming service

Not stated

CBEST and TIBER-EU from a practice marketed to US buyers

7

TrustedSec

Fairlawn, OH

Penetration Testing

None

Adversarial Attack Simulation with a purple team phase; purple team service

Not stated

Full-scope red teams that end in purple teaming

8

SpecterOps

Alexandria, VA and Seattle, WA

Penetration Testing

None

Red team, purple team assessments, attack path assessments

Ongoing attack path advisory

Identity attack paths and detection engineering

9

Praetorian

United States

Penetration Testing

None

Red team; purple team replay

Platform for continuous exposure validation

Short, objective-led red teams with detection engineering

10

Bishop Fox

Tempe, AZ

Penetration Testing

None

Red teaming and adversary emulation; purple teaming supported

Cosmos continuous platform (separate product)

Modular, objective-led red teams

11

CrowdStrike

Austin, TX

Not listed

None

Red team and blue team exercise; adversary emulation exercise

Not stated

Training the SOC during the exercise

12

GuidePoint Security

Reston, VA

Penetration Testing

None

Red teaming; purple teaming with its incident response team

Not stated

Testing incident response readiness

"Not stated" means the vendor's own site does not say. Ask for it in writing.


1. Stingrai

Stingrai is a global CREST-accredited penetration testing services company founded in Toronto, Canada in 2021, trusted by companies from startups to enterprises to meet audit requirements for SOC 2, ISO 27001, CMMC, PCI DSS and HIPAA. OSCE³, OSWE, OSEP, CREST CRT certified pentesters, who are also world-class security researchers and bug bounty hunters. Choose from fully human-led or hybrid (AI agents plus human penetration testers) engagements across web, API, mobile, AI and LLM, cloud, network, Active Directory and social engineering penetration tests and red team engagements.

What a bank's or insurer's procurement team can check. The firm-level accreditation is on the CREST Marketplace supplier page for Stingrai Inc, which lists Canada as the head office and Europe and North America as regions, separate from the CREST CRT certifications individual testers hold. Ratings are 5.0 from 20 reviews on Clutch. The team has published 18 CVEs and appears in the Halls of Fame of Apple, Google, the US Department of Defense and the US Federal Reserve, and the team lead brings 16 years in penetration testing, red teaming and exploit development. Two named penetration testers run each human-led engagement, reviewed by the team lead and an engagement partner, under founder Arafat Afzalzada, who has 11 years in offensive security.

How the red team runs. Each engagement opens with threat intelligence and scoping that fix objectives, rules of engagement and success criteria against MITRE ATT&CK, TIBER-EU or DORA. Operators then work through reconnaissance, initial access by phishing, vishing, physical entry or an exposed service, lateral movement through Active Directory and cloud identity, and the agreed objective, from data exfiltration to disruption of a critical business process. The three modes serve different questions: assumed breach for internal resilience, black-box full chain for the perimeter and the people, and threat intelligence-led scenarios built with threat intelligence partners, so the threat intelligence and the red teaming come from separate providers, the split I-CRT recommends.

What the deliverables contain. Detection measurement is a contractual deliverable. The red team report carries an executive and board summary, a chronological attack narrative, a detection and response timeline showing per stage what was prevented, logged silently, alerted and acted on, MITRE ATT&CK technique mapping and root-cause findings, followed by a replay and debrief with your SOC. Purple team engagements return validated detection rules, tuning recommendations for SIEM, EDR, firewall and IPS policies, results from SOAR playbook tests and mean time to detect measured per technique.

Delivery. Findings post to the PTaaS portal as they are confirmed, with live chat to the assigned testers, Jira and Slack integration, free on-call remediation support and retesting of remediated findings, and human-led and hybrid engagements include an attestation letter. Red team and purple team work runs as a one-time annual exercise timed to a B-13 or audit cycle, or as a continuous adversary emulation program that re-tests detection content on a schedule. Snipe, Stingrai's autonomous AI agent, covers web applications and their APIs only; red teaming, purple teaming, social engineering, physical, network, Active Directory and cloud work is done by named penetration testers.

Pricing: red team, purple team and adversary simulation engagements are quoted per scope through get a quote. The published packages on the pricing page cover exactly one web application and its APIs: US$3,000 for an Autonomous Pentest or US$6,800 for a Hybrid Pentest per assessment, or US$650 and US$1,275 per month on 12-month continuous plans.

Strength: named operators, all three red team modes plus purple teaming, and detection timings written into the deliverable, one-time or continuous. Limitation: Stingrai's CREST accreditation is for penetration testing rather than Threat Led Penetration Testing or CBEST, so a UK CBEST test needs a CBEST-accredited firm such as NCC Group or LRQA; and the team is small, so a multi-month DORA-style program needs scheduling lead time. Best for: North American banks, insurers, critical infrastructure operators and large enterprises that need intelligence-led red teaming and purple teaming under B-13, alongside an annual NYDFS penetration test, or for board assurance, from named, certified operators.

2. NCC Group

NCC Group's global headquarters is in Manchester, with a North American regional headquarters in Chicago and an office in Waterloo, Ontario (office locations). Its attack simulation practice offers "simulated red team and black team attacks, purple team defense improvement, and gold team crisis management exercises," and a Regulatory Simulated Attack service to "prepare for and assess against CBEST, TIBER-EU, iCAST, AASE, CORIE, and FEER regulations," in which threat intelligence "generates scenarios, TTPs, and threat actors to emulate." Its purple team exercises "assess your internal cyber team's defensive capacity and preventative controls." The CREST Marketplace shows CREST threat-led accreditations matched among the ranked firms only by LRQA: Threat Led Penetration Testing, TLPT-FS for threat intelligence and testing, Threat Intelligence for Simulated Attack, and partner-assured CBEST and STAR-FS for both threat intelligence and testing, plus TIBER-EU and GBEST alignment, with 19 years of membership and North America among its regions. Named operators, a continuous red team option and pricing are not stated.

Strength: CREST threat-led accreditations matched among the ranked firms only by LRQA, backed by offices in Chicago and Waterloo. Limitation: NCC Group also sells managed extended detection and response, so if it already monitors your environment, document how the red team stays independent of the monitoring team. Best for: groups with UK or EU entities that need CBEST, TIBER-EU or DORA TLPT alongside North American red teaming.

3. Mandiant

Mandiant, part of Google Cloud, sells a Red Team Assessment that "draws from tactics, techniques, and procedures (TTPs) found in incident response engagements to simulate a realistic and persistent attack scenario in your environment," using "non-destructive methods" to assess the security team's "detection and response capabilities in real-time." The page lists consultants "experienced with critical infrastructure sectors including: energy, healthcare, manufacturing, and telecommunications," custom objectives such as access to PCI data, and separate technical and executive reports. Its technical assurance services add a Purple Team Assessment: "Testing and coaching to improve your security team's detection and response capabilities against realistic attack scenarios," which its datasheet aligns with MITRE ATT&CK. The CREST Marketplace lists Mandiant (part of Google Cloud) with Threat Led Penetration Testing, TLPT-FS, partner-assured CBEST and STAR-FS testing and TIBER-EU alignment, under an Irish head office with Europe and the Middle East as regions. Named operators, a continuous option and pricing are not stated.

Strength: red team scenarios drawn from frontline incident response, plus threat-led accreditation for European entities. Limitation: the CREST threat-led listing belongs to an entity whose listed regions are Europe and the Middle East, so confirm which team delivers North American work and which credentials it carries. Best for: critical infrastructure operators and financial institutions that want red teaming informed by incident response casework.

4. NetSPI

NetSPI lists its headquarters in Minneapolis and an office in Toronto, Ontario (offices). Its Red Team Operations page offers three engagement types: assumed breach scenario-based testing, black box, and threat intelligence-led testing in which NetSPI "partners with selected globally respected threat intelligence providers" and supports compliance "with regulations such as DORA, TIBER-EU, and more." The page says NetSPI is "backed by accreditations from CBEST and CREST" and recommends "scheduling tests annually as a baseline, then as your security maturity grows, move towards continuous and ongoing scenario-based assessments." The CREST Marketplace lists Penetration Testing and Threat Led Penetration Testing with ten years of membership and Europe and North America as regions; it shows no partner-assured CBEST listing, so ask for the CBEST reference during procurement. NetSPI is the only one of the 32 Threat Led Penetration Testing holders headquartered in the United States or Canada.

Strength: a US-headquartered firm with CREST's threat-led accreditation and a Toronto office. Limitation: the same page distinguishes red teaming from attack simulation, which it describes as detective controls testing that "validates security controls through structured unit testing on a continuous basis," so confirm which engagement type a proposal prices. Best for: North American banks and insurers that want a domestic firm holding CREST's threat-led accreditation.

5. IBM X-Force Red

IBM lists its corporate address in Armonk, New York (contact). Its X-Force Red adversary simulation services cover "customized red teaming, purple teaming, threat intelligence-based testing, and managed testing options." Purple team scenarios are "mapped to the MITRE ATT&CK Framework" and run "in close collaboration with your blue teams to validate manual and automated detections," threat intelligence-based testing is offered for "satisfying requirements for DORA TLPT, TIBER-EU, and other threat intelligence-based testing frameworks," and a managed red team service provides continuous testing with a dedicated on-call tester and monthly sprints with reporting. The CREST Marketplace lists IBM for Penetration Testing, Incident Response and Vulnerability Assessment with 12 years of membership, under a UK head office, with North America among its regions. Named operators and pricing are not stated.

Strength: red, purple, threat intelligence-based and managed red teaming from one provider, including a continuous option. Limitation: the CREST listing does not include the threat-led specialism, so for a designated DORA test confirm how the Article 27 tester requirements will be evidenced. Best for: enterprises that want red, purple and continuous red teaming under one contract.

6. LRQA

LRQA is a UK group with its registered office in Birmingham that markets red teaming to US buyers on its US site. It states that it delivers "red teaming engagements that meet the highest standards in line with global regulatory frameworks, including CBEST, iCAST, STAR-FS, and TIBER-EU," and that "each Red Team engagement includes a technical lead, a Red Team member, and an attack manager." After testing, it compares the defenders' own timeline of events with the red team's, using questions aligned to the NIST Cyber Security Framework. The CREST Marketplace lists Threat Led Penetration Testing, TLPT-FS for threat intelligence and testing, Threat Intelligence for Simulated Attack, partner-assured CBEST and STAR-FS for both threat intelligence and testing, and TIBER-EU alignment, with 17 years of membership and North America among its regions. Named operators, a continuous option and pricing are not stated.

Strength: CBEST threat intelligence and testing accreditation under one roof, with an attack manager on every engagement. Limitation: a UK-headquartered practice, so confirm where the operators assigned to a North American engagement are based. Best for: groups that need CBEST, STAR-FS or TIBER-EU testing and want the same provider for North American red teams.

7. TrustedSec

TrustedSec, at 3485 Southwestern Boulevard in Fairlawn, Ohio, calls its red team service Adversarial Attack Simulation: "an objective-driven assessment that mimics real-world adversaries to test the effectiveness of your security program." Its six phases run from pre-planning and threat modeling, through social engineering and initial access "using ethical phishing, vishing, SMS, and physical breach techniques" and a defensive inclusion and purple teaming phase in which "we work alongside your security team to refine detection capabilities and enhance incident response," to reporting and an executive debrief. A separate purple team service, Adversarial Detection & Countermeasures, focuses on "detection, deflection, and deterrence." The CREST Marketplace lists TrustedSec for Penetration Testing in North America, with two years of membership. Named operators and pricing are not stated.

Strength: purple teaming built into the red team method rather than sold afterwards, with vishing and physical scope. Limitation: no threat-led scheme listing on the CREST Marketplace, so a designated CBEST test needs one of the accredited firms above. Best for: full-scope red teams that end in a working purple team session.

8. SpecterOps

SpecterOps lists offices in Alexandria, Virginia and Seattle (contact) and offers BloodHound Enterprise for identity attack path management. Its services include red team operations in which "our red team brings deep adversary expertise and leading-edge AI tooling and tradecraft to simulate that behavior against your environment," testing "both traditional infrastructure and AI systems"; Purple Team Assessments that "evaluate preventative and detective controls using comprehensive test cases that represent real attack variations"; and attack path assessments across "AD, Entra ID, GitHub, Okta, and JAMF." It also helps clients "stand up red team, purple team, threat hunting, detection, or AI red team programs." The CREST Marketplace lists Specter Ops Inc for Penetration Testing in North America, with two years of membership. Pricing is not stated.

Strength: identity attack paths and detection engineering, plus help building an internal red or purple team. Limitation: the services page does not describe physical or voice social engineering, so confirm whether they are in a quoted full-scope scenario. Best for: enterprises whose risk sits in Active Directory, Entra ID and identity providers.

9. Praetorian

Praetorian, a US firm on the CREST Marketplace, runs red team engagements that "emulate the tactics of nation-state adversaries and advanced persistent threats to expose weaknesses across your people, processes and technology," with core operators who are "former NSA and CIA officers and top-tier security researchers with decades of offensive experience." Objectives on its page include demonstrating "direct financial loss through the transfer of monetary funds to a nominated bank account," and it states that "most engagements run from two to six weeks including planning, execution, and reporting." Its purple team service replays the original attack chain "in a collaborative, interactive fashion with your security team" and implements detection engineering logic in the client's existing stack. The CREST Marketplace lists Praetorian Security, Inc. for Penetration Testing in North America, with two years of membership. Pricing is not stated.

Strength: a published engagement length and detection engineering inside the purple team phase. Limitation: two to six weeks including planning and reporting is short for a covert full-scope operation against a mature SOC, so agree operator days on target in writing. Best for: financial services teams that want a money-movement objective tested and detections built afterwards.

10. Bishop Fox

Bishop Fox lists its global headquarters at 1414 W Broadway Road in Tempe, Arizona (contact). Its red teaming and adversary emulation service "covertly executes carefully crafted attacks to measure the efficacy of your Blue Team," follows the MITRE ATT&CK framework, and uses a modular "building block" approach that defines strategic objectives, methodologies, knowledge types and threat graphing. The page states that Bishop Fox is an FS-ISAC Affiliate Partner, and its report "outlines timeframe of events with detailed breakdown of actions performed, defensive performance, and achievement against target objectives." The CREST Marketplace lists Bishop Fox for Penetration Testing in Europe and North America, with four years of membership. Pricing is not stated.

Strength: modular engagements and an event-timeline report measured against objectives. Limitation: the same page markets Cosmos, a continuous offensive security platform, so check whether a proposal prices the red team service or the platform. Best for: financial services teams that want modular, objective-led red teams.

11. CrowdStrike

CrowdStrike, whose press releases are datelined Austin, Texas, lists two hands-on adversary exercises among its Prepare services, alongside a tabletop exercise and penetration testing. Its Red Team / Blue Team Exercise has "the CrowdStrike Red Team attacks and the Blue Team helps your team defend against a targeted attack within your environment," tracing "active reconnaissance, delivery and exploitation, command and control, operations and after-action review," with incident response training during simulation pauses. Its Adversary Emulation Exercise tests "your security team against the latest threats posing the greatest risk to your industry" and measures maturity "across the phases of the MITRE ATT&CK framework." CrowdStrike is not listed on the CREST Marketplace. Named operators and pricing are not stated.

Strength: a red team and blue team exercise that trains the SOC while the attack runs. Limitation: the emulation page says the scenarios draw on "the CrowdStrike Falcon platform," which CrowdStrike sells per endpoint, so if Falcon protects your estate, decide how the test stays independent of the product being measured. Best for: SOC teams that want coaching built into the exercise.

12. GuidePoint Security

GuidePoint Security lists its address as 1900 Reston Metro Plaza in Reston, Virginia. Its red teaming service combines tactics "from our open-source intelligence gathering, social engineering and penetration testing offerings into a multi-pronged attack that closely mimics a sophisticated adversarial assault," including attempts to "circumvent physical security controls" and to exploit trust "via email, voice and in-person interactions." Its purple teaming service combines its Digital Forensics and Incident Response and Threat and Attack Simulation teams "to transform tabletop exercises into live-fire scenarios." The CREST Marketplace lists GuidePoint Security for Penetration Testing in North America, with three years of membership. Named operators and pricing are not stated.

Strength: purple teaming that pairs red operators with an incident response team. Limitation: its catalog also includes breach and attack simulation as a service, so confirm that the engagement you buy is operator-led. Best for: organizations testing incident response readiness with a live exercise.


Firms considered and not ranked

MDSec holds CREST Threat Led Penetration Testing and partner-assured CBEST and is TIBER-EU aligned, but its CREST listing names Europe as its only region, and on 30 July 2026 Bank of America announced plans to acquire MDSec Consulting Limited, with completion expected in the fourth quarter of 2026.

Pen Test Partners, Dionach and CovertSwarm are UK-headquartered, hold partner-assured CBEST threat-led accreditation, list North America on the CREST Marketplace and publish red team services. Each also has a US entity: Pen Test Partners Inc in New York, Dionach LLC in Nashville and CovertSwarm Inc in Delaware, and CovertSwarm appointed a Head of Adversary Simulation for North America in June 2025. They are worth a call for a group that needs CBEST alongside North American red teaming; this list stops at twelve firms.

Accenture, KPMG and Deloitte hold CREST's Threat Led Penetration Testing accreditation, but each listing sits with a named entity or network, such as Deloitte Consultative Services B.V. in the Netherlands and KPMG's international network of member firms, so confirm that the entity signing a North American statement of work holds the accreditation you are relying on.

Optiv's attack simulation service spans logical, physical and social attack paths and is built to prepare a purple team, but the page names no threat-led framework or ATT&CK mapping, which this ranking weighted.

ISA Cybersecurity in Toronto lists red and purple team engagements among its assessment services and has consultants in Canada with "Top Secret," "Secret" and "Reliability" clearance levels, but no dedicated red team service page appears in its sitemap.

Breach and attack simulation software runs a catalogue of techniques on a schedule. It is useful for regression-testing detections, but it is a product rather than a red team provider, so none is ranked.

How much does red teaming cost in 2026?

Red team and adversary simulation engagements are priced on operator days and calendar time, so the clock drives the cost, and threat-led programs add a separate threat intelligence provider, a control group and a closing replay. The primary texts give the clocks.

Engagement

Duration in the source

Source

DORA TLPT

At least 12 weeks of active red team testing; red team test report within 4 weeks of its end

Regulation (EU) 2025/1190, Articles 11(5) and 12(2)

TIBER-EU

A minimum of 12 weeks of active testing

TIBER-EU framework, January 2025

CBEST

Average project of 9 to 12 months; penetration testing phase about 14 weeks

Bank of England CBEST Implementation Guide, 2024

OSFI I-CRT

Initiation 6 to 8 weeks, threat intelligence 6 to 10, execution 8 to 12, closure 4 to 6 (indicative)

OSFI I-CRT framework

CISA red team assessment

About three months

CISA advisory AA24-326A

Commercial red team

Two to six weeks including planning, execution and reporting, in Praetorian's published figure

Praetorian red team page

Stingrai quotes red team, purple team and adversary simulation engagements per scope through get a quote. Its published package prices cover exactly one web application and its APIs: US$3,000 for an Autonomous Pentest, which is Snipe alone with no penetration testers, and US$6,800 for a Hybrid Pentest, where penetration testers and Snipe test together, each per assessment, or US$650 and US$1,275 per month on 12-month continuous plans. The "No High or Critical Finding = Don't Pay" guarantee applies to the Autonomous tier only. Current figures are on the pricing page, and indicative red team bands are in our red team engagement cost guide.

Four things move a red team quote most: the number of scenarios and modes, whether a separate threat intelligence provider is required, whether physical and voice social engineering are in scope, and the regulatory overhead of a control group, test managers, replay and purple teaming.

Buyer checklist: how to evaluate a red team vendor's tradecraft and safety

The EU's TLPT rules spell out red team safety duties in binding detail, and they are worth borrowing even when no regulator has designated you.

  1. Who exactly will operate, and can we see each operator's CV, certifications and the date each was earned? The EU rules expect CVs and copies of certifications, and a CCRTM is valid for three years.

  2. Which accreditation do you hold, at which legal entity, and where can we see it? Check the CREST Marketplace yourself and match the entity to the one signing the statement of work.

  3. Is your threat intelligence provider separate from the red team? I-CRT recommends separate vendors, and the EU rules require the two teams to be separated.

  4. What restoration will you perform at the end? Ask for deletion of compromised credentials and secrets, command and control deactivation, scope and date kill switches, and an inventory of every implant and account removed. CISA's red team got in through a web shell left from a third party's previous security assessment.

  5. What will you never do? The EU rules bar unauthorized destruction of equipment, uncontrolled modification of information, intentionally compromising the continuity of critical or important functions, unauthorized inclusion of out-of-scope systems and unauthorized disclosure of results.

  6. How will you separate a real incident from the test? Agree a need-to-know control group, trusted agents and a contact who can be reached at any hour.

  7. Will per-stage detection timings be a contractual deliverable, and will you replay the attack with our blue team and run a purple team session afterwards?

  8. When will the control group grant a leg-up, so a stalled scenario still tests detection rather than ending early?

  9. What professional indemnity insurance do you carry, and does it cover misconduct and negligence, as DORA's Article 27 requires for TLPT testers?

  10. Can we speak to references from comparable regulated engagements? The EU rules ask external testers for at least five.

The pentest and red team RFP question bank turns these into scored procurement questions.

Frequently Asked Questions

Who provides the best adversary simulation and red teaming services in 2026?

The best adversary simulation and red teaming service providers in 2026 are Stingrai, NCC Group, Mandiant, NetSPI, IBM X-Force Red, LRQA, TrustedSec, SpecterOps, Praetorian, Bishop Fox, CrowdStrike and GuidePoint Security. Stingrai ranks first: a CREST-accredited penetration testing service provider at firm level with two named penetration testers from a team holding OSCE³, OSWE, OSEP, CREST CRT and CISSP on every human-led engagement, running assumed breach, black-box full chain and threat intelligence-led red teams plus purple teaming, one-time or continuous. NCC Group, Mandiant and NetSPI follow for threat-led accreditation backed by offices in Chicago and Waterloo, red teaming drawn from incident response and a US-headquartered CREST threat-led accreditation.

What is the difference between red teaming, adversary simulation and purple teaming?

A red team is an objective-based, covert test of whether defenders detect and stop an adversary reaching what matters most. CREST notes that red team engagements are often known as simulated attacks or adversary simulation, and regulated versions such as DORA TLPT, CBEST and I-CRT build each scenario from threat intelligence about the actors most likely to target the institution. Purple teaming is, in the words of Regulation (EU) 2025/1190, a collaborative testing activity that involves both the testers and the blue team, used to tune detections technique by technique. A penetration test instead finds as many exploitable vulnerabilities as it can in an agreed scope.

Does OSFI require red teaming for Canadian banks and insurers?

Guideline B-13, effective 1 January 2024, says FRFIs should set defined triggers and minimum frequencies for intelligence-led threat assessments, and should regularly run tests and exercises such as penetration testing and red teaming using an intelligence-led approach. OSFI's I-CRT framework, which describes itself as a how-to guide rather than a policy instrument, currently applies to all systemically important banks and internationally active insurance groups, with an assessment recommended at least once in each three-year supervisory cycle. Other FRFIs may request an assessment, and OSFI decides case by case.

What does DORA TLPT require from a red team provider?

Article 27 of DORA limits TLPT testers to those of the highest suitability and reputability, with expertise in threat intelligence, penetration testing and red team testing, certified by an accreditation body in a Member State or adhering to formal codes of conduct or ethical frameworks, able to provide independent assurance or an audit report on how they manage TLPT risks, and covered by professional indemnity insurance. Regulation (EU) 2025/1190 adds at least 12 weeks of active testing, restoration procedures such as kill switches and a closing replay and purple teaming exercise, and for external testers a red team of at least a manager with five years of experience and two testers with two years each, plus at least five references.

What are CREST CCSAS and CCSAM, and what replaced them?

They are CREST's individual simulated attack qualifications. The specialist exam is now the CREST Certified Red Team Specialist (CCRTS), which CREST says was previously known as the CREST Certified Simulated Attack Specialist (CCSAS). CREST still lists the CREST Certified Simulated Attack Manager (CCSAM), while the Bank of England's 2024 CBEST guide asks a penetration testing provider for a CREST Certified Red Team Manager (CCRTM), or The Cyber Scheme's CSRTM, alongside CCRTS specialists. A CCRTM remains valid for three years from the date of the exam.

Which US rules apply to red teaming at banks, insurers and critical infrastructure operators?

New York's 23 NYCRR 500.5 requires covered entities to conduct penetration testing from both inside and outside their information systems' boundaries, by a qualified internal or external party, at least annually; a red team adds evidence about detection and response on top of that test. For critical infrastructure, CISA conducts red team assessments on request, and its advisory AA24-326A describes one run over about three months. US groups with EU or UK entities may also be identified for DORA TLPT or asked to run CBEST.

How long does a red team engagement take?

It depends on the framework. The EU's TLPT rules require at least 12 weeks of active red team testing and TIBER-EU sets the same minimum, the Bank of England puts the average CBEST project at 9 to 12 months, OSFI's I-CRT gives indicative phases of 6 to 8, 6 to 10, 8 to 12 and 4 to 6 weeks, and CISA ran its published critical infrastructure assessment over about three months. Commercial engagements are shorter: Praetorian, for example, says most of its red team engagements run two to six weeks including planning, execution and reporting.

How much does red teaming cost in 2026?

Red team, purple team and adversary simulation engagements are quoted per scope, because operator days and calendar time drive the price and threat-led programs add a separate threat intelligence provider and a longer clock. Stingrai quotes them through its get a quote page. Its published package prices cover exactly one web application and its APIs, at US$3,000 for an Autonomous Pentest and US$6,800 for a Hybrid Pentest per assessment, or US$650 and US$1,275 per month on 12-month continuous plans.

How should we check a red team vendor's safety before signing?

Borrow the EU's rules even if you are not designated. Regulation (EU) 2025/1190 expects CVs and certifications, professional indemnity insurance, at least five references, restoration procedures that include command and control deactivation, scope and date kill switches and removal of backdoors, and a ban on out-of-scope systems and uncontrolled changes. CISA's advisory AA24-326A shows why cleanup matters: its red team gained initial access through a web shell left from a third party's previous security assessment.


Ready to scope a red team or purple team exercise?

A red team earns its fee when it tells you something a penetration test cannot: whether anyone on your side noticed, how long it took and what they did next. Stingrai is a CREST-accredited penetration testing service provider whose penetration testing, red teaming and purple teaming support the evidence B-13, I-CRT-style and NYDFS programs ask for, delivered as a one-time annual exercise or as a continuous program, with named penetration testers, per-stage detection timings and a SOC replay. Book a free scoping call, get a quote for a red team or purple team scope, or see the published package prices on the pricing page.

0 views

0

X

Related reading

Best Penetration Testing Companies for Construction and Engineering Firms (2026)
Network SecuritySocial Engineering

Best Penetration Testing Companies for Construction and Engineering Firms (2026)

The best penetration testing companies for construction and engineering firms in 2026, ranked, with what CMMC, CPCSC, owners and insurers actually require.

30 min read

Best Enterprise Penetration Testing Companies (2026): Ranked for Global Programs, Procurement and Continuous Coverage
Network SecurityWeb App Security

Best Enterprise Penetration Testing Companies (2026): Ranked for Global Programs, Procurement and Continuous Coverage

The best enterprise penetration testing companies in 2026, ranked on capacity, CREST and threat-led schemes, vendor security, MSA terms and board reporting.

31 min read

Best Penetration Testing Companies for Hotels and Hospitality (2026): Ranked for PCI DSS, Guest Data and Franchise Networks
Network SecurityWeb App Security

Best Penetration Testing Companies for Hotels and Hospitality (2026): Ranked for PCI DSS, Guest Data and Franchise Networks

The best penetration testing companies for hotels and hospitality groups in 2026, ranked, with what PCI DSS 11.4, the FTC Marriott order and PIPEDA require.

31 min read

Contents

X