Singapore detected 284,300 infected systems in 2025, a 142% increase on the previous year, according to the Cyber Security Agency of Singapore's Singapore Cyber Landscape 2025/2026, published 30 June 2026. In the same period the APT actor UNC3886 attempted an intrusion against all four of Singapore's major telecommunications operators, prompting Operation CYBER GUARDIAN, the largest coordinated cyber incident response in the country's history.
Singapore is also the only market in this series where penetration testing is a licensed activity. Under Part 5 of the Cybersecurity Act, a provider cannot legally offer penetration testing to the Singapore market without a licence, and that single fact should reorder how you shortlist. The leading licensed providers for 2026 are Vantage Point Security, Ensign InfoSecurity, STAR Labs SG, watchTowr, Centurion Information Security and Swarmnetics.
Penetration Testing Is a Licensed Activity in Singapore
This is the part most buyer's guides get wrong, so it is worth stating precisely.
Section 24(1) of the Cybersecurity Act makes it an offence to engage in the business of providing a licensable cybersecurity service, or to advertise that you provide one, without a licence. Two services are currently licensable: penetration testing and managed security operations centre monitoring. The framework commenced on 11 April 2022, and the grace period for existing providers closed on 11 October 2022. Providing an unlicensed licensable service carries a fine of up to S$50,000, imprisonment of up to two years, or both, per the Cyber Security Agency of Singapore.
The framework is administered by the Cybersecurity Services Regulation Office (CSRO), set up on 11 April 2022 to issue and revoke licences, maintain the public register, and investigate breaches.
Three points from the official CSRO guidance matter for procurement:
Overseas providers are in scope. The CSRO states that "resellers, third-party vendors or overseas CSPs including the affiliates of a licensee who provide licensable cybersecurity services to the Singapore market would need to be licensed." A provider with no Singapore office is not exempt.
"Singapore market" is defined broadly. It covers "persons who engage or intend to engage in or advertise its businesses of providing licensable cybersecurity services in Singapore," and generally includes "persons with customers located in Singapore."
Subcontractors count. If your prime vendor quietly subcontracts the testing, the subcontractor needs its own licence. Ask who is actually holding the keyboard.
One narrow exemption exists: a company providing licensable services solely to its own related companies, such as an in-house testing team, does not require a licence.
Two 2026 changes are worth diarising. From 16 March 2026, applicants and licensees must hold an active Cyber Trust mark (CTM) Promoter (Tier 3) certification or equivalent, with a grace period to 31 December 2026 to obtain it. From 13 July 2026, renewal applications can be submitted up to one day before licence expiry. If you are signing a multi-year testing agreement, confirm your provider's plan for the CTM condition before the grace period closes.
How to check a provider's licence
The CSRO publishes the full register of licensees, updated weekly, at csro.gov.sg/resources/licensed-service-providers. Download the business-entity list and search for the exact legal entity that will sign your contract, not the marketing brand. As of the 7 August 2026 edition, 404 business entities hold a penetration testing licence and 319 hold a managed SOC monitoring licence.
The register groups licensees by the Cyber Trust mark tier they hold: 64 at Advocate (Tier 5), 2 at Performer (Tier 4) and 338 at Promoter (Tier 3). Read that grouping carefully. Cyber Trust mark tiers are assigned according to an organisation's own digital maturity and size, with Advocate aimed at large organisations of leading maturity, so the tier describes the provider's own security posture, not the technical skill of its testers. It is a useful due-diligence signal and a poor proxy for testing quality.
Why Singapore Pentesting Demand Is Rising in 2026
The threat picture worsened on the metrics that matter to enterprises. Beyond the 284,300 infected systems, CSA recorded 165 ransomware cases in 2025, up from 159 in 2024, with SMEs disproportionately affected. Phishing reports actually fell 21% to roughly 4,800, but CSA attributes the shift to AI-generated lures, voice clones and deepfakes that are harder to count and harder to catch.
MAS TRM Guidelines set the bar for financial services. The Technology Risk Management Guidelines devote section 13.2 to penetration testing. Clause 13.2.1 expects "a combination of blackbox and greybox testing" for online financial services. Clause 13.2.3 expects testing on the production environment with proper safeguards. Clause 13.2.4 is the one your auditor will quote: for systems "directly accessible from the Internet, the FI is expected to conduct PT to validate the adequacy of the security controls at least once annually or whenever these systems undergo major changes or updates." Note what the text does not say: it does not impose a blanket annual mandate on every system. Frequency elsewhere is risk-based, determined by criticality and exposure.
PDPA turned breaches into a reporting and penalty event. Since 1 February 2021, a breach that causes significant harm or affects 500 or more individuals must be notified to the PDPC within 72 hours of establishing it is notifiable. Financial penalties reach 10% of annual Singapore turnover for organisations turning over more than S$10 million, or S$1 million, whichever is higher.
CII obligations are tightening. CSA has required all critical information infrastructure owners to attain Cyber Trust mark certification by end-2027, extending expectations beyond the designated CII systems the Cybersecurity Act already regulates. CSA also expanded the Cyber Essentials and Cyber Trust marks in 2025 to add mandatory cloud and AI security requirements, and reports that more than 800 organisations held at least one Cyber Essentials certification as of early 2026.
The practical consequence: an annual scan-and-PDF no longer satisfies a Singapore board, a MAS examiner or a PDPC investigator. Buyers are moving toward continuous testing backed by testers who publish real research.
How This Ranking Was Built, and a Disclosure
Every provider named below was checked against the CSRO business-entity register dated 7 August 2026 before being considered. Providers were then assessed on CREST accreditation, depth and seniority of the testing bench, published vulnerability research, Singapore market track record, and fit against common buyer scenarios. Vendors whose primary product is vulnerability scanning, attack surface discovery or compliance consulting rather than penetration testing were excluded, with one deliberate exception explained in its entry.
Disclosure: this guide is published by Stingrai, and Stingrai does not appear in the ranking. The ranking is limited to entities on the CSRO register, and Stingrai is not a licensed cybersecurity service provider in Singapore. Stingrai Inc is a CREST-accredited Penetration Testing service provider headquartered in Toronto with a London office, founded in 2021, whose researchers have published 18 CVEs and present at DEF CON and BSides. That is the basis for the editorial analysis here, and it is not a basis for inclusion in a Singapore ranking. Readers evaluating providers for Singapore-regulated scopes should verify licence status directly on the CSRO register rather than relying on any guide, including this one.
Quick Comparison: Best VAPT Providers in Singapore
Company | Best For | Methodology | Key Signals |
|---|---|---|---|
1. Vantage Point Security | All-round Singapore testing at scale | Manual-first, platform-assisted | Singapore HQ, founded 2014, 50+ CREST-accredited consultants, offices in Jakarta and Bangkok, licensed at CTM Tier 5 |
2. Ensign InfoSecurity | Enterprise, government and CII scale | Manual-first consultancy plus MSSP | Singapore HQ, Temasek-backed, Asia's largest pure-play cybersecurity firm, six licensed Singapore entities at CTM Tier 5 |
3. STAR Labs SG | Deep research, hardware and appliances | Vulnerability research led | Singapore, two-time Master of Pwn at Pwn2Own, credits from Microsoft, Google, Apple, Oracle and Samsung |
4. watchTowr | Continuous validation of external exposure | Continuous automated testing plus research | Singapore HQ, US$19m Series A led by Peak XV, watchTowr Labs research output, CREST listed |
5. Centurion Information Security | Independent boutique testing | Manual-first consultancy | First Singapore company CREST-approved for penetration testing, small senior bench |
6. Swarmnetics | Mid-market web, mobile and cloud | Manual testing plus adversarial simulation | Singapore core team, CREST and OSCP certified, licensed at CTM Tier 5 |
7. The Big Four (Deloitte, PwC, KPMG, EY) | Board-level risk and governance | Consulting | All four licensed in Singapore, audit bundling, premium pricing |
1. Vantage Point Security
Vantage Point Security is a Singapore-headquartered specialist founded in 2014, and the most complete all-round choice for Singapore buyers in 2026. Penetration testing is the core business rather than an attachment to a managed service, and the firm fields more than 50 CREST-accredited consultants across Southeast Asia, delivering what it describes as over 80,000 hours of application security and penetration testing work a year.
It holds licence CS/PTS/C-2022-0158RR and sits in the Cyber Trust mark Advocate (Tier 5) group on the CSRO register, alongside ISO 27001:2022 certification and a SOC 2 attestation. Offices in Singapore, Jakarta and Bangkok make it a practical single supplier for a regional estate, which matters if your Singapore holding company owns Indonesian and Thai subsidiaries.
The firm runs an internal delivery platform, Velocity, with a documented test-case library mapped to a wide set of standards. That is the right answer to the most common complaint about boutique testing: consistency between one consultant and the next.
Pros
Genuine regional coverage: Singapore, Indonesia and Thailand under one accredited supplier, which removes the multi-vendor stitching that regional groups usually endure.
Bench depth at boutique focus: 50-plus CREST-accredited consultants is a large dedicated testing team by Singapore standards, without Big Four commercial overhead.
Breadth of scope: web, cloud, infrastructure, IoT and hardware, source code review, red team and LLM testing under one roof.
Cons
Less public vulnerability research than STAR Labs or watchTowr, so if you are buying for pure 0-day depth on an appliance, look further down this list.
Platform is internal, not a customer-facing PTaaS portal, so developer-workflow integration is lighter than a platform-first vendor.
Best For: Singapore and Southeast Asian organisations that want one accredited supplier covering a full testing programme across multiple countries.
2. Ensign InfoSecurity
Ensign InfoSecurity is the default answer for large Singapore enterprises, government-linked entities and CII owners. Formed in 2018 through the merger of Quann and Accel Systems & Technologies, it is a joint venture between Temasek and StarHub, headquartered at 6 Commonwealth Lane in Singapore, with regional offices across Malaysia, Hong Kong, Thailand and India. It is widely described as Asia's largest pure-play cybersecurity firm and ranks among the top global MSSPs.
Ensign holds six licensed Singapore entities in the penetration testing category, all in the Advocate (Tier 5) group, with the primary entity licensed as CS/PTS/C-2022-0181R. Services span vulnerability assessment, penetration testing, red teaming and adversarial attack simulation, on top of managed detection and threat intelligence.
One 2026 procurement note: StarHub agreed in April 2026 to unwind an assignment of rights covering a 16.81% stake, receiving S$115 million, which reduces its effective stake and increases Temasek's control. Ownership is shifting, though the delivery organisation is unaffected.
Pros
Scale and clearance: built for multi-year national-scale programmes, with the procurement machinery Singapore government and CII tenders expect.
Testing plus detection under one contract: offensive findings can feed directly into a managed SOC, which is rare at this quality level in the region.
Regional delivery footprint across five markets for groups with distributed infrastructure.
Cons
Calibrated for enterprise: a single scoped web app test is disproportionate to the commercial overhead, and startups will find the engagement model heavy.
Consultant seniority varies across a delivery organisation of this size. Name your test lead in the statement of work.
Best For: Banks, government agencies, CII owners and large enterprises that need scale, clearance and an offensive-plus-defensive contract.
3. STAR Labs SG
STAR Labs SG is the deepest pure vulnerability-research bench in the Singapore market, and the right call when the target is a product rather than a web form. The team has won Master of Pwn at Pwn2Own twice, holds acknowledgements from Microsoft, Google, Apple, Oracle and Samsung, and publishes original research at top-tier conferences.
It is licensed as CS/PTS/C-2022-0106RR and sits in the Advocate (Tier 5) group. Testing scope covers web and mobile applications, APIs, network infrastructure, cloud across AWS, Azure and GCP, and device firmware.
The distinction that matters: most providers staff a test with consultants who run a methodology. STAR Labs staffs tests with researchers who break browsers, operating systems and enterprise appliances competitively. If your risk sits in a shipped product, an embedded device or a security appliance you depend on, that difference is the whole engagement.
Pros
Elite exploit-development capability, verified publicly at Pwn2Own rather than asserted in a capability statement.
Hardware and firmware depth that very few providers in Asia can match.
Research output is public and checkable, which is the strongest available signal that a vendor does offensive work rather than compliance paperwork.
Cons
Not a compliance-paperwork shop: if you need a high-volume annual test cycle across 40 low-risk applications, this is over-specified and priced accordingly.
Smaller bench than the enterprise providers, so book specialist work well ahead of a deadline.
Best For: Product companies, device manufacturers, and enterprises whose critical risk sits in firmware, appliances or complex native software.
4. watchTowr
watchTowr is the deliberate category exception in this ranking. Its primary product is preemptive exposure management, a continuously running platform that discovers external attack surface and validates exploitability, rather than a scoped point-in-time penetration test. It is included because it holds a Singapore penetration testing licence (CS/PTS/C-2022-0192R), is listed on the CREST Marketplace as a penetration testing provider, and solves a problem the other six do not.
Founded by Benjamin Harris and headquartered at 135 Cecil Street in Singapore, the company raised a US$19 million Series A in October 2024 led by Peak XV, with participation from Prosus Ventures and Cercano Management, taking total funding to US$29 million. It holds ISO 27001 and SOC 2 Type 2.
watchTowr Labs is among the most prolific public vulnerability-research teams in the world, routinely publishing analysis of exploited edge-device and appliance vulnerabilities within days of disclosure. That research feeds the platform's detection content, which is the real argument for it: when a new edge-device flaw lands, you find out whether you are exposed in hours rather than at your next scheduled test.
Pros
Closes the between-tests gap, which is where most real compromises happen.
Research-driven detection on exactly the edge devices and appliances that ransomware crews target first.
Singapore-headquartered with global enterprise references and strong institutional backing.
Cons
Not a replacement for a scoped manual pentest. It will not satisfy an auditor asking for a MAS TRM greybox test of an authenticated application with multiple user roles.
Business-logic and authorisation flaws in bespoke applications remain the domain of manual testing.
Best For: Organisations with large, changing internet-facing estates that need continuous validation running alongside, not instead of, an annual manual test.
5. Centurion Information Security
Centurion Information Security is the independent boutique on this list, and notable as the first Singapore-headquartered company approved by CREST for the delivery of penetration testing services. It is licensed as CS/PTS/C-2022-0041RR.
The practice is deliberately small and senior: independent penetration testing, source code review, vulnerability assessment and security consulting, delivered by a hand-selected consultant bench rather than a large pyramid. Clients range from SMEs through multinationals to government entities.
For a mid-market Singapore buyer, this is often the sweet spot. You get a CREST-accredited, licensed provider whose senior people are actually on your engagement, without paying an enterprise programme premium or being routed to a junior consultant.
Pros
Senior testers on the engagement, not a bench-warming model, because the firm is small enough that the people who scope are the people who test.
Long-standing CREST pedigree as Singapore's first CREST-approved penetration testing company.
Independently owned, so there is no parent-company cross-sell pressure on scope.
Cons
Finite capacity. A boutique cannot absorb a sudden enterprise-wide programme, so plan lead times.
Lighter platform tooling. Reporting is consultancy-grade rather than a developer-facing continuous portal.
Best For: Singapore SMEs and mid-market organisations that want CREST-accredited, licensed testing with senior people and no enterprise overhead.
6. Swarmnetics
Swarmnetics is a Singapore-based provider licensed as CS/PTS/C-2022-0090RR and grouped at Cyber Trust mark Advocate (Tier 5). Its core team is based in Singapore and consists of CREST-certified penetration testers who also hold OSCP.
Service coverage is broad for a firm of its size: vulnerability assessment across network, web application and cloud; penetration testing across infrastructure, applications, cloud and IoT; configuration review for hosts, firewalls and cloud services; secure code review and software composition analysis; and adversarial simulation including phishing, red team and purple team exercises. The firm reports having tested more than 800 web and mobile applications and 6,000 networks and servers.
Pros
Certification density on the delivery team, with CREST and OSCP held by the core Singapore testers rather than by a separate credentialled minority.
Purple team capability at mid-market pricing, which is unusual and valuable if you have a SOC you have never actually stress-tested.
Broad scope coverage from code review through to adversarial simulation.
Cons
Thinner public research output than STAR Labs or watchTowr.
Less suited to the largest regulated programmes, where the enterprise providers have the governance machinery.
Best For: Singapore mid-market organisations wanting broad VAPT coverage plus purple teaming from a licensed, CREST-certified team.
7. The Big Four (Deloitte, PwC, KPMG, EY)
All four hold Singapore penetration testing licences: Deloitte Singapore Assurance and Deloitte Singapore T&T Cyber at Advocate (Tier 5), PricewaterhouseCoopers Risk Services at Advocate (Tier 5), and KPMG Services and Ernst & Young Advisory at Promoter (Tier 3).
Pros: Unmatched ability to bundle penetration testing into statutory audit, MAS-facing regulatory reporting and global transformation programmes. Board and audit-committee credibility is the product.
Cons: Substantially more expensive than specialists for an equivalent technical scope, and delivery teams are frequently generalist risk consultants rather than dedicated offensive researchers. Turnaround is slower.
Best For: Large multinationals and regulated groups where penetration testing is one line inside a much larger audit or risk contract.
Other Singapore Providers Worth Shortlisting
The seven above cover most buying scenarios. Several other licensed providers are strong on the right scope. Licence status below is from the CSRO business-entity register dated 7 August 2026.
Firm | Origin | Licence | Where it fits |
|---|---|---|---|
softScheck Singapore | German origin, Singapore entity | CS/PTS/C-2022-0082RR | CREST-accredited testing with a strong German-engineering methodology reputation |
wizlynx | Swiss group, Singapore entity | CS/PTS/C-2022-0183R | CREST-approved penetration testing, red teaming and social engineering for regional enterprises |
ST Engineering Info-Security | Singapore | CS/PTS/C-2022-0119RR | Defence, government and OT-adjacent scopes inside a large Singapore engineering group |
NCS | Singapore | CS/PTS/C-2022-0219R | Public-sector programmes where testing attaches to a wider systems-integration contract |
Firmus | Singapore | CS/PTS/C-2022-0110RR | Mid-market VAPT and managed security for regional clients |
Blackpanda | Singapore | CS/PTS/C-2022-0222R | Incident response led, useful when testing should feed a DFIR retainer |
Bugcrowd | United States | CS/PTS/C-2024-0473R | Crowdsourced pentest-as-a-service, licensed at Advocate (Tier 5) |
HackerOne | United States | CS/PTS/C-2024-0539 | Bug bounty and crowdsourced testing, explicitly contemplated by MAS TRM clause 13.2.2 |
YesWeHack | France | CS/PTS/C-2022-0245R | European bug bounty platform with a licensed Singapore entity |
A brand-history note. Buyers still search for Horangi, historically the best-known Singapore application security startup. Horangi was acquired by Bitdefender, with the deal completing in August 2023, and the brand now sits inside Bitdefender's portfolio focused on cloud security posture management. Horangi does not appear on the CSRO register under its own name; Bitdefender APAC Pte. Ltd. holds the penetration testing licence (CS/PTS/C-2022-0184R). Similarly, buyers searching for Privasec should note that the licensed entity on the register is Sekuro Operations Pte. Ltd. (CS/PTS/C-202607-732), following Privasec's absorption into the Sekuro group.
CSA Licence vs CREST vs Cyber Essentials vs Cyber Trust
Singapore has four commonly confused credentials, and two of them share a name with a completely different British scheme. Here is what each actually certifies.
The CSRO penetration testing licence is a legal requirement, not a quality mark. It confirms the entity may lawfully provide penetration testing to the Singapore market, and that its key officers passed a fit-and-proper assessment covering fraud, dishonesty, bankruptcy and prior licence revocation. It does not assess technical testing competence. Treat it as a gate, not a differentiator: every serious candidate must clear it.
CREST is a voluntary international accreditation body that audits member companies against a standard covering process, data handling and tester competency, and separately certifies individuals. It is the closest thing to a technical quality signal in this list. Importantly, CREST accreditation and the CSRO licence are not substitutes for each other. The licence is compulsory and CREST is not; CREST assesses testing practice and the licence does not. Verify company accreditation on the CREST Marketplace rather than trusting a logo, because accreditations lapse.
The Cyber Trust mark is a CSA certification of an organisation's own cybersecurity preparedness, awarded across five tiers: Supporter, Practitioner, Promoter, Performer and Advocate. Tiers map to organisational size and digital maturity, so Advocate is aimed at large, highly mature organisations. Since 16 March 2026 it also functions as a licence condition: licensees must hold CTM Promoter (Tier 3) or equivalent, with a grace period to 31 December 2026. Separately, CSA has required all CII owners to attain Cyber Trust mark certification by end-2027.
The Cyber Essentials mark is CSA's entry-level certification, aimed primarily at SMEs, covering baseline controls and now extended to include cloud, operational technology and AI security requirements. Do not confuse it with the United Kingdom's Cyber Essentials scheme, which is a different programme run by IASME on behalf of the NCSC with different controls and a different assessment model. A vendor citing "Cyber Essentials" in a Singapore tender should be asked which country's scheme they mean.
CREST in Singapore has a formal local presence. The CREST Singapore Chapter was established in 2016 in partnership with CSA and the Association of Information Security Professionals, with support from MAS and the Association of Banks in Singapore, and the first CREST-accredited examination facility in Asia opened at the Singapore Institute of Technology. That gives CREST genuine standing with Singapore financial-sector buyers, but it is a separate scheme from the statutory licence and confers no licensing exemption.
How Much Does VAPT Cost in Singapore in 2026?
Pricing varies widely by scope, depth and assurance framework. The chart below shows typical 2026 Singapore dollar ranges.
Engagement Type | Typical Range (SGD) | Notes |
|---|---|---|
Small web app or single API | S$3,000–9,000 | Under roughly 25 endpoints, unauthenticated plus one role. Very small single-site tests are advertised from about S$1,500 |
Mid-size SaaS or mobile app | S$9,000–25,000 | 25 to 100 endpoints, authenticated, multi-role access |
Network pentest (internal and external) | S$12,000–35,000 | Subnets, Active Directory, lateral movement, egress review |
Cloud pentest (AWS, Azure, GCP) | S$14,000–38,000 | IAM review plus configuration, runtime and application layers |
MAS TRM aligned scope | S$20,000–60,000 | Blackbox plus greybox on production, evidence packaged for examiners |
Annual PTaaS retainer | S$25,000–85,000 | Continuous testing, retests, portal access |
Red team / adversary simulation | S$40,000–120,000 | Multi-week, goal-oriented, SOC and EDR stress test |
Ranges are indicative and compiled from published Singapore provider pricing and market guides. Big Four firms typically quote above these bands for an equivalent technical scope. Two Singapore-specific cost factors are worth budgeting for: retest inclusion, which many regional providers price separately, and regional scope creep, where a Singapore holding company discovers mid-engagement that its Indonesian or Thai subsidiaries were never in scope.
SMEs should also check funding support. CSA offers up to 70% co-funding for cybersecurity advisory services under its CISO-as-a-Service programme, and supports the Cyber Resilience Centre for health checks and post-incident assistance.
How to Choose a Penetration Testing Company in Singapore
Verify the licence first, on the register, for the exact contracting entity. Do not accept a logo or a claim. Download the current list from the CSRO register and match the legal entity name and UEN on your contract. If testing will be subcontracted, verify the subcontractor separately.
Ask about the Cyber Trust mark condition. With the grace period closing on 31 December 2026, ask any prospective provider to confirm they hold or are on track for CTM Promoter (Tier 3) or equivalent. A provider who cannot answer this in August 2026 has not read their own licence conditions.
Match the credential to the scope. MAS-regulated systems need testers who understand clause 13.2 and can produce blackbox plus greybox evidence on production. CII scopes need providers who work at that governance level. Everything else is best served by CREST accreditation plus named senior testers.
Check the testers, not the brand. Ask for bios of the people who will run your test, including OSCP, OSCE3, CREST CRT and published research. A provider who will not name the test lead in the statement of work is telling you something.
Insist on manual validation. Automated scanners miss business-logic flaws, IDOR and chained exploits. Every finding should be manually validated, and every report should distinguish confirmed exploitation from theoretical risk.
Ask what happens after the report. Retest inclusion, remediation support and integration with your developer workflow separate a useful engagement from an expensive PDF. Confirm whether retests are included or billed.
Confirm regional scope up front. If your group operates across ASEAN, decide now whether one supplier covers every entity or whether you accept multiple vendors, and check that each is licensed where required.
Our pentest and red team RFP question bank covers the procurement questions in more depth, and our comparison of penetration testing methodologies explains what to specify in a statement of work.
What to Scope in a Singapore VAPT Engagement
Confirm the provider covers the testing types your risk actually sits in.
Web application testing: SQL injection, cross-site scripting, IDOR and business-logic flaws in customer-facing platforms.
API security testing: REST and GraphQL endpoints, broken authentication and broken object-level authorisation.
Mobile application testing: iOS and Android, insecure storage, certificate pinning bypass and data leakage.
Network testing: external and internal infrastructure, Active Directory and lateral movement paths.
Cloud testing: AWS, Azure and GCP configuration, IAM privilege paths and runtime exposure.
Red teaming and adversary simulation: goal-oriented testing of detection and response, not just vulnerability discovery.
Source code review: white-box analysis that catches classes of flaw dynamic testing cannot reach.
For compliance-driven programmes, confirm the report maps findings to the framework your assessor cites, whether that is MAS TRM, PDPA, PCI DSS 4.0, SOC 2 or ISO 27001. If you are unsure whether your obligation requires a full penetration test or a vulnerability assessment, our guide to what compliance frameworks really require resolves the distinction.
Frequently Asked Questions
Who are the best penetration testing companies in Singapore in 2026?
The strongest licensed providers for Singapore buyers in 2026 are Vantage Point Security, Ensign InfoSecurity, STAR Labs SG, watchTowr, Centurion Information Security and Swarmnetics. Vantage Point Security is the best all-round choice, with more than 50 CREST-accredited consultants and offices across Singapore, Indonesia and Thailand. Ensign InfoSecurity is the pick for enterprise, government and critical information infrastructure scale. STAR Labs SG has the deepest vulnerability-research capability, having won Master of Pwn at Pwn2Own twice. watchTowr suits continuous validation of large external estates. Centurion Information Security and Swarmnetics serve the mid-market. The Big Four suit board-level programmes. All are on the official CSRO licence register.
Do penetration testing providers need a licence in Singapore?
Yes. Penetration testing is a licensable cybersecurity service under Part 5 of the Cybersecurity Act, and section 24(1) makes it an offence to provide or advertise such a service without a licence, punishable by a fine of up to S$50,000, up to two years' imprisonment, or both. The requirement applies to overseas providers serving the Singapore market even without a local presence, and to subcontractors performing the testing on behalf of another vendor. The only significant exemption is for companies providing the service solely to their own related companies. Verify any provider on the register published by the Cybersecurity Services Regulation Office, which listed 404 licensed business entities as of 7 August 2026.
How much does VAPT cost in Singapore in 2026?
Singapore VAPT engagements typically cost S$3,000 to S$9,000 for a small web application or single API, S$9,000 to S$25,000 for a mid-size SaaS or mobile application, S$12,000 to S$35,000 for a network penetration test and S$14,000 to S$38,000 for cloud engagements. A MAS TRM aligned scope generally runs S$20,000 to S$60,000, annual PTaaS retainers range S$25,000 to S$85,000, and red team simulations run S$40,000 to S$120,000. Very small single-site tests are advertised from around S$1,500. Big Four firms typically quote above these ranges for equivalent technical scope.
What is the difference between VAPT and a penetration test?
VAPT stands for vulnerability assessment and penetration testing, and it bundles two distinct activities that Singapore buyers frequently conflate. A vulnerability assessment is breadth-first and largely automated: it enumerates known weaknesses, misconfigurations and missing patches across an estate. A penetration test is depth-first and manual: a tester attempts to exploit and chain findings to demonstrate real business impact, including business-logic and authorisation flaws that no scanner detects. MAS TRM treats them separately, in clauses 13.1 and 13.2 respectively. If a quote is priced like a scan, you are buying a vulnerability assessment regardless of what the proposal calls it.
Does MAS TRM require annual penetration testing?
Not universally, and the distinction matters. MAS TRM Guidelines clause 13.2.4 states that for systems "directly accessible from the Internet, the FI is expected to conduct PT to validate the adequacy of the security controls at least once annually or whenever these systems undergo major changes or updates." For systems that are not internet-facing, the guidelines direct that frequency be determined by criticality and cyber-risk exposure rather than a fixed calendar. Clause 13.2.1 expects a combination of blackbox and greybox testing for online financial services, and clause 13.2.3 expects testing on the production environment with proper safeguards. Clause 13.2.2 explicitly contemplates bug bounty programmes as a complement to, not a replacement for, penetration testing.
What is the difference between Cyber Essentials and the Cyber Trust mark in Singapore?
Both are CSA certifications, and they sit at different levels. The Cyber Essentials mark is the entry-level certification aimed primarily at SMEs, covering baseline controls and extended in 2025 to include cloud, operational technology and AI security requirements. The Cyber Trust mark is the advanced certification, awarded across five tiers from Supporter through Practitioner, Promoter and Performer to Advocate, with tiers assigned according to organisational size and digital maturity. Since 16 March 2026 the Cyber Trust mark also acts as a penetration testing licence condition, requiring licensees to hold Promoter (Tier 3) or equivalent, with a grace period to 31 December 2026. Note that Singapore's Cyber Essentials mark is a different scheme from the United Kingdom's Cyber Essentials, despite the shared name.
Which Singapore penetration testing companies are CREST accredited?
Among the providers in this guide, Vantage Point Security fields more than 50 CREST-accredited consultants across Southeast Asia, Centurion Information Security was the first Singapore-headquartered company approved by CREST for penetration testing delivery, Swarmnetics fields a Singapore core team of CREST-certified testers who also hold OSCP, and watchTowr is listed on the CREST Marketplace as a penetration testing provider. Ensign InfoSecurity maintains CREST-approved entities in the region including Malaysia, Hong Kong and South Korea. softScheck Singapore and wizlynx are also CREST-accredited. Confirm current status on the CREST Marketplace, because accreditations renew on a cycle and can lapse.
How often should a Singapore organisation run a penetration test?
At minimum annually, and after any material change to the environment. For MAS-regulated financial institutions, internet-facing systems carry an explicit expectation of at least annual testing or testing after major change. Organisations releasing software frequently increasingly supplement the annual test with continuous testing that retests on code change, which closes the window between scheduled assessments. Given that CSA recorded a 142% rise in infected systems in 2025, the gap between annual tests is where most practical risk now accumulates. For background on cadence and depth, see our comparison of penetration testing methodologies.
Related Reading
A closing note on verification
Every provider named in this guide was checked against the Cybersecurity Services Regulation Office business-entity register dated 7 August 2026, and every regulatory claim links back to its primary publisher so any statement here can be audited independently. Licence status changes: entities are added, renewed and removed weekly. Before you sign, download the current register and check the contracting entity yourself. It takes two minutes and it is the single highest-value control in Singapore penetration testing procurement.



