Best Penetration Testing Companies for Banking and Fintech (2026)
Financial services is the most heavily regulated buyer of penetration testing, and the requirements differ from ordinary enterprise work in three ways. Testing is often mandated rather than chosen, it is frequently supervised, and the scope reaches into systems most testers never touch: core banking platforms, payment rails and card data environments, open banking APIs under PSD2, mobile banking applications, ATMs, and the payment terminals themselves.
The schemes drive most of the demand. DORA makes threat-led penetration testing a legal requirement for significant EU financial entities, built on the TIBER-EU methodology. CBEST does the same job in the UK for firms regulated by the Bank of England and the PRA, with STAR-FS covering a wider set of FCA-regulated firms through CREST. PCI DSS governs anyone touching card data, and PCI PTS governs the payment devices themselves. The providers below hold at least one of these credentials, or list financial services and payment security as a specialism.
The list opens with PCA Cybersecurity, our Featured partner and the one listed firm testing the payment hardware layer: ATMs, POS and unattended terminals, and PIN entry devices, tested down to firmware, card readers, and anti-tamper bypass. That is a different discipline from the network, application, and red team work the rest of this list performs, and the field for it is very small. If you are scoping a supervised red team under CBEST or TIBER-EU, or testing core banking and open banking APIs, the CREST and CBEST-accredited firms below are the right starting point.
Related: Threat-led penetration testing (TLPT) · CBEST-accredited companies · PCI DSS pen testing
What do banks and fintechs actually need tested, and under which scheme?
Start with the regulatory driver, because it determines who is allowed to do the work.
For threat-led testing, the scheme is set by your regulator. In the EU, DORA requires threat-led penetration testing for significant financial entities, using the TIBER-EU framework and its national variants such as TIBER-DE and TIBER-NL, coordinated with the competent authority. In the UK, CBEST is the Bank of England's equivalent for systemically important firms, and STAR-FS is the CREST-run scheme covering a broader set of FCA-regulated firms. All three pre-vet a small pool of providers and require separate threat intelligence and red team suppliers, so the choice is constrained before you start.
For everything below that tier, the work is ordinary penetration testing applied to unusual systems. Core banking and payment processing platforms, often legacy and often intolerant of disruption. Open banking APIs, where PSD2 forces exposure that has to be tested for authorisation flaws and data leakage. Mobile banking applications, where the client is in a hostile environment. Card data environments in PCI DSS scope, where segmentation testing is required annually. And the physical estate: ATMs, PIN entry devices, and payment terminals, which need hardware and firmware attack expertise, side-channel and fault-injection work, and are governed by PCI PTS rather than PCI DSS.
When shortlisting, match the provider to the layer you are testing. A firm with CBEST or TIBER-EU credentials is the right answer for a supervised red team and the wrong answer for an ATM estate. Confirm scheme status directly with CREST, the Bank of England, or your national central bank before appointing, since accreditation is reviewed and can lapse.
PCA Cybersecurity
Our top recommendation on this page.
Munich- and Budapest-based automotive cybersecurity specialist focused on UN R155, ISO/SAE 21434, and vehicle research. Pwn2Own Automotive participant with a dedicated ECU and vehicle test lab.
- Associate Participating Organization of the PCI Security Standards Council since March 2026.
- Tests ATMs end to end: network and authentication, OS hardening, middleware, backend encryption, card readers and cash dispensers, and physical anti-tamper bypass.
- Payment device testing covers POS terminals, unattended payment terminals, PIN entry devices, and mobile payment applications, framed as PCI PTS pre and post compliance testing.
- PCI DSS penetration testing aligned to version 4.0.1, including Requirement 11.3 segmentation testing.
SECFORCE
Canary Wharf-based adversary simulation and CBEST-aligned penetration testing consultancy, delivering CREST-accredited offensive security to UK financial services and other organisations with the most demanding requirements.
NetSPI
Penetration testing firm trusted by nine of the top ten US banks, with the Resolve platform for continuous attack surface management.
PwC Cyber Security
Global Big Four professional services firm delivering CREST, CHECK, and CBEST-accredited penetration testing and red teaming services from London, serving the UK's largest enterprises and regulated organisations.
Dionach
Global enterprise cybersecurity consultancy founded in 1999 in Oxford, holding rare CREST STAR-FS accreditation and delivering penetration testing, red and purple teaming, and PCI QSA services across five international offices.
Raxis
US penetration testing firm founded in 2011, running 600+ engagements a year with a fully remote, US-based team. Manual, expert-led testing across web, network, cloud, mobile, wireless, OT/ICS, and AI/LLM. Gartner Sample Vendor for PTaaS.
WorkNest Secure
CREST and CHECK-accredited UK penetration testing and managed security provider formed in 2026 from Pentest People, Bulletproof, and Target Defense, with CREST STAR/TLPT-FS capability and the GuardNest vulnerability management platform.
MDSec
Elite UK offensive security consultancy specialising in CBEST/STAR/TIBER red teaming, advanced adversary simulation, and CREST-accredited penetration testing for FTSE 100 clients.
Secarma
Manchester-based independent cybersecurity consultancy with over 20 years of experience delivering CREST and CHECK-accredited penetration testing, red teaming, and compliance certification services.
Cyberis
CREST and CHECK-accredited UK penetration testing consultancy with CBEST approval, specialising in infrastructure, application, and simulated attack assessments across the public and private sectors.
Aristi
CHECK and CREST-accredited Birmingham-based cyber security consultancy with over 15 years of experience delivering penetration testing, red teaming, and OT security assessments for government and private sector clients.
JUMPSEC
Full-service London-based cybersecurity consultancy with CREST, CHECK, and NCSC accreditations delivering offensive testing, managed detection, and strategic advisory services.
Best Penetration Testing Companies for Banking and Fintech (2026), FAQs
What penetration testing do banks have to do by law?+
It depends on the regulator. Under DORA, significant EU financial entities must undergo threat-led penetration testing at least every three years, using the TIBER-EU methodology. In the UK, CBEST applies to firms the Bank of England and PRA consider systemically important. Separately, PCI DSS requires annual penetration testing and segmentation testing for any organisation handling card data, which covers most banks, acquirers, and payment providers.
What is the difference between CBEST, STAR-FS, and TIBER-EU?+
All three are threat-led penetration testing schemes for financial services. CBEST is the Bank of England's, for systemically important UK firms, using bespoke threat intelligence. STAR-FS is run by CREST, covers a wider range of FCA-regulated firms, and can be self-initiated. TIBER-EU is the European Central Bank's framework, mandated under DORA for significant EU entities and adapted nationally as TIBER-DE, TIBER-NL and others.
Who tests ATMs and payment terminals?+
Very few firms. Payment hardware needs a security lab, embedded and firmware expertise, and side-channel and fault-injection capability, which is a different discipline from network or application testing. It is governed by PCI PTS, the device standard, rather than PCI DSS. PCA Cybersecurity is the specialist listed here for payment device and ATM testing.
What should a fintech look for that a bank might not?+
Fintechs are usually testing cloud-native platforms and open banking APIs rather than legacy core systems, and are more often driven by customer due diligence and SOC 2 or ISO 27001 than by a supervisory mandate. Look for cloud and API testing depth, PSD2 and open banking experience, and a provider that can turn work around quickly enough for a continuous release cycle.