Penetration Testing for ST4S Assessment Evidence
Independent manual testing for education technology suppliers that need clear, service-specific security evidence for Safer Technologies 4 Schools assessment preparation.
Framework content reviewed against ST4S Supplier Guide 2026.1 on 12 September 2026.
T1 testing cadence
The current guide places penetration testing within a continuous monitoring plan and describes testing after a major change or at least annually.
Its strongest response option includes external independent resources conducting the penetration test.
EV10 report evidence
The guide lists the most recent redacted penetration-testing report for the assessed service as EV10 evidence related to T1.
The report must remain specific to the service and scope actually tested.
Source: ST4S Supplier Guide 2026.1 . Requirements can change; confirm the current guide and assessment-team instructions before submission.
Security scope for an education platform
Scope is agreed around the product version, roles, integrations and infrastructure that need evidence. Testing is performed only with written authorization.
Evidence-ready deliverables
Prior assessment-evidence experience
CyberSecurityArm has delivered recurring penetration testing for an online education provider whose report was submitted during an ST4S assessment and accepted as supporting evidence.
No confidential report or assessment content is reproduced, and this experience does not imply an ST4S endorsement of CyberSecurityArm.
Public EdTech client feedback
“We work with Florjan every year for our penetration and vulnerability testing.”
Zenva Schools · 5.0 public Upwork feedback · July 2026
This feedback verifies recurring EdTech security work; it is not presented as proof of the separate ST4S evidence statement above.
View the public Upwork profileA controlled engagement from scope to re-test
Confirm the assessed service, version, roles, integrations, evidence needs and authorized boundaries.
Agree rules of engagement, safe testing windows, escalation contacts and sensitive-data handling.
Perform manual-led testing with targeted tooling and record reproducible evidence.
Deliver technical and executive reporting, then support remediation questions.
Re-test agreed fixes and issue an updated status without changing the original scope silently.
Frequently asked questions
Important assessment boundary
CyberSecurityArm is an independent security-testing provider. It is not ST4S, Education Services Australia, NSIP or an education authority. A penetration test supports only part of the broader assessment and does not create or guarantee an ST4S outcome, endorsement, recommendation or product approval. CyberSecurityArm does not use or issue the ST4S Product Badge.
Scope an ST4S evidence-focused penetration test
Share the product type, approximate roles and integrations, target timing and assessment version. Do not include credentials or vulnerability details.