Accreditation Standards

CREST Accredited Penetration Testing

CREST accreditation is the company-level quality assurance standard that verifies a penetration testing firm's technical capability, quality management, ethical conduct, and legal compliance.

CREST accreditation is the company-level quality assurance standard awarded by the Council for Registered Ethical Security Testers (CREST) that verifies a penetration testing firm's technical capability, quality management, ethical conduct, and legal compliance.

Procurement teams, security managers, and compliance officers use it as a vendor-risk filter, not as decorative proof of quality. This guide explains what CREST assesses, how company accreditation differs from individual certification, how the standard compares with CHECK and ISO 27001, and when it should be a mandatory buying criterion rather than an optional logo.

CREST is a not-for-profit organisation headquartered in the UK. It exists to raise the quality floor in the cyber security services industry, where technical competence and ethical conduct still vary widely between providers. The scheme gives buyers an independent way to distinguish firms that have submitted to assessment from firms that only claim to be competent.

CREST Company Accreditation

An organisational assessment of the firm that will contract, insure, quality-check, and report the work. This is the stronger default requirement in procurement.

CREST Individual Certification

A personal technical qualification for testers who pass CREST examinations such as CRT, CSTL, and CTL. It proves a named person can actually test.

CREST accreditation applies to companies. CREST certification applies to individuals. That distinction sits behind every sound buying decision, and confusing the two is the most common mistake in RFPs. CREST covers several service categories:

  • penetration testing
  • vulnerability assessment
  • incident response
  • threat intelligence

Penetration testing is the primary focus for most buyers using the standard as a vendor gate. Always match the accredited category to the work you are buying. A firm accredited for a neighbouring service is not automatically accredited for the test you need.

CREST accreditation is not a marketing badge. It is a third-party verification mechanism with an assessment process behind it. If you are building a shortlist, treat accreditation as a baseline trust signal, then apply a structured method for how to choose a pentesting company based on scope fit, team quality, and reporting, not the logo alone.

CREST Company Accreditation vs. Individual Certification: What's the Difference?

CREST company accreditation is an organisational assessment of a firm, while CREST individual certification is a personal technical qualification awarded to testers who pass CREST examinations such as CRT, CSTL, and CTL.

Company accreditation covers technical capability, quality management systems, ethical standards, legal compliance, and operational processes. Individual certification proves that a named tester has passed CREST's technical exams. Company accreditation answers whether the firm can contract, control, and deliver the work. Individual certification answers whether a named person can actually test.

The two are linked. A CREST-accredited company must employ a minimum number of CREST-certified individuals, so company accreditation includes individual certification plus an organisational assessment. For procurement, company accreditation is the stronger default requirement because it assesses the firm that will contract, insure, quality-check, and report the work. Individual certificates alone do not prove that the business has repeatable delivery, data handling, or ethical oversight.

CriterionCREST company accreditationCREST individual certification
What is assessedOrganisational technical capability, quality management, ethics, legal compliance, and operational processesPersonal technical competence through CREST examinations (for example CRT, CSTL, CTL)
Who it applies toThe penetration testing firmThe individual tester
What it guaranteesThe firm has met CREST's minimum organisational standards and employs certified testersThe named person has demonstrated exam-level technical skill
How a buyer should use itUse as the primary vendor filter in RFPs and shortlistsUse to check the specific people assigned to your engagement

Require both where the risk justifies it: an accredited firm, then named certified testers. Accreditation covers minimum organisational standards, not excellence. It does not guarantee that every tester on every engagement is equally experienced, and accredited firms are not interchangeable. Ask:

  • who will actually test your systems
  • which CREST certifications they hold
  • how long they have worked on comparable scopes
  • whether a junior tester will be unsupervised on a high-value asset

Use company accreditation as the filter. Use named-team evidence as the quality check.

How CREST Accreditation Works: What Firms Actually Have to Prove

CREST accreditation works by evaluating a firm across technical capability, quality management systems, ethical conduct, legal compliance, and operational processes, then requiring that standard to be maintained through periodic review and renewal.

In practice, CREST-accredited status means the firm had to prove it can deliver the service, run it consistently, handle client information securely, carry appropriate insurance, and operate within the law. Technical capability is verified through CREST-certified individuals and practical assessment of the firm's testing capability, not through a scan licence and a template report. The organisational side checks whether the company can repeat that standard across engagements rather than relying on one star tester.

  • Initial application and documentation review: the firm submits evidence of how it delivers services, manages quality, and meets legal and ethical obligations.
  • Technical assessment: CREST examines whether the organisation can actually perform the accredited service, supported by certified testers and a real testing capability.
  • Organisational assessment: quality management systems, ethical conduct, legal compliance, operational processes, appropriate insurance, and robust security controls are in scope. This is where buyers get assurance about data handling, delivery discipline, and professional conduct, not only about exploit skill.
  • Award of accredited status for the relevant service category, such as penetration testing rather than a neighbouring service the buyer did not ask for.
  • Ongoing compliance: accreditation is not a one-time event. Firms must maintain the standard and renew through periodic reviews. A listing that was true last year is not automatically true on the day you award.

The badge certifies that those dimensions were assessed, not that every future report will be equally strong. It certifies process and capability, not a specific engagement outcome. Use it as evidence of verified process, then still judge methodology, scoping discipline, and the team named on your statement of work.

What CREST Accreditation Means for Your Engagement

CREST accreditation means an engagement is more likely to:

  • follow a verified testing methodology
  • produce fewer false positives
  • deliver higher-quality reporting
  • give clearer remediation guidance
  • supply evidence you can defend in a compliance review

Those outcomes matter because a weak test can fail without obvious warning. You still pay the invoice, but you inherit false comfort, noisy findings, or a report that cannot survive audit questions about method, coverage, and tester competence.

Accredited firms have had their processes and ethical standards checked by a third party. That reduces the chance of incomplete testing, unprofessional conduct, or a report that fails an audit because the method cannot be explained. It does not remove your need to define scope, accept rules of engagement, or review sample reporting before award.

CREST-accredited firms may command a premium and can shrink the provider pool. Treat that premium as payment for verified capability and lower vendor risk, not as proof that a cheaper non-accredited test is worthless. The cost of a shallow test, a missed critical finding, a failed audit, or a report you cannot defend usually exceeds the difference in professional fees. Requiring CREST is an investment in risk reduction when the engagement can affect regulation, reputation, or a high-value target. It is optional overhead when those conditions are absent and you already have other strong quality evidence.

Require CREST if

You operate in a regulated industry, supply government or critical services, face formal audit, buy for a high-value target, or need a defensible third-party quality signal in an RFP. Write it as a mandatory company-level requirement, then still score the named team.

Weigh other factors more heavily if

The engagement is lower risk, the budget is tightly constrained, and you already have strong references, a tightly written scope, and named testers whose individual credentials you can check. A well-recommended non-accredited firm can still be acceptable, provided you do not treat the organisational assurance as equivalent.

How to Verify a Provider's CREST Accreditation

You verify a provider's CREST accreditation by checking the official CREST-approved register, confirming the service category and validity period, then validating the certified people who will run your test.

Do this before you add a firm to a shortlist or award a contract, not after legal has started drafting. Checking for a CREST logo is not verification. For regulated industries, write CREST company accreditation into the RFP as a mandatory requirement so the filter is applied before commercial negotiation. Build the checks below into the selection timetable rather than treating them as post-signature due diligence.

  • Official register: visit the official CREST-approved register on the CREST website and search for the company name exactly as it appears on contracts and invoices, including group, trading, and legal-entity names.
  • Service category: verify that the accreditation covers the service you need, for example penetration testing, not only vulnerability assessment, incident response, or threat intelligence.
  • Validity and renewal: check the accreditation's validity period and renewal status so you are not relying on an expired listing.
  • Certified bench: confirm the number of CREST-certified individuals the firm employs. A thin bench is a delivery risk even when the company badge is genuine.
  • Named team: ask about the specific team for your engagement, including individual certifications (CRT, CSTL, CTL, or equivalent CREST grades) and experience on comparable assets. Company status does not tell you who will be in the testing window.
  • Direct confirmation: contact CREST directly if the register, the proposal, and the company's claims do not match, or if you cannot reconcile the listed entity with the contracting party.

Accreditation is a gate. Sample reports, references, scoping quality, and named testers still decide who wins the work. If a bidder cannot show a current register listing for the right service, do not accept a logo on a slide as a substitute.

CREST vs. CHECK vs. ISO 27001: How the Standards Compare

CREST is a company-level competence standard for cyber security testing services, CHECK is the UK government's penetration testing scheme managed by the National Cyber Security Centre (NCSC), and ISO 27001 is a broad information security management standard that applies to any organisation.

Choose the requirement from the job you need done. Do not stack every badge because a proposal looks safer with more logos. The right certification depends on context:

  • CREST is strong for UK and EMEA enterprise testing
  • CHECK is the specific gate for certain UK government work
  • ISO 27001 answers a different question about the supplier's own security management
AttributeCRESTCHECKISO 27001
What it isAccreditation and certification for cyber security testing servicesUK government penetration testing schemeInformation security management system standard
Who oversees itCREST (Council for Registered Ethical Security Testers)NCSCISO, via accredited certification bodies
What it provesCompany testing capability plus certified individuals, for CREST service categoriesFitness to test certain UK government and related systems under CHECK rulesThe organisation manages information security through a certified ISMS
When buyers should require itUK and EMEA enterprise testing, commercial assurance, and many government-adjacent contractsSpecified UK government work where CHECK is a procurement conditionWhen you need evidence of the provider's own security management, not tester skill
Geographic weightUK-headquartered, widely recognised across EMEA and beyondUK government-focusedInternational, not testing-specific

CREST and CHECK are not substitutes. CHECK is the gate for certain UK government work. CREST is broader and more useful as an international commercial quality signal. Many capable firms hold both, which is the clean answer when you buy for mixed government and commercial estates. If the contract is specified CHECK work, CREST alone will not satisfy the scheme. If the contract is commercial or cross-border, CHECK alone may be narrower than you need.

CREST and ISO 27001 are complementary. ISO 27001 does not prove penetration testing competence. CREST does not replace an information security management system. A firm can hold both, and a buyer can require both when the contract needs testing skill and evidence that the supplier protects client data. Cyber Essentials Plus, where it appears in UK buying packs, is likewise not a substitute: it speaks to an organisation's own cyber hygiene, not to CREST-assessed testing competence.

Individual certifications such as OSCP or SANS/GPEN assess a person's skills. They do not assess the company. Use them to interrogate the named team after the company has cleared CREST, CHECK, or both. No single credential fits every context. CREST is strong for UK and EMEA enterprise and government-adjacent buying. CHECK is the specific requirement where NCSC's scheme applies. ISO 27001 answers a different question about management systems.

CREST in the UK Context: Why It Matters for UK and EMEA Buyers

CREST matters for UK and EMEA buyers because it is a UK-headquartered standard that procurement teams already recognise, while remaining usable across European and wider EMEA supplier panels.

NCSC oversees CHECK, the UK government's penetration testing scheme. For specified government work, CHECK can be the mandatory route. CREST sits alongside that landscape as the broader professional standard for testing firms, which is why government-related buying often references CREST even when CHECK is the scheme that unlocks a particular contract. The two frequently appear together in due diligence packs because one is scheme-specific and the other is the wider competence mark for testing companies.

UK government procurement frameworks use recognisable assurance marks so buyers are not forced to invent their own definition of a competent tester. CREST accreditation is referenced in that environment because it is an independent assessment of testing companies, not a self-declared skill list. Suppliers to government, to critical national infrastructure-related organisations, and to private firms that inherit government-style due diligence therefore treat CREST as a practical eligibility signal. If you sell into or buy from that ecosystem, omitting CREST often means extra justification later, not less paperwork now.

For a UK commercial buyer, CREST is usually the right company-level requirement for penetration testing assurance. For a UK public-sector or CNI-related buyer, confirm whether CHECK is also required, then look for firms that can evidence both. CREST's UK base and EMEA recognition make it a coherent standard if you buy from the UK and deliver or report into European operations without switching quality languages mid-contract.

Frequently Asked Questions

What are the CREST accreditation standards?

CREST accreditation standards cover a firm's technical capability, quality management, ethical conduct, legal compliance, and operational processes for defined service categories such as penetration testing. A firm must also employ CREST-certified individuals and demonstrate organisational controls, including appropriate insurance and robust security practices.

The standard is maintained through ongoing compliance and renewal, not a single pass. Confirm that the accredited category matches the service you are buying.

What is the difference between CREST accreditation and CREST certification?

CREST accreditation applies to companies and assesses organisational standards. CREST certification applies to individuals and assesses personal technical competence through CREST examinations. A CREST-accredited company must employ a minimum number of CREST-certified individuals.

Require company accreditation as the vendor filter, then confirm the certifications of the testers assigned to the job. Asking only for CREST-certified testers leaves the contracting firm's processes, insurance, and quality management unchecked.

Is CREST certification worth it?

Yes, CREST certification is worth it for testers who need a recognised technical proof point, and CREST company accreditation is worth requiring when you need organisational assurance for enterprise, regulated, or government-related testing. For buyers, the value is third-party verification of capability and process, which reduces vendor risk, supports audit narratives, and simplifies UK and EMEA procurement.

The trade-off is a smaller provider pool and a possible fee premium, which is usually justified when a failed, shallow, or indefensible test would cost more than the difference. For a low-risk internal check with strong named testers and references, accreditation may be one factor among several rather than the deciding one.

How do I verify a company's CREST accreditation?

You verify a company's CREST accreditation by searching the official CREST-approved register, confirming the service category and validity period, and checking the certified team named for your engagement. Match the legal entity on the contract to the listed name, and confirm the listing covers penetration testing if that is what you are buying.

If the register, the proposal, and the company name on the contract disagree, contact CREST before you award. Put this check in the selection timetable, not in post-signature due diligence.

What is the difference between CREST and CHECK penetration testing?

CREST is a broader accreditation for cyber security testing firms, recognised across the UK, EMEA, and beyond. CHECK is the NCSC-managed UK government penetration testing scheme required for certain government work. They answer different procurement questions.

CHECK is the condition where the government scheme applies. CREST is the wider commercial and international competence mark. Many firms hold both, which is the practical combination when you buy for mixed commercial and UK government estates.

Does CREST accreditation guarantee quality penetration testing?

No, CREST accreditation does not guarantee quality on every engagement. It verifies that the firm met CREST's organisational standards and employs certified testers. Quality still depends on scope, methodology, and the specific people assigned.

Accreditation is the baseline, not the ceiling. Use it as the filter, then evaluate team composition, sample reports, comparable experience, and engagement design before you buy.

Ready to make CREST a mandatory buying criterion?

Use company accreditation as the vendor filter, then judge the named team, sample reports, and scope fit before you award. Treat the badge as verified process, not as a substitute for due diligence.