Two different things, one word
CREST accredits organisations, and it also certifies individuals. These are separate and a tender requirement almost always means the first.
Company-level accreditation means the organisation has been assessed: its methodology, its quality processes, its data handling, its complaints procedure. It is audited and renewed.
Individual certification means one named person has passed an examination. Valuable, but it says nothing about the company they work for, and it does not transfer.
A provider with one CREST-certified tester on staff can write "CREST" on a proposal without technically lying, and many buyers will read that as the accreditation their tender asked for. If your contract requires an accredited provider and you buy from an unaccredited one, the report may be rejected at exactly the point you cannot afford it to be.
How to check, properly
- Search the CREST member directory for the company name, exactly as it appears on the quote.
- Check the accreditation covers the discipline you are buying. Penetration testing, incident response and threat intelligence are separately accredited.
- If you find only an individual, ask the provider directly: "is the company itself CREST accredited, and can you send the listing?" A straight answer takes seconds.
Ours is here. Any accredited provider will hand you theirs without hesitating.
CREST, CHECK and what your buyer probably means
| Named in the requirement | What it actually means | Who needs it |
|---|---|---|
| CREST | Company assessed against CREST's standards for the named discipline | Most commercial and public sector contracts |
| CHECK | NCSC scheme for testing UK government systems handling protectively marked data | Central government and some critical national infrastructure |
| "Accredited" with no scheme named | Ambiguous. Ask the buyer in clarifications | Worth a clarification question, which costs you nothing |
| Nothing named | Any competent provider, but the report still has to stand up | Judge on methodology and the report, not the logo |
If your requirement names CHECK and you are offered CREST, that is not the same thing and it may not be accepted. If it names CREST and you are offered CHECK, that usually is acceptable, but confirm rather than assume.
What accreditation does not tell you
It is a floor, not a ranking. It says the organisation has been assessed against a standard. It does not tell you whether the tester assigned to your job is any good, whether the scope covers what matters, or whether the report will be readable by the people who have to act on it.
So check the accreditation, then ask the questions that actually vary: how many tester-days am I buying, how many user roles will be tested, is testing authenticated, who writes the report, and is a retest included. Those decide the value you get far more than the badge does.
What it costs
CREST-accredited day rates in the UK run roughly £800 to £1,200. Unaccredited or offshore work runs £250 to £500, and at that price you are usually buying an automated vulnerability scan with a cover page rather than manual testing. If your tender names CREST, the cheaper number is not a saving. It is a wasted spend, because the report will not satisfy the requirement.
What the report has to contain
Accreditation gets a provider onto the shortlist. The report is what the buyer, the auditor or the underwriter actually reads, and the same five things get checked every time.
- A named provider and a named tester, with the accreditation stated rather than implied.
- The methodology, named and aligned to a recognised standard, so the reader knows what was and was not attempted.
- Evidence and reproduction steps for each finding, not a severity label on its own.
- A severity rating with a rationale, so a director can tell a real problem from a hardening suggestion.
- A retest confirming closure. A report full of open criticals proves only that you had a test.
If you are buying against a tender clause, read what the clause actually asks for before you compare quotes. "CREST-accredited provider" and "CREST-certified tester" are different requirements and a provider may meet one without the other.
Fixed fee or scoped
Two tests have genuinely fixed scope and can be bought outright: an external infrastructure test of up to ten public IP addresses, and a standard CMS website test. Both are delivered by a CREST-registered tester at a CREST-accredited company, so both satisfy a clause asking for either.
Anything with multiple user roles, a payments flow, an API or an internal network is scoped and quoted. That is not a sales step, it is the difference between a price that reflects your environment and a price that reflects a guess.
Questions worth asking before you sign
Who specifically will do the testing, and what do they hold? Will the person who scopes it be the person who does it? Is the report signed by the tester or by someone who did not do the work? Is retesting included or charged? And what happens if something critical is found on a Friday evening?
None of these are awkward questions. A provider who finds them awkward has answered them.
Check your provider in two minutes
Tick what you have actually verified, rather than what you were told.