Buying a penetration test

Your tender says CREST. What does that actually mean?

There is a difference between a company holding CREST accreditation and one employee holding a CREST certification. Buyers rarely know it. Some providers rely on that.

Two different things, one word

CREST accredits organisations, and it also certifies individuals. These are separate and a tender requirement almost always means the first.

Company-level accreditation means the organisation has been assessed: its methodology, its quality processes, its data handling, its complaints procedure. It is audited and renewed.

Individual certification means one named person has passed an examination. Valuable, but it says nothing about the company they work for, and it does not transfer.

A provider with one CREST-certified tester on staff can write "CREST" on a proposal without technically lying, and many buyers will read that as the accreditation their tender asked for. If your contract requires an accredited provider and you buy from an unaccredited one, the report may be rejected at exactly the point you cannot afford it to be.

How to check, properly

  1. Search the CREST member directory for the company name, exactly as it appears on the quote.
  2. Check the accreditation covers the discipline you are buying. Penetration testing, incident response and threat intelligence are separately accredited.
  3. If you find only an individual, ask the provider directly: "is the company itself CREST accredited, and can you send the listing?" A straight answer takes seconds.

Ours is here. Any accredited provider will hand you theirs without hesitating.

CREST, CHECK and what your buyer probably means

The accreditations that turn up in UK tender wording
Named in the requirementWhat it actually meansWho needs it
CRESTCompany assessed against CREST's standards for the named disciplineMost commercial and public sector contracts
CHECKNCSC scheme for testing UK government systems handling protectively marked dataCentral government and some critical national infrastructure
"Accredited" with no scheme namedAmbiguous. Ask the buyer in clarificationsWorth a clarification question, which costs you nothing
Nothing namedAny competent provider, but the report still has to stand upJudge on methodology and the report, not the logo

If your requirement names CHECK and you are offered CREST, that is not the same thing and it may not be accepted. If it names CREST and you are offered CHECK, that usually is acceptable, but confirm rather than assume.

What accreditation does not tell you

It is a floor, not a ranking. It says the organisation has been assessed against a standard. It does not tell you whether the tester assigned to your job is any good, whether the scope covers what matters, or whether the report will be readable by the people who have to act on it.

So check the accreditation, then ask the questions that actually vary: how many tester-days am I buying, how many user roles will be tested, is testing authenticated, who writes the report, and is a retest included. Those decide the value you get far more than the badge does.

What it costs

CREST-accredited day rates in the UK run roughly £800 to £1,200. Unaccredited or offshore work runs £250 to £500, and at that price you are usually buying an automated vulnerability scan with a cover page rather than manual testing. If your tender names CREST, the cheaper number is not a saving. It is a wasted spend, because the report will not satisfy the requirement.

What the report has to contain

Accreditation gets a provider onto the shortlist. The report is what the buyer, the auditor or the underwriter actually reads, and the same five things get checked every time.

If you are buying against a tender clause, read what the clause actually asks for before you compare quotes. "CREST-accredited provider" and "CREST-certified tester" are different requirements and a provider may meet one without the other.

Fixed fee or scoped

Two tests have genuinely fixed scope and can be bought outright: an external infrastructure test of up to ten public IP addresses, and a standard CMS website test. Both are delivered by a CREST-registered tester at a CREST-accredited company, so both satisfy a clause asking for either.

Anything with multiple user roles, a payments flow, an API or an internal network is scoped and quoted. That is not a sales step, it is the difference between a price that reflects your environment and a price that reflects a guess.

Questions worth asking before you sign

Who specifically will do the testing, and what do they hold? Will the person who scopes it be the person who does it? Is the report signed by the tester or by someone who did not do the work? Is retesting included or charged? And what happens if something critical is found on a Friday evening?

None of these are awkward questions. A provider who finds them awkward has answered them.

Check your provider in two minutes

Tick what you have actually verified, rather than what you were told.

Buy a fixed-fee CREST test

Both of these are delivered by a CREST-registered tester at a CREST-accredited company, so the report satisfies a tender clause asking for either. Anything larger is scoped and quoted, which is what a wider scope deserves.

Delivered by a CREST-registered tester at a CREST-accredited company. Verify us on the CREST marketplace.

Optional add-ons
Additional IP addressesIn blocks of 5, beyond the first 10 × £500

Total: £3,000 + VAT

Payment is taken by Stripe. We never see or store your card details. Rules of engagement are agreed in writing before any testing starts.

Not sure your tender requirement is being met?

Send us the clause. We will tell you what it actually requires, whether a quote you have already had satisfies it, and what it should cost. No obligation and no sales call.

Your details are handled by a real person, never fed into AI.