CHECK or CREST: Which Accreditation Your Contract Needs

CHECK is the NCSC’s scheme for testing systems that handle government information, and it is a requirement rather than a preference where it applies. CREST is an industry accreditation that most commercial buyers, insurers and auditors accept. If your contract names one of them, that is the answer. If it does not, CREST is usually the right level to insist on.

Cyber security accreditation badge over a network mesh representing scheme approval

What CHECK actually covers

CHECK is run by the NCSC and approves companies to test systems processing government information, including public sector networks and parts of critical national infrastructure. Approval covers the company and the individuals, with team leaders and team members holding assessed qualifications, and consultants are security cleared. The scheme exists so a government buyer can be confident about who is on their network and how the work is conducted. If you supply the public sector and the contract references CHECK, a CREST accredited supplier without CHECK status will not satisfy it. Central government buyers usually specify the requirement in the invitation to tender rather than leaving it to the contract.

Where CREST fits

CREST accredits companies against standards for process, data handling and staff competence, and certifies individual testers at registered and certified levels. It is the accreditation most private sector contracts and questionnaires ask for, and it is widely referenced in supplier assurance packs. For a business meeting PCI DSS obligations, satisfying an ISO 27001 auditor or answering a customer’s security questionnaire, CREST accreditation is normally sufficient and is what your buyer will recognise. Insurers ask about it at renewal too, since it gives them a proxy for the quality of the work behind your answers.

“Buyers sometimes treat accreditation as a badge and stop there. Ask which of the accredited staff will run your engagement, because a company can hold accreditation while assigning your work to its newest joiner. The accreditation tells you the process is sound. The named consultant tells you what the report will be worth.”

William Fieldhouse, Director, Aardwolf Security Ltd

Racks of servers representing the infrastructure a tester is trusted to access

Individual qualifications and what they mean

Company accreditation and personal qualification answer different questions. Certifications such as OSCP demonstrate practical exploitation skill and say nothing about how a company handles your report or vets its staff. CREST registered and certified qualifications sit alongside them and are assessed against a defined syllabus. A useful shortlist question is which qualifications the assigned consultant holds and how long they have been testing, because seniority affects findings more than any badge on the proposal.

Verifying before you sign

Check the claim rather than accepting the logo. The NCSC publishes the list of CHECK approved companies and CREST maintains a directory of its members, and both take a minute to search. Ask whether the accreditation covers the specific service you are buying, since a company may be accredited for infrastructure testing and not for web applications. When choosing a penetration testing company, ask for the scope of their accreditation in writing, and if your contract requires cleared staff, request a quote from an accredited team that can confirm clearance levels before the engagement is booked.

Frequently asked questions about testing accreditation

These questions come up whenever procurement reviews a security supplier.

Do you need accreditation for a small web application test?

Not strictly, and it remains the simplest way to filter suppliers. If your customers or insurers will ever ask who tested your systems, an accredited supplier saves you explaining the choice later.

Does accreditation guarantee a good report?

It guarantees a standard of process, data handling and staff assessment. Report quality varies within that, which is why asking for a sample report remains the most useful thing you can do.

Leave a Comment