WorkNest

Blog

Understanding CHECK & CREST Penetration Testing

In cyber security, CHECK and CREST penetration testing are two of the best ways to secure your organisation. In this specialist guide, we explore how they work and how they can be applied to protect against long-term cyber threats.

Background Image

The Basics of CHECK and CREST

These are two separate penetration testing accreditations, from the National Cyber Security Centre (NCSC), and the Council of Registered Ethical Security Testers (CREST), respectively. Using a CHECK or CREST certified company for penetration testing services ensures that you are using a competent, legitimate vendor that adheres to industry best practice. For this reason both CHECK and CREST are valuable certifications for penetration testing companies to hold.

CHECK is more formally called a ‘IT Health Check Service’, and is an NCSC initiative for protecting government and public sector systems in line with government policy. CREST, on the other hand, is from the Council of Registered Ethical Security Testers, and accreditation has been developed to ensure the very highest standards of security testing.

But first, let’s recap the basics of penetration testing so we’re all on the same page.

Penetration tests, or “pen tests,” as they are commonly referred to within the cyber security industry and IT communities, are used to find potential vulnerabilities within a company computer system. Penetration testing is carried out by experienced professional security testers, better known as ethical hackers, hired to run the necessary checks on IT systems. It is important to note that penetration tests are usually conducted by external companies (like us) for the simple reason that IT specialists within the company are too close to the process of building its systems to take an objective look at the infrastructure and identify weak points.

External cybersecurity specialists or agencies, such as Bulletproof, pride themselves on providing accurate and detailed penetration testing, with the main vulnerabilities usually outlined in a final report, including prioritising results, giving remediation advice and suggestions for improvements. Penetration Testing should be well resourced by every business, with many types of penetration test available for all types of technology: cloud, web apps, mobile apps, networks, IoT/OT and more. All too often penetration is pushed along the pipeline until a security breach has been identified – by which point systems have inevitably been compromised. We take a closer look at why it is so crucial to carry out regular Pen Tests with trusted third-party providers.

Pen testing is one of the best ways for a company to protect itself from hackers, from the prying eyes of the competition, and from other cyber threats. This is because the process of penetration testing is designed to methodically uncover security risks that a real cybercriminal would try to use to break into systems. The only difference is that in the case of penetration testing, nothing really gets stolen, and no data is left exposed – all vulnerability exploits are carried out with the sole purpose of patching them up after the test is finished. That said, penetration testing is not the same as modelling a real-world attack. For that there’s another service you need: red teaming.

Penetration testing helps businesses to identify their greatest areas of risk and where their systems are vulnerable. They can also serve to test an organisation’s existing security controls and determine their current cyber resilience. Another key reason is that penetration testing supports compliance:

  • GDPR

  • ISO 27001

  • PCI DSS

  • FTC

  • SOC 2

These are just some of the certification and compliance standards that request or require regular penetration testing.

So we’ve seen that carrying out regular penetration tests for your businesses IT infrastructure is necessary if you want to keep yours and your customers’ data safe and secure. However, this does not mean that you can just hire any coding freelancer or IT whiz with a computer science degree to test the security of your systems. Aside from the obvious pitfall of running into a real-life hacker, you also run the risk of hiring someone with subpar skills or lacking due diligence processes.

Thankfully, there are accreditation schemes that grant cybersecurity companies the legitimacy they need for potential clients to weed out the professionals from the amateurs and bad actors. CHECK and CREST pen tests are two of the most popular pen test accreditation schemes in the UK.

CHECK-certified agencies are required for government departments and associated organisations, and advised for public sector bodies. If an organisation is not public sector, then it does not require a CHECK-certified service provider to conduct penetration testing. In any other instance, the CREST certification is what you should look for in your penetration testing service providers, as it is the best measure of a cybersecurity company’s legitimacy and competence that is also internationally recognised. Appointing a CREST registered penetration tester ensures that your organisation's security measures are thoroughly evaluated by highly qualified professionals.

There are merits to both CHECK and CREST depending on which sector of business you are in. Companies who provide CHECK services will be required for organisations which make up the UK’s national infrastructure, whereas CREST-approved agencies are suitable for organisations across all other sectors. What is important is that penetration testing forms a critical part of assessing the cyber resilience of an organisation.

The government-backed nature of CHECK means that it is typically more expensive than a CREST certified penetration test, whilst not providing any meaningful improvement in assurance or outcome. It’s for this reason we recommend CREST penetration testing for all organisations.

That's unless you're strictly required by regulation or legislation to procure a CHECK test.

Make Sure You Prioritise Cyber Security

Penetration testing is crucial for identifying vulnerabilities in your networks, systems and apps, and for meeting compliance requirements. The end goal of a penetration test is to help businesses secure their user and business-critical data, which should be a top priority for every organisation, regardless of type and size.

CREST-approved services are the go-to accreditation schemes for helping to identify professional cyber security vendors and tell them apart from the amateurs, ensuring that you have access to industry-approved penetration tests conducted by the experts.

Talk to an expert

Share your challenge with us and we’ll help you find the right level of support for your business.

Your certified partner

Proven standards, trusted expertise, complete peace of mind

Award logo 1
Award logo 2
Award logo 3
Award logo 4
Award logo 5
Award logo 6
Award logo 7
Worknest logo
© 2020-2026 WorkNest. All rights reserved. (888) 243-3110