Credentials, and where to verify them
Every accreditation the company holds and every certification the person doing your work holds, each with the independent register you can check it on yourself. If a provider will not show you this page, ask why.
Cyber security is sold on trust, which makes it easy to sell on assertion. This page exists so you do not have to take anything here on assertion. Every accreditation and every certification below names the body that awarded it and links to the independent register you can check it on.
Who does the work
Solusec is led by Daly Whyte, with over 25 years across IT and cyber security. Every engagement is overseen personally: the person who scopes your work is the person who carries it out and the person who writes the report. That is unusual enough in this market to be worth stating plainly, and it is the reason a single name can be held accountable for everything below.
The background is deliberately full-spectrum rather than specialised: offensive testing, defensive and blue team operations, and audit and assurance. Over 500 accepted bug bounty findings, testing on the invitation-only Synack Red Team, and an invitation to the Masterclass finals of the UK Cyber Security Challenge.
Company accreditations
These are held by Solusec Ltd as a business and are independently audited. For procurement teams, insurers and public sector buyers, these are the ones that get checked.
| Accreditation | Awarded by | Verify |
|---|---|---|
| CREST Accredited Penetration Testing Provider Methodology, reporting, data handling and staff competence audited against CREST's Penetration Testing Accreditation Standard. | CREST | CREST marketplace |
| CREST AI-Enabled Penetration Testing Among the first ten organisations worldwide to hold it. | CREST | CREST marketplace |
| Cyber Essentials Certification Body Appointed to assess and certify Cyber Essentials. Assessing now. | IASME, the NCSC's sole delivery partner | IASME register |
| Cyber Essentials Plus Certification Body Appointed to assess Cyber Essentials Plus from late October 2026. | IASME | Our CE Plus dates |
| IASME Cyber Assurance Certification Body IASME's flagship information security standard, a proportionate alternative to ISO 27001. | IASME | IASME register |
| Defence Cyber Certification Body, Level 0 Appointed to certify DCC Level 0 under Def Stan 05-138 Issue 4. | IASME, for the MOD | What DCC covers |
| Certified: Cyber Essentials Plus, IASME Cyber Assurance, IASME Quality Principles Held by Solusec as a certified organisation, not only as an assessor. | IASME | IASME register |
Individual certifications
Held by the person doing the work rather than by the business. A company accreditation held over an unqualified team means very little, which is why these are published alongside.
| Certification | What it is | Awarded by |
|---|---|---|
| OSCP | OffSec Certified Professional. A 24-hour practical examination in compromising live systems, not a multiple-choice paper. | OffSec |
| OSWE | OffSec Web Expert. Advanced web application exploitation, including source code review and bypassing authentication logic. | OffSec |
| CRT | CREST Registered Penetration Tester. An individual CREST examination, and a contractual requirement for many UK government engagements. | CREST |
| CISSP | Certified Information Systems Security Professional. Security architecture, risk management, governance and compliance at senior level. | ISC2 |
| PraCSP | Practitioner in Security Testing, on the national professional register for the cyber security sector. | UK Cyber Security Council |
| BTL2 | Blue Team Level 2. Advanced defensive certification assessed through hands-on threat hunting and incident response. | Security Blue Team |
| CSOM | Certified Security Operations Manager. Planning and leading detection, incident response and SOC functions. | Centri |
| IASME Assessor | Certified to assess Cyber Essentials and IASME Cyber Assurance submissions. | IASME |
| DCC Level 0 Assessor | Certified to assess Defence Cyber Certification at Level 0. | IASME, for the MOD |
What to ask any provider, including us
If you are comparing providers, these four questions separate the ones worth shortlisting from the ones that are not. They are the questions we would want asked of us.
- Name the person who will do the work, and show me their certifications. A company logo is not a qualification. If nobody will be named before you sign, you are buying whoever is free that week.
- Which register can I verify that on? CREST, IASME and the UK Cyber Security Council all publish public registers. A claim that cannot be checked against one of them is a claim.
- Is the accreditation at company level, individual level, or both? They are different things and both matter. The difference between CREST and CHECK is worth understanding before you compare quotes.
- Who signs the report, and are they the person who did the testing? Reports signed by someone who did not do the work are common and are worth less.
What we will not claim
We do not hold CHECK status, which is the NCSC scheme required for some central government work. If your contract specifies CHECK, we will tell you so and point you elsewhere rather than argue the equivalence. We do not implement controls for clients, so we are never assessing our own work. And where a date has not arrived yet, such as Cyber Essentials Plus assessment, the page says the date rather than saying coming soon.
Common questions
Who will actually carry out my assessment or test?
Daly Whyte, the founder. Solusec is deliberately senior-led: the person who scopes the engagement is the person who does it and the person who writes the report. There is no sales layer and no handover to a junior analyst.
How do I verify these accreditations independently?
CREST accreditation is listed on the CREST marketplace, which is a public supplier register. Cyber Essentials, IASME Cyber Assurance and Quality Principles are on the IASME register. Practitioner registration is on the UK Cyber Security Council professional register. Every claim on this page links to the register that holds it.
What is the difference between company accreditation and individual certification?
Company accreditation audits the business: its methodology, reporting, data handling, insurance and staff competence. CREST accreditation and certification body status are both of this kind. Individual certifications sit with the person: OSCP, OSWE, CRT, CISSP. Buyers who know the market check both, because a company accreditation held over a team of unqualified testers means very little, and a qualified individual inside an unaccredited company cannot sign a CREST-accredited report.
Is CREST accreditation the same as being CREST registered?
No. CREST accredits companies against the Penetration Testing Accreditation Standard. CREST registration, such as CRT, is an individual examination. Solusec holds both, at company level and at individual level, which is less common than the marketing in this sector suggests.
Does the same person do both the testing and the certification?
Yes, and that is the point. The Cyber Essentials and Cyber Essentials Plus assessments are carried out by a practising penetration tester, so the audit is done by someone who spends the rest of the week getting past exactly the controls being checked. We do not implement your controls for you, so the assessment stays independent.
What is the CREST AI-Enabled accreditation?
A CREST accreditation covering the testing of AI-enabled systems and the use of AI within a testing methodology. Solusec was among the first ten organisations worldwide to hold it.
Related
Solusec
Typically replies within one business day
Had an incident, or need a penetration test or Cyber Essentials at short notice?
Tell us what you're dealing with and we'll come back to you.
+44 (0)1902 288763 ✉️ Email us
info@solusec.co.uk 📝 Leave a message
We'll reply within one business day
Know exactly who is doing your work.
Every accreditation on this page is on a public register. Check us, then talk to the person who will carry out the work.