Credentials, and where to verify them

Every accreditation the company holds and every certification the person doing your work holds, each with the independent register you can check it on yourself. If a provider will not show you this page, ask why.

Cyber security is sold on trust, which makes it easy to sell on assertion. This page exists so you do not have to take anything here on assertion. Every accreditation and every certification below names the body that awarded it and links to the independent register you can check it on.

Who does the work

Solusec is led by Daly Whyte, with over 25 years across IT and cyber security. Every engagement is overseen personally: the person who scopes your work is the person who carries it out and the person who writes the report. That is unusual enough in this market to be worth stating plainly, and it is the reason a single name can be held accountable for everything below.

The background is deliberately full-spectrum rather than specialised: offensive testing, defensive and blue team operations, and audit and assurance. Over 500 accepted bug bounty findings, testing on the invitation-only Synack Red Team, and an invitation to the Masterclass finals of the UK Cyber Security Challenge.

Company accreditations

These are held by Solusec Ltd as a business and are independently audited. For procurement teams, insurers and public sector buyers, these are the ones that get checked.

AccreditationAwarded byVerify
CREST Accredited Penetration Testing Provider
Methodology, reporting, data handling and staff competence audited against CREST's Penetration Testing Accreditation Standard.
CRESTCREST marketplace
CREST AI-Enabled Penetration Testing
Among the first ten organisations worldwide to hold it.
CRESTCREST marketplace
Cyber Essentials Certification Body
Appointed to assess and certify Cyber Essentials. Assessing now.
IASME, the NCSC's sole delivery partnerIASME register
Cyber Essentials Plus Certification Body
Appointed to assess Cyber Essentials Plus from late October 2026.
IASMEOur CE Plus dates
IASME Cyber Assurance Certification Body
IASME's flagship information security standard, a proportionate alternative to ISO 27001.
IASMEIASME register
Defence Cyber Certification Body, Level 0
Appointed to certify DCC Level 0 under Def Stan 05-138 Issue 4.
IASME, for the MODWhat DCC covers
Certified: Cyber Essentials Plus, IASME Cyber Assurance, IASME Quality Principles
Held by Solusec as a certified organisation, not only as an assessor.
IASMEIASME register

Individual certifications

Held by the person doing the work rather than by the business. A company accreditation held over an unqualified team means very little, which is why these are published alongside.

CertificationWhat it isAwarded by
OSCPOffSec Certified Professional. A 24-hour practical examination in compromising live systems, not a multiple-choice paper.OffSec
OSWEOffSec Web Expert. Advanced web application exploitation, including source code review and bypassing authentication logic.OffSec
CRTCREST Registered Penetration Tester. An individual CREST examination, and a contractual requirement for many UK government engagements.CREST
CISSPCertified Information Systems Security Professional. Security architecture, risk management, governance and compliance at senior level.ISC2
PraCSPPractitioner in Security Testing, on the national professional register for the cyber security sector.UK Cyber Security Council
BTL2Blue Team Level 2. Advanced defensive certification assessed through hands-on threat hunting and incident response.Security Blue Team
CSOMCertified Security Operations Manager. Planning and leading detection, incident response and SOC functions.Centri
IASME AssessorCertified to assess Cyber Essentials and IASME Cyber Assurance submissions.IASME
DCC Level 0 AssessorCertified to assess Defence Cyber Certification at Level 0.IASME, for the MOD

What to ask any provider, including us

If you are comparing providers, these four questions separate the ones worth shortlisting from the ones that are not. They are the questions we would want asked of us.

  1. Name the person who will do the work, and show me their certifications. A company logo is not a qualification. If nobody will be named before you sign, you are buying whoever is free that week.
  2. Which register can I verify that on? CREST, IASME and the UK Cyber Security Council all publish public registers. A claim that cannot be checked against one of them is a claim.
  3. Is the accreditation at company level, individual level, or both? They are different things and both matter. The difference between CREST and CHECK is worth understanding before you compare quotes.
  4. Who signs the report, and are they the person who did the testing? Reports signed by someone who did not do the work are common and are worth less.

What we will not claim

We do not hold CHECK status, which is the NCSC scheme required for some central government work. If your contract specifies CHECK, we will tell you so and point you elsewhere rather than argue the equivalence. We do not implement controls for clients, so we are never assessing our own work. And where a date has not arrived yet, such as Cyber Essentials Plus assessment, the page says the date rather than saying coming soon.

Common questions

Who will actually carry out my assessment or test?

Daly Whyte, the founder. Solusec is deliberately senior-led: the person who scopes the engagement is the person who does it and the person who writes the report. There is no sales layer and no handover to a junior analyst.

How do I verify these accreditations independently?

CREST accreditation is listed on the CREST marketplace, which is a public supplier register. Cyber Essentials, IASME Cyber Assurance and Quality Principles are on the IASME register. Practitioner registration is on the UK Cyber Security Council professional register. Every claim on this page links to the register that holds it.

What is the difference between company accreditation and individual certification?

Company accreditation audits the business: its methodology, reporting, data handling, insurance and staff competence. CREST accreditation and certification body status are both of this kind. Individual certifications sit with the person: OSCP, OSWE, CRT, CISSP. Buyers who know the market check both, because a company accreditation held over a team of unqualified testers means very little, and a qualified individual inside an unaccredited company cannot sign a CREST-accredited report.

Is CREST accreditation the same as being CREST registered?

No. CREST accredits companies against the Penetration Testing Accreditation Standard. CREST registration, such as CRT, is an individual examination. Solusec holds both, at company level and at individual level, which is less common than the marketing in this sector suggests.

Does the same person do both the testing and the certification?

Yes, and that is the point. The Cyber Essentials and Cyber Essentials Plus assessments are carried out by a practising penetration tester, so the audit is done by someone who spends the rest of the week getting past exactly the controls being checked. We do not implement your controls for you, so the assessment stays independent.

What is the CREST AI-Enabled accreditation?

A CREST accreditation covering the testing of AI-enabled systems and the use of AI within a testing methodology. Solusec was among the first ten organisations worldwide to hold it.

Related

Know exactly who is doing your work.

Every accreditation on this page is on a public register. Check us, then talk to the person who will carry out the work.