- CREST
- Commercial pentest accreditation
- CHECK
- NCSC scheme for HMG systems
- Most tenders
- Accept CREST
- Solusec
- CREST accredited
What each one is
- CREST is the professional body that accredits penetration-testing companies and individuals against assessed standards of skill and process. It's the mark most private-sector clients, insurers and public tenders ask for when they want independent, competent testing.
- CHECK is a National Cyber Security Centre (NCSC) scheme specifically for testing the IT systems of UK government and public-sector bodies — the classic use is an IT Health Check (ITHC) for systems handling government information. CHECK team members hold recognised qualifications (the CREST examinations are accepted as meeting CHECK's competency requirements).
When you need CHECK
CHECK is required when the thing being tested is a UK government or public-sector system that specifically calls for it — for example an ITHC mandated as a condition of connecting to government infrastructure. If your contract names CHECK or ITHC, that's the route.
When CREST is what's meant
For the vast majority of commercial work — testing your own applications and infrastructure, satisfying a client's due diligence, an insurer's requirement, or a tender that asks for ‘accredited penetration testing’ — CREST is the recognised standard. Many buyers write ‘CREST or equivalent’; CREST is the equivalent.
Where we fit
Solusec provides CREST-accredited penetration testing, delivered by a CREST-registered tester. If your specific requirement is a CHECK ITHC for a government system, tell us — we'll be straight about whether CREST covers what you've been asked for, and point you the right way if a formal CHECK engagement is genuinely required.
Common questions
Is CHECK better than CREST?
Neither is ‘better’ — they're for different things. CHECK is the NCSC scheme for testing government systems; CREST accredits commercial testing skill and process. For most commercial work, CREST is what buyers mean.
My tender says ‘CREST or equivalent’ — what qualifies?
CREST accreditation itself is the recognised standard that satisfies ‘or equivalent’ wording. If a buyer specifically requires CHECK, they'll name CHECK or an IT Health Check (ITHC).
Do I need CHECK for a private-sector client?
Almost never. CHECK is for UK government and public-sector systems. A private client's due diligence, an insurer or a commercial tender will want CREST-accredited testing.
Are CREST and CHECK qualifications related?
Yes — the CREST examinations are accepted as meeting CHECK's competency requirements for team members, which is why the two are often mentioned together.
Related
Solusec
Typically replies within one business day
Had an incident, or need a pen test at short notice?
Tell us what you're dealing with and we'll come back to you.
+44 (0)1902 288763 ✉️ Email us
info@solusec.co.uk 📝 Leave a message
We'll reply within one business day