CREST vs CHECK: Which Do You Need?

Two names that get confused in tenders. CREST accredits commercial penetration testing; CHECK is the NCSC scheme for testing government and public-sector systems. Here's how to tell which one your requirement actually needs.

CREST
Commercial pentest accreditation
CHECK
NCSC scheme for HMG systems
Most tenders
Accept CREST
Solusec
CREST accredited

What each one is

  • CREST is the professional body that accredits penetration-testing companies and individuals against assessed standards of skill and process. It's the mark most private-sector clients, insurers and public tenders ask for when they want independent, competent testing.
  • CHECK is a National Cyber Security Centre (NCSC) scheme specifically for testing the IT systems of UK government and public-sector bodies — the classic use is an IT Health Check (ITHC) for systems handling government information. CHECK team members hold recognised qualifications (the CREST examinations are accepted as meeting CHECK's competency requirements).

When you need CHECK

CHECK is required when the thing being tested is a UK government or public-sector system that specifically calls for it — for example an ITHC mandated as a condition of connecting to government infrastructure. If your contract names CHECK or ITHC, that's the route.

When CREST is what's meant

For the vast majority of commercial work — testing your own applications and infrastructure, satisfying a client's due diligence, an insurer's requirement, or a tender that asks for ‘accredited penetration testing’ — CREST is the recognised standard. Many buyers write ‘CREST or equivalent’; CREST is the equivalent.

Where we fit

Solusec provides CREST-accredited penetration testing, delivered by a CREST-registered tester. If your specific requirement is a CHECK ITHC for a government system, tell us — we'll be straight about whether CREST covers what you've been asked for, and point you the right way if a formal CHECK engagement is genuinely required.

Common questions

Is CHECK better than CREST?

Neither is ‘better’ — they're for different things. CHECK is the NCSC scheme for testing government systems; CREST accredits commercial testing skill and process. For most commercial work, CREST is what buyers mean.

My tender says ‘CREST or equivalent’ — what qualifies?

CREST accreditation itself is the recognised standard that satisfies ‘or equivalent’ wording. If a buyer specifically requires CHECK, they'll name CHECK or an IT Health Check (ITHC).

Do I need CHECK for a private-sector client?

Almost never. CHECK is for UK government and public-sector systems. A private client's due diligence, an insurer or a commercial tender will want CREST-accredited testing.

Are CREST and CHECK qualifications related?

Yes — the CREST examinations are accepted as meeting CHECK's competency requirements for team members, which is why the two are often mentioned together.

Related

Not sure if you need CREST or CHECK?

Send us the requirement wording. We'll tell you honestly which applies — and whether our CREST-accredited testing covers it.