What Is an IT Health Check (ITHC)?

A specific thing with specific requirements, not a general review of how healthy your IT is. Here is what an ITHC actually involves, and how to tell whether you need one.

Scheme
NCSC CHECK
Led by
CHECK Team Leader (CTL)
Clearance
SC as standard
Report
Copy goes to NCSC

Being clear about what we are

Solusec is CREST accredited. We are not an NCSC-approved CHECK Service Provider, so we cannot deliver an IT Health Check under the CHECK scheme.

This page exists because a lot of organisations are told they need an ITHC when the requirement they are actually working to says something different. If that is you, send us the wording and we will tell you honestly whether you need a CHECK provider or whether a CREST accredited test satisfies it. That conversation is free either way.

What an ITHC actually is

“IT Health Check” sounds generic. It is not. In UK public sector procurement it refers to the CHECK scheme, developed and run by the National Cyber Security Centre to identify vulnerabilities in systems handling government information.

An IT Health Check delivered under CHECK is a penetration test with a specific set of additional requirements attached:

  • It must be carried out by an NCSC-approved CHECK company.
  • It must be led by an individual holding the CHECK Team Leader (CTL) qualification.
  • All testers must hold at least the CHECK Team Member (CTM) qualification.
  • All testers must hold at least SC clearance.
  • Exploitation of identified vulnerabilities must be permitted: you cannot scope it as a scan.
  • On completion, a copy of the report goes to the NCSC.

The NCSC also defines a mandatory scope for CHECK tests, set out in the annexes of the Assured CHECK Scheme Standard. This is not a test you can trim to fit a budget.

What CHECK does not cover

Worth knowing, because it catches people out: the CHECK scheme is limited to penetration testing. Build reviews, cloud configuration reviews and firewall rule reviews cannot be delivered under CHECK.

A CHECK company can still perform them, but not under the scheme, and they have to be reported separately. If your requirement asks for a configuration review and calls it part of the ITHC, that wording needs clarifying before anyone quotes.

Who actually needs a CHECK ITHC

CHECK exists for environments where compromise has serious consequences. In practice that means:

  • Central government departments, and systems handling data classified OFFICIAL or above.
  • Critical National Infrastructure.
  • Public Services Network (PSN) and Health and Social Care Network (HSCN) connections, depending on the code of connection you are working to.
  • GovAssure submissions, as technical assurance evidence.

If you are none of those, there is a reasonable chance the word “ITHC” has been copied into a document from a template rather than chosen deliberately.

The distinction that saves people money

This is the part worth reading carefully.

Some requirements mandate CHECK specifically. A local authority tender may state that organisations must be accredited to CHECK, and in that case only a CHECK company will do: a CREST report scores nothing, however good the testing was.

Other requirements are less prescriptive, and accept testing by an accredited provider without naming CHECK. Some PSN code of connection submissions fall into this category, and CREST accredited testing is commonly accepted.

The only way to know which you are dealing with is to read the actual wording. We will do that for free, and if the answer is “you need a CHECK provider”, we will tell you that plainly rather than trying to talk you into something that will not satisfy your buyer.

Two schemes with confusingly similar names

The NCSC CHECK scheme and the PSN IT Health Check are separate things. Documents use the phrase interchangeably and they should not. If a requirement mentions an ITHC, establish which one it means before scoping anything.

The change that affects colleges

Further education is a good example of ITHC requirements moving. The DfE previously required an annual IT health check for colleges and specialist post-16 institutions. From the 2024/25 funding year that was replaced with mandatory Cyber Essentials certification, and the College Financial Handbook 2026 now requires colleges to maintain Cyber Essentials annually.

If you are a college still budgeting for an ITHC because you always have, that requirement has changed. We cover what replaced it on our College Financial Handbook page.

How CHECK and CREST relate

They are complementary rather than competing. The NCSC and CREST collaborate on the examinations that underpin CHECK qualifications: CREST certifications are one of the routes to CHECK Team Member and Team Leader status.

The difference is what the accreditation covers. CHECK assures testing into government and high-risk environments, with clearance requirements and NCSC oversight of the report. CREST assures the company against an audited standard for commercial penetration testing, and is what most private sector procurement, client questionnaires and cyber insurers actually ask for.

A CREST accredited provider is not a lesser tester. It is a different assurance route, aimed at a different buyer.

What we can help with

If your requirement genuinely needs CHECK, you need a CHECK company and we will say so. If it does not, and a great many do not, we deliver CREST accredited penetration testing covering the same technical ground: external infrastructure, internal networks, web applications and APIs, cloud environments, and build and configuration reviews.

Send us the requirement. Reading it is free and it is usually the most useful half hour in the whole process.

Common questions

What is an IT Health Check?

In UK public sector terms, an ITHC is a penetration test delivered under the NCSC CHECK scheme. It must be carried out by an NCSC-approved CHECK company, led by a CHECK Team Leader, with all testers holding at least CHECK Team Member qualifications and SC clearance. Exploitation must be permitted, and a copy of the report goes to the NCSC.

Can Solusec deliver a CHECK IT Health Check?

No. We are CREST accredited, not an NCSC-approved CHECK Service Provider. If your requirement mandates CHECK you need a CHECK company. If it does not specify CHECK, CREST accredited testing is often accepted, and we are happy to read the requirement and tell you which applies.

Do I definitely need CHECK, or will CREST do?

It depends entirely on the wording. Central government, systems handling OFFICIAL or above, and some codes of connection mandate CHECK specifically. Other requirements ask for testing by an accredited provider without naming a scheme, and CREST is commonly accepted there. Read the actual clause rather than assuming.

What is the difference between CHECK and CREST?

CHECK is the NCSC scheme assuring penetration testing into government and high-risk environments, with security clearance requirements and NCSC oversight. CREST accredits companies against an audited standard for commercial penetration testing. The two are related, CREST examinations are a route to CHECK qualifications, but they serve different buyers.

Does an ITHC cover configuration and build reviews?

Not under the CHECK scheme, which is limited to penetration testing. A CHECK company can carry out build, cloud and firewall reviews, but not as part of the CHECK engagement, and they must be reported separately. If your requirement bundles them together, that is worth clarifying before anyone quotes.

Do colleges still need an IT Health Check?

The DfE replaced the annual IT health check requirement for colleges and specialist post-16 institutions with mandatory Cyber Essentials from the 2024/25 funding year, and the College Financial Handbook 2026 requires colleges to maintain that certification annually. If you are budgeting for an ITHC out of habit, check the current requirement.

How often is an ITHC required?

Typically annually, and after any significant change to the environment. The precise expectation depends on the code of connection or framework you are working to.

Related

Ready to talk?

Scoping conversations are free and there is no sales team to get past. Tell us what you're dealing with and we'll tell you honestly what you need.