- Common requirement
- CREST accredited provider
- Typical lead time
- 2–3 weeks
- Expedited
- Often under 1 week
- Free
- Requirement review
Send us the clause before you do anything else
Tender wording around security testing is written by procurement teams, not security teams, and it is frequently ambiguous. We read the actual clause for free, because getting this wrong is expensive in a way that is entirely avoidable.
The three things worth establishing before you spend a penny:
- Does it require a completed test, or evidence of a programme? Plenty of tenders accept a contracted and scheduled test, or a signed statement of testing policy. If yours does, you have more time than you think.
- Does it name CREST, or an equivalent? If accreditation is specified, a report from a non-accredited provider scores zero regardless of quality.
- What scope does it imply? "Annual penetration testing of systems processing authority data" is a narrower requirement than most bidders assume, and scoping to the actual wording usually costs less.
Where bids lose marks
The report does not match the requirement
The most common failure. A supplier holds a report, submits it, and it covers the wrong scope, is eighteen months old, or comes from a provider without the accreditation the tender specifies. The evaluator cannot award marks for a document that does not meet the stated criteria, and there is no opportunity to correct it after submission.
Accreditation claimed but not held
Watch the wording in your own bid as carefully as in your provider's proposal. "Our testing is carried out by CREST-qualified consultants" is a claim about individuals. "We use a CREST accredited provider" is a claim about the company, and it is verifiable. If an evaluator checks the CREST marketplace and cannot find your provider, that is a credibility problem across your whole submission.
No remediation evidence
Increasingly, tenders ask not just for a test but for evidence that findings were addressed. A report full of open critical findings can score worse than no report. Retest and a closure statement are what turns a test into evidence.
Late
Portals close. There is no discretion, no extension and no appeal. If your timeline is genuinely too tight, we will tell you at the first conversation rather than take the work and let you find out two days before submission.
What you get from us
A report written with an evaluator in mind: clear scope statement, methodology, findings with severity and evidence, remediation status, and our accreditation details with a verifiable link. Retest included as standard, so open findings can be shown closed.
If you need a letter of attestation ahead of the full report to meet a submission date, ask. We can usually provide one.
A caution on price at bid stage
Bid margins are tight and the temptation to buy the cheapest available test is strong. Be careful. A cheap test that produces a report the evaluator cannot score means you have paid twice: once for the useless report, and again for the contract you did not win.
If budget is genuinely the constraint, the answer is usually a tighter scope from an accredited provider, not a wider scope from an unaccredited one. We will help you work out which.
Common questions
Our tender closes in two weeks. Is that possible?
Often, yes, for a contained scope. Send us the requirement and we will tell you honestly the same day. If it is not achievable we will say so rather than take the work — a rushed test that misses the deadline helps nobody.
Can we submit a scheduled test rather than a completed one?
Sometimes. A meaningful number of tenders accept evidence of a contracted and scheduled test, or a documented testing policy. It depends entirely on the wording, which is why reading the actual clause first is worth the half hour.
The tender says 'CREST or equivalent'. What counts?
Ambiguous, and worth clarifying with the buyer if the portal allows questions. In practice CREST is the safest answer because it is the named standard and independently verifiable. Anything you have to argue for at evaluation stage is a risk.
We have an old report. Will it do?
Depends on age and scope. Most tenders specify testing within the last twelve months, and the scope must cover the systems the contract concerns. Send us both the report and the requirement and we will tell you whether it holds up.
Do you help with the bid response itself?
We can provide the technical evidence and explain what it demonstrates in terms an evaluator will understand. We are not bid writers, and we would not pretend to be.
Related
Solusec
Typically replies within one business day
Hi 👋 Need a hand with pen testing, Cyber Essentials, or something urgent? Pick whichever suits you:
💬 WhatsApp usQuick questions, quick answers 📞 Call us
+44 (0)1902 288763 ✉️ Email us
info@solusec.co.uk 📝 Leave a message
We'll reply within one business day