CREST Accredited Penetration Testing

Manual, expert-led testing that finds the weaknesses automated scanners miss — with findings written so your engineers can act on them and your board can understand them.

Accreditation
CREST Penetration Testing
Typical lead time
2–3 weeks
Report turnaround
5 working days
Retest
Included as standard

What you actually get

A penetration test is only as good as the person doing it. Automated scanning has its place, but it will not chain three low-severity issues into an account takeover, and it will not understand that your booking system lets one customer read another's records because the object reference is predictable. That takes a human who has done it before.

Every Solusec engagement is delivered personally by a CREST-qualified tester. There is no sales team translating your requirements badly, and no junior analyst running a scanner and reformatting the output. You speak to the person doing the work, before, during and after.

Scoping that doesn't waste your budget

We scope on a call, not through a 40-field web form. If your environment is smaller than you think, we will tell you and quote less. If a proposed scope leaves an obvious gap — an unauthenticated admin portal nobody mentioned, a forgotten staging environment on the same subnet — we will say so before you sign anything.

Testing

Work is carried out against a documented methodology aligned to CREST, OWASP and NCSC guidance. You get a named tester, an agreed testing window, and a direct channel for the duration. Critical findings are reported the moment we confirm them, not held back for the final report — if we find something that puts you at immediate risk, you hear about it that day.

Reporting

Two audiences, one document. An executive summary that a non-technical director can read and act on, and technical detail with full reproduction steps, evidence and remediation guidance that your developers or IT provider can work straight from. No 200-page scanner dump, no padding, no severity inflation to make the report look impressive.

Retesting

Fixing findings is the point. Retest of remediated issues is included as standard rather than sold as an extra, and you get an updated report reflecting the closed items — which is what your client, insurer or auditor actually wants to see.

Types of testing we deliver

Most organisations need a combination. We will help you work out which, and in what order, based on where your real exposure is rather than what is easiest to sell.

  • Web application and API testing — authenticated and unauthenticated, business logic, access control, injection, session handling.
  • Infrastructure and network testing — external perimeter and internal, including Active Directory attack paths.
  • Cloud security assessment — AWS and Azure configuration, identity, privilege escalation paths.
  • AI and LLM testing — prompt injection, data leakage, agent tool abuse, guardrail bypass.
  • Mobile application testing — iOS and Android, including local storage and API interaction.
  • Build and device reviews — laptop, server and workstation gold-image assessment.

Why CREST accreditation matters

CREST accredits the company, not just the individual. Our methodology, reporting standards, data handling, insurance and staff competence have all been independently audited against the CREST Penetration Testing Accreditation Standard.

In practice that matters in three places: public sector and enterprise procurement frameworks frequently mandate it; cyber insurance underwriters use it to judge whether an engagement was carried out to an acceptable standard; and if you ever have to demonstrate due diligence after an incident, "we used a CREST accredited provider" is a materially stronger position than "we used a consultant".

Common questions

How much does a penetration test cost?

Cost is driven by scope and complexity rather than a fixed price list — principally the number of user roles, the amount of distinct functionality, and how much information you can provide up front. We explain what moves the number on our pricing page, and we will always tell you if a smaller scope would serve you better.

How long does a test take?

Most engagements run three to five days of testing, with the report delivered within five working days of testing completing. Lead time from agreeing scope to starting is usually two to three weeks. If you are up against a contractual or audit deadline, tell us and we will be honest about whether we can meet it.

Will testing disrupt our systems?

Testing is conducted carefully and we agree rules of engagement in advance, including any systems that must not be touched and any time windows to avoid. Denial-of-service testing is never carried out unless explicitly requested and scoped. We maintain a direct line throughout so anything unexpected can be stopped immediately.

Do you test production or staging?

Both are viable and each has trade-offs. Production gives the most accurate picture but requires more care; staging is safer but only useful if it genuinely mirrors production. We will discuss which is appropriate for your situation during scoping.

What is the difference between a penetration test and a vulnerability scan?

A vulnerability scan is automated, runs in minutes and produces a list of known issues matched against signatures. A penetration test is a human attempting to compromise your systems the way an attacker would, including chaining several individually minor issues into a serious one. Scanners cannot do that, and most compliance requirements that specify penetration testing will not accept a scan in its place.

Related

Ready to talk?

Scoping conversations are free and there is no sales team to get past. Tell us what you're dealing with and we'll tell you honestly what you need.