Urgent CREST penetration test
When the clause names CREST and the date is close, the constraint is rarely the testing. It is accredited availability, and reading the requirement correctly.
Send us the deadline and the clause
If the requirement names CREST, paste the actual wording. It decides how constrained you are, and reading it usually opens options that were not obvious. We will tell you honestly whether your date is achievable.
Read the clause before you book anything
Most people calling about an urgent CREST penetration test have read a requirement, taken the strictest possible meaning from it, and started ringing round. That is understandable with a date approaching, and it is often wrong. Four wordings turn up repeatedly and they mean different things.
| If the wording says | What it requires | How much this constrains you |
|---|---|---|
| CREST-accredited provider, or CREST member company | Accreditation held by the company, verifiable independently | Most constrained. The entity on your contract has to hold it. |
| CREST-registered tester, or CREST certified consultant | A qualification held by the individual doing the work | Less constrained. A firm without company accreditation can staff this. |
| CHECK, or IT Health Check | The NCSC scheme for government and public-sector systems | Different scheme. CREST accreditation alone does not satisfy it. |
| Independent third party, or suitably qualified | Independence and competence, with no named scheme | Least constrained. Your options are much wider than you think. |
The distinction matters most when you are short of time, because it decides how small the pool of providers is. If your clause is in the fourth row, a week is usually workable. If it is in the first, you are drawing from a much shorter list and the sooner you start the better. See CREST vs CHECK if the requirement names both, which happens more often than it should.
Verify the accreditation before you sign, not after
This takes two minutes and it is the step people skip when they are rushing. CREST publishes its accredited member companies, so the check is simply whether the provider is listed and whether the name listed matches the legal entity on your contract and your invoice.
Three things that look like accreditation and are not. An individual tester’s CREST certification, which says nothing about the company employing them. An accreditation held by a parent company or a delivery partner, which does not transfer to the entity you are contracting with. And membership of an adjacent body presented in similar language. None of these is dishonest in itself, but a report from the wrong kind of provider may not satisfy the requirement, and you will find that out at the point where you have no time left to fix it.
Accredited capacity is the bottleneck, not the testing
A five-day test takes five days for everybody. The reason an urgent CREST penetration test is harder to source than an urgent test is not the work, it is the bench. CREST-registered testers at accredited companies are a smaller pool than testers generally, so at two weeks’ notice a non-accredited provider can usually find somebody while an accredited one is working from a narrower set of names.
The practical consequence is an ordering one. Ask about availability before you finish scoping, rather than after. Scoping can be done in a call and refined later; a slot that has gone has gone. If you are ringing round, ask each provider for the dates they can actually start rather than their lead time in general, because those are different questions and only one of them is useful to you.
What compresses on an accredited engagement, and what does not
Being specific about this saves a week of negotiation.
| Stage | Compressible | What that means in practice |
|---|---|---|
| Scoping | Yes, to a same-day call | No forty-field form before anyone will speak to you. |
| Authorisation and rules of engagement | Partly | The most common cause of delay. It needs somebody who can commit the organisation, and if the systems are hosted or managed by a third party their written authorisation can take longer than the test. |
| Mobilising a CREST-registered tester | Depends on the bench | This is the step that makes accredited work harder to expedite. Ask for dates, not lead times. |
| The testing days | No | A five-day test does not become a two-day test because the deadline moved. It becomes a two-day test, with two days of coverage. |
| Quality assurance on the report | Not below a floor | Documented review of the deliverable is part of what the accreditation is. A report that skipped it is not the thing your clause asked for. |
| Issuing the report | Yes | Critical findings go to you the moment they are confirmed. A draft or an attestation letter can be issued ahead of the full document. |
| Your remediation time | No | A report landing the day before your deadline leaves nothing to fix anything with, which may defeat the point of the exercise. |
If the date genuinely cannot be met
This is more survivable than it feels, because a good many requirements are written to establish that testing is happening rather than that it has finished. In rough order of how often they are accepted:
- A signed engagement with dates on it. A contracted and scheduled test, on the provider’s letterhead, satisfies a surprising proportion of tender and insurer clauses as written.
- An attestation letter. Issued once testing completes, ahead of the full report, confirming what was tested and when. Useful where the buyer needs evidence of completion but not the findings.
- A narrower scope that meets the clause. If the requirement names one application, it names one application. Testing the whole estate because it felt safer is a common way to miss a date you could have made.
- Conditional close with the report as a deliverable. Common on contracts where the security requirement is a condition of service rather than of signature.
Which of these is available depends entirely on the words in front of you, which is why the first thing worth doing is pasting the clause into an email to whoever you are asking. Summarising it loses exactly the detail that decides the answer.
Where we stand on this
Solusec is accredited by CREST at company level and is a CREST member company, so the accreditation belongs to the entity that contracts with you and appears on your invoice. We are also among the first ten firms worldwide accredited by CREST for AI-Enabled Penetration Testing. Testing is delivered by a CREST-registered tester.
There is no rush premium. Short-notice work is priced the same as planned work, and what a penetration test costs sets out the ranges by test type. What we will not do is agree to a date we cannot meet properly, and we would rather tell you that on the first call than three days before your submission.
If you are choosing a provider partly on turnaround rather than already behind a date, fast CREST penetration test covers what compressing an engagement actually costs you and how to compare providers on speed honestly. If your deadline is real but your requirement does not name CREST, urgent penetration testing covers lead times and what drives urgency across every type of engagement, and is probably the more useful page.
Common questions
Does my clause actually require a CREST-accredited company?
Can a CREST-accredited provider test faster than a non-accredited one?
Do you charge more for urgent CREST work?
How do I verify that a provider is CREST accredited?
My deadline is next week. Is it worth starting at all?
Is CHECK the same thing as CREST?
Related
Solusec
Typically replies within one business day
Had an incident, or need a penetration test or Cyber Essentials at short notice?
Tell us what you're dealing with and we'll come back to you.
+44 (0)1902 288763 ✉️ Email us
info@solusec.co.uk 📝 Leave a message
We'll reply within one business day
Ready to talk?
Scoping conversations are free and there is no sales team to get past. Tell us what you're dealing with and we'll tell you honestly what you need.