Fast CREST penetration testing › What CREST audits
If your tender names CREST, you will have found plenty of material explaining that it accredits companies rather than individuals, and how to check a provider is listed. That is the identification problem and it is worth solving. This is the question underneath it: once you have established a provider genuinely holds the accreditation, what have you actually learned about them?
More than most buyers assume, and less than most providers imply.
Accreditation is granted against processes, not personnel
The assessment examines how an organisation works, with real engagements pulled as evidence. Broadly it covers six areas.
Documented methodology, and evidence it is followed
Having a methodology is easy. The audit looks for evidence that actual engagements followed it, which is a different and much harder thing to fake. If the methodology states that authenticated testing covers each user role, the assessor can ask to see a job where four roles existed and check that four roles were tested. This is the clause that puts a floor under honest day counts, and it is the reason a CREST quote is often larger than the one beside it for apparently identical work.
How findings are evidenced and retained
Each finding in a report should be supported by what was actually done and what came back. The audit looks at whether that evidence exists, whether it is retained coherently, and whether severity ratings are reasoned rather than lifted wholesale from a tool's default score.
Data handling end to end
How client data reaches the tester, how it is stored during the engagement, how it is encrypted, who can reach it, how long it is kept and how it is destroyed. For a buyer this is quietly one of the most valuable parts, because a penetration test hands a third party a detailed map of your weaknesses, and that document is itself an asset worth attacking.
Tester vetting and continuing competence
Who is allowed to do the work, what background checks were run, and how technical currency is maintained. Not a guarantee that any given tester is excellent, but a floor beneath who is sent to your site.
Report review before delivery
A second person reads the report, checks the evidence supports the findings and the severities, and returns it if it does not. This costs between half a day and two days depending on the size of the report, and it is the first step to disappear when a provider is competing purely on turnaround. Its absence does not show in a quote. It shows in a report that rates everything medium and cites a scanner plugin ID as its evidence.
Complaints and redress
There has to be a route for a client to complain, and it has to lead somewhere. This matters more than it sounds, and it is covered properly below.
It is audited, renewed, and losing it is visible
Accreditation is not a certificate bought once and displayed forever. It is periodically reassessed, and a company that stops meeting the standard stops being listed. That is the whole reason the public register is the thing to check rather than the logo on a proposal: the logo is a picture, and the register is current.
Which gives you a small piece of ongoing diligence most buyers never do. If you are engaging a provider annually, check the listing each time rather than only at first purchase. It takes a minute, and a provider whose accreditation has lapsed between your first engagement and your second is not going to open the conversation by telling you.
Accreditation is per discipline
This is the most common misreading of a register entry. CREST accredits separately for different disciplines: penetration testing, incident response, threat intelligence, security operations centre services and others. A company accredited for one is not thereby accredited for all.
So the check is not "are they listed" but "are they listed for the thing I am buying". If your requirement is a penetration test and the provider's accreditation is in incident response, the listing is genuine and the answer to your question is still no. The same care applies to newer accreditations: Solusec holds CREST's AI-Enabled Penetration Testing accreditation as well as the penetration testing one, and those are two entries covering two different things, not one entry described two ways.
The four things it deliberately tells you nothing about
This is the part that gets left out of provider marketing, for obvious reasons. Accreditation is a floor, not a ranking, and there are four questions it does not answer at all.
| Question | Why accreditation cannot answer it |
|---|---|
| Is the tester assigned to my job any good? | The organisation is assessed, and its vetting and competence processes with it. The individual allocated to your engagement in March is not. |
| Is my scope the right scope? | Scoping is a conversation between you and the provider. A methodically perfect test of the wrong systems is still a test of the wrong systems. |
| Is the price reasonable? | CREST does not regulate commercial terms. Accredited providers vary by a factor of two on the same work. |
| Will the report be readable by the people who have to act on it? | Review is assessed for technical soundness. Whether your finance director can understand the executive summary is not a standards question. |
So check the accreditation, and then ask the questions that actually vary between two accredited providers: how many tester-days am I buying, how many user roles are covered, is testing authenticated, who writes the report and who reviews it, and is a retest included. Those decide what you get far more than the badge does.
The complaints route, which almost nobody uses
Worth knowing because it is the only real leverage a buyer has after the fact. An accredited company is required to operate a complaints procedure, and if that procedure fails you, the accrediting body is a second avenue. That is a meaningfully different position from a dispute with an unaccredited supplier, where your only routes are the contract and the small claims track.
It is rarely needed and it is not a reason on its own to pay more. But if you are weighing an accredited provider against an unaccredited one at a lower price, this is a real difference that belongs in the comparison alongside whether the report will satisfy your requirement.
How to read a register entry properly
Three things, in order, and it takes about two minutes.
- Search the company name exactly as it appears on the quote. Trading names, group parents and subsidiaries all cause honest confusion here, and occasionally dishonest confusion. If the entity on the quote is not the entity on the register, ask which one is doing the work and which one is signing the contract.
- Check the discipline. Covered above, and the one most often skipped.
- Check it is current. The register is live. A screenshot in a proposal is not.
If you find only an individual named, ask the provider directly whether the company itself is accredited and to send the listing. Any accredited provider will do that in one reply without hesitating, and a slow or qualified answer to that question is itself the answer.
Does CREST accreditation mean every tester at the company is CREST certified?
No. The organisation is assessed, including how it vets testers and maintains their competence, but accreditation is not a statement that each individual holds a personal certification. If it matters to you that the specific person on your job holds one, ask which certification and at what level, and ask it before you sign rather than after.
Is CHECK better than CREST?
They are different rather than ranked. CHECK is the NCSC scheme for testing UK government systems handling protectively marked data. CREST is the broader commercial accreditation. If your requirement names CHECK, CREST is not automatically a substitute and you should confirm rather than assume. If it names CREST, a CHECK provider is usually acceptable, but again confirm.
How often is accreditation reassessed?
Periodically, on a renewal cycle, with the register reflecting current status rather than historic. The practical implication for a buyer is to check the listing at each engagement rather than only at the first, because a lapse between your engagements will not be volunteered.
If a provider is accredited, do I still need to check their methodology?
Yes, though for a different reason. Accreditation tells you a documented methodology exists and is followed. It does not tell you whether the scope you have agreed covers what matters to your organisation. That is a conversation about your systems, and no accreditation substitutes for it.
Buying an accredited test
Solusec is CREST accredited at company level, a CREST member company, and among the first ten firms worldwide accredited for AI-Enabled Penetration Testing. The listing is public and we will send it to you without being asked twice.