
A clear breakdown of the three main UK security testing standards and when each applies.
UK organisations face multiple security testing standards, each with different purposes and requirements. Understanding when each applies helps ensure you're meeting the right bar, and not overpaying for standards you don't need.
CHECK is the NCSC's scheme for assuring penetration testing services to UK government and Critical National Infrastructure (CNI). It's not a certification for individual testers, it's an approval scheme for companies providing testing to specific sectors.
| Role | Description |
|---|---|
| CHECK Team Leader (CTL) | Senior tester who can lead engagements. Must pass NCSC examinations and demonstrate significant experience. Responsible for methodology, quality, and final report. |
| CHECK Team Member (CTM) | Supports the Team Leader. Can perform testing under supervision but cannot lead engagements independently. |
CHECK Green Company can test systems up to OFFICIAL-SENSITIVE
CHECK Green Light Company can test systems up to SECRET (requires additional security clearances)
CREST is an international accreditation body for cybersecurity service providers. Unlike CHECK (which is UK government-specific), CREST operates globally and serves commercial markets.
| Certification | Level & Focus |
|---|---|
| CPSA | Entry-level – Demonstrates foundational security knowledge |
| CRT | Infrastructure penetration testing certification |
| CRTWA | Web application testing specialisation |
| CCT | Advanced level – Infrastructure or application specialisation |
| CCSAM | Red team operations and simulated attack management |
CBEST is the Bank of England's framework for threat intelligence-led penetration testing of UK financial institutions. It predates TIBER-EU and shares many characteristics with it.
Not all regulated firms require CBEST, it's typically requested of systemically important institutions. The regulators determine who should participate.
| Aspect | CBEST Difference |
|---|---|
| Methodology | Threat intelligence-driven, not generic methodology |
| Environment | Testing on live production systems, not isolated test environments |
| Stealth | Blue team typically unaware until debrief |
| Oversight | Bank of England/FCA involved throughout |
These standards aren't mutually exclusive:
For most commercial organisations, CREST accreditation provides appropriate assurance. CHECK matters primarily for government work. CBEST is a specialist requirement for major financial institutions.
We deliver testing aligned with CHECK, CREST and CBEST guidance. Testing is led by a Cyber Scheme Team Leader (CSTL) who also holds OSCP, CRTP and CRTO.
One monthly plan, one front door: penetration testing, Cyber Essentials, AI security, training and advice, from £1,500 a month. No hidden costs.