Forefront IT Security Services
BlogCompliance
Compliance

CHECK, CREST, and CBEST: UK Security Testing Standards

November 2025Forefront IT Security Services3 min read

A clear breakdown of the three main UK security testing standards and when each applies.

Understanding UK Testing Standards

UK organisations face multiple security testing standards, each with different purposes and requirements. Understanding when each applies helps ensure you're meeting the right bar, and not overpaying for standards you don't need.

CHECK (IT Health Check Service)

What It Is

CHECK is the NCSC's scheme for assuring penetration testing services to UK government and Critical National Infrastructure (CNI). It's not a certification for individual testers, it's an approval scheme for companies providing testing to specific sectors.

Who Needs CHECK?

  • Central government departments
  • NHS trusts and healthcare organisations
  • Critical National Infrastructure (energy, water, transport)
  • Defence contractors handling classified information
  • Organisations meeting Government Security Classifications Policy

CHECK Team Roles

RoleDescription
CHECK Team Leader (CTL)Senior tester who can lead engagements. Must pass NCSC examinations and demonstrate significant experience. Responsible for methodology, quality, and final report.
CHECK Team Member (CTM)Supports the Team Leader. Can perform testing under supervision but cannot lead engagements independently.

CHECK Approval Levels

CHECK Green Company can test systems up to OFFICIAL-SENSITIVE

CHECK Green Light Company can test systems up to SECRET (requires additional security clearances)

CREST (Council of Registered Ethical Security Testers)

What It Is

CREST is an international accreditation body for cybersecurity service providers. Unlike CHECK (which is UK government-specific), CREST operates globally and serves commercial markets.

Who Needs CREST?

  • Financial services (banks often mandate CREST-accredited testing)
  • Large enterprises seeking independent assurance
  • Organisations in regulated sectors (insurance, retail banking)
  • Companies pursuing SOC 2 or similar certifications

CREST Individual Certifications

CertificationLevel & Focus
CPSAEntry-level – Demonstrates foundational security knowledge
CRTInfrastructure penetration testing certification
CRTWAWeb application testing specialisation
CCTAdvanced level – Infrastructure or application specialisation
CCSAMRed team operations and simulated attack management

CREST Company Accreditation Requirements

  • Appropriate processes and methodologies
  • Sufficient certified staff
  • Professional indemnity insurance
  • Quality management systems
  • Information security practices

CBEST (Bank of England Framework)

What It Is

CBEST is the Bank of England's framework for threat intelligence-led penetration testing of UK financial institutions. It predates TIBER-EU and shares many characteristics with it.

CBEST Applies To

  • Bank of England (PRA) Regulated Prudential Regulation Authority supervised firms
  • FCA Regulated Financial Conduct Authority supervised firms

Not all regulated firms require CBEST, it's typically requested of systemically important institutions. The regulators determine who should participate.

CBEST Engagement Structure

  1. Threat Intelligence A qualified TI provider produces targeted intelligence on threats to the specific firm
  2. Penetration Testing A CBEST-approved provider executes realistic attack scenarios based on the TI
  3. Control Function An independent third party (often Big 4) oversees the engagement

CBEST vs Standard Penetration Testing

AspectCBEST Difference
MethodologyThreat intelligence-driven, not generic methodology
EnvironmentTesting on live production systems, not isolated test environments
StealthBlue team typically unaware until debrief
OversightBank of England/FCA involved throughout

When to Use Each Standard

You Need CHECK If:

  • Part of UK central government
  • Operate Critical National Infrastructure
  • Contract requires government standards
  • Handle classified information (OFFICIAL-SENSITIVE+)

You Need CREST If:

  • Board/auditors require quality assurance
  • In financial services (client expectation)
  • Want proven tester competence
  • Pursuing SOC 2 or similar certifications

You Need CBEST If:

  • BoE or FCA has specifically requested it
  • Systemically important financial institution
  • Threat profile warrants TI-led testing

Overlap and Relationships

These standards aren't mutually exclusive:

  • Many CHECK companies are also CREST-accredited
  • CBEST requires providers to meet both CREST and NCSC standards
  • Individual testers often hold both CHECK and CREST certifications

For most commercial organisations, CREST accreditation provides appropriate assurance. CHECK matters primarily for government work. CBEST is a specialist requirement for major financial institutions.

Standards-Aligned Testing

We deliver testing aligned with CHECK, CREST and CBEST guidance. Testing is led by a Cyber Scheme Team Leader (CSTL) who also holds OSCP, CRTP and CRTO.

Security Front Door

Find the right level of security for your business.

One monthly plan, one front door: penetration testing, Cyber Essentials, AI security, training and advice, from £1,500 a month. No hidden costs.

Forefront
UK Penetration Testing & Red Team Operations
Loading...