Choosing a penetration testing provider involves placing considerable trust in an external organisation. Testers may be given access to sensitive systems, applications and infrastructure, while the quality of their work directly influences the assurance you gain from the assessment.
CREST accreditation provides organisations with an independent way to assess whether a penetration testing company has demonstrated appropriate technical capability, service methodologies, data security practices and quality controls.
For many buyers, CREST is also an important procurement consideration. Accreditation may be requested by customers, auditors, regulators or internal security teams seeking confidence that testing will be delivered against recognised industry standards.
This article explains what CREST penetration testing means, what accreditation tells you about a provider and when choosing a CREST-accredited company may be particularly important.
What is CREST penetration testing?
CREST penetration testing refers to security testing delivered by an organisation accredited by CREST for penetration testing services.
The objective of the assessment remains the same as other forms of penetration testing, which is to identify and safely validate security weaknesses using techniques similar to those employed by real-world attackers.
CREST accreditation provides an additional layer of independent assurance around the organisation delivering the service. Accredited companies are assessed against requirements covering areas such as technical capability, testing methodologies, information security, quality management and service delivery.
This helps buyers distinguish between organisations that simply offer penetration testing and providers that have undergone external assessment against defined industry standards.
What is CREST?
CREST is an international not-for-profit accreditation and certification body for the cyber security industry.
CREST accredits organisations that provide services including penetration testing and other areas of cyber security, while also administering professional certifications for individual practitioners. This distinction is important, because company accreditation and individual certification are different things.
A CREST-accredited company has been assessed at an organisational level. This includes reviewing evidence relating to its processes, service methodologies, data security practices and governance.
Individual certifications, such as the CREST Practitioner Security Analyst (CPSA), CREST Registered Penetration Tester (CRT), CREST Certified Tester – Infrastructure (CCT INF) and CREST Certified Tester – Application (CCT APP), assess the knowledge and capabilities of individual security professionals.
When selecting a provider, it is therefore worth understanding both the accreditation held by the company and the experience and qualifications of the consultants who will actually perform your assessment.
What does CREST accreditation tell you about a penetration testing provider?
CREST accreditation provides independent assurance that a company has been assessed against established standards relevant to the services it delivers. For penetration testing providers, this can include evidence covering areas such as:
- Technical capability and competence
- Service methodologies and testing processes
- Information security and the handling of sensitive customer data
- Quality management and assurance processes
- Legal and regulatory considerations
- Communication and engagement management
- Logging, auditing and record keeping
These controls matter because penetration testing is a highly trusted activity. Testers may gain detailed knowledge of vulnerabilities, internal systems and security controls, and in some cases will be authorised to attempt exploitation of sensitive environments.
A mature provider should therefore demonstrate more than just technical skill . It should also have clear processes governing how assessments are scoped, authorised, delivered, reviewed and reported. CREST accreditation provides buyers with an independent indication that these areas have been formally considered and assessed.
When might you need a CREST-accredited penetration testing provider?
There is no universal requirement for every penetration test to be performed by a CREST-accredited company. However, there are several situations where accreditation may be required or strongly preferred. These can include customer security requirements or supplier due diligence, regulatory, compliance and audit programmes.
In other cases, an organisation may simply choose a CREST-accredited provider because it wants additional independent assurance over the quality and governance of the company delivering the assessment.
This can be particularly valuable where a penetration testing report will be shared with customers, auditors, investors or other external stakeholders.
If you are unsure what level of assurance you require, an experienced provider should be able to help you understand the available options when choosing a penetration testing partner.
Do you always need a CREST-accredited provider?
The right provider depends on the objectives of the assessment, the environment being tested and any regulatory, contractual or customer requirements that apply.
Some organisations may have no formal requirement to use a CREST-accredited company. In those cases, technical experience, reporting quality, methodology, sector knowledge and post-assessment support should all form part of the decision.
Nevertheless, accreditation can provide useful independent assurance when selecting between providers that may otherwise appear similar. It demonstrates that the company has undergone external assessment against recognised standards and maintains documented processes around how its services are delivered.
For many buyers, particularly those operating in regulated industries or serving enterprise customers, that assurance can make procurement and due diligence considerably easier.
CREST accreditation vs tester certification
It is common for buyers to use the terms accreditation and certification interchangeably, but they refer to different things.
CREST accreditation applies to companies. It assesses the organisation, its processes and its ability to deliver specific cyber security services against CREST standards.
CREST certifications apply to individuals. They assess the knowledge and technical capability of security professionals at different levels and across different disciplines.
A company may employ CREST-certified individuals without itself being accredited for penetration testing services. Equally, company accreditation does not remove the need to understand who will perform the work and whether those consultants have appropriate experience for the technologies in scope.
When evaluating providers, ask questions such as:
- Is the company itself CREST accredited for penetration testing?
- What qualifications and experience do the assigned consultants hold?
- Has the provider tested similar technologies and environments before?
- How are findings quality assured before reporting?
What should you expect from a CREST penetration testing engagement?
A CREST-accredited provider should be able to clearly explain how your assessment will be scoped, authorised, delivered and reported. The precise approach will vary according to the systems being tested and your objectives, but a typical engagement will involve:
- Understanding your requirements: The provider should establish what needs to be tested, why the assessment is being performed and what level of assurance you need.
- Defining scope and rules of engagement: The test scope, authorised activities, exclusions, testing windows and any operational concerns should be clearly documented before testing begins.
- Performing the assessment: Consultants assess the agreed systems using appropriate manual and automated techniques, adapting the approach to the technologies and risks involved.
- Validating findings: Potential vulnerabilities should be reviewed and validated before being reported, helping reduce false positives and provide a realistic assessment of risk.
- Reporting and remediation guidance: The final report should clearly explain the vulnerabilities identified, their potential impact and practical recommendations for remediation.
- Post-assessment support: A good provider should remain available to discuss findings, clarify remediation advice and support retesting where appropriate.
The exact duration and price of an engagement will depend on factors such as scope, complexity and the systems involved. Our guide to penetration testing costs explains these factors in more detail.
Why choose a CREST-approved penetration testing provider?
The main benefit of using a CREST-accredited company is independent assurance. Rather than relying solely on a provider’s own claims about quality or expertise, buyers can see that the organisation has undergone external assessment against defined standards.
This can provide greater confidence regarding the supplier’s process maturity, cyber security practices, quality, technical capabilities, governance and professional conduct. CREST member companies are also subject to a Code of Conduct and a formal complaints and resolution process, providing an additional layer of accountability.
Accreditation should still form part of a wider evaluation. Buyers should also consider relevant technical experience, sector knowledge, reporting quality, remediation support and the suitability of the proposed methodology.
How do you choose the right CREST penetration testing provider?
CREST accreditation provides valuable assurance, but organisations should still look carefully at the provider behind the accreditation. The quality of a penetration testing engagement is influenced by the people delivering it, the depth of the testing, the clarity of the report and the support available after findings have been identified.
Consider asking:
- Has the company tested environments similar to ours?
- Who will perform the assessment?
- What experience do the assigned consultants have?
- Can we see an example report?
- How will critical findings be communicated?
- Is remediation guidance included?
- Does the provider offer retesting?
- How quickly will the final report be delivered?
- Can the assessment be adapted around operational or regulatory requirements?
Why is it important to use a CREST-approved provider?
Working with a CREST-approved penetration testing provider ensures you’re in safe and experienced hands. You should have the confidence that your penetration test is thorough and comprehensive. Your provider must carry out a test that’s technically accurate and covers the required scope of your IT controls to ensure your primary security concerns are assessed.
Legal issues are of high importance when conducting penetration testing. The testing company will know how to gain access to your IT systems and the weak spots within your security across the organisation that have been discovered in your test. Your penetration testing provider will need to seek specific authorisation from you to conduct the test.
The CREST accreditation gives you the assurance that your provider has the appropriate policies, processes and procedures to carry out penetration testing and protect your information. You can gain peace of mind that the support provided is the best in the industry.
Sentrium is a CREST-accredited penetration testing provider
Sentrium is a UK-based, CREST-accredited cyber security consultancy delivering penetration testing across web applications, APIs, networks, cloud environments, mobile applications and other technologies.
Our consultants focus on providing meaningful security assurance rather than simply producing a list of vulnerabilities. Assessments are tailored to the environment, objectives and risk profile of each organisation, with clear reporting and practical remediation guidance provided throughout the engagement.
High and critical findings are communicated as soon as they are identified, allowing remediation to begin before the final report is delivered. We also include retesting of high and critical findings for 30 days after completion of the assessment.
You can learn more about our penetration testing services, or request a tailored penetration testing quote to discuss your requirements with our team.