Skip to main content

What’s the difference between CHECK and CREST penetration testing?

Understand how Check and Crest penetration testing differs

Kathy Gwinnett avatar
Written by Kathy Gwinnett
Updated over 2 months ago

Both CHECK and CREST are recognised standards for high-quality penetration testing, but they serve slightly different purposes:

CHECK Penetration Testing

  • UK Government-Approved: CHECK is a scheme run by the UK National Cyber Security Centre (NCSC).

  • Scope: Primarily used for organisations handling UK government or public sector data, requiring assurance that testing is performed to strict government-approved standards.

  • Testers: Only security companies and individuals accredited under the CHECK scheme can deliver this service. They must hold UK security clearance.

  • Output: Provides assurance that testing meets the NCSC’s requirements for protecting sensitive government systems and data.

CREST Penetration Testing

  • Industry-Recognised: CREST is an international, not-for-profit accreditation and certification body.

  • Scope: Widely used across both public and private sectors worldwide to ensure high-quality, professional penetration testing.

  • Testers: CREST-accredited companies and testers are independently assessed for technical competence, methodologies, and ethical standards.

  • Output: Provides confidence that testing follows globally recognised best practices, regardless of sector.

    In summary:

    • CHECK = Government-specific standard (mandatory for certain government contracts).

    • CREST = Industry-wide quality assurance (recognised globally).

    • Many organisations outside government choose CREST as it demonstrates rigorous, independent testing standards.

    • Citation Cyber is accredited under both schemes, meaning we can deliver testing to whichever standard your project or compliance requirements demand.

Did this answer your question?