Skip to main content

What’s the difference between CHECK and CREST penetration testing?

Understand how Check and Crest penetration testing differs

Written by Kathy Gwinnett

Both CHECK and CREST are recognised standards for high-quality penetration testing, but they serve slightly different purposes:

CHECK Penetration Testing

  • UK Government-Approved: CHECK is a scheme run by the UK National Cyber Security Centre (NCSC).

  • Scope: Primarily used for organisations handling UK government or public sector data, requiring assurance that testing is performed to strict government-approved standards.

  • Testers: Only security companies and individuals accredited under the CHECK scheme can deliver this service. They must hold UK security clearance.

  • Output: Provides assurance that testing meets the NCSC’s requirements for protecting sensitive government systems and data.

CREST Penetration Testing

  • Industry-Recognised: CREST is an international, not-for-profit accreditation and certification body.

  • Scope: Widely used across both public and private sectors worldwide to ensure high-quality, professional penetration testing.

  • Testers: CREST-accredited companies and testers are independently assessed for technical competence, methodologies, and ethical standards.

  • Output: Provides confidence that testing follows globally recognised best practices, regardless of sector.

    In summary:

    • CHECK = Government-specific standard (mandatory for certain government contracts).

    • CREST = Industry-wide quality assurance (recognised globally).

    • Many organisations outside government choose CREST as it demonstrates rigorous, independent testing standards.

    • Citation Cyber is accredited under both schemes, meaning we can deliver testing to whichever standard your project or compliance requirements demand.

Did this answer your question?