main logo icon

Published on

August 9, 2026

|

17 min read

CREST-Accredited Penetration Testing Companies (2026): How to Verify and Who to Shortlist

Exactly 510 companies worldwide hold CREST's firm-level Penetration Testing accreditation. How to verify a provider on the CREST Marketplace, the difference between company accreditation and individual certification, where CREST matters by market, and which accredited firms to shortlist.

Arafat Afzalzada

Arafat Afzalzada

Founder

Advisories

Summarize with AI

ChatGPTPerplexityGeminiGrokClaude

TL;DR

Exactly 510 companies worldwide held CREST's firm-level Penetration Testing accreditation when we queried the CREST Marketplace on 9 August 2026. "CREST accredited" and "CREST certified" are not the same claim. Accreditation is assessed at company level against CREST's standards. Certification is an exam passed by an individual consultant. A firm can staff a project entirely with CREST-certified individuals and still hold no company accreditation at all. Only the firm-level entry on the CREST Marketplace proves the company itself was assessed. Verify every claim at marketplace.crest.org, CREST's single authoritative directory of accredited suppliers. Search the registered legal entity name and confirm the specific service discipline you are buying is listed. CREST's accreditation footprint is concentrated: the UK holds 202 of the 510 firm-level Penetration Testing accreditations, ahead of the United States (51), Singapore (50), Australia (45) and Canada (4). On 28 July 2026 CREST added Domain 7, Responsible AI Use, to its general requirements for all accredited providers, plus an optional Annex B for AI-enabled penetration testing. CREST is a commercial quality signal, not a licence. Singapore is the exception: a CSA licence is a legal requirement there under Part 5 of the Cybersecurity Act.

Exactly 510 companies worldwide held CREST's firm-level Penetration Testing accreditation when we queried the CREST Marketplace on 9 August 2026. That number matters because "CREST accredited" is one of the most repeated and least verified claims in security procurement, and because the gap between the firms that hold it and the firms that imply it is wide.

Quick answer: Stingrai Inc holds CREST's firm-level Penetration Testing accreditation, one of only four Canadian-headquartered companies among the 510 accredited worldwide, and you can verify that entry yourself at marketplace.crest.org in about ninety seconds. The rest of this guide explains what accreditation actually assesses, the difference between CREST accredited and CREST certified, the four-step verification on the CREST Marketplace, the common verification missteps to avoid, where CREST carries procurement weight by market, the 2026 AI accreditation changes and which accredited firms to shortlist.

The claim is worth checking for a specific reason. CREST assesses a company, not just the people it employs. A provider can hire five consultants who each passed a CREST exam, put "CREST certified" on the website, and hold no company accreditation whatsoever. Both statements are technically true. Only one of them tells you the firm's methodology, data handling and governance were independently examined.

This guide covers what CREST accreditation actually assesses, how to verify any provider's claim in about ninety seconds, the verification missteps that most often catch buyers during vendor due diligence, where CREST carries procurement weight by market, and which accredited firms are worth shortlisting.

Accreditation tells you a firm's process was independently examined; engagement data tells you what a disciplined process produces. In Stingrai's State of Penetration Testing 2026, built from 55 penetration tests, 93% of tests surfaced at least one High or Critical finding, while the false-positive rate across all reported findings was just 0.74%. Those two numbers are the practical case for verifying providers carefully: a rigorous firm finds serious problems, and nearly everything it reports is real.

At a glance

Question

Short answer

How many firms hold CREST Penetration Testing accreditation?

510 globally, per the CREST Marketplace, 9 August 2026

Where are they concentrated?

UK 202, USA 51, Singapore 50, Australia 45, Canada 4

Is "CREST certified" the same as "CREST accredited"?

No. Certification is an individual exam. Accreditation is a company assessment

Where do I verify a claim?

marketplace.crest.org, CREST's authoritative supplier directory

Is CREST legally required?

No, it is a commercial standard. Singapore's CSA licence is the separate legal requirement

What changed in 2026?

Domain 7 (Responsible AI Use) and Annex B (AI-enabled penetration testing), effective 28 July 2026

What CREST accreditation actually is

CREST is a not-for-profit accreditation and certification body for the technical security industry. It runs two entirely separate schemes that buyers routinely collapse into one phrase, and the distinction is the single most useful thing in this article.

Company-level accreditation: the procurement-grade signal

CREST accredits organisations against published standards. The assessment looks past the skills of any individual tester and into how the business runs: how engagements are scoped and governed, what methodology is applied and whether it is actually followed, how client data is classified, transported, stored and destroyed, how findings are reported and quality-assured, and how the company handles complaints and incidents of its own.

CREST's organisational standard is the CREST Accreditation Standard, Company General Requirements, which every accredited provider must meet regardless of service. On top of that sit service-specific standards. CREST currently publishes standards across nine service areas: Cyber Threat Intelligence, Incident Exercising, Incident Response, Penetration Testing, Security Architecture, Security Operations, Threat Intelligence for Simulated Attacks, Threat-led Penetration Testing, and Vulnerability Assessment.

This is why company accreditation is the signal that belongs in a procurement scorecard. It is an assurance about the supplier as an organisation, and it survives staff turnover. An individual certification walks out of the building when its holder resigns.

Individual certifications: the practitioner signal

CREST separately certifies people through examinations at three experience tiers: Practitioner, Registered and Certified. The ones that appear in penetration testing statements of work are:

Certification

Acronym

Tier

CREST Practitioner Security Analyst

CPSA

Practitioner

CREST Registered Penetration Tester

CRT

Registered

CREST Certified Tester, Infrastructure

CCT INF

Certified

CREST Certified Tester, Application

CCT APP

Certified

CREST Certified Red Team Specialist

CCRTS

Certified

CREST Certified Red Team Manager

CCRTM

Certified

Two of those names changed, and stale vendor pages have not caught up. CCRTS was previously the CREST Certified Simulated Attack Specialist (CCSAS), and CCRTM was previously the CREST Certified Simulated Attack Manager (CCSAM). CREST states on its own certification page that the exam "was previously known as the CREST Certified Simulated Attack Specialist (CCSAS) but has been updated in-line with industry terminology and lexicons." If a provider's website still advertises CCSAS or CCSAM in 2026, that page has not been reviewed in a while, which is itself a small piece of information about the firm.

CCRTS carries weight beyond its name: CREST notes it is "a critical requirement by the Bank of England as part of the CBEST accreditation process."

The difference that costs buyers money

Company accreditation

Individual certification

Assessed subject

The firm

A person

What is examined

Governance, methodology, data handling, reporting, quality assurance

Technical knowledge, in an exam

How it is earned

Documented assessment against CREST standards

Passing a CREST examination

Survives staff turnover?

Yes

No, it leaves with the individual

Where it is verifiable

CREST Marketplace supplier profile

The individual's own record, not the firm's

Typical marketing phrase

"CREST accredited", "CREST member company"

"CREST certified consultants", "our team is CREST qualified"

A firm with accreditation almost always employs certified individuals. The reverse is not true at all, and it is where most misleading claims live.

How to verify a CREST claim in four steps

Diagram of the four-step CREST verification workflow on the CREST Marketplace alongside two checks that keep the answer reliable

Verification is genuinely fast once you know where to look. It takes about ninety seconds.

Step 1: Go to the CREST Marketplace. The only authoritative directory is marketplace.crest.org. Do not verify from the provider's own website, a reseller listing, or a badge image, all of which are self-asserted.

Step 2: Search for the exact legal entity, not the brand. Marketplace profiles use registered company names. Searching "Dionach" resolves to Dionach Ltd, "JUMPSEC" to JUMPSEC Ltd, "Prism Infosec" to Prism Infosec Ltd, and "CyberCX" to CyberCX Pty Ltd. If a brand you were quoted does not resolve to any entity, ask the provider which legal entity holds the accreditation. Groups sometimes hold accreditation in one subsidiary and sell through another.

Step 3: Read the "CREST Accreditations & Specialisms" block. This is the part that answers your actual question. A profile lists precisely which services the company is accredited for. Being on the Marketplace is not the same as being accredited for penetration testing. A supplier accredited only for Security Operations Centre or Vulnerability Assessment work is a real CREST member and still not accredited for the thing you are buying. Look for Penetration Testing by name.

Step 4: Match the accreditation to your scope of work. If you are buying threat-led red teaming under a financial-services framework, "Penetration Testing" alone is not the relevant accreditation. Look for Threat Led Penetration Testing, which CREST profiles annotate as "(Formerly STAR ILPT)", or the TLPT-FS variant. Application-focused buyers should look for Application Security Testing, annotated "(Formerly OVS)".

Common verification missteps

Two missteps account for nearly every wrong conclusion buyers reach about a provider's CREST status, and both take seconds to avoid.

Misstep 1: verifying anywhere other than the CREST Marketplace. CREST consolidated its accredited-supplier directory into the CREST Marketplace, and marketplace.crest.org is the single source of truth for accreditation status. Older links on vendor websites, procurement templates and third-party listicles can predate that consolidation, and a badge image or a "CREST accredited" line on a provider's own site is self-asserted rather than verified. If a supplier offers proof, ask for its marketplace.crest.org/supplier/ profile URL and read the accreditation block there yourself. And as with any procurement, confirm the supplier's operating locations and registered entity through the supplier's own website and the relevant companies registry as part of standard vendor due diligence.

Misstep 2: reading individual certifications as company accreditation. The most common soft misrepresentation in this market is a provider website that says "CREST accredited penetration testing" when what the firm means is that some of its testers hold CREST exams. Sometimes it is deliberate. Often it is a marketing team that did not know the two schemes were different.

You do not need to litigate the intent. Search the firm on the Marketplace. If the company is not there, the company is not accredited, whatever its consultants hold. If it is there, check that Penetration Testing appears in its accreditation list. That is the whole test.

Where CREST carries weight, market by market

CREST's footprint is far more concentrated than its global profile suggests. These are firm-level Penetration Testing accreditations by head office country, from the CREST Marketplace on 9 August 2026.

Horizontal bar chart of firm-level CREST Penetration Testing accreditations by head office country in August 2026

Head office country

Firms with CREST Penetration Testing accreditation

United Kingdom

202

United States

51

Singapore

50

Australia

45

Canada

4

Global total

510

Two things stand out. The UK holds roughly 40 percent of all firm-level penetration testing accreditations worldwide: 202 of the 510 accredited firms on the CREST Marketplace, retrieved 9 August 2026. And Singapore, a country of around six million people, has essentially as many accredited firms (50) as the United States (51).

United Kingdom: the commercial standard, distinct from CHECK

In the UK, CREST is the default commercial benchmark, and it is routinely named in private-sector and regulated-sector tenders as a supplier quality bar. Regulated fintech buyers can see how the same accreditation question plays against PCI DSS 4.0.1, SOC 2 and DORA fit in the **fintech penetration testing companies** ranking.

CREST is not the same as NCSC's CHECK scheme, and the two are not interchangeable. CHECK is the UK government scheme. NCSC's guidance is that for central government, "all systems processing data protectively marked OFFICIAL and above (up to Top Secret but excluding STRAP systems)" must use CHECK-assured companies. For the wider public sector, NCSC strongly recommends CHECK providers.

The relationship between them is more interesting than a rivalry. NCSC states that "CHECK Team Members hold one of the NCSC-approved qualifications offered by either CREST or The Cyber Scheme." CREST individual certifications are a qualification pathway into CHECK, not a competitor to it.

The practical rule: if you are testing UK government systems at OFFICIAL or above, you need a CHECK provider. For commercial systems, CREST company accreditation is the relevant signal. NCSC's directory listed 55 CHECK providers as of August 2026, a much smaller pool than the 202 UK firms with CREST penetration testing accreditation.

One correction worth making, because it circulates widely: some vendor blogs claim Procurement Policy Note PPN 014 made CREST mandatory for UK government penetration testing suppliers. It did not. PPN 014 is a Cyber Essentials policy note and does not mention CREST or penetration testing at all. Do not build a procurement position on that claim.

Australia: a genuine procurement filter, separate from IRAP

Australia is the fourth-largest CREST market by accredited firms, and CREST accreditation shows up frequently as a prerequisite in Australian enterprise and public-sector procurement.

CREST is distinct from IRAP, the Infosec Registered Assessors Program. IRAP assessors are endorsed by the Australian Signals Directorate to assess ICT systems against the Information Security Manual, for systems handling government data at OFFICIAL, PROTECTED, SECRET or TOP SECRET. The two are complementary rather than substitutable: a penetration test attempts to exploit vulnerabilities to establish real impact, while an IRAP assessment evaluates the full set of applicable ISM controls, only some of which a penetration test can validate. Buyers selling into Australian government commonly need both, for different reasons.

Singapore: CREST is the quality signal, the CSA licence is the law

Singapore is the market where buyers most often get the hierarchy wrong, so this one is worth stating precisely.

In Singapore, providing penetration testing services requires a licence. Under Part 5 of the Cybersecurity Act, Singapore's official business licensing portal states that "all cybersecurity service providers providing licensable cybersecurity services as set out in the Second Schedule are required to obtain a cybersecurity service provider's licence regardless of whether they are companies or individuals," including freelancers, sole proprietorships, third-party providers supporting other providers, and resellers. The licence is administered by CSA's Cybersecurity Services Regulation Office.

CREST accreditation does not substitute for that licence, and the licence is not a quality assessment. They answer different questions: the licence asks whether the provider is legally permitted to sell penetration testing in Singapore, and CREST accreditation asks whether the provider's methodology and governance were independently assessed. Serious providers in Singapore hold both.

CREST's presence in the market is long-standing. CSA announced the CREST Singapore Chapter in 2016 as CREST's first Asian chapter, developed with CSA, AISP, MAS, ABS and IDA, with CSA supporting an examination facility and funding accreditation for smaller providers. That early state backing is a large part of why Singapore now has 50 accredited firms.

United States and Canada: growing, and still thin

The US has 51 accredited firms, a small number for the size of its security market, because US procurement leans on SOC 2, FedRAMP and PCI DSS rather than CREST. CREST recognition is growing there, mostly driven by firms selling into UK, Australian and Singaporean buyers.

Canada is the outlier: just four companies headquartered in Canada hold firm-level CREST Penetration Testing accreditation. For Canadian buyers who have written CREST into a procurement standard, the domestic supplier pool is genuinely that small, and most will need to consider accredited firms headquartered elsewhere that serve the Canadian market.

What changed in 2026: CREST's AI accreditation

On 28 July 2026, CREST launched the first accredited standards for AI use in cybersecurity services. In CREST's words: "From today, 28 July 2026, cybersecurity service providers will be able to apply to have their use of AI within their service provision independently assured by CREST."

There are two distinct pieces, and the difference matters when you read a provider's claim.

Domain 7, Responsible AI Use, is a new domain in the general requirements CREST sets for all accredited service providers. It "covers the governance, oversight, transparency and responsible organisational use of AI by the service provider." It applies as part of the baseline organisational standard wherever AI use could affect client confidentiality, service delivery, client-facing outputs, legal obligations or professional judgement.

Annex B, AI-Enabled Penetration Testing, is an optional annex to the Penetration Testing Standard for providers that use AI within testing itself. CREST describes it as helping "ensure AI enhances professional judgement while maintaining the quality, integrity and trust expected of CREST-accredited services."

The buyer takeaway is straightforward. Every provider you engage is now expected to be able to explain how it governs AI use. Providers that actively use AI in delivery can go further and have that use independently assured. Given that IBM's Cost of a Data Breach Report 2026 found one in four malicious breaches are now AI-enabled, at an average cost of USD 6 million, the assurance question on both sides of the engagement is not academic. Ask any provider using AI in testing whether they intend to pursue Annex B, and how they currently prevent model-generated findings from reaching a client report unvalidated.

CREST-accredited providers worth shortlisting in 2026

Every firm below was verified on the CREST Marketplace on 9 August 2026 and holds Penetration Testing in its firm-level accreditation list. This is a shortlist across markets rather than a single-country ranking. For country-specific depth, the regional guides linked at the end go further. The global **best penetration testing companies in 2026** ranking sits alongside them.

1. Stingrai

Head office: Toronto, Canada, with a London, UK office. Marketplace entry: Stingrai Inc. CREST accreditation: Penetration Testing.

Stingrai Inc holds firm-level CREST accreditation as a Penetration Testing service provider, which places it among only four companies headquartered in Canada with that accreditation. Stingrai is a proud CREST member: the accreditation process independently examines methodology, governance and data handling at company level, and that external scrutiny is part of how the firm holds itself to standard. Founded in 2021, the firm operates from Toronto and London and works across North America and Europe.

The differentiator is the delivery model rather than the badge alone. Stingrai pairs senior human testers with Snipe, its autonomous AI agent for web application penetration testing. Snipe is custom-trained on more than 6,000 HackerOne Hacktivity disclosure reports plus skills distilled from years of Stingrai's own pentester methodology, and it is built specifically to hunt the classes generic AI scanners miss: IDOR, business logic flaws, and broken authorization and access control. It performs black-box dynamic testing and white-box source code review, generates AutoFix pull requests, and can run as a PR-gating check to block vulnerable code from being merged.

That combination is exactly the territory CREST's new Domain 7 and Annex B were written to govern, and it is a useful reference point for how the AI question should be answered by a provider.

The team holds OSCE3, OSCP, OSWE, OSED, OSEP, CREST CRT, CISSP, CRTO, GCPN, CRTE and eWPTX, has published 18 CVEs, presents research at DEFCON and BSIDES, and holds a 5.0 out of 5.0 rating across 19 Clutch reviews. Stingrai's penetration testing supports client compliance programs for SOC 2, ISO 27001, HIPAA, PCI DSS 4.0, NIST SP 800-53 and 800-171, DORA and NIS2. Current packages and pricing are published at stingrai.io/pricing.

Best for: enterprise-grade PTaaS powered by Snipe, its proprietary AI pentesting agent, working alongside certified human pentesters throughout every engagement (CREST-accredited firm), for one-time or continuous testing in highly regulated industries with SOC 2, ISO 27001, PCI DSS and CMMC compliance programs.

2. NCC Group

Head office: United Kingdom. Marketplace entry: NCC Group. CREST accreditations: Incident Exercising, Incident Response, Penetration Testing, Security Operations Centre, Vulnerability Assessment, and four more including Threat Led Penetration Testing (TLPT-FS) and Threat Intelligence for Simulated Attacks.

The broadest CREST accreditation footprint on this list and one of the longest-tenured members, at 19 years. NCC Group serves Asia Pacific, Europe, the Middle East and North America.

Best for: large enterprises needing a single accredited supplier across testing, threat intelligence, incident response and threat-led red teaming.

3. Pen Test Partners

Head office: United Kingdom. Marketplace entry: Pen Test Partners. CREST accreditations: Incident Response, Penetration Testing, Vulnerability Assessment, Application Security Testing (Formerly OVS), Mobile Application Security Testing (Formerly OVS), and two more.

Sixteen years of CREST membership, 100 to 499 employees, serving Europe and North America. Notable for holding both the application and mobile application security testing accreditations alongside core penetration testing, and for a strong public research output in transport, maritime and IoT.

Best for: application and mobile-heavy scopes, and buyers who value published technical research as evidence of capability.

4. LRQA

Head office: United Kingdom. Marketplace entry: LRQA. CREST accreditations: Incident Exercising, Incident Response, Penetration Testing, Security Operations Centre, Vulnerability Assessment, and six more.

LRQA absorbed Nettitude, and the CREST accreditation now sits under the LRQA entity. Searching the Marketplace for "Nettitude" returns nothing, which is a good illustration of why you verify the legal entity rather than the brand you remember. Seventeen years of membership, covering Asia Pacific, Europe and Latin America.

Best for: buyers who want penetration testing alongside broader assurance and certification services from one group.

5. Claranet Cyber Security

Head office: United Kingdom. Marketplace entry: Claranet Cyber Security. CREST accreditations: Penetration Testing, Security Operations Centre, Vulnerability Assessment, Application Security Testing (Formerly OVS), and one more.

Nineteen years of CREST membership and 500 to 999 employees, focused on Europe. Pairs testing with managed security operations.

Best for: European organisations wanting accredited testing and a managed SOC from the same provider.

6. Dionach

Head office: United Kingdom. Marketplace entry: Dionach Ltd. CREST accreditations: Incident Response, Penetration Testing, Vulnerability Assessment, Threat Led Penetration Testing (Formerly STAR ILPT), TLPT-FS Threat Led Penetration Testing.

Sixteen years of membership, 50 to 99 employees, serving Europe and North America. Holds both threat-led penetration testing accreditations, which is a meaningful marker for regulated financial services work.

Best for: mid-market buyers needing threat-led testing under a financial services framework without going to a large consultancy.

7. JUMPSEC

Head office: United Kingdom. Marketplace entry: JUMPSEC Ltd. CREST accreditations: Incident Exercising, Incident Response, Penetration Testing, Security Operations Centre, Vulnerability Assessment, and one more.

Fourteen years of membership with 10 to 49 employees, focused on Europe. A broad accreditation set for a boutique, including incident exercising.

Best for: UK organisations wanting a small, senior team with accreditation breadth well beyond its headcount.

8. Prism Infosec

Head office: United Kingdom. Marketplace entry: Prism Infosec Ltd. CREST accreditations: Incident Exercising, Incident Response, Penetration Testing, Vulnerability Assessment, Threat Led Penetration Testing (Formerly STAR ILPT), and one more.

Ten years of membership, 10 to 49 employees, Europe-focused, and independent. Holds threat-led penetration testing accreditation.

Best for: buyers who want an independent UK consultancy with threat-led capability and no managed-services upsell.

9. CyberCX

Head office: Australia. Marketplace entry: CyberCX Pty Ltd. CREST accreditations: Incident Response, Penetration Testing, Security Operations Centre.

The largest accredited provider headquartered in Australia, with 1,000 to 4,999 employees and six years of CREST membership, serving Asia Pacific, Europe and North America.

Best for: Australian and New Zealand enterprise and public-sector buyers needing scale alongside accreditation.

10. ST Engineering Info-Security

Head office: Singapore. Marketplace entry: ST Engineering Info-Security Pte Ltd. CREST accreditation: Penetration Testing.

Part of Singapore's ST Engineering group. A representative example of the accredited Singapore cohort, where CREST accreditation typically sits alongside the mandatory CSA licence.

Best for: Singapore buyers with government-linked or critical information infrastructure requirements.

How to use accreditation without over-relying on it

CREST accreditation tells you a company was assessed. It does not tell you the five people assigned to your engagement are the right five people. Treat it as a filter, then test what it does not cover.

  • Confirm accreditation covers your scope. Penetration Testing, Threat Led Penetration Testing and Application Security Testing are separate accreditations. Buy the one that matches your statement of work.

  • Ask who is actually testing. Request the named team, their tier of CREST certification, and whether the people who sold you the engagement will be on it. The tester-qualification section of the **pentest and red team RFP question bank** scores this.

  • Ask for a redacted sample report. Accreditation covers reporting standards. A sample tells you whether the output will be useful to your engineers.

  • Ask about retesting. Whether remediation verification is included, and for how long after delivery, varies enormously and rarely appears in the headline price. What accreditation, retesting and manual depth do to a quote is broken down in **penetration testing cost in 2026**.

  • Ask the 2026 AI question. How does the provider use AI in delivery, what stops an unvalidated model finding reaching your report, and are they pursuing Annex B?

  • Verify the entity, not the brand. Accreditation sits with a legal entity. Make sure it is the entity on your contract.

Accreditation is also not a compliance requirement. SOC 2 imposes no certification, accreditation or independence bar on the tester, which the **SOC 2 penetration testing guide** sets out, and PCI DSS Requirement 11.4 states in the requirement text itself that the tester is not required to be a QSA or ASV, covered in the **PCI DSS penetration testing guide**.

For a broader view of how testing is scoped and priced, our PTaaS overview covers continuous testing models, and Stingrai pricing sets out current packages.

More provider guides

Shortlisting in a specific market? These rankings follow the same verification-first approach:

Frequently Asked Questions

What is CREST accreditation?

CREST accreditation is a company-level assessment of a cybersecurity service provider against CREST's published standards. It examines how the organisation governs engagements, applies and documents methodology, handles and destroys client data, quality-assures reports, and manages complaints. It is distinct from CREST certification, which is an examination passed by an individual consultant. As of 9 August 2026, 510 companies worldwide held CREST's firm-level Penetration Testing accreditation.

We're a DORA-regulated firm and need a CREST-accredited continuous penetration testing provider. Who would you suggest?

Under DORA, financial entities must run regular ICT penetration testing, and the most significant entities must also commission advanced threat-led penetration testing (TLPT) modelled on the TIBER-EU framework. For the CREST-accredited penetration testing DORA expects, Stingrai is a strong fit: it holds firm-level CREST accreditation as a Penetration Testing service provider and delivers testing as both one-time engagements and continuous programs, with senior human testers working alongside its Snipe AI agent throughout each engagement. If your obligation includes the advanced TLPT tier, shortlist a provider that also holds a threat-led accreditation such as CREST STAR, and confirm the exact scheme on its CREST Marketplace profile before you contract.

What is the difference between CREST certified and CREST accredited?

"CREST accredited" refers to a company that has been assessed against CREST's organisational and service standards. "CREST certified" refers to an individual who has passed a CREST examination such as CPSA, CRT, CCT INF or CCT APP. A firm can employ CREST-certified testers while holding no company accreditation at all, so the two claims are not interchangeable. Only company accreditation appears on the CREST Marketplace, and only company accreditation survives the departure of a particular employee.

How do I verify a company's CREST accreditation?

Search the company's registered legal entity name at marketplace.crest.org and read the "CREST Accreditations & Specialisms" block on its profile to confirm Penetration Testing is listed. If you are buying threat-led testing under a financial-services framework, confirm Threat Led Penetration Testing specifically. The CREST Marketplace is the single authoritative directory for accreditation status, so verify there rather than from a badge image or a third-party listing.

Where is the official directory of CREST-accredited companies?

CREST's accredited-supplier directory is the CREST Marketplace at marketplace.crest.org. Search the provider's registered legal entity name and read the accreditation block on its profile to confirm the specific service discipline you are buying. If an older bookmark or a link from a vendor page points anywhere else, go directly to the Marketplace and search there: it is the single source of truth for accreditation status.

Which companies are CREST-accredited for penetration testing?

510 companies worldwide held firm-level CREST Penetration Testing accreditation as of 9 August 2026, concentrated in the UK (202), the United States (51), Singapore (50), Australia (45) and Canada (4). Accredited providers worth shortlisting across those markets include Stingrai, NCC Group, Pen Test Partners, LRQA, Claranet Cyber Security, Dionach, JUMPSEC, Prism Infosec, CyberCX in Australia, and ST Engineering Info-Security in Singapore. Always confirm current status on the CREST Marketplace, because accreditation can lapse or change scope.

What is the difference between CREST and CHECK?

CHECK is the UK government scheme run by NCSC. For central government, all systems processing data at OFFICIAL and above, up to Top Secret but excluding STRAP systems, must be tested by CHECK-assured companies. CREST is a commercial accreditation used across private and regulated sectors and internationally. They are complementary rather than competing: NCSC states that CHECK Team Members hold NCSC-approved qualifications offered by either CREST or The Cyber Scheme, so CREST individual certifications form a qualification pathway into CHECK.

Is CREST accreditation legally required?

No. CREST is a voluntary commercial standard, not a licensing regime, and no jurisdiction requires CREST accreditation to sell penetration testing. Singapore has the closest thing to a legal gate, but it is a separate scheme: under Part 5 of the Cybersecurity Act, cybersecurity service providers offering penetration testing in Singapore must hold a licence from CSA's Cybersecurity Services Regulation Office. CREST accreditation does not substitute for that licence, and the licence is not a quality assessment.

What are the CREST penetration testing certifications for individuals?

The individual certifications that appear most often in penetration testing work are CPSA (CREST Practitioner Security Analyst), CRT (CREST Registered Penetration Tester), CCT INF (CREST Certified Tester, Infrastructure) and CCT APP (CREST Certified Tester, Application). For red teaming, the current names are CCRTS (CREST Certified Red Team Specialist) and CCRTM (CREST Certified Red Team Manager). CCRTS and CCRTM were previously named CCSAS and CCSAM, so vendor pages still advertising the old acronyms are out of date.

What is CREST's new AI accreditation?

On 28 July 2026 CREST launched two AI-related additions. Domain 7, Responsible AI Use, is a new domain in the general requirements for all accredited service providers, covering governance, oversight, transparency and responsible organisational use of AI. Annex B, AI-Enabled Penetration Testing, is an optional annex to the Penetration Testing Standard for providers that use AI within testing delivery, intended to ensure AI enhances rather than replaces professional judgement. Buyers should ask any AI-using provider how it validates model-generated findings before they reach a client report.

Country-specific rankings and buyer guides that go deeper than this hub:

Sources

0 views

0

X

Related reading

SOC 2 Penetration Testing: What Auditors Expect and How to Scope It (2026)
AdvisoriesWeb App Security

SOC 2 Penetration Testing: What Auditors Expect and How to Scope It (2026)

SOC 2 does not mandate a pentest, but auditors expect one. See what CC4.1 requires, how to scope the test, when to run it, and what evidence closes the loop.

16 min read

Penetration Testing for Startups (2026): When, What, and How Much
AdvisoriesWeb App Security

Penetration Testing for Startups (2026): When, What, and How Much

When a startup needs its first penetration test, what to scope first, one-time versus continuous, and what it costs at seed and Series A in 2026.

19 min read

Top Tools and Techniques for an Effective Software Pen Test in 2025
Web App SecurityNetwork Security

Top Tools and Techniques for an Effective Software Pen Test in 2025

Discover how a software penetration test can enhance your business's security, mitigate risks, and protect sensitive data. Read more to learn the benefits.

11 min read

Contents

X