main logo icon

Published on

August 9, 2026

|

17 min read

CREST-Accredited Penetration Testing Companies (2026): How to Verify and Who to Shortlist

Exactly 510 companies worldwide hold CREST's firm-level Penetration Testing accreditation. How to verify a provider on the CREST Marketplace, the traps that mislead buyers, where CREST matters by market, and which accredited firms to shortlist.

Arafat Afzalzada

Arafat Afzalzada

Founder

Advisories

Summarize with AI

ChatGPTPerplexityGeminiGrokClaude

TL;DR

Exactly 510 companies worldwide held CREST's firm-level Penetration Testing accreditation when we queried the CREST Marketplace on 9 August 2026. "CREST accredited" and "CREST certified" are not the same claim. Accreditation is assessed at company level against CREST's standards. Certification is an exam passed by an individual consultant. A firm can staff a project entirely with CREST-certified individuals and still hold no company accreditation at all. Only the firm-level entry on the CREST Marketplace proves the company itself was assessed. Verify every claim at marketplace.crest.org. The old member directory at crest-approved.org/member_companies/ no longer works: the index now redirects to the CREST homepage and deep links bounce to the Marketplace. Every supplier profile on the CREST Marketplace displays the same registered address in Coventry, UK. That is CREST's own address, not the supplier's. Never use it for vendor due diligence. CREST's accreditation footprint is concentrated: the UK holds 202 of the 510 firm-level Penetration Testing accreditations, ahead of the United States (51), Singapore (50), Australia (45) and Canada (4). On 28 July 2026 CREST added Domain 7, Responsible AI Use, to its general requirements for all accredited providers, plus an optional Annex B for AI-enabled penetration testing. CREST is a commercial quality signal, not a licence. Singapore is the exception: a CSA licence is a legal requirement there under Part 5 of the Cybersecurity Act.

Exactly 510 companies worldwide held CREST's firm-level Penetration Testing accreditation when we queried the CREST Marketplace on 9 August 2026. That number matters because "CREST accredited" is one of the most repeated and least verified claims in security procurement, and because the gap between the firms that hold it and the firms that imply it is wide.

The claim is worth checking for a specific reason. CREST assesses a company, not just the people it employs. A provider can hire five consultants who each passed a CREST exam, put "CREST certified" on the website, and hold no company accreditation whatsoever. Both statements are technically true. Only one of them tells you the firm's methodology, data handling and governance were independently examined.

This guide covers what CREST accreditation actually assesses, how to verify any provider's claim in about ninety seconds, the two traps on the CREST Marketplace that quietly mislead buyers doing vendor due diligence, where CREST carries procurement weight by market, and which accredited firms are worth shortlisting.

At a glance

Question

Short answer

How many firms hold CREST Penetration Testing accreditation?

510 globally, per the CREST Marketplace, 9 August 2026

Where are they concentrated?

UK 202, USA 51, Singapore 50, Australia 45, Canada 4

Is "CREST certified" the same as "CREST accredited"?

No. Certification is an individual exam. Accreditation is a company assessment

Where do I verify a claim?

marketplace.crest.org only. The old directory is dead

Is CREST legally required?

No, it is a commercial standard. Singapore's CSA licence is the separate legal requirement

What changed in 2026?

Domain 7 (Responsible AI Use) and Annex B (AI-enabled penetration testing), effective 28 July 2026

What CREST accreditation actually is

CREST is a not-for-profit accreditation and certification body for the technical security industry. It runs two entirely separate schemes that buyers routinely collapse into one phrase, and the distinction is the single most useful thing in this article.

Company-level accreditation: the procurement-grade signal

CREST accredits organisations against published standards. The assessment looks past the skills of any individual tester and into how the business runs: how engagements are scoped and governed, what methodology is applied and whether it is actually followed, how client data is classified, transported, stored and destroyed, how findings are reported and quality-assured, and how the company handles complaints and incidents of its own.

CREST's organisational standard is the CREST Accreditation Standard, Company General Requirements, which every accredited provider must meet regardless of service. On top of that sit service-specific standards. CREST currently publishes standards across nine service areas: Cyber Threat Intelligence, Incident Exercising, Incident Response, Penetration Testing, Security Architecture, Security Operations, Threat Intelligence for Simulated Attacks, Threat-led Penetration Testing, and Vulnerability Assessment.

This is why company accreditation is the signal that belongs in a procurement scorecard. It is an assurance about the supplier as an organisation, and it survives staff turnover. An individual certification walks out of the building when its holder resigns.

Individual certifications: the practitioner signal

CREST separately certifies people through examinations at three experience tiers: Practitioner, Registered and Certified. The ones that appear in penetration testing statements of work are:

Certification

Acronym

Tier

CREST Practitioner Security Analyst

CPSA

Practitioner

CREST Registered Penetration Tester

CRT

Registered

CREST Certified Tester, Infrastructure

CCT INF

Certified

CREST Certified Tester, Application

CCT APP

Certified

CREST Certified Red Team Specialist

CCRTS

Certified

CREST Certified Red Team Manager

CCRTM

Certified

Two of those names changed, and stale vendor pages have not caught up. CCRTS was previously the CREST Certified Simulated Attack Specialist (CCSAS), and CCRTM was previously the CREST Certified Simulated Attack Manager (CCSAM). CREST states on its own certification page that the exam "was previously known as the CREST Certified Simulated Attack Specialist (CCSAS) but has been updated in-line with industry terminology and lexicons." If a provider's website still advertises CCSAS or CCSAM in 2026, that page has not been reviewed in a while, which is itself a small piece of information about the firm.

CCRTS carries weight beyond its name: CREST notes it is "a critical requirement by the Bank of England as part of the CBEST accreditation process."

The difference that costs buyers money

Company accreditation

Individual certification

Assessed subject

The firm

A person

What is examined

Governance, methodology, data handling, reporting, quality assurance

Technical knowledge, in an exam

How it is earned

Documented assessment against CREST standards

Passing a CREST examination

Survives staff turnover?

Yes

No, it leaves with the individual

Where it is verifiable

CREST Marketplace supplier profile

The individual's own record, not the firm's

Typical marketing phrase

"CREST accredited", "CREST member company"

"CREST certified consultants", "our team is CREST qualified"

A firm with accreditation almost always employs certified individuals. The reverse is not true at all, and it is where most misleading claims live.

How to verify a CREST claim in four steps

Crest Verification Traps 2026

Verification is genuinely fast once you know where to look. It takes about ninety seconds.

Step 1: Go to the CREST Marketplace. The only authoritative directory is marketplace.crest.org. Do not verify from the provider's own website, a reseller listing, or a badge image, all of which are self-asserted.

Step 2: Search for the exact legal entity, not the brand. Marketplace profiles use registered company names. Searching "Dionach" resolves to Dionach Ltd, "JUMPSEC" to JUMPSEC Ltd, "Prism Infosec" to Prism Infosec Ltd, and "CyberCX" to CyberCX Pty Ltd. If a brand you were quoted does not resolve to any entity, ask the provider which legal entity holds the accreditation. Groups sometimes hold accreditation in one subsidiary and sell through another.

Step 3: Read the "CREST Accreditations & Specialisms" block. This is the part that answers your actual question. A profile lists precisely which services the company is accredited for. Being on the Marketplace is not the same as being accredited for penetration testing. A supplier accredited only for Security Operations Centre or Vulnerability Assessment work is a real CREST member and still not accredited for the thing you are buying. Look for Penetration Testing by name.

Step 4: Match the accreditation to your scope of work. If you are buying threat-led red teaming under a financial-services framework, "Penetration Testing" alone is not the relevant accreditation. Look for Threat Led Penetration Testing, which CREST profiles annotate as "(Formerly STAR ILPT)", or the TLPT-FS variant. Application-focused buyers should look for Application Security Testing, annotated "(Formerly OVS)".

CREST migrated its member directory out of its main website and into a separate Marketplace domain. Old links do not survive gracefully, and a surprising number of vendor pages, procurement templates and third-party "CREST companies" listicles still point at the retired paths.

We tested the legacy URLs on 9 August 2026:

Legacy URL

What happens now

crest-approved.org/member_companies/

Redirects to the CREST homepage. The directory index is gone

crest-approved.org/member_companies/<company>/

Redirects to marketplace.crest.org/supplier/<company>/

crest-approved.org/membership/member-companies/

404 Not Found

The deep-link redirect still works, which is the dangerous part: it means some old links resolve and others silently dump you on a homepage with no directory in sight. If a supplier sends you a "proof" link on the crest-approved.org/member_companies/ path, it is a link they have not checked recently. Ask for the marketplace.crest.org/supplier/ URL instead.

Trap 2: the address on the profile is not the supplier's address

This one is genuinely misleading and we have not seen it documented anywhere else.

Every supplier profile on the CREST Marketplace displays the same registered address: Seven Stars House, 1 Wheler Road, Coventry, West Midlands, CV3 4LB, UK. That is CREST's own registered address, not the supplier's.

We confirmed it across every profile we checked, and the result holds regardless of where the company is actually based. An Australian firm shows a Coventry address. A Canadian firm shows a Coventry address. A UK firm shows a Coventry address that is still not its own.

Supplier

Actual head office country

Address shown on CREST profile

NCC Group

United Kingdom

Seven Stars House, Coventry, UK

CyberCX Pty Ltd

Australia

Seven Stars House, Coventry, UK

Stingrai Inc

Canada

Seven Stars House, Coventry, UK

Claranet Cyber Security

United Kingdom

Seven Stars House, Coventry, UK

Dionach Ltd

United Kingdom

Seven Stars House, Coventry, UK

If you are running vendor due diligence, supplier onboarding, or a data-residency assessment, and you copy the address from a CREST profile into your vendor record, you have just recorded the accreditation body's office as your supplier's location. Use the profile's head office location field and the "Visit Website" link to establish where a company actually operates, and confirm the registered entity through the relevant companies registry.

Trap 3: "CREST accredited" that means "we employ certified people"

The most common soft misrepresentation is a website that says "CREST accredited penetration testing" when what the firm means is that some of its testers hold CREST exams. Sometimes it is deliberate. Often it is a marketing team that did not know the two schemes were different.

You do not need to litigate the intent. Search the firm on the Marketplace. If the company is not there, the company is not accredited, whatever its consultants hold. If it is there, check that Penetration Testing appears in its accreditation list. That is the whole test.

Where CREST carries weight, market by market

CREST's footprint is far more concentrated than its global profile suggests. These are firm-level Penetration Testing accreditations by head office country, from the CREST Marketplace on 9 August 2026.

Crest Accreditation By Country 2026

Head office country

Firms with CREST Penetration Testing accreditation

United Kingdom

202

United States

51

Singapore

50

Australia

45

Canada

4

Global total

510

Two things stand out. The UK holds roughly 40 percent of all firm-level penetration testing accreditations worldwide. And Singapore, a country of about six million people, has essentially as many accredited firms as the United States.

United Kingdom: the commercial standard, distinct from CHECK

In the UK, CREST is the default commercial benchmark, and it is routinely named in private-sector and regulated-sector tenders as a supplier quality bar.

CREST is not the same as NCSC's CHECK scheme, and the two are not interchangeable. CHECK is the UK government scheme. NCSC's guidance is that for central government, "all systems processing data protectively marked OFFICIAL and above (up to Top Secret but excluding STRAP systems)" must use CHECK-assured companies. For the wider public sector, NCSC strongly recommends CHECK providers.

The relationship between them is more interesting than a rivalry. NCSC states that "CHECK Team Members hold one of the NCSC-approved qualifications offered by either CREST or The Cyber Scheme." CREST individual certifications are a qualification pathway into CHECK, not a competitor to it.

The practical rule: if you are testing UK government systems at OFFICIAL or above, you need a CHECK provider. For commercial systems, CREST company accreditation is the relevant signal. NCSC's directory listed 55 CHECK providers as of August 2026, a much smaller pool than the 202 UK firms with CREST penetration testing accreditation.

One correction worth making, because it circulates widely: some vendor blogs claim Procurement Policy Note PPN 014 made CREST mandatory for UK government penetration testing suppliers. It did not. PPN 014 is a Cyber Essentials policy note and does not mention CREST or penetration testing at all. Do not build a procurement position on that claim.

Australia: a genuine procurement filter, separate from IRAP

Australia is the fourth-largest CREST market by accredited firms, and CREST accreditation shows up frequently as a prerequisite in Australian enterprise and public-sector procurement.

CREST is distinct from IRAP, the Infosec Registered Assessors Program. IRAP assessors are endorsed by the Australian Signals Directorate to assess ICT systems against the Information Security Manual, for systems handling government data at OFFICIAL, PROTECTED, SECRET or TOP SECRET. The two are complementary rather than substitutable: a penetration test attempts to exploit vulnerabilities to establish real impact, while an IRAP assessment evaluates the full set of applicable ISM controls, only some of which a penetration test can validate. Buyers selling into Australian government commonly need both, for different reasons.

Singapore: CREST is the quality signal, the CSA licence is the law

Singapore is the market where buyers most often get the hierarchy wrong, so this one is worth stating precisely.

In Singapore, providing penetration testing services requires a licence. Under Part 5 of the Cybersecurity Act, Singapore's official business licensing portal states that "all cybersecurity service providers providing licensable cybersecurity services as set out in the Second Schedule are required to obtain a cybersecurity service provider's licence regardless of whether they are companies or individuals," including freelancers, sole proprietorships, third-party providers supporting other providers, and resellers. The licence is administered by CSA's Cybersecurity Services Regulation Office.

CREST accreditation does not substitute for that licence, and the licence is not a quality assessment. They answer different questions: the licence asks whether the provider is legally permitted to sell penetration testing in Singapore, and CREST accreditation asks whether the provider's methodology and governance were independently assessed. Serious providers in Singapore hold both.

CREST's presence in the market is long-standing. CSA announced the CREST Singapore Chapter in 2016 as CREST's first Asian chapter, developed with CSA, AISP, MAS, ABS and IDA, with CSA supporting an examination facility and funding accreditation for smaller providers. That early state backing is a large part of why Singapore now has 50 accredited firms.

United States and Canada: growing, and still thin

The US has 51 accredited firms, a small number for the size of its security market, because US procurement leans on SOC 2, FedRAMP and PCI DSS rather than CREST. CREST recognition is growing there, mostly driven by firms selling into UK, Australian and Singaporean buyers.

Canada is the outlier: just four companies headquartered in Canada hold firm-level CREST Penetration Testing accreditation. For Canadian buyers who have written CREST into a procurement standard, the domestic supplier pool is genuinely that small, and most will need to consider accredited firms headquartered elsewhere that serve the Canadian market.

What changed in 2026: CREST's AI accreditation

On 28 July 2026, CREST launched the first accredited standards for AI use in cybersecurity services. In CREST's words: "From today, 28 July 2026, cybersecurity service providers will be able to apply to have their use of AI within their service provision independently assured by CREST."

There are two distinct pieces, and the difference matters when you read a provider's claim.

Domain 7, Responsible AI Use, is a new domain in the general requirements CREST sets for all accredited service providers. It "covers the governance, oversight, transparency and responsible organisational use of AI by the service provider." It applies as part of the baseline organisational standard wherever AI use could affect client confidentiality, service delivery, client-facing outputs, legal obligations or professional judgement.

Annex B, AI-Enabled Penetration Testing, is an optional annex to the Penetration Testing Standard for providers that use AI within testing itself. CREST describes it as helping "ensure AI enhances professional judgement while maintaining the quality, integrity and trust expected of CREST-accredited services."

The buyer takeaway is straightforward. Every provider you engage is now expected to be able to explain how it governs AI use. Providers that actively use AI in delivery can go further and have that use independently assured. Given that IBM's Cost of a Data Breach Report 2026 found one in four malicious breaches are now AI-enabled, at an average cost of USD 6 million, the assurance question on both sides of the engagement is not academic. Ask any provider using AI in testing whether they intend to pursue Annex B, and how they currently prevent model-generated findings from reaching a client report unvalidated.

CREST-accredited providers worth shortlisting in 2026

Every firm below was verified on the CREST Marketplace on 9 August 2026 and holds Penetration Testing in its firm-level accreditation list. This is a shortlist across markets rather than a single-country ranking. For country-specific depth, the regional guides linked at the end go further.

1. Stingrai

Head office: Toronto, Canada, with a London, UK office. Marketplace entry: Stingrai Inc. CREST accreditation: Penetration Testing.

Stingrai Inc holds firm-level CREST accreditation as a Penetration Testing service provider, which places it among only four companies headquartered in Canada with that accreditation. Founded in 2021, the firm operates from Toronto and London and works across North America and Europe.

The differentiator is the delivery model rather than the badge alone. Stingrai pairs senior human testers with Snipe, its autonomous AI agent for web application penetration testing. Snipe is custom-trained on more than 6,000 HackerOne Hacktivity disclosure reports plus skills distilled from years of Stingrai's own pentester methodology, and it is built specifically to hunt the classes generic AI scanners miss: IDOR, business logic flaws, and broken authorization and access control. It performs black-box dynamic testing and white-box source code review, generates AutoFix pull requests, and can run as a PR-gating check to block vulnerable code from being merged.

That combination is exactly the territory CREST's new Domain 7 and Annex B were written to govern, and it is a useful reference point for how the AI question should be answered by a provider.

The team holds OSCE3, OSCP, OSWE, OSED, OSEP, CREST CRT, CISSP, CRTO, GCPN, CRTE and eWPTX, has published 18 CVEs, presents research at DEFCON and BSIDES, and holds a 5.0 out of 5.0 rating across 19 Clutch reviews. Stingrai's penetration testing supports client compliance programs for SOC 2, ISO 27001, HIPAA, PCI DSS 4.0, NIST SP 800-53 and 800-171, DORA and NIS2. Current packages and pricing are published at stingrai.io/pricing.

Best for: buyers who want firm-level CREST accreditation plus genuinely AI-augmented delivery, and North American or UK organisations that need both.

2. NCC Group

Head office: United Kingdom. Marketplace entry: NCC Group. CREST accreditations: Incident Exercising, Incident Response, Penetration Testing, Security Operations Centre, Vulnerability Assessment, and four more including Threat Led Penetration Testing (TLPT-FS) and Threat Intelligence for Simulated Attacks.

The broadest CREST accreditation footprint on this list and one of the longest-tenured members, at 19 years. NCC Group serves Asia Pacific, Europe, the Middle East and North America.

Best for: large enterprises needing a single accredited supplier across testing, threat intelligence, incident response and threat-led red teaming.

3. Pen Test Partners

Head office: United Kingdom. Marketplace entry: Pen Test Partners. CREST accreditations: Incident Response, Penetration Testing, Vulnerability Assessment, Application Security Testing (Formerly OVS), Mobile Application Security Testing (Formerly OVS), and two more.

Sixteen years of CREST membership, 100 to 499 employees, serving Europe and North America. Notable for holding both the application and mobile application security testing accreditations alongside core penetration testing, and for a strong public research output in transport, maritime and IoT.

Best for: application and mobile-heavy scopes, and buyers who value published technical research as evidence of capability.

4. LRQA

Head office: United Kingdom. Marketplace entry: LRQA. CREST accreditations: Incident Exercising, Incident Response, Penetration Testing, Security Operations Centre, Vulnerability Assessment, and six more.

LRQA absorbed Nettitude, and the CREST accreditation now sits under the LRQA entity. Searching the Marketplace for "Nettitude" returns nothing, which is a good illustration of why you verify the legal entity rather than the brand you remember. Seventeen years of membership, covering Asia Pacific, Europe and Latin America.

Best for: buyers who want penetration testing alongside broader assurance and certification services from one group.

5. Claranet Cyber Security

Head office: United Kingdom. Marketplace entry: Claranet Cyber Security. CREST accreditations: Penetration Testing, Security Operations Centre, Vulnerability Assessment, Application Security Testing (Formerly OVS), and one more.

Nineteen years of CREST membership and 500 to 999 employees, focused on Europe. Pairs testing with managed security operations.

Best for: European organisations wanting accredited testing and a managed SOC from the same provider.

6. Dionach

Head office: United Kingdom. Marketplace entry: Dionach Ltd. CREST accreditations: Incident Response, Penetration Testing, Vulnerability Assessment, Threat Led Penetration Testing (Formerly STAR ILPT), TLPT-FS Threat Led Penetration Testing.

Sixteen years of membership, 50 to 99 employees, serving Europe and North America. Holds both threat-led penetration testing accreditations, which is a meaningful marker for regulated financial services work.

Best for: mid-market buyers needing threat-led testing under a financial services framework without going to a large consultancy.

7. JUMPSEC

Head office: United Kingdom. Marketplace entry: JUMPSEC Ltd. CREST accreditations: Incident Exercising, Incident Response, Penetration Testing, Security Operations Centre, Vulnerability Assessment, and one more.

Fourteen years of membership with 10 to 49 employees, focused on Europe. A broad accreditation set for a boutique, including incident exercising.

Best for: UK organisations wanting a small, senior team with accreditation breadth well beyond its headcount.

8. Prism Infosec

Head office: United Kingdom. Marketplace entry: Prism Infosec Ltd. CREST accreditations: Incident Exercising, Incident Response, Penetration Testing, Vulnerability Assessment, Threat Led Penetration Testing (Formerly STAR ILPT), and one more.

Ten years of membership, 10 to 49 employees, Europe-focused, and independent. Holds threat-led penetration testing accreditation.

Best for: buyers who want an independent UK consultancy with threat-led capability and no managed-services upsell.

9. CyberCX

Head office: Australia. Marketplace entry: CyberCX Pty Ltd. CREST accreditations: Incident Response, Penetration Testing, Security Operations Centre.

The largest accredited provider headquartered in Australia, with 1,000 to 4,999 employees and six years of CREST membership, serving Asia Pacific, Europe and North America.

Best for: Australian and New Zealand enterprise and public-sector buyers needing scale alongside accreditation.

10. ST Engineering Info-Security

Head office: Singapore. Marketplace entry: ST Engineering Info-Security Pte Ltd. CREST accreditation: Penetration Testing.

Part of Singapore's ST Engineering group. A representative example of the accredited Singapore cohort, where CREST accreditation typically sits alongside the mandatory CSA licence.

Best for: Singapore buyers with government-linked or critical information infrastructure requirements.

How to use accreditation without over-relying on it

CREST accreditation tells you a company was assessed. It does not tell you the five people assigned to your engagement are the right five people. Treat it as a filter, then test what it does not cover.

  • Confirm accreditation covers your scope. Penetration Testing, Threat Led Penetration Testing and Application Security Testing are separate accreditations. Buy the one that matches your statement of work.

  • Ask who is actually testing. Request the named team, their tier of CREST certification, and whether the people who sold you the engagement will be on it.

  • Ask for a redacted sample report. Accreditation covers reporting standards. A sample tells you whether the output will be useful to your engineers.

  • Ask about retesting. Whether remediation verification is included, and for how long after delivery, varies enormously and rarely appears in the headline price.

  • Ask the 2026 AI question. How does the provider use AI in delivery, what stops an unvalidated model finding reaching your report, and are they pursuing Annex B?

  • Verify the entity, not the brand. Accreditation sits with a legal entity. Make sure it is the entity on your contract.

For a broader view of how testing is scoped and priced, our PTaaS overview covers continuous testing models, and Stingrai pricing sets out current packages.

Frequently Asked Questions

What is CREST accreditation?

CREST accreditation is a company-level assessment of a cybersecurity service provider against CREST's published standards. It examines how the organisation governs engagements, applies and documents methodology, handles and destroys client data, quality-assures reports, and manages complaints. It is distinct from CREST certification, which is an examination passed by an individual consultant. As of 9 August 2026, 510 companies worldwide held CREST's firm-level Penetration Testing accreditation.

What is the difference between CREST certified and CREST accredited?

"CREST accredited" refers to a company that has been assessed against CREST's organisational and service standards. "CREST certified" refers to an individual who has passed a CREST examination such as CPSA, CRT, CCT INF or CCT APP. A firm can employ CREST-certified testers while holding no company accreditation at all, so the two claims are not interchangeable. Only company accreditation appears on the CREST Marketplace, and only company accreditation survives the departure of a particular employee.

How do I verify a company's CREST accreditation?

Search the company's registered legal entity name at marketplace.crest.org and read the "CREST Accreditations & Specialisms" block on its profile to confirm Penetration Testing is listed. Two cautions apply. The legacy directory at crest-approved.org/member_companies/ no longer works, with the index redirecting to CREST's homepage. And every Marketplace supplier profile displays CREST's own registered address in Coventry, UK, rather than the supplier's address, so never use that field for vendor due diligence.

Which companies are CREST-accredited for penetration testing?

510 companies worldwide held firm-level CREST Penetration Testing accreditation as of 9 August 2026, concentrated in the UK (202), the United States (51), Singapore (50), Australia (45) and Canada (4). Accredited providers worth shortlisting across those markets include Stingrai, NCC Group, Pen Test Partners, LRQA, Claranet Cyber Security, Dionach, JUMPSEC, Prism Infosec, CyberCX in Australia, and ST Engineering Info-Security in Singapore. Always confirm current status on the CREST Marketplace, because accreditation can lapse or change scope.

What is the difference between CREST and CHECK?

CHECK is the UK government scheme run by NCSC. For central government, all systems processing data at OFFICIAL and above, up to Top Secret but excluding STRAP systems, must be tested by CHECK-assured companies. CREST is a commercial accreditation used across private and regulated sectors and internationally. They are complementary rather than competing: NCSC states that CHECK Team Members hold NCSC-approved qualifications offered by either CREST or The Cyber Scheme, so CREST individual certifications form a qualification pathway into CHECK.

Is CREST accreditation legally required?

No. CREST is a voluntary commercial standard, not a licensing regime, and no jurisdiction requires CREST accreditation to sell penetration testing. Singapore has the closest thing to a legal gate, but it is a separate scheme: under Part 5 of the Cybersecurity Act, cybersecurity service providers offering penetration testing in Singapore must hold a licence from CSA's Cybersecurity Services Regulation Office. CREST accreditation does not substitute for that licence, and the licence is not a quality assessment.

What are the CREST penetration testing certifications for individuals?

The individual certifications that appear most often in penetration testing work are CPSA (CREST Practitioner Security Analyst), CRT (CREST Registered Penetration Tester), CCT INF (CREST Certified Tester, Infrastructure) and CCT APP (CREST Certified Tester, Application). For red teaming, the current names are CCRTS (CREST Certified Red Team Specialist) and CCRTM (CREST Certified Red Team Manager). CCRTS and CCRTM were previously named CCSAS and CCSAM, so vendor pages still advertising the old acronyms are out of date.

What is CREST's new AI accreditation?

On 28 July 2026 CREST launched two AI-related additions. Domain 7, Responsible AI Use, is a new domain in the general requirements for all accredited service providers, covering governance, oversight, transparency and responsible organisational use of AI. Annex B, AI-Enabled Penetration Testing, is an optional annex to the Penetration Testing Standard for providers that use AI within testing delivery, intended to ensure AI enhances rather than replaces professional judgement. Buyers should ask any AI-using provider how it validates model-generated findings before they reach a client report.

Country-specific rankings and buyer guides that go deeper than this hub:

Sources

0 views

0

X

Related reading

Top Tools and Techniques for an Effective Software Pen Test in 2025
Web App SecurityNetwork Security

Top Tools and Techniques for an Effective Software Pen Test in 2025

Discover how a software penetration test can enhance your business's security, mitigate risks, and protect sensitive data. Read more to learn the benefits.

The State of Cybersecurity: Key Statistics and Trends
Advisories

The State of Cybersecurity: Key Statistics and Trends

Explore evolving cyber threats, ransomware, phishing, malware and discover key statistics, data breaches, and trends from 2019-2024’s digital era.

10 minutes min read

Supabase: Powerful, but One Misconfiguration Away From Disaster
Network SecurityWeb App Security

Supabase: Powerful, but One Misconfiguration Away From Disaster

The Supabase anon key is safe to expose only with Row Level Security enabled. See what service_role bypasses and the 2026 publishable key deadline.

11 min read

Contents

X