Back to Articles

CREST vs Standard Penetration Testing: Which Does Your Business Need?

CREST vs Standard Penetration Testing: Which Does Your Business Need?

CREST penetration testing is not a different kind of hacking. It is the same technical work wrapped in an independently audited assurance layer — a layer that governs who is allowed to hold the keyboard, what methodology they must follow, how findings are graded, how your data is handled afterwards, and what happens when the engagement goes wrong. A “standard” pen test from a competent but non-accredited provider can produce an equally sharp technical result. What it cannot do is prove that to a third party who was not in the room.

That distinction is the whole decision. This comparison sets out exactly what CREST accreditation verifies and what it does not, where a non-accredited test is genuinely the sensible purchase, which UK compliance regimes and procurement processes effectively force your hand, and how to weigh the price gap against the assurance you are actually buying. By the end you should be able to look at a quote, work out which tier of assurance it represents, and decide whether you are under-buying, over-buying, or paying exactly the right amount for the audience that will read the report.

What CREST accreditation actually verifies

CREST is a not-for-profit accreditation and certification body for the technical security industry, founded in the UK in 2006 and now operating internationally. It does two separate things that buyers routinely conflate. It accredits companies against an assessed set of business processes, and it certifies individuals through practical, invigilated examinations. A provider can employ CREST-certified testers without the company itself being a CREST member, and a CREST member company can put an uncertified junior on your job unless your contract says otherwise. Understanding which of the two you are being sold is the first defence against a misleading tender response.

Company accreditation is a documentary and evidential assessment. A member company submits its testing methodology, its scoping and rules-of-engagement process, its data classification and destruction policy, its vetting standards for staff, its professional indemnity cover, its complaints and dispute-resolution route, and — the part most buyers do not realise — redacted sample reports that are read and marked by assessors. The company signs the CREST Code of Conduct, which creates an escalation path that exists outside your commercial relationship with the supplier. Membership is renewed on a defined cycle rather than granted once and forgotten, and accreditation can be suspended or withdrawn.

Individual certification is a ladder, and the rung matters. The CPSA (Practitioner Security Analyst) is a written entry-level exam covering assessment methodology. The CRT (Registered Tester) adds a practical, hands-on examination and is the level most working testers hold. The CCT qualifications (Certified Tester, split into Infrastructure and Application variants) are senior, examine the ability to run an engagement end to end, and are the level the NCSC recognises for CHECK team leaders. Above that sit the simulated-attack certifications (CCSAM and CCSAS) used in threat-intelligence-led testing. A quote that says “CREST qualified testers” without naming the certification is telling you almost nothing.

What CREST does not verify is worth stating just as plainly. It does not audit every individual engagement. It does not guarantee that your specific test will find a specific vulnerability. It does not price the work, set a minimum day count, or stop a member company from accepting a scope so thin that the test is close to meaningless. It is a floor on process and competence, not a ceiling on quality — and there are excellent non-accredited testers in the UK who would embarrass some accredited teams on pure technical depth.

Pro Tip

Ask for two things in writing before you sign: the specific CREST certification held by the named lead tester on your engagement, and confirmation that the company accreditation covers the discipline you are buying. CREST accredits separate services — penetration testing, OVS application verification, red teaming, incident response, SOC — and membership in one does not imply assessment in another.

Where the assurance gap actually shows up

If you strip away the marketing, the practical differences between an accredited and a non-accredited engagement cluster into a handful of areas. The chart below shows how consistently each area is covered across the two tiers, based on the patterns Cloudswitched sees when reviewing incoming client reports and tender responses. These are indicative figures describing how often the control is demonstrably present, not published survey data.

Documented, repeatable methodology
96%
Named tester certification evidenced
91%
Formal data handling & destruction policy
88%
Independent complaints escalation route
84%
Report peer-reviewed before release
79%
Consistent CVSS scoring and risk ratings
73%
Retest included or contractually defined
61%

Read that chart carefully, because the interesting number is the last one. Retesting — the second look that confirms your remediation actually worked — is the control most often missing on both sides of the accreditation line. Accreditation raises the floor on process discipline, but it does not automatically buy you the thing that most improves your security posture, which is the closing of the loop. If you take one commercial lesson from this article, make it that you should negotiate retest terms explicitly regardless of which tier you buy.

The second observation is that the gap narrows sharply at the top of the non-accredited market. A boutique of three ex-consultancy testers who left a CREST member company to go independent will usually carry their methodology, their report template and their scoring discipline with them. What they lose is the external audit of those things. For a client who can technically assess the work themselves, that loss may be immaterial. For a client whose insurer, regulator or largest customer will read the report, the loss is the entire point.

CREST vs standard penetration testing: the headline numbers

Before going deeper, here are the four figures that shape most UK buying decisions. Treat them as market-observed bands rather than fixed prices — day rates vary by region, by discipline and by how tightly the scope is drawn.

15–35%
Typical day-rate premium for a CREST member company over a competent non-accredited provider
£950–£1,400
Common UK day-rate band for CREST-accredited penetration testing in 2026
2–4 days
Realistic effort for a small external infrastructure test at either tier
3–6 weeks
Typical lead time to book an accredited team versus 1–3 weeks for a smaller independent

The premium is smaller than most buyers expect, and that surprises people who assume accreditation is a luxury tier. On a three-day external infrastructure test the difference between a £800 and a £1,150 day rate is roughly £1,050 — material to a ten-person business, close to noise for a company with a compliance deadline and a client questionnaire on the desk. The premium becomes significant on large, multi-week programmes, which is exactly where the assurance argument is also strongest. That symmetry is inconvenient but real.

Lead time is the variable buyers underestimate most. Accredited teams are in demand, and the UK market has pronounced seasonality — the run-up to financial year end and the annual renewal cycle for compliance-driven tests both create queues. If a client questionnaire lands on your desk with a 30-day response window and you have not started scoping, the practical choice may be made for you. Our 2026 pricing guide breaks the day-rate mathematics down by test type if you need to build a budget line before you choose a tier.

Scoring the two tiers against what buyers actually need

Assurance is not one thing. It is a bundle of separate guarantees, and different buyers need different items from the bundle. A software business selling to enterprise procurement teams needs evidential weight above all. A manufacturer with an ageing OT network needs technical depth in an unusual environment. A charity with a £4,000 security budget needs a competent pair of eyes and a report its trustees can read. The grids below score each tier honestly on the dimensions that matter, using high, medium and low risk badges to flag where each option leaves you exposed.

Standard (non-accredited) pen test — residual risk
Third-party acceptance of the report High risk
Verified tester competence High risk
Recourse if the engagement goes wrong High risk
Consistency across repeat annual tests Medium risk
Raw technical capability Low risk
Cost and scheduling flexibility Low risk
CREST-accredited pen test — residual risk
Third-party acceptance of the report Low risk
Verified tester competence Low risk
Recourse if the engagement goes wrong Low risk
Consistency across repeat annual tests Low risk
Under-scoping by the buyer Medium risk
Budget strain on a small estate Medium risk
Risks neither tier removes
Findings that are never remediated High risk
Scope that excludes your real crown jewels High risk
Point-in-time drift after the test date High risk
Weak internal patching cadence Medium risk
Untested backup and recovery Medium risk

The third card is the one to sit with. Accreditation solves for the quality of the assessment, not the quality of your response to it. A CREST report with fourteen unremediated high-severity findings sitting in a shared drive twelve months later is worse than a non-accredited report with four findings that were all fixed inside a fortnight — worse commercially, worse technically, and considerably worse if the ICO ever asks what you did with the information you held. Buying the higher tier and then failing to act on it is the most expensive mistake in this whole category.

Note also the “under-scoping by the buyer” risk that sits at medium even on the accredited side. Accredited providers will scope to what you ask them to scope. If your asset inventory is wrong — and for most UK SMEs it is, particularly around forgotten subdomains, legacy VPN endpoints and shadow SaaS — then you will receive a rigorous, well-evidenced, professionally scored assessment of the wrong estate. The discovery work described in our complete guide to penetration testing matters more to your outcome than the badge on the cover page.

CREST accredited pen test vs standard pen test: the direct comparison

Here are the two options side by side on the terms that actually differ. The right-hand card is highlighted not because it is universally correct, but because it is the correct default for any organisation whose report will be read by someone outside the business — and that now describes the majority of UK companies that buy testing at all.

Standard penetration test

Competent provider, no external accreditation

Typical day rate £600–£950
Tester competence Self-declared or vendor-certified
Methodology Provider’s own, unaudited
Report format Varies widely by firm
Complaints route Your contract only
Accepted for PCI DSS Possible, acquirer-dependent
Accepted for NCSC CHECK work No
Lead time 1–3 weeks typical
Best for Internal assurance, first-ever test, tight budgets

CREST-accredited penetration test

Member company, certified named testers

Typical day rate £950–£1,400
Tester competence Examined and independently certified
Methodology Assessed against CREST criteria
Report format Sample reports marked at accreditation
Complaints route CREST Code of Conduct escalation
Accepted for PCI DSS Yes, widely preferred by QSAs
Accepted for NCSC CHECK work Yes, where the firm holds CHECK status
Lead time 3–6 weeks typical
Best for Compliance, supply chain, regulated sectors, insurance

Two clarifications, because both columns are routinely misread. First, “accepted for PCI DSS” does not mean the standard names CREST. It does not. PCI DSS v4.0.1 Requirement 11.4 asks for testing performed by a qualified resource with organisational independence, and leaves the definition of “qualified” to be evidenced. CREST is the most common way UK businesses evidence it, which is a very different statement from a mandate. If your acquirer or QSA accepts another route, that route is valid.

Second, CHECK is a separate scheme entirely. The NCSC runs CHECK for testing public sector and HMG systems, and a CHECK team leader must hold a senior qualification from an NCSC-recognised body — CREST’s CCT is one route, and Tigerscheme’s Senior Security Tester and the Cyber Scheme’s CSTL are others. A company being a CREST member does not make it a CHECK company. If you are bidding for public sector work that requires CHECK, ask for the CHECK green-light status explicitly.

The third alternative that rarely appears in comparison tables is the individual holding a strong offensive certification — OSCP, OSWE, and their equivalents — while working outside any company accreditation. These are hard, practical exams and their holders are frequently excellent testers. They simply sit outside the accreditation framework, which means their competence is evidenced to you but not through a body your customer’s procurement team will recognise. That is a communication problem rather than a capability problem, but on a tender it costs you the same either way.

What an accredited engagement looks like week by week

Process discipline is the thing accreditation is really buying, so it helps to see where that discipline shows up in the calendar. The timeline below describes a typical four-to-six week cycle for a mid-sized external and internal infrastructure test at a UK company of 60–150 staff. A non-accredited engagement often compresses stages two, three and eight, which is precisely where the time goes when things are done properly.

Week 0 — Driver and audience definition
Establish who will read the report: your board, an insurer, a QSA, a prospect’s procurement team, or an NHS commissioner. This single answer determines the tier you need and should be settled before any provider is contacted. Writing it down also protects you later when someone asks why you paid what you paid.
Week 1 — Asset discovery and scope drafting
Enumerate external IP ranges, domains and subdomains, cloud tenancies, VPN and remote-access endpoints, and any third-party hosted applications you are contractually allowed to test. Expect surprises. The average SME estate contains at least one internet-facing service nobody in the room can name.
Week 1–2 — Rules of engagement and authorisation
Sign the authorisation letter, agree testing windows, define out-of-scope systems, set the emergency stop contact on both sides, and confirm cloud provider notification requirements. Accredited providers will not begin without this. Some non-accredited providers will, which is a warning sign rather than a convenience.
Week 2 — Reconnaissance and automated discovery
Passive intelligence gathering, port and service enumeration, certificate transparency mining, and credential-exposure checks against breach corpora. This stage is heavily tooled at every tier; the difference is what the tester does with the output rather than how they generate it.
Week 3 — Manual exploitation and chaining
The genuinely skilled portion. Business-logic flaws, authentication and session weaknesses, privilege escalation, lateral movement, and the chaining of individually low-severity findings into a materially high-severity outcome. Critical findings should be reported to you the same day rather than held for the report.
Week 4 — Reporting and peer review
Findings written up with evidence, reproduction steps, consistent severity scoring and prioritised remediation guidance. Under an accredited process the report is reviewed by a second qualified tester before it leaves the building — a control that catches scoring inconsistency and unsupported claims.
Week 4–5 — Debrief and remediation planning
A working session, not a slide deck. Technical staff walk through each finding, agree owners and target dates, and separate the things that must be fixed this week from the things that belong in next year’s roadmap. Insist that your own engineers attend, not just management.
Week 6–10 — Remediation and retest
Fixes applied, then a targeted retest confirming closure and producing a clean summary letter. This is the artefact that satisfies most client questionnaires and insurers, and the one most often omitted from the original quote. Negotiate it into the contract at the outset, not after the invoice.
Month 12 — Annual cycle and change-driven retest
Annual testing is the compliance minimum in most regimes, but the more useful trigger is significant change: a new internet-facing application, a migration, an acquisition, or a substantial network redesign. Testing to the calendar alone means testing an estate that stopped existing months ago.

Notice how much of that timeline is not testing. Weeks nought to two are governance, and weeks four to ten are communication and verification. Buyers who feel they are “paying for paperwork” are half right — and the paperwork is the part that survives contact with an auditor. If your only requirement is a technical opinion for internal consumption, you can legitimately compress this to a fortnight and pay accordingly.

What each tier costs in practice

The table below sets out the tiers most UK buyers will encounter, with realistic 2026 cost envelopes for a typical small-to-mid engagement. Costs assume UK-delivered work with a named lead tester; offshore delivery undercuts every band shown and brings its own data-residency questions that are worth asking before, not after, your data leaves the country.

Tier What you get Typical day rate Small engagement cost Right for
Automated vulnerability scanning Tool-driven detection of known published flaws, no manual validation, high false-positive rate £50–£300 per month £600–£3,600 per year Continuous hygiene between tests. Not a penetration test and should never be sold as one.
Standard penetration test Manual testing by a competent non-accredited tester, provider’s own methodology and report format £600–£950 £1,800–£3,800 (3–4 days) First-ever test, internal assurance, budget-constrained charities and micro-businesses.
CREST-accredited penetration test Member-company process, certified named testers, peer-reviewed report, Code of Conduct recourse £950–£1,400 £2,850–£5,600 (3–4 days) Compliance evidence, supply-chain questionnaires, cyber insurance, regulated sectors.
CREST OVS application verification Web and mobile application testing assessed against the OWASP verification standards £1,000–£1,500 £5,000–£12,000 (5–8 days) Software vendors, SaaS businesses, anyone whose product is the thing being assessed.
CHECK / threat-intelligence-led testing NCSC CHECK delivery, or STAR / STAR-FS style intelligence-led simulated attack £1,200–£2,000 £25,000–£120,000+ (multi-week) Public sector systems, financial services under regulator-driven frameworks, mature security teams.

The step that catches people out is the third-to-fourth row transition. A business that has bought a £3,000 infrastructure test for three years running, then builds a customer-facing web application, often assumes the next test costs roughly the same. It does not. Application testing is measured in functionality and user roles rather than in hosts, and a moderately complex multi-tenant application with three privilege levels is a five-to-eight day job before anyone has looked at the API. Budget for it as a separate line.

The other cost most buyers forget is their own time. Expect to spend two to five internal days across scoping, providing access, attending the debrief and coordinating remediation, plus whatever engineering effort the findings generate. On a small estate that internal cost is frequently larger than the invoice. Building it into the business case up front makes the conversation with your finance director considerably shorter.

Which UK compliance regimes effectively require CREST

This is where the decision usually gets made for you. Very few UK regimes name CREST in their legal text, but a large and growing share of procurement processes, insurer questionnaires and framework agreements name it in practice. The distinction between “mandated” and “effectively mandated” is one you can argue in a meeting and lose in a tender.

68%
Indicative share of UK enterprise and public-sector security questionnaires reviewed by Cloudswitched that name CREST, CHECK or an equivalent accreditation by name

PCI DSS. Requirement 11.4 of PCI DSS v4.0.1 requires internal and external penetration testing at least annually and after any significant infrastructure or application change, using an industry-accepted methodology and a resource that is qualified and organisationally independent. The standard does not say CREST. It says qualified. In UK practice, QSAs and acquiring banks accept CREST as the cleanest way to evidence “qualified”, and challenging that with a non-accredited provider means your QSA has to form their own judgement about competence. Some will. Many would rather not. If you are in scope for PCI DSS at anything above SAQ-A, budget for the accredited tier and spend your negotiating energy on scope instead.

NHS Data Security and Protection Toolkit. NHS organisations and their suppliers work to the DSPT, which for NHS trusts is now aligned to the NCSC Cyber Assessment Framework. Penetration testing evidence supports several assertions, and NHS procurement frameworks and commissioner assurance processes very commonly specify CREST-accredited or CHECK-delivered testing. If you supply clinical software, patient-facing digital services or hosted infrastructure into the NHS, treat accreditation as a cost of market entry rather than an upgrade.

Public sector and CHECK. For testing HMG and wider public-sector systems, the NCSC CHECK scheme is the relevant route. A CHECK engagement must be led by a team leader holding a senior qualification from an NCSC-recognised body, and delivered by a company holding CHECK status. A non-accredited provider simply cannot deliver this work, so the comparison does not arise.

Financial services. Regulator-driven, intelligence-led testing frameworks sit above ordinary penetration testing. CBEST, operated by the Bank of England, and the equivalent regimes across Europe are threat-intelligence-led simulated attacks delivered by a small pool of accredited providers, with CREST’s STAR and STAR-FS accreditations forming one recognised route. These programmes are scoped in months and hundreds of thousands of pounds, and are irrelevant to the majority of SMEs — but if your firm is in scope, no amount of cost comparison changes the answer.

ISO 27001 and Cyber Essentials. Neither names CREST. ISO 27001:2022 expects technical vulnerability management to be evidenced, and a penetration test is a common way to do it; the certification body will assess your process, not your tester’s badge. Cyber Essentials is a different animal again — the basic level is a verified self-assessment and Cyber Essentials Plus adds a hands-on technical audit by an IASME-appointed certification body. That audit is not a penetration test and does not substitute for one, a confusion we unpick in our step-by-step Cyber Essentials guide.

Cyber insurance and supply chain. The fastest-moving driver of all. Insurers increasingly ask whether testing was performed by an accredited provider, and enterprise procurement teams have standardised on the question because it is easy to score. A supplier questionnaire that asks “is your penetration testing provider CREST accredited?” is a yes/no box. There is no field for “no, but our tester is excellent.”

Assurance coverage by dimension

Another way to frame the decision is to ask how much of each assurance dimension each tier actually delivers. The rows below score a well-run engagement at each tier against the dimensions that appear in real client questionnaires and insurer forms. Percentages are Cloudswitched’s assessment of typical coverage, offered as a planning aid rather than a measurement.

Typical coverage — CREST-accredited engagement

Evidenced tester competence
95%
Methodology consistency year on year
92%
Report acceptance by third parties
90%
Data handling and destruction assurance
88%
Severity scoring reliability
85%
Escalation route independent of supplier
82%
Depth in niche environments (OT, mainframe)
64%
Scheduling flexibility at short notice
48%
Suitability for a sub-£2,500 budget
31%

The bottom three rows are the honest case for the standard tier. Accreditation does not confer specialist depth in unusual environments — industrial control systems, embedded devices, legacy mainframe estates — where the relevant expertise often sits with a handful of independent specialists who have spent fifteen years in that niche. Nor does it help you when a client questionnaire arrives on a Thursday with a two-week deadline. And it plainly does not fit a £2,000 budget without cutting the scope so hard that the assurance value collapses.

If you recognise your organisation in those three rows, the correct move is usually not to buy a thin accredited test. It is to buy a properly scoped standard test now, fix what it finds, and plan the accredited engagement for the next budget cycle when the estate is in better shape and the report will read well rather than badly.

A decision framework: which tier do you actually need?

Score your organisation out of 100 using the weightings below and read the result off the gauge. Award the full weighting where the statement is clearly true, half where it is partly true, and zero where it does not apply: an external party will read the report (25), you are in scope for PCI DSS or NHS DSPT or a public-sector framework (25), you hold or process sensitive personal data at volume (15), you are pursuing or renewing cyber insurance (10), you sell to enterprise customers with security questionnaires (10), you have had a prior incident or a known unremediated finding (10), and your annual security budget exceeds £10,000 (5).

64/100
The threshold above which Cloudswitched recommends CREST-accredited testing

Below 35. A standard penetration test is the right purchase. Spend the difference on remediation, on multi-factor authentication coverage, and on getting your asset inventory accurate. Buying assurance nobody will read is a poor use of a small budget.

35 to 64. The grey zone, and the most common place for a UK SME to sit. Here the sensible pattern is often a hybrid: a standard test in year one to clear the obvious debt, an accredited test in year two once the estate can withstand scrutiny, and accredited testing thereafter. Alternatively, buy accredited testing for the internet-facing perimeter only and standard testing for the internal network, which concentrates the assurance spend where external readers will look.

Above 64. Buy the accredited tier and stop optimising. At this score the report has an external audience with the power to cost you a contract, a policy renewal or a regulatory finding, and the £1,000–£2,000 saved by going non-accredited is dwarfed by the cost of a single failed questionnaire. Direct your negotiation towards scope, retest inclusion and the seniority of the named tester instead of towards the day rate.

Common mistakes when choosing between the two

Most of the value destroyed in this decision is destroyed before the test starts. These are the errors Cloudswitched sees most often when reviewing quotes, reports and questionnaire responses on behalf of clients.

  • Treating “CREST” as a single claim. A supplier can be a CREST member for incident response and not for penetration testing. It can employ one CCT-certified consultant and staff your job with an unqualified junior. Ask which accreditation, which certification, and which named individual will lead your engagement.
  • Buying accreditation instead of scope. An accredited two-day test of six IP addresses tells you almost nothing about a business running forty cloud services. Scope is the primary determinant of value at every tier; accreditation is the secondary one. Spending your whole budget on the badge and none on the days is the most common way to end up with an expensive, useless document.
  • Assuming a vulnerability scan satisfies a pen-test requirement. Automated scanning is a hygiene control, not an assessment. If a questionnaire asks for penetration testing and you submit a scan report, expect the question to come back — and expect the second conversation to be harder than the first.
  • Ignoring retest terms. Roughly two in five quotes we review have no defined retest provision at all. The retest letter is what most third parties actually want to see, because it evidences closure rather than discovery. Negotiate it into the original contract with a stated validity window.
  • Letting the compliance deadline pick the tier. Leaving procurement until six weeks before an audit means accredited teams are booked and you take whoever is free. Start scoping three to four months ahead and the choice stays yours.
  • Confusing Cyber Essentials Plus with a penetration test. They answer different questions. Cyber Essentials Plus verifies that five specific technical controls are correctly implemented on a sample of devices. A penetration test asks what an attacker could achieve against your whole estate. Presenting one where the other was requested reads as either confusion or evasion.
  • Excluding the systems you are most worried about. Removing the production database, the finance system or the legacy application from scope because “it might fall over” is understandable and self-defeating. If it might fall over under a controlled test, it will certainly fall over under an uncontrolled attack. Test it in a maintenance window instead of excluding it.
  • Never re-running the decision. The tier that was right when you were a twelve-person consultancy is rarely right once you are ninety people with an enterprise client list. Revisit the driver-and-audience question annually, at the same time you scope the test itself.
Watch out

Be sceptical of any provider that quotes a fixed price before seeing an asset list, will start without a signed authorisation letter, cannot name the lead tester, or describes an automated scan as a penetration test. These four signals cross the accreditation line in both directions — they appear at non-accredited providers more often, but membership of any scheme does not immunise a supplier against selling you a thin engagement.

A real-world example: when the badge changed the outcome

A 74-person UK software business selling workforce-scheduling software to local authorities and NHS trusts had tested annually for four years with a well-regarded independent consultant. The reports were genuinely good — detailed, well-evidenced, and acted upon. The technical security posture was above average for a company of that size. Then two things happened in the same quarter: a large NHS trust issued a framework tender with a supplier assurance annexe that asked, as a scored question, whether penetration testing was performed by a CREST-accredited or CHECK-approved provider; and their cyber insurance renewal introduced the same question with a premium loading attached to a negative answer.

Neither question was about technical quality. The company’s testing was demonstrably competent. But the tender question carried five per cent of the total technical score, and in a field where the top three bidders were separated by under two points, that was decisive. The company lost the framework place. The insurance loading was smaller in cash terms — a low four-figure annual increase — but it applied every year and compounded the commercial argument.

The remedy took one testing cycle. They moved the annual external and application test to an accredited provider at a day-rate premium of roughly twenty per cent, or about £2,400 a year on their scope, and kept the independent consultant on a separate retainer for architecture review and pre-release testing, where his depth was worth more than any badge. The following year they scored full marks on the assurance annexe. The technical findings, incidentally, were broadly the same as the previous consultant had been reporting — which is precisely the point.

We were not buying better testing. We were buying a form of the same testing that our customers’ procurement teams were allowed to accept. Once we framed it as a sales cost rather than a security cost, the business case took about four minutes.

The lesson generalises in both directions. If nobody outside your business will ever read the report, that twenty per cent premium buys you very little. If the report is a sales asset, it is one of the cheapest sales assets you will ever purchase. The same logic that governs testing spend governs adjacent controls too — the email security posture we describe in our Microsoft 365 email security guide shows up on the same questionnaires, scored the same way.

The 12-point procurement checklist

Whichever tier you choose, work through this list before you sign. It is written so that a non-technical finance or operations lead can run it, because in most UK SMEs that is who actually holds the pen.

  1. Write down who will read the report — board, insurer, QSA, customer procurement, regulator, or nobody outside the business. Everything else follows from this answer.
  2. Identify your binding compliance driver, if any: PCI DSS, NHS DSPT, a public-sector framework, ISO 27001 surveillance, or a specific contractual clause. Quote the clause in your request for quotation.
  3. Produce an accurate asset inventory covering external IPs, domains and subdomains, cloud tenancies, remote-access endpoints and third-party hosted applications. Expect this to take longer than you think.
  4. Decide test types explicitly — external infrastructure, internal infrastructure, web application, mobile application, cloud configuration review, wireless, social engineering. Do not let the provider infer them.
  5. Ask which specific accreditation the company holds and for which discipline, and request the membership reference so you can verify it independently rather than trusting a logo on a PDF.
  6. Ask for the named lead tester and their certification level — CPSA, CRT, CCT INF, CCT APP, or an equivalent from another recognised body. Put the name in the contract with a substitution clause.
  7. Confirm the day count and how it is split between testing and reporting. A quote expressed only in pounds is a quote you cannot compare against another one.
  8. Require same-day notification of critical findings rather than discovery at the report stage. This should be a contractual term, not an assumed courtesy.
  9. Agree retest scope, timing and cost up front, including how long after the original test the retest remains available at the agreed price.
  10. Check data handling: where evidence and findings are stored, in which jurisdiction, for how long, how they are destroyed, and what happens to them if the supplier is acquired.
  11. Verify professional indemnity and cyber liability cover at a level proportionate to your estate, and confirm the authorisation letter names the correct legal entities on both sides.
  12. Plan the remediation capacity before the test. Book engineering time for the fortnight after the debrief. A report nobody has capacity to act on is a liability rather than an asset.
Note

Items 1, 2 and 3 decide the tier. Items 5 and 6 are where accreditation claims are verified or exposed. Items 8, 9 and 12 are where most of the real-world security value is won or lost, and they apply identically whether you buy accredited testing or not. If you only have time for six of the twelve, do those.

CREST vs standard penetration testing at a glance

The summary table below condenses the comparison into the facts most often needed in a board paper or a supplier questionnaire response.

Question Standard penetration test CREST-accredited penetration test
Who verifies competenceThe provider, and youAn independent accreditation body
Company-level assessmentNoneMethodology, policies, sample reports assessed
Individual certificationVendor certifications or noneCPSA, CRT, CCT INF, CCT APP, CCSAM, CCSAS
Typical UK day rate 2026£600–£950£950–£1,400
Premium over the other tierRoughly 15–35%
Typical lead time1–3 weeks3–6 weeks
Named in PCI DSS textNoNo — but widely accepted as evidence of “qualified”
Usable for NCSC CHECK workNoOnly where the firm also holds CHECK status
Typical NHS and public-sector acceptanceCase by case, often rejectedGenerally accepted
Scored positively on insurer questionnairesRarelyCommonly
Independent complaints routeNo — contract onlyYes — Code of Conduct escalation
Peer review of the reportProvider-dependentExpected as part of assessed process
Depth in niche or legacy environmentsSometimes strongerVariable — ask for relevant references
Retest included by defaultOften notOften not — negotiate either way
Best fitFirst test, internal assurance, tight budgetsCompliance, supply chain, insurance, regulated sectors

How Cloudswitched approaches the choice

Cloudswitched does not treat the accreditation question as a product decision made at the point of sale. We start with the driver-and-audience exercise described above, build an accurate asset inventory before anyone quotes a day rate, and set the scope against the compliance clause or questionnaire that triggered the requirement in the first place. Where an accredited engagement is the right answer, we scope it properly and evidence it clearly. Where a standard test would serve you better this year, we will say so — and we will tell you what has to change before the accredited test is worth buying.

Not sure which tier your business actually needs?

Send us the questionnaire, the compliance clause or the tender annexe that prompted the question, and we will tell you what a credible test of your estate involves and which tier it needs to sit in.

Talk to a Penetration Testing Specialist

Frequently Asked Questions

What is CREST penetration testing?

CREST penetration testing is testing delivered by a company accredited by CREST, a not-for-profit body that assesses technical security providers, and typically carried out by testers holding CREST certifications. The accreditation covers the company’s methodology, scoping process, data handling, staff vetting, insurance and complaints procedure, and includes assessors reading redacted sample reports. The individual certifications — CPSA, CRT, CCT Infrastructure and CCT Application among others — are examined qualifications rather than attendance certificates. The practical effect for a buyer is that competence and process are evidenced by an independent third party rather than asserted by the supplier, which matters when someone outside your business has to accept the report.

Is a CREST accredited pen test better than a standard one?

It is more assured, which is not quite the same as better. On raw technical capability, the best non-accredited testers in the UK match or exceed the average accredited engagement, particularly in specialist environments like industrial control systems or legacy mainframe estates. What accreditation guarantees is a floor: a documented methodology, examined testers, peer-reviewed reporting, defined data handling and an escalation route outside your commercial relationship. If your report will be read by an insurer, a QSA, a regulator or a customer’s procurement team, that evidenced floor is the product you are buying. If the report is purely for internal use and you can assess the work yourself, the premium buys you comparatively little.

Does PCI DSS require a CREST penetration test?

No. PCI DSS v4.0.1 Requirement 11.4 requires internal and external penetration testing at least annually and after significant change, performed using an industry-accepted methodology by a resource that is qualified and organisationally independent. The standard does not name CREST or any other scheme. In UK practice, however, CREST accreditation is the most common and least contested way to evidence that the tester was qualified, and many QSAs and acquiring banks expect it. A non-accredited provider can satisfy the requirement if your assessor accepts the evidence of competence you present, but you are relying on their judgement rather than on a recognised credential.

How much more does CREST penetration testing cost in the UK?

Expect a day-rate premium of roughly 15 to 35 per cent. In 2026 terms that typically means £950 to £1,400 a day for accredited work against £600 to £950 for a competent non-accredited provider. On a three-day external infrastructure test the difference is around £1,000 to £1,400 in total. The premium becomes far more material on multi-week application or red-team programmes, where a twenty per cent uplift on twenty days is a five-figure number. Remember that scope drives cost far more than accreditation does: a badly scoped accredited test is more expensive and less useful than a well-scoped standard one.

What is the difference between CREST and the NCSC CHECK scheme?

CHECK is run by the NCSC specifically for testing HMG and wider public-sector systems. A CHECK engagement must be delivered by a company holding CHECK status and led by a team leader holding a senior qualification from an NCSC-recognised body — CREST’s CCT is one route, and Tigerscheme’s Senior Security Tester and the Cyber Scheme’s CSTL are others. CREST is a broader commercial accreditation body covering penetration testing, application verification, red teaming, incident response and security operations. Being a CREST member does not make a company a CHECK company. If a tender specifies CHECK, ask suppliers for their CHECK status directly rather than accepting CREST membership as a substitute.

Which CREST certification should my tester hold?

It depends on the engagement. CPSA is the written entry-level qualification and is not sufficient on its own for a lead role. CRT, the Registered Tester certification, includes a practical examination and is the level most working testers hold; it is a reasonable minimum for a team member on a straightforward infrastructure test. CCT Infrastructure or CCT Application are the senior certifications, examine the ability to run an engagement end to end, and are what you should expect from the named lead on anything complex or compliance-driven. For intelligence-led simulated attack work, look for CCSAM or CCSAS. Ask for the certification by name and put it in the contract.

Can a small business justify CREST accredited testing?

Frequently yes, and the deciding factor is rarely company size. A twelve-person software business selling into the NHS has a stronger case than a two-hundred-person manufacturer with no external reporting obligations. Work through the scoring framework in this article: if an external party will read the report, if you are in scope for a named compliance regime, or if enterprise security questionnaires appear in your sales process, the premium usually pays for itself in a single avoided procurement failure. If none of those apply, spend the money on scope, remediation and getting your asset inventory right instead.

Does a CREST report guarantee my systems are secure?

No, and any provider suggesting otherwise is misselling. A penetration test is a point-in-time assessment of a defined scope by a human being working within a fixed time budget. It cannot prove the absence of vulnerabilities, it does not cover systems you excluded, and it says nothing about the state of your estate the week after the test window closes. Accreditation raises confidence in how the assessment was conducted; it does not extend the assessment’s reach or shelf life. Sustained assurance comes from combining periodic testing with continuous vulnerability management, disciplined patching and change-triggered retesting.

How often should we run a penetration test?

Annually is the baseline that most compliance regimes and insurers expect, and it is the right cadence for a stable estate. The more useful trigger is significant change: a new internet-facing application, a cloud migration, a major network redesign, an acquisition, or a substantial change to authentication. Testing purely to the calendar means you may be assessing an estate that has already moved on. Many UK businesses settle on an annual full test supplemented by targeted testing at each significant release, with continuous automated scanning filling the gaps between the two.

What is CREST OVS and do we need it?

CREST OVS is the OWASP Verification Standard accreditation, covering web and mobile application testing assessed against the OWASP Application Security Verification Standard and its mobile equivalent. It matters if your product is software rather than your infrastructure. An infrastructure penetration test will find exposed services and misconfigurations; it will not systematically verify authentication logic, session management, access control between tenants or business-logic flaws in your application. If you are a SaaS vendor and your customers are assessing your product rather than your office network, OVS-aligned application testing is the more relevant purchase.

Can we switch between accredited and non-accredited providers year to year?

You can, and there is an argument for rotating providers to get fresh perspective. The cost is comparability: different methodologies and severity-scoring conventions make year-on-year trend reporting harder, and a mixed history looks inconsistent to an auditor asking how your posture has changed. If you do rotate, keep a stable internal risk register that normalises findings to your own severity scale so the trend survives the change of supplier. Switching down from accredited to non-accredited after a compliance-driven year is the one move to avoid, because it will read as a regression on the next questionnaire.

What should we do first if we have never had a penetration test?

Build an accurate asset inventory before you contact anyone. Most first tests are undermined by an incomplete picture of the estate rather than by the tester. Then run a standard, properly scoped external infrastructure test to clear the obvious debt — exposed management interfaces, unsupported software, weak remote access, credentials in breach corpora. Fix what it finds. Only then consider whether an accredited engagement is warranted, because the second test will read very differently once the first round of findings is closed, and you will not be paying an accredited day rate to discover problems a cheaper test would have found.

Decide the tier before you compare the quotes

The comparison between a CREST accredited pen test and a standard one is decided by who has to believe the report, not by which tester is cleverer. Settle that question first and the rest of the procurement becomes straightforward: you will know which providers to approach, which questions to score, and where in the quote your money is actually going. Cloudswitched can run that assessment with you and scope the engagement against your real compliance driver rather than a generic template.

Scope your penetration test to the right tier

Bring us the questionnaire, the asset list or just the budget line, and we will help you decide whether accreditation is a requirement or an option in your case.

Talk to a Penetration Testing Specialist
Tags:Penetration Testing
CloudSwitched

London-based managed IT services provider offering support, cloud solutions and cybersecurity for SMEs.

CloudSwitched Service

Penetration Testing

CREST-accredited and standard pen tests — infrastructure, web app, cloud and Microsoft 365

Learn More
CloudSwitchedPenetration Testing
Explore Service

Technology Stack

Powered by industry-leading technologies including SolarWinds, Cloudflare, BitDefender, AWS, Microsoft Azure, and Cisco Meraki to deliver secure, scalable, and reliable IT solutions.

SolarWinds
Cloudflare
BitDefender
AWS
Hono
Opus
Office 365
Microsoft
Cisco Meraki
Microsoft Azure

Latest Articles

28
  • Azure Cloud

Azure Disaster Recovery: A UK Business Guide to Building a Tested Failover Plan for Cloud Servers in 2026

28 Aug, 2026

Azure disaster recovery is the discipline that decides whether a ransomware detonation, a failed storage migration or a regional service degradation costs your...

Read more
27
  • Cloud Email

Email Security in Microsoft 365: A UK Business Guide to Stopping Phishing, Spoofing and Business Email Compromise in 2026

27 Aug, 2026

Microsoft 365 email security is the set of tenant configuration decisions, domain authentication records and human controls that determine whether a fraudulent...

Read more
26
  • Penetration Testing

CREST vs Standard Penetration Testing: Which Does Your Business Need?

26 Aug, 2026

CREST penetration testing is not a different kind of hacking. It is the same technical work wrapped in an independently audited assurance layer a layer that...

Read more

Enquiry Received!

Thank you for getting in touch. A member of our team will review your enquiry and get back to you within 24 hours.