CREST-APPROVED PENETRATION TESTING

CREST-Approved Penetration Testing for UK Businesses

CREST is the UK’s gold-standard accreditation for penetration testing. We are an active CREST member firm, verifiable directly on the CREST marketplace. Every engagement is delivered to CREST methodology and quality standards. Reports accepted by FCA, NCSC, NHS, ICO, SOC 2 auditors, and cyber insurers, without translation work.

  • Unlimited retesting
  • Unlimited pre-retesting
  • No hidden fees
Accredited & recognised
Cyber Essentials certified Cyber Essentials Plus certified IASME certifying body ISO 27001 certified ISO 9001 certified Crown Commercial Service supplier UK Cyber Security Council member
CREST
Approved member firm
20+
CREST-certified services
Free
Retests, no time limit
24h
Scope to active testing
CLIENT REFERENCE
“I would highly recommend EJN Labs to any organisation seeking reliable, detailed, and well-managed penetration testing services, particularly for government or enterprise-level projects.”
SquareOneImran SaghirProject Lead, SquareOne
CLIENT REFERENCE
“There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.”
CelloriDan WilcocksonCo-Founder, Cellori
WHY IT MATTERS
1

the only UK accreditation body whose membership is explicitly recognised by NCSC, FCA, and the UK Government Digital Marketplace.

Self-certified pen testing reports won’t pass audit. CREST-approved testing will.

Many cybersecurity firms claim to deliver “professional” penetration testing without any external accreditation. Their reports are self-certified.

When ISO auditors, FCA-regulated firms’ compliance teams, NHS DSPT assessors, or cyber insurance underwriters review the report, they ask: who validates the methodology? who holds the testers accountable? is this firm independently verified?

CREST (the Council of Registered Ethical Security Testers) is the only UK accreditation body whose membership is explicitly recognised by NCSC, FCA, and the UK Government Digital Marketplace.

EVERY SERVICE TYPE

CREST-Approved Penetration Testing: Every Service Type

CREST methodology applied to every engagement. Choose the service type; we deliver to the same accreditation standard.

01

Web App Pen Testing

OWASP Top 10 + ASVS, manual exploitation of business-logic flaws, IDOR, SSRF, broken authentication. CREST-certified testers.

02

Mobile App Pen Testing

iOS + Android against OWASP MASVS. Frida runtime, SSL pinning bypass, biometric bypass, backend API. CREST-certified testers.

03

API Pen Testing

OWASP API Top 10 (BOLA, BFLA, BOPLA), REST + GraphQL + gRPC. Schema-aware coverage.

04

External Pen Testing

PTES + NIST SP 800-115. Public-IP attack surface, exposed services, subdomain takeover, weak SSL/TLS.

05

AWS Cloud Security

CIS AWS Foundations Benchmark v3.0. IAM, S3, EKS, Lambda, KMS. Manual exploitation chains.

06

Azure Cloud Security

CIS Microsoft Azure Foundations v3.0. Entra ID, RBAC, Key Vault, AKS, Storage.

07

GCP Cloud Security

CIS Google Cloud Platform Foundations v3.0. IAM impersonation, GKE, Cloud Storage, Secret Manager.

08

Red Teaming

MITRE ATT&CK-mapped adversary simulation. STAR-aligned + TIBER-UK methodology.

09

VAPT

Combined automated scanning + manual exploitation. Audit-grade compliance evidence.

10

Threat Intelligence

CREST CTI capabilities. Sector-specific threat actor profiling, dark-web monitoring.

11

Attack Surface Monitoring

Continuous external asset discovery, exposed services, leaked credentials.

12

Cyber Essentials Plus

IASME-accredited Cyber Essentials Certifying Body. Pre-audit gap analysis, full CE+ testing.

FOUR-PHASE METHODOLOGY

CREST Penetration Testing: From Scope to Attestation

Every CREST engagement follows the four-phase delivery model. Findings tagged to specific control IDs. Reports accepted by every UK auditor.

01

Scope & Threat Model

CREST-aligned scoping call. Threat model agreed with the customer. Rules of engagement signed. Fixed-price quote confirmed before work begins.

02

Live Findings

Critical findings reported live during testing, not held back to the final report. Direct engineer access via the EJN portal.

03

Manual Exploitation

Hands-on testing by a CREST-certified pentester. Business-logic exploitation, chained vulnerabilities, privilege escalation, impact validation.

04

Report & Retest

CREST-acceptable report format. Findings mapped to specific control IDs. Free retest within 30 days. Letter of attestation provided.

CREDENTIALS

Verified Accreditations Auditors Accept

Every credential below is independently verifiable. UK procurement teams, FCA supervisors, ISO 27001 / SOC 2 auditors, and cyber insurance underwriters all recognise these standards.

GET YOUR QUOTE

Get a fixed CREST pen test quote in 24 hours

A fixed-price quote back in one business day, from a named CREST assessor. No sales pipeline, no chasing.

  • CREST and IASME accredited. Testing your auditors and clients already recognise.
  • Fast-track testing within 24 hours where required. Free retest of every fix included.
  • Live findings via your client portal, not a four-week PDF.
  • Fixed price from £3,500 for a single-role, single-app scope, agreed up front. Most engagements run £5,000 and up. No day-rate surprises.
What clients say
There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.
CelloriDan WilcocksonCo-Founder, Cellori

Under NDA Further named references available on a scoping call.

What happens next
  1. We reply within one business day with a fixed-price quote from a named CREST assessor.
  2. You approve the scope and we book a start date, usually within 24 hours.
  3. Live findings land in your client portal as we test, with a free retest of every fix.
Accredited & recognised
CREST member Cyber Essentials certified Cyber Essentials Plus certified IASME certifying body ISO 27001 certified ISO 9001 certified UK Cyber Security Council Crown Commercial Service supplier

Get your fixed pen test quote in 24 hours

24h reply CREST tester Free retests

or book a 20-min scoping call first

We reply within one business day. Your data stays with us. No newsletter signup.

COMPLIANCE READY

CREST Reports Accepted by Every UK Audit Framework

CREST methodology is explicitly recognised by NCSC, FCA, ISO auditors, and UK Government. Reports submitted directly without translation.

FCA Cyber Resilience

CREST is the FCA’s recognised standard for penetration testing in regulated financial services. Reports accepted by FCA examiners.

NCSC IT Health Check

CREST and NCSC CHECK are the two recognised UK government standards. CREST membership is verified independently.

PCI DSS

CREST-aligned testing satisfies Req 11.3 (application + network) and Req 11.2 (vulnerability scanning) requirements.

ISO 27001 + SOC 2

CREST-tested findings pre-mapped to Annex A.12.6.1 / Trust Services Criteria. ISO + SOC 2 auditors accept directly.

NHS DSPT

CREST testing accepted as evidence for the NHS Data Security and Protection Toolkit.

Cyber Insurance

CREST-tested reports accepted by cyber insurance underwriters as evidence of due diligence.

PRICING

Transparent CREST Penetration Testing Pricing

All CREST engagements include the same accreditation standard. Price varies by service type and scope complexity.

✦ ALWAYS · ON EVERY TIER · NO EXCEPTIONS ✦
Free retests, no time limit
Free rescheduling
No cancellation fees
24-hour scope to active testing
Live findings to client portal
Executive + technical report
60-min walkthrough call
Letter of attestation
SMALL / SMB
£4,000–£8,000
Depends on app complexity

External / web / API / mobile single-target engagement. CREST-certified delivery. Typically 3-5 day engagement.

Get a fixed quote
ENTERPRISE
£18,000+
Depends on app complexity

Full-stack engagement (multiple cloud accounts, hybrid AD, complex web + API + mobile). Typically 12-15+ days.

Get a fixed quote

Full UK pen test cost guide

WHY EJN LABS

What You Actually Get

What distinguishes our service from automated scans and box-tick competitors.

What You Get From CREST Penetration Testing

Independently accredited methodology, CREST-certified testers, audit-acceptable reports, free retests, and a CREST-aligned attestation letter.

Verifiable on crest.org

Our CREST membership is verifiable independently at marketplace.crest.org. Auditors check this directly.

Audit-Ready Out-of-the-Box

Reports pre-mapped to FCA, NCSC, PCI DSS, ISO 27001, SOC 2, NHS DSPT, cyber insurance. No translation work for your team.

Free Retests Within 30 Days

Every remediated finding retested for free. CREST-aligned validation. No additional engagement fee.

UK CREST + IASME + ISO 27001 + ISO 9001

Multiple independent accreditations. Reports accepted by every UK auditor and regulator.

Letter of Attestation

Every engagement closes with a CREST-aligned letter of attestation, the signed proof auditors, regulators, and insurers ask for.

FAQ

Frequently Asked

What is CREST penetration testing?

CREST is the UK’s gold-standard penetration testing accreditation. CREST member firms undergo rigorous independent assessment of methodology, governance, technical capability, and individual tester competence. CREST-tested reports are accepted by NCSC, FCA, ISO auditors, and cyber insurers.

How do I verify your CREST membership?

Our CREST membership is verifiable directly at marketplace.crest.org/supplier/ejn-labs-ltd . Auditors typically check this URL during compliance reviews.

How does CREST differ from CHECK?

CREST is for the broader UK private sector and accepted by NCSC. CHECK is specifically NCSC-accredited testing for UK government work. The two have similar methodology rigor; CHECK is required for HMG contracts, CREST is the industry-standard for everything else.

Is CREST recognised internationally?

CREST has growing international recognition. CREST is the dominant standard in UK, Australia, Singapore, and the Middle East. In the US, customers more often request OSCP / OSCE individual certifications. Our team holds both: CREST firm membership and CREST/OSCP/OSCE individual certifications.

How much does CREST penetration testing cost?

Small engagements £4,000-£8,000. Mid-market combined engagements (most commonly commissioned) £8,000-£18,000. Enterprise full-stack engagements £18,000+. UK day rates for CREST-certified testers are £1,100-£1,400 per day.

What service types do you offer under CREST?

All service types: web app, mobile, API, external infrastructure, internal infrastructure, AWS / Azure / GCP cloud, red teaming, threat intelligence, attack surface monitoring, VAPT, code review, social engineering. Same CREST accreditation standard across every service.

Will CREST testing satisfy our PCI DSS Req 11.3?

Yes. CREST-aligned testing methodology satisfies PCI DSS Req 11.3 (application and network penetration testing) requirements. Our PCI DSS engagements specifically follow Req 11.3.x methodology.

Will CREST testing satisfy our ISO 27001 audit?

Yes. CREST-aligned testing satisfies ISO 27001 Annex A.12.6.1 (technical vulnerability management). Our reports include a control-mapping summary that ISO auditors accept as evidence.

Will CREST testing reduce our cyber insurance premium?

UK cyber-insurance underwriters increasingly require CREST-attested annual testing for renewal, particularly above £100k premium tier. While we cannot guarantee a premium reduction, demonstrable CREST testing is now a near-mandatory baseline for many insurance products.

How long does CREST testing take?

Single-target engagements typically 3-5 working days. Multi-target combined engagements 7-10 days. Enterprise full-stack 12-15+ days. Test duration is determined during scoping based on scope complexity.

Are your testers all CREST-certified?

Yes. Every consultant working on CREST engagements holds at minimum CREST CRT (Registered Tester) qualifications. Many also hold OSCP, OSCE, OSWE for additional rigour.

Do you sign NDAs?

Yes. Standard NDA before any technical detail is shared. We operate under a project-specific master agreement that includes data handling, deliverable IP, and breach notification clauses. Custom MSAs and AUP terms are accepted for enterprise and public-sector clients.

EXPLORE EVERY SERVICE

20+ CREST-certified testing services in one place

Web, mobile, API, cloud, AI, infrastructure, red team. Pick the test that fits your environment.

Penetration testing services
READY TO START

Get a fixed CREST pen test quote in 24 hours

A CREST-certified consultant will contact you within one business day with a fixed price, a realistic timeline, and the named consultant. No sales pipeline.