New PSN Connection? The Penetration Testing Public Bodies Need for the Compliance Certificate

New PSN Connection? The Penetration Testing Public Bodies Need for the Compliance Certificate

By EJN Labs · 22 Jul 2026 · 9 min read

PSN compliance penetration testing is not optional. To obtain or renew a Public Services Network compliance certificate, the Cabinet Office requires an IT Health Check (ITHC) report from an independent testing provider, completed within the last 12 months. Most public bodies commission a CREST-accredited firm, and a typical ITHC costs between £4,800 and £12,600 depending on scope.

Why PSN compliance penetration testing decides your connection

PSN compliance penetration testing, delivered as an IT Health Check, is the evidence at the centre of the compliance certificate, the gate you cannot route around whether you are connecting for the first time or renewing. The Cabinet Office’s PSN team will not certify on policies and self-assessment alone.

They expect an independent technical test of the connecting estate, with findings and your remediation plan submitted alongside the application.

That makes the ITHC a hard dependency in your connection timeline: no test, no certificate, and remediation of serious findings has to be credible before submission. Public bodies that leave the ITHC until the month before expiry risk losing connectivity to services their staff depend on.

What the PSN compliance regime actually requires

The regime requires a valid compliance certificate, renewed annually, for any organisation connecting to the Public Services Network, whether a public body or a supplier where the contract specifies it. The PSN is the government’s shared network for secure inter-organisation communication.

The PSN is governed by the Cabinet Office, and the submission itself has three core elements.

  • A completed Code of Connection (CoCo), in which your Senior Information Risk Owner (SIRO) or equivalent signs off the security posture of the connecting estate.
  • An IT Health Check report from an independent testing provider, carried out within the previous 12 months. This is an explicit requirement, not a recommendation.
  • A remediation action plan showing how significant ITHC findings are being fixed, with owners and dates.

The PSN team assesses whether the residual risk your connection presents to the shared network is acceptable. A recent ITHC with a credible remediation plan is normally straightforward; an out-of-date test or unaddressed critical findings invites questions, conditions or refusal.

One honest caveat: the government has been moving departments away from the PSN towards internet-based services for several years, but while your organisation still connects to it, the obligation stands in full. Plan on needing a current ITHC every year you remain connected.

Who can perform the ITHC

PSN guidance requires the ITHC to be carried out by a qualified, independent testing provider. For central government departments, the NCSC’s CHECK scheme applies. For the wider public sector, which is most PSN-connected organisations, an ITHC delivered by a CREST-accredited firm is the accepted route. If you are unsure which category applies, your PSN compliance contact will confirm it, and any reputable provider will ask during scoping rather than after.

Accreditation is not the only practical constraint. ITHC work for public bodies frequently involves data that must not leave the UK, and some engagements require on-site attendance, so where the testing team is based matters as much as the scheme it belongs to. Read what CREST accreditation covers on our CREST penetration testing page.

What an ITHC for PSN compliance covers

The principle is simple: everything that touches, or could reach, your PSN connection needs assurance. A public-body ITHC usually includes the following.

  • External infrastructure. Your internet-facing perimeter: firewalls, VPN endpoints, remote access gateways, published services and mail. This is standard external infrastructure penetration testing.
  • Internal network testing. The servers, workstations and network devices routable to the PSN. Testers look for missing patches, weak credentials, insecure protocols and paths that would let a compromised device reach the PSN gateway.
  • Build reviews. Sample configuration reviews of representative workstation and server builds against the hardening standard claimed in your CoCo.
  • Remote access and third-party links. How staff, contractors and suppliers get in, including MSP connections, a recurring source of findings.
  • Wireless and VoIP. Included when those services share infrastructure with PSN-connected segments.

The most common scoping mistake is treating the ITHC as external-only. An internal component is expected, so if a quote looks surprisingly cheap, check whether internal testing and build reviews are in it.

How a PSN ITHC engagement runs

A well-run ITHC follows a predictable path, which lets you plan backwards from your certificate deadline.

  1. Scoping. The provider works with your IT and information governance leads to enumerate the connected estate: IP ranges, device counts, build types, remote access routes and any segments explicitly out of scope.
  2. Testing. External work is usually done remotely; internal testing is done on site or through a securely shipped test device. For a mid-sized public body this phase typically takes one to two weeks.
  3. Reporting. You receive a report that grades each finding by severity and is written to be submitted as ITHC evidence: clear scope statement, methodology, findings and reproduction detail.
  4. Remediation and retest. You fix what matters, build the remediation action plan, and the provider retests the critical and high findings so your submission shows closed items rather than open promises.

Book the test at least three months before certificate expiry, leaving room for remediation, retesting and PSN team queries. Our penetration testing checklist covers the preparation steps that stop scoping delays eating that buffer.

What a PSN ITHC costs and how scope drives the price

ITHC pricing is driven by days of testing effort, and days are driven by the size of the connected estate: external footprint, internal host count, build types and sites. UK day rates for this work typically run from £1,200 to £1,400, and the ranges below reflect that.

Engagement sizeTypical scopeEffortTypical cost
Small public bodyModest external footprint, single site, limited internal segment4 to 6 days£4,800 to £8,400
Mid-sized body, standard ITHCExternal, internal network, build reviews, remote access6 to 9 days£7,200 to £12,600
Large or multi-site estateMultiple sites, large internal estate, several build types, retest10 to 15 days£12,000 to £21,000

Most public bodies land between £4,800 and £12,600, with large multi-site estates above it. Treat these as typical UK ranges rather than a quote: the honest number comes from scoping your actual estate, which is what our quote form starts. For wider context, see our guide to penetration testing cost in the UK.

Where PSN is heading: FN4G and GovAssure

PSN is a legacy network, and it is worth planning on that basis. The Cabinet Office’s Future Networks for Government programme, run through the Central Digital and Data Office, has been moving public bodies away from PSN since 2018 towards internet-first, cloud-centric networking, on the grounds that a bespoke shared network is both expensive and increasingly hard to secure. If you are connecting for the first time, the question worth asking before you start a compliance cycle is whether a PSN connection is the right long-term answer for your organisation, or whether an internet-first design reaches the same place with fewer standing obligations.

Government assurance has moved in the same direction. GovAssure, launched in April 2023, replaced the cyber elements of the Departmental Security Health Check and assesses government critical systems against the NCSC Cyber Assessment Framework through annual Independent Assurance Reviews. From April 2026, only companies belonging to the NCSC Cyber Resilience Audit scheme are eligible to deliver those reviews. None of this removes the ITHC obligation while a PSN connection remains in place, but it does mean testing commissioned now is better planned as one part of a CAF-aligned assurance picture than as a one-off certificate exercise.

How to choose an ITHC provider

Three checks separate a report that clears the submission from one that creates work. First, match the scheme to your organisation type: a central government department needs a CHECK-accredited provider, while the wider public sector can use a CREST-accredited firm or the Cyber Scheme. Ask the question before you request a quote, because it rules providers in or out rather than being a preference. Second, confirm the quote includes an internal phase and build reviews rather than external testing alone, since an external-only price will look attractive and then leave a gap in the submission. Third, ask to see how findings are written up: a report in clear severity and remediation language goes into a submission as it stands, while generic scanner output has to be translated first.

EJN Labs is a CREST-accredited UK penetration testing firm, certified to ISO 27001 and Cyber Essentials Plus, with UK-based testers.

Frequently Asked Questions

Is penetration testing mandatory for a PSN compliance certificate?

Yes. The Cabinet Office’s PSN compliance process explicitly requires an IT Health Check report from an independent testing provider as part of the certificate submission, alongside the Code of Connection and a remediation action plan. The ITHC must have been completed within the previous 12 months.

In effect, then, a valid certificate means an annual penetration test of the connected estate.

What does a PSN ITHC cost?

Most public bodies pay £4,800 to £12,600, based on UK day rates of £1,200 to £1,400 and typical efforts of 4 to 9 days. A small single-site estate sits at the lower end, while a standard ITHC with external, internal and build review components sits higher.

Large multi-site estates needing 10 to 15 days run £12,000 to £21,000. Exact pricing comes from scoping your estate.

Who is allowed to carry out the ITHC?

An independent, qualified testing provider. Central government departments fall under the NCSC’s CHECK scheme, while the wider public sector, which covers most PSN-connected organisations such as councils and local public bodies, can use a CREST-accredited firm. Confirm your category with your PSN compliance contact during scoping, and confirm the provider uses UK-based testers if your data or network segments must remain in the UK.

What should be in scope for a PSN IT Health Check?

Everything that touches or can reach your PSN connection should be in scope, because the PSN team assesses the risk your whole connected estate poses to the shared network. That means external-facing infrastructure, internal segments routable to the PSN gateway, remote access routes, and third-party or MSP connections.

Representative workstation and server builds belong in scope too. External-only testing is a common and costly scoping mistake.

How long before certificate renewal should we book the ITHC?

Book at least three months before expiry. The test itself typically takes one to two weeks for a mid-sized body, but you also need time to remediate critical and high findings, have them retested, assemble the remediation action plan and respond to any PSN team queries.

Organisations that book late risk submitting with open critical findings, or losing connectivity while the renewal is resolved.

Get your ITHC booked before the deadline gets expensive

If your PSN certificate is due for renewal, or you are connecting for the first time, the fastest way to a firm price is a short scoping conversation. Sharing your estate size, sites and renewal date through our CREST penetration testing quote form is the fastest route to a scoped day count and a fixed price for the infrastructure testing behind a submission.

Leave a Reply

Your email address will not be published. Required fields are marked *