By EJN Labs · 22 Jun 2026 · 8 min read
CREST accreditation is independent assurance that a penetration testing provider works to recognised professional and technical standards. CREST is a not-for-profit body that certifies cybersecurity firms and the individuals who test, covering quality processes, ethics, insurance and data handling, so a UK buyer knows the testing is competent and accountable.
The word “CREST” appears on almost every penetration testing website, but few explain what it actually verifies. This guide answers the question behind a buying decision: what is CREST accreditation, what does CREST mean for the quality of your test, and how do you confirm a provider’s claim is genuine. As a CREST-accredited firm, we explain it from the inside, then show you how to check any provider on the public registry. For the full overview, see our parent guide to CREST penetration testing.
What is CREST? The body behind the accreditation
CREST, the Council of Registered Ethical Security Testers, is a not-for-profit accreditation and certification body for the technical security industry. It raises and polices standards in penetration testing, threat intelligence, incident response and security operations, giving buyers a reliable way to identify rigorous providers.
The body exists to solve a problem buyers used to face. Without accreditation there was no dependable way to tell a genuinely rigorous firm from someone with a scanner and a logo.
So what does CREST mean in practice? An independent, internationally recognised authority has examined either a company’s working practices or an individual’s technical ability, and confirmed both meet a published standard. Government bodies, regulators and large enterprises reference CREST when they specify who may test their systems, which is why CREST certification is now a default expectation in UK procurement.
The two layers of CREST accreditation: company and individual
CREST accreditation operates on two separate layers, and a credible provider satisfies both. Many buyers assume one tester holding a certificate makes the whole firm accredited. It does not, and the difference helps you ask sharper questions.
Company-level accreditation
Company-level CREST accreditation assesses the organisation, not just its people. To stay accredited, a firm submits evidence across areas that protect you as a buyer:
- Quality and methodology: documented, repeatable testing processes so results do not depend on which individual is assigned.
- Data handling and security: how your findings, credentials and sensitive data are stored, transmitted and destroyed, which matters given a pen test report is a map of your weaknesses.
- Professional indemnity insurance: appropriate cover, so there is financial recourse if something goes wrong.
- Ethics and conduct: a binding code of conduct, with sanctions for breach.
- Complaints and recourse: a route to escalate to CREST if a member firm falls short, which a buyer does not have with a non-accredited supplier.
This company layer is what buyers most often overlook, yet it is where most of the protection lives: accountable processes, insurance and a complaints route are what you fall back on if things go wrong.
Individual certifications
The second layer is the people. CREST individual certifications are earned through rigorous practical examinations, not multiple-choice quizzes:
- CPSA (CREST Practitioner Security Analyst): the entry-level assessment of core security knowledge and basic methodology.
- CRT (CREST Registered Tester): a hands-on practical exam confirming a tester can find and exploit vulnerabilities competently, the common baseline for a working penetration tester.
- CCT (CREST Certified Tester): the senior level, split into application and infrastructure tracks, demonstrating expert skill and the judgement to lead engagements.
These practical exams are demanding by design: CREST certified penetration testing means the individual touching your systems has proven, examined ability rather than a self-declared job title. Ask a provider which certifications their testers hold to check the work goes to qualified people, not whoever happens to be free.
Why CREST accreditation matters to a UK buyer
For someone choosing a provider, CREST accreditation translates into four concrete buyer protections.
Verified competence. An independent body has examined the testers, so you are not taking a sales team’s word for their skill. This is the single biggest reason CREST certification reduces buying risk, because penetration testing quality is otherwise almost impossible to judge from outside until the report lands.
Professional standards. Accredited firms follow documented methodologies, so your test is thorough and repeatable rather than dependent on one person’s habits.
Data protection and insurance. A penetration test exposes your most sensitive weaknesses. Company accreditation means vetted controls around how that information is handled, with professional indemnity cover behind the engagement.
Recourse. If an accredited member falls short you can escalate to CREST, whereas with an unaccredited supplier your only recourse is whatever sits in the contract. For a fuller comparison, see our explainer on CREST vs CHECK vs non-accredited penetration testing.
How to verify a provider on the CREST registry
Any provider can write “CREST” on a website. The protection only exists if the accreditation is current and genuine, so verification takes two minutes and should be standard practice:
- Go to the official CREST website and open the public member company registry.
- Search for the provider by company name. An accredited firm appears as a current member, with the disciplines they are accredited for (for example, penetration testing).
- Confirm the accreditation covers the service you are buying. A firm may be accredited for one discipline and not another, so check the scope, not just the presence of a listing.
- Where relevant, ask the provider which named team members hold CPSA, CRT or CCT, and confirm those individuals will be on your engagement.
If a provider is not on the registry, or is listed only for an unrelated discipline, treat the CREST claim as unproven. Marketing a logo without current membership is a red flag, and we cover others in our guide to the red flags to watch for when choosing a penetration testing company.
CREST is not the only accreditation: how it fits
CREST is the headline credential for technical competence, but a mature provider usually holds others that prove the organisation around the testing is sound. Cyber Essentials and Cyber Essentials Plus show baseline cyber hygiene on the firm’s own systems, ISO 27001 certifies a working information security management system (which matters because the provider holds your sensitive findings), and ISO 9001 certifies quality management. A provider with CREST but no information security certification of its own is worth a second question about how it protects your report.
How EJN Labs measures up
EJN Labs is a CREST-accredited penetration testing firm, confirmable on the public CREST registry rather than on our word. We satisfy the company layer (documented methodology, vetted data handling, professional indemnity and a code of conduct) and the individual layer: engagements are delivered by senior and principal testers holding CREST certifications, never junior staff assigned to keep a day rate down. Alongside CREST we hold Cyber Essentials, Cyber Essentials Plus, ISO 27001 and ISO 9001, so the organisation protecting your findings is itself audited and accredited.
Every engagement includes a named scoping call, fixed pricing built from a defined day count, and a free retest to confirm issues were actually fixed. The guidance here is simply the standard we are held to. To compare us against the market, see our breakdown of the best UK penetration testing provider criteria.
Frequently Asked Questions
What is CREST accreditation in simple terms?
CREST accreditation is independent confirmation that a penetration testing provider, and the individuals who test, meet recognised professional and technical standards. A not-for-profit body assesses the firm’s quality processes, ethics, data handling and insurance, giving UK buyers assurance of competence and accountability.
CREST also examines the testers themselves through practical exams, so individual competence is proven rather than assumed.
What does CREST mean for the quality of my penetration test?
CREST means the work is done to a documented methodology by testers whose ability has been independently examined, not self-declared. Because competence is verified by an external body rather than claimed by the provider, CREST certified penetration testing reduces a risk you cannot otherwise judge from outside.
Company accreditation adds further protection: vetted data handling, professional indemnity insurance and a route of recourse to CREST if the provider falls short.
What is the difference between company and individual CREST certification?
Company CREST accreditation assesses the organisation’s processes, security, insurance and conduct, while individual certifications such as CPSA, CRT and CCT confirm a tester’s practical ability through rigorous exams. They are two separate layers of assurance, and a credible provider holds both.
When you buy, check the firm is an accredited member and that named, certified individuals will be on your engagement.
How do I check if a penetration testing company is really CREST accredited?
Search the official CREST public member company registry by company name. An accredited firm appears as a current member alongside the disciplines it is accredited for, so confirm the listing covers penetration testing specifically rather than an unrelated service line.
If a provider is not listed, or is only listed for an unrelated discipline, treat the CREST claim as unproven.
Is CREST accreditation a legal requirement for penetration testing?
No. CREST accreditation is not a legal requirement, but it is widely required in UK procurement, by enterprise customers and by some compliance schemes. Many buyers and their own clients insist on a CREST-accredited provider because it is the most recognised independent proof of competence and accountability available.
Choosing an accredited provider
Understanding what CREST accreditation verifies is the foundation of a sound buying decision. Use the registry to confirm any provider’s claim, ask which certified individuals will test your systems, and weigh company-level protections, not just logos. For the wider process, read our guides on how to choose a penetration testing company and the questions to ask before hiring a provider.
When you are ready to engage a CREST-accredited team, request a CREST penetration testing quote and we will return a fixed scope and price delivered by senior, certified testers. For the full overview, see our CREST penetration testing hub.




Leave a Reply