A tender document names CHECK penetration testing as a hard requirement. The compliance team pulls up its usual supplier list, only to find most of those firms hold CREST accreditation, not CHECK. The two get treated as interchangeable in casual conversation, but a procurement officer checking credentials against a government contract will not accept one for the other.
CHECK is the UK’s official penetration testing scheme for assessing government systems, administered directly by the National Cyber Security Centre (NCSC). Under the current CHECK Scheme Standard v1.1, published in November 2024, only companies employing NCSC-approved testers can legally describe their work as CHECK testing. This guide explains what CHECK actually certifies, how it differs from CREST, and who needs it. It also covers what changed when the scheme moved its qualification requirements onto the UK Cyber Security Council’s framework in 2025 and 2026.
What Is CHECK Penetration Testing?
CHECK pen testing is the NCSC’s scheme for accrediting companies and individuals to carry out penetration testing on UK government and public sector systems. The scheme name itself is shorthand for the process: government customers commission an “IT Health Check.” CHECK-approved firms are the only ones licensed to deliver it under that name.
Unlike a general commercial penetration test, CHECK testing follows a formal standard covering three areas: company-level approval, individual tester qualifications, and reporting requirements. The CHECK Scheme Standard sets out exactly how a testing company must operate to keep its approval. Testers, in turn, must independently hold current qualifications before they can work on a CHECK engagement.
Crucially, CHECK pen testing is not a certification an individual organisation earns for its own systems. Instead, it certifies testing companies and testers as qualified to test other organisations’ systems. A government department doesn’t get CHECK certified. It commissions a CHECK-approved supplier to perform its ITHC.
CHECK Team Leader (CTL) and CHECK Team Member (CTM) Requirements
The people doing the testing, not just the company employing them, must hold specific individual qualifications. Because these requirements changed substantially in the current scheme version, this is where many firms run into compliance gaps.
| Role | Qualification Required | Clearance | Employment Status |
|---|---|---|---|
| CHECK Team Leader (CTL) | UK Cyber Security Council Professional Title, Security Testing specialism, Principal level (PriCSP) or Chartered level (ChCSP) | SC clearance minimum | Permanent employee, not contracted from another CHECK company |
| CHECK Team Member (CTM) | UK Cyber Security Council Professional Registration, Security Testing specialism, Practitioner level | SC clearance minimum | No independent employment restriction specified |
Since 2025, the UK Cyber Security Council has become the body that formally defines these testing titles, replacing the older model where NCSC-approved examinations stood alone. According to CREST’s published guidance on the transition, CTLs needed to hold their Professional Title by 31 March 2025. CTMs must do the same by 31 March 2026. Anyone who misses their deadline becomes ineligible to work on CHECK engagements. For this reason, the NCSC has stopped covering examination fees for candidates who apply after 1 April 2025.
For firms managing their own testing bench, this deadline is not a distant compliance item. In fact, it is a March 2026 cutoff. Any CTM still working under the old qualification model needs to have completed the transition already, or be actively mid-process.
CHECK vs. CREST Penetration Testing: What’s the Difference?
CHECK and CREST penetration testing are frequently mentioned in the same breath, and for good reason: CREST now plays a formal role inside the CHECK scheme itself. But they are not the same accreditation, and understanding the distinction matters for anyone reading a tender requirement carefully.
| Factor | CHECK | CREST |
|---|---|---|
| Administered by | NCSC (UK government) | CREST, an independent not-for-profit accreditation body |
| Scope | UK government and public sector systems specifically | Commercial, financial, and international penetration testing broadly |
| Legal status of the name | Restricted; only NCSC-approved firms may use “CHECK” | Open to any firm that earns CREST company and individual accreditation |
| Individual qualifications | UK CSC Professional Titles (Security Testing specialism) | CREST’s own exams (CCT INF, CCT APP), now mapped to equivalent UK CSC titles |
| Typical use case | ITHC for government departments, PSN-connected systems | Financial services, private sector enterprise, international clients |
| Geographic recognition | UK-specific | UK-based but internationally recognised |
The practical overlap is this: since the 2025 scheme changes, CREST acts as a Licensed Body administering UK CSC Professional Registrations. As a result, CREST’s existing technical exams now map to equivalent UK CSC titles that satisfy CHECK’s individual qualification requirement. That includes CCT INF for infrastructure testing and CCT APP for application testing. In other words, a tester’s CREST-earned technical qualification can now form part of the pathway to becoming CHECK-qualified. Even so, the firm itself still needs separate NCSC company approval to legally deliver work under the CHECK name.
For a compliance officer reading a supplier’s credentials, the question to ask is not: are they CREST accredited? Instead, ask: “Are they NCSC CHECK-approved, and do their testers hold current UK CSC Security Testing titles?” A firm can be excellent at CREST-accredited commercial testing without holding CHECK company approval at all.
Who Actually Needs CHECK-Accredited Testing?
CHECK pen testing is not a general-purpose requirement. It applies in specific, identifiable circumstances.
1. Government departments and public sector bodies
Any UK central government department, agency, or public body commissioning a formal IT Health Check for accreditation purposes typically must use a CHECK-approved supplier. The ITHC itself is the deliverable the scheme was built around.
2. Organisations connecting to the Public Services Network (PSN)
Historically, PSN Code of Connection compliance required an ITHC as part of the accreditation process for any organisation connecting to the network. CHECK-approved testers were the accepted route for that assessment.
3. Suppliers to government contracts with security clearance requirements
CTLs and CTMs must hold SC clearance at minimum. For this reason, CHECK testing is also the practical route for any engagement where personnel security vetting is a contractual requirement, not just a technical one.
Outside these contexts, CREST accreditation, or another recognised penetration testing standard, is usually the more relevant credential to look for. Commercial organisations without government contracts rarely need to specify CHECK by name. Doing so can unnecessarily narrow the supplier pool for reasons that don’t apply to their actual risk profile.
What CHECK-Ready Evidence Looks Like vs. What Falls Short
CHECK compliance is as much about who is allowed to do the work as what the work finds. Given that, the clearest way to show the gap is to compare two supplier claims a procurement team might receive.
Weak evidence (fails a CHECK requirement check):
“Our team is CREST certified and has extensive government testing experience.” This tells a procurement officer nothing about whether the specific testers assigned hold current UK CSC Professional Titles. Nor does it confirm whether the company itself holds NCSC CHECK approval, or whether the named CTL’s SC clearance is current.
CHECK-ready evidence (satisfies the requirement):
Specifically: a named CTL with a current UK CSC Chartered or Principal Cyber Security Professional title in Security Testing, plus evidence of active SC clearance. Add to that confirmation of permanent employment status with the testing company, and the company’s current NCSC CHECK approval reference. Each element traces to a specific, checkable credential rather than a general claim of experience.
The first statement sounds credible. The second is verifiable, and verifiable is what a government procurement process actually requires.
How Qualysec Supports CHECK and CREST-Aligned Penetration Testing
Navigating which accreditation actually applies, and confirming a testing partner genuinely holds it, is where many organisations lose time during procurement. Consider it the step most tender responses get wrong first.
Accreditation Verification Before Engagement
Qualysec helps organisations confirm exactly what a specific engagement requires – CHECK vs CREST pen testing or another framework – before commissioning testing. That avoids the common mistake of assuming CREST accreditation alone satisfies a government CHECK requirement.
Penetration Testing Structured for Government and Enterprise Clients
Qualysec’s penetration testing methodology follows the reporting and technical rigour expected of CHECK-standard ITHC engagements, producing findings structured for both public sector accreditation processes and enterprise security programmes.
Compliance Documentation for Procurement Review
For organisations preparing tender responses or supplier due diligence packages, Qualysec produces documentation that clearly traces tester qualifications and clearance status. This methodology maps directly to what a specific framework actually requires, replacing general claims of experience with checkable evidence.
Schedule a penetration testing consultation with Qualysec.
Conclusion
CHECK vs CREST pen testing solve different problems. That’s true even though both regularly appear on a security team’s shortlist of credentials to check. CHECK accredited penetration testing is the NCSC’s own scheme, restricted to firms it approves directly, and built specifically for testing UK government and public sector systems. CREST is broader, more commonly seen in commercial and financial services testing, and now plays a formal supporting role inside the CHECK qualification pathway itself.
The CTM deadline for the new UK Cyber Security Council Professional Title lands on 31 March 2026. Given that, any organisation relying on CHECK-approved testers should confirm now, not after a tender deadline, that its named testers hold current titles. Qualifications under the scheme’s older model no longer satisfy the requirement.
Contact Qualysec to confirm the right accreditation for your next penetration test.
Frequently Asked Questions
1. What is CHECK penetration testing?
CHECK accredited penetration testing is the NCSC’s scheme for accrediting companies and individual testers to carry out penetration testing, known as IT Health Checks, on UK government and public sector systems. Only firms holding NCSC CHECK company approval, with testers holding current UK Cyber Security Council Professional Titles in Security Testing, can legally describe their work as CHECK testing.
2. What is the difference between CHECK and CREST penetration testing?
NCSC CHECK certification is a UK government scheme, administered by the NCSC, specifically for testing public sector systems. CREST is an independent accreditation body covering commercial and international penetration testing more broadly. Since 2025, CREST’s technical exams map to the UK Cyber Security Council titles that satisfy part of the CHECK individual qualification requirement. Even so, CREST accreditation alone does not make a firm CHECK-approved.
3. What qualifications do CHECK Team Leaders and Team Members need?
CHECK Team Leaders need a UK Cyber Security Council Professional Title at Principal or Chartered level in the Security Testing specialism. They also need SC clearance at minimum and permanent employment status with their CHECK company. CHECK Team Members need the equivalent Professional Registration at Practitioner level, also with SC clearance at minimum. CTLs need their title by 31 March 2025; CTMs face the same deadline on 31 March 2026.
4. Who needs CHECK-accredited penetration testing?
CHECK penetration testing applies mainly to UK government departments and public sector bodies commissioning a formal IT Health Check for accreditation purposes. It also covers organisations connecting to government networks where an ITHC forms part of the compliance process, and suppliers to contracts requiring security-cleared testing personnel. Commercial organisations without government contracts typically look to CHECK vs CREST pen testing or other recognised standards instead.
5. Is NCSC CHECK certification the same as an IT Health Check (ITHC)?
No. An ITHC is the security assessment itself, the deliverable a government body commissions. CHECK penetration testing is the NCSC scheme that governs which companies and individual testers are approved to legally perform that assessment. A government department commissions an ITHC from a CHECK-approved supplier; it does not itself hold CHECK certification.






