Qualysec
Blog

A Guide to CREST Penetration Testing: Process, Benefits and Provider Selection

CREST penetration testing is a security assessment carried out by a CREST-accredited provider to identify and verify weaknesses in your systems.

Updated on July 21, 2026
Read Time: 14 min
CONNECT WITH US

An enterprise prospect asks whether your latest penetration test was performed by a CREST-accredited provider. Your team has a recent penetration test report, but suddenly that isn’t enough. Should you repeat the assessment, or is CREST simply another certification logo? 

Before choosing a CREST penetration testing provider, it helps to understand what a CREST engagement involves. Like any penetration test, its effectiveness depends on the agreed scope and available time. It also depends on the access provided and testing rules. No assessment can evaluate assets that fall outside those boundaries.

The rest of the guide will help you make an informed decision before selecting a provider.

What Is CREST Penetration Testing?

CREST penetration testing is a security assessment carried out by a CREST-accredited provider to identify and verify weaknesses in your systems. The assessment combines manual testing with suitable automated tools and produces evidence-based findings that help you understand real security risks.

It is important to understand that CREST is not a different penetration testing technique. Instead, it gives you greater confidence in the organisation delivering the assessment. That includes:

  • Service delivery procedures
  • Tester competence
  • Defined testing methodologies
  • Secure handling of client information
  • Quality review
  • Professional conduct
  • Reporting and remediation support

The exact assets tested always depend on the agreed scope. A CREST penetration testing engagement can include web applications, APIs, mobile applications, cloud environments, internal and external infrastructure, and IoT systems, but only those selected for the assessment.

Why Does CREST Accreditation Matter?

Anyone can claim to provide penetration testing. What is harder to judge is how that work is planned, reviewed, and managed behind the scenes. That is where accreditation adds value. It gives you an independent benchmark when comparing providers.

Instead of relying on marketing claims, you know the provider has established processes for:

  • Assigning suitable testing personnel
  • Following documented methodologies
  • Protecting client evidence and sensitive data
  • Reviewing technical findings before delivery
  • Managing complaints and escalation through defined procedures

That matters long after the test is finished. A well-prepared report is easier for developers to reproduce, gives procurement teams more confidence during supplier reviews, supports customer and audit requests, and helps management decide which security issues need attention first.

Accreditation is still only one part of the picture. The final result depends on the agreed scope, the tester’s capability, the access available, and the conditions of the environment being assessed.

CREST recommends choosing certified penetration testing providers that employ highly skilled, ethical, and technically competent professionals. CREST-accredited companies meet the industry’s highest standards, helping organizations build trusted, long-term security partnerships. Get a quote now.

CREST Accredited Company vs CREST Certified Tester

A provider’s website might mention a certified tester and display a CREST logo. It may promote a CREST penetration test. These are not the same thing.

Term What it means What you should verify
CREST-accredited company An organisation assessed for a particular cybersecurity service discipline Current listing, legal company name, and relevant accreditation
CREST certified tester An individual who has passed a relevant CREST examination Qualification level, current role, and project experience
CREST penetration test An engagement delivered within the applicable accredited service framework Scope, assigned team, methodology, reporting, and retesting
CREST member An organisation holding a recognised CREST membership or accreditation status The exact service covered by its status

One certified professional does not automatically make the whole organisation CREST accredited. Company accreditation and individual certification are assessed separately.

Before signing an agreement, ask who will carry out the assessment, who will review the findings, and whether subcontractors will be involved. Also verify the provider using its legal company name in the official CREST Marketplace instead of relying only on a logo shown on its website.

When Do Businesses Need CREST Penetration Testing?

There is no universal requirement to use CREST penetration testing. It becomes more valuable when someone outside your organisation needs to review or rely on the final report.

Common examples include:

  • Enterprise customer security assessments
  • Supplier and vendor due diligence
  • SOC 2 or ISO 27001 audit preparation
  • Financial services and fintech risk reviews
  • Cyber insurance assessments
  • Merger and acquisition due diligence
  • Public sector or regulated procurement
  • Product launches involving sensitive or high value data

Although the assessment can support compliance and assurance activities, it does not automatically satisfy frameworks such as ISO 27001, SOC 2, PCI DSS, or GDPR. Those frameworks have their own requirements.

A simple question can help you decide: Who needs to trust and accept the penetration testing report?

If the assessment is only for internal security improvement and no customer, auditor, contract, or procurement process requires an accredited provider, a reputable non-CREST penetration test can still be a suitable choice.

How CREST Penetration Testing Works

From Scoping to Retesting The CREST Testing Process

 

The exact approach varies between providers, but a well-managed engagement should follow a clear path from planning and authorised testing to reporting, remediation, and closure.

1. Scoping and Rules of Engagement

Every engagement starts by defining why the assessment is being performed. The objective could be customer assurance, audit preparation, release validation, or investigating a high-risk system.

The scope should clearly identify:

  • URLs and applications
  • API endpoints
  • IP addresses
  • Cloud accounts
  • User roles
  • Third party integrations
  • Administrative functions
  • Any systems excluded from testing

The rules of engagement should also document:

  • Written authorisation
  • Testing dates and approved time windows
  • Allowed and prohibited techniques
  • Production safety restrictions
  • Data exfiltration limits
  • Stop test conditions
  • Emergency contacts
  • Critical finding escalation procedures

A missing asset or unclear exclusion can leave important systems untested or create misunderstandings about what was actually assessed. That is why scoping is one of the most important parts of the entire engagement.

2. Reconnaissance and Attack Surface Mapping

Before testing begins, the team maps the target environment to understand how users, applications, and connected systems interact. This provides the context needed to identify realistic attack paths rather than testing isolated components.

The review typically includes:

  • Subdomain and service discovery
  • Application and API mapping
  • Authentication flow analysis
  • User role and permission mapping
  • Cloud exposure review
  • Trust boundaries and third-party integrations

This step often reveals weaknesses that automated scanners cannot recognise because they lack the context of how the application actually works.

3. Manual Vulnerability Testing

After the initial review, testers begin exploring how the application behaves in real situations. They try different user actions, unexpected request sequences, and edge cases that automated tools cannot evaluate on their own. This is often where the most serious security issues are uncovered.

Automated scanners can identify known technical weaknesses, but they cannot reliably evaluate authorization logic, business workflows, or chained attack paths. Those require human analysis. 

  • Broken access control
  • Tenant isolation failures
  • Authentication and password reset bypasses
  • Session management flaws
  • API authorisation issues
  • Pricing or approval workflow manipulation
  • Privilege escalation
  • Chained vulnerabilities

Many of these weaknesses only appear after several actions are combined or normal business workflows are deliberately misused. That is why they still require human judgement.

4. Controlled Exploitation and Impact Validation

Not every security finding poses the same level of risk. When permitted under the agreed rules, testers validate selected findings through controlled exploitation to confirm whether they can be abused in a real attack. The proof should be enough to demonstrate the impact without affecting normal operations.

Evidence can include:

  • Accessing another user’s records
  • Escalating from a standard account to an administrator
  • Bypassing authentication controls
  • Reaching an internal system
  • Viewing a limited sample of exposed data

Once the impact has been confirmed, testing stops. There is no reason to access additional records or continue exploiting the same weakness after sufficient evidence has been collected.

5. Reporting and Quality Review

The report is what your team will rely on after the assessment, so it should be reviewed before it is delivered. A technical review helps confirm that the findings are accurate, the evidence supports the conclusions, and the recommendations are practical.

A good report should include:

  • Objectives and scope
  • Testing dates and limitations
  • Methodology
  • Overall risk summary
  • Severity-rated findings
  • Affected assets
  • Evidence and reproduction steps
  • Business impact
  • Root cause
  • Prioritised remediation guidance

Sometimes the real risk comes from several weaknesses used together. In that case, the report should explain the complete attack chain instead of treating each finding separately.

Looking for a sample penetration testing report? See what’s included and what to expect from a professional security assessment. Download it now.

6. Remediation, Retesting and Closure

Once the report is delivered, your team starts fixing the confirmed issues. During this stage, the testing provider should be available to answer developer questions and explain the recommended fixes where needed. Good communication often speeds up remediation.

Retesting then confirms whether:

  • The original vulnerability has been fixed.
  • The root cause has been addressed.
  • Related attack paths still exist.
  • The fix has introduced another security issue.

Before you agree to the engagement, ask a few practical questions. Is retesting included in the price? How many rounds are covered? How long do you have to request a retest after fixing the issues? Will you receive an updated report or only a confirmation letter? Getting these answers early helps avoid surprises later.

Get CREST-Accredited Penetration Testing Services

Qualysec delivers CREST-accredited VAPT services with real-world attack simulations, validated findings, and actionable remediation reports.

Get a Quote Today

CREST Member

CREST Penetration Testing vs Standard Pentesting and CHECK

CREST vs Standard Penetration Testing

Both approaches aim to identify and validate security weaknesses. The difference lies in the assurance surrounding the provider rather than the testing objective itself.

Area Standard penetration test CREST penetration test
Provider assurance Depends on the chosen vendor Provider assessed against applicable CREST requirements
Tester qualifications Vary between providers Relevant qualifications and experience can be verified
Methodology May be structured or informal Expected to follow controlled, documented procedures
Data handling Depends on provider policies Organisational controls form part of provider assurance
Reporting Quality can vary considerably Evidence based reporting and quality review are expected
External acceptance Depends on vendor reputation Often carries stronger procurement and audit credibility

A standard penetration test is not automatically lower quality. Many experienced providers deliver excellent assessments without CREST accreditation. The right choice depends on your business needs and any customer or procurement requirements.

CREST vs CHECK Penetration Testing

CREST and CHECK are different assurance schemes. The one you need depends on the requirements of your contract or procurement process.

Factor CREST CHECK
Organisation CREST International UK National Cyber Security Centre
Main purpose Provider accreditation and professional certification Assured testing for relevant UK public sector and CNI environments
Reach International Primarily UK public sector and critical infrastructure
When selected Customer, auditor, procurement, or internal assurance requirement Contract or assurance requirement specifically calls for CHECK

Always check the wording of the contract, tender, or system classification before selecting a provider. CREST and CHECK should not be treated as interchangeable. Not every UK public sector engagement requires CHECK.

How Much Do CREST Penetration Testing Services Cost and How Long Do They Take?

There is no fixed price or standard timeline. Every engagement is scoped around the systems being tested and the effort needed to assess them properly.

The final estimate is usually based on:

  • Number of applications, APIs, IP addresses, or cloud accounts
  • Number of user roles
  • Application complexity
  • Multi-tenant architecture
  • Internal or external access
  • Authentication and single sign-on arrangements
  • Testing restrictions
  • Reporting requirements
  • Retesting
  • Required delivery timeline

For example, a small application with one user role will usually require less effort than a financial platform with multiple roles and cloud services.

To receive an accurate quotation, be prepared to share:

  • URLs or IP ranges
  • API documentation
  • Technology stack
  • User roles
  • Architecture overview
  • Testing objective
  • Required deadline
  • Compliance or procurement requirements

Leave enough time after the report is delivered for remediation and retesting. Planning for these stages early helps keep your project or audit on schedule. Get a Free Penetration Testing Quote

How to Choose a CREST Penetration Testing Provider

Before comparing prices or timelines, confirm who will actually carry out the assessment. A few checks at this stage can prevent problems later.

Check Why it matters
Legal company name Verify the provider in the official CREST directory.
Accreditation scope Confirm it covers penetration testing, not another service.
Testing team Ask who will lead, perform, and review the engagement.
Experience Check relevant technology and industry expertise.
Delivery model Find out whether employees, contractors, or subcontractors will perform the work.

Review the Proposed Scope and Methodology

The proposal should explain what will be tested and how the engagement will be carried out. 

Ask about What to confirm
Scope APIs, administrative functions, integrations, user roles, and business critical workflows
Manual testing How much of the assessment relies on manual testing
Exploitation Whether controlled exploitation is included and any restrictions that apply
Critical findings How serious issues will be communicated during testing
Evidence handling Where evidence is stored, who can access it, and when it will be deleted

Assess Reporting and Retesting

Review item What to check
Sample report Request a redacted copy
Finding details Evidence, reproduction steps, business impact, root cause, and remediation guidance
Quality review Peer review or senior technical sign off
Remediation support Whether a remediation call or workshop is included
Retesting Included rounds, deadline, additional charges, and updated report or closure letter

Do not choose a provider on price alone. A low quote often reflects a smaller scope rather than better value. Also, avoid booking the assessment immediately before an audit or product launch. Leave enough time to fix issues and complete any required retesting.

Work with a CREST Certified Security Team

CREST Accredited Penetration Testing Provider

Qualysec is a CREST Certified Company that helps organisations identify and fix security weaknesses across web applications, APIs, mobile apps, cloud environments, external networks, and IoT systems. Every assessment combines expert-led manual testing with targeted automation to uncover real attack paths, access control issues, and business logic flaws that automated scans alone can overlook.

With 350+ clients, 2,500+ penetration testing assessments, and projects delivered across 38+ countries, Qualysec supports organisations ranging from growing businesses to global enterprises. If you are planning a security assessment, speak with our security team to discuss your scope or request a tailored quotation.

Talk to an expert to learn more about our CREST cybersecurity services.

Conclusion

CREST helps organisations evaluate the quality and assurance behind a penetration testing provider, but it should never replace careful scoping, experienced testers, or clear remediation planning. The best outcomes come from combining accredited delivery with a well-defined assessment that reflects the way your systems are actually used. 

Even so, accreditation cannot replace a well-defined scope, suitable testers, sufficient access, or timely remediation. Before approving an engagement, verify the provider, testing team, methodology, reporting approach, and retesting arrangements.

FAQs

What does CREST stand for in cybersecurity?

CREST is an international cybersecurity accreditation and professional certification body. It assesses cybersecurity service providers against recognised standards and certifies security professionals through technical examinations.

Is CREST penetration testing mandatory?

Not in every case. Some organisations request it through contracts, tenders, customer security reviews, insurance requirements, or procurement policies. It can strengthen audit and assurance activities, but whether you need it depends on the requirements of the engagement.

How can I verify a CREST accredited penetration testing provider?

Start with the official CREST Marketplace and search using the provider’s legal company name. Then check that the accreditation covers penetration testing and ask who will carry out and review the assessment.

Is a CREST penetration test the same as a vulnerability scan?

No. A vulnerability scan looks for known issues using automated tools. A penetration test goes further by validating findings, exploring realistic attack paths, assessing business impact, and providing practical remediation advice.

Does CREST accreditation guarantee that every vulnerability will be found?

No security assessment can promise complete coverage. The outcome depends on the agreed scope, available access, testing time, permitted techniques, the tester’s experience, and any changes made to the environment during or after the engagement.

Pabitra Kumar Sahoo

About Pabitra Kumar Sahoo

Pabitra Kumar Sahoo is the Co-Founder and Chief Operating Officer (COO) at Qualysec. With a deep commitment to elevating global cybersecurity standards, he directs corporate operations and service strategy, helping enterprises mitigate compliance debt and defend their digital infrastructure through elite, human-led penetration testing.

Leave a Comment.

Your email address will not be published. Required fields are marked *

Related Blogs

Subscribe to Newsletter

Get the latest cybersecurity insights, compliance tips, and vulnerability reports delivered directly to your inbox.