Many people are confused about the differences between the CREST vs CHECK vs CBEST vs TIBER-EU vs DORA TLPT questions because these are not competitive products. They have varying levels of operation. The accreditation of CHECK is a baseline accreditation, and that of CREST is UK government work. Advanced threat-led regimes for financial institutions are CBEST, TIBER-EU and DORA TLPT. This guide will indicate which is suitable for you.
Key Takeaways
- The CREST, CHECK, CBEST, TIBER-EU and DORA TLPT schemes are complementary and are not competing.
- All other accreditations for CREST penetration testing rely on the basics of CREST penetration testing accreditation.
- In the CREST vs CHECK distinction, the public-sector and UK government systems have their own NCSC scheme: CHECK.
- CBEST’s comparison is with TIBER-EU, which is for EU finance, and CBEST’s is for UK finance.
- The DORA TLPT requirements now have an impact on systemically important entities in EU countries.
Why These Schemes Get Confused
The acronyms can come in rapid succession when you are buying security testing. It seems like you must pick between them when it comes to alternatives like CREST, CHECK, CBEST, TIBER-EU or DORA TLPT. They are not. The relationship between CREST vs CHECK vs CBEST vs TIBER-EU vs DORA TLPT is hard to get right and can mean paying too much for the right level of assurance and missing out on the level a regulator expects.
There is no surprise that there is some overlap in the personnel and provision that underlies the schemes, given that they have different aims, but it is still a point of confusion. A firm that gets the CREST accreditation may provide a number of widely varying jobs. That’s right, there are examples: a routine web app test, a CHECK engagement for a government client and a CBEST assessment for a bank. The type of credential depends on who you are, what you are protecting and whether or not any regulator is looking on.
This guide explains all five. It defines each scheme, defines who it applies to and how it relates. It provides you with a decision process and a comparison table to help you determine which one would best fit your organisation. At the end, the CREST vs CHECK vs CBEST vs TIBER-EU vs DORA TLPT landscape will be clear for all of you, be it a UK SME, a government supplier or an EU financial institution.
Understanding the Hierarchy of Testing Schemes
There’s one principle that all of the others follow. There are multiple layers of these schemes ranging from a broad benchmark of quality to intensive testing, driven by the regulator and by threats. Knowing what hierarchy the acronyms follow will help you to know which scheme applies to you, rather than memorising each acronym individually.
CREST: The Foundational Accreditation
The bottom of the hierarchy is the Council of Registered Ethical Security Testers (CREST). It is an international non-profit accreditation organisation in the field of technical security. Both companies and individual testers can be accredited by CREST (data handling, methodology, legal compliance and quality assurance (CREST)). It is the quality mark on which the schemes above are based.
The CREST penetration testing accreditation is accepted as a standard of competence and professionalism worldwide. A company needs to prove that they have skilled employees, standardised procedures, insurance and safe data handling to obtain it. Annual resubmission/full reassessment every three years. A CREST accreditation is the one most commercially relevant quality filter for most commercial buyers.
Importantly, CREST is the underpinning of specialist schemes. CHECK team members operate in CREST-accredited buildings; a CREST-accredited provider delivers CBEST engagements. In CREST vs CHECK vs CBEST vs TIBER-EU vs DORA TLPT, there is no “option 5” as CREST is not a standalone alternative choice. It is the foundation that enables the other layers. When general assurance is all you require, a standard penetration testing process is often your starting and ending point.
CHECK: For UK Government Systems
One level up, and specific to the public sector, is CHECK. A UK National Cyber Security Centre (NCSC) conducted scheme for penetration testing of governmental and public-sector systems, especially those that process data classified at OFFICIAL or higher level of security classification (NCSC). CHECK exists to assure the security testing of UK government IT.
The CREST vs CHECK comparison is a hierarchical one and not a competitive one. A company must be CREST accredited before they can deliver CHECK engagements. On top of this, CHECK adds in the UK-government-specific requirements. Team leaders must possess recognised senior qualifications, and CHECK team members usually need to have a security clearance (UK). In short, the CREST vs CHECK distinction is additive: it is CREST accreditation with a public-sector layer added.
So who needs CHECK? In the real world, your customer determines the choice of CREST vs CHECK. You must use CHECK to test UK government systems or to bid for government contracts that demand it. For commercial organisations without government systems in scope, standard cybersecurity compliance and CREST accreditation are usually enough, rendering CHECK unnecessary. The answer is independent of brand; it is strictly about the scope of the data.
CBEST: Threat-Led Testing for UK Finance
We are entering a new, more advanced, and threat-based level.The Bank of England, the Prudential Regulation Authority, and the Financial Authority call the Bank of England’s Intelligence-driven Penetration Testing Framework for Systemically Important Financial Institutions of the United Kingdom CBEST. They have operated it under their supervision. This is not a standard network penetration test or CREST/CHECK-type test.
CBEST simulates the actions of real cyber attackers targeting an organisation’s important business services. It isn’t a scoped scan – we use custom threat intelligence to initiate a realistic red team attack of live systems. CREST-accredited providers provide engagements with specialist CBEST qualifications, specialist consultants qualified by CCRTS, and engagements managed by CCRTM. This is why we place CBEST above baseline testing in the hierarchy.
The rigour is real. In the 2025 CBEST thematic, regulators shared sector-wide findings and made a call to organisations to tackle the underlying causes, following a live penetration testing exercise of 13 of the UK’s most heavily regulated financial institutions against real threats (Bank of England, 2025). The regulators also now recommend that providers rotate between assessments, in order to minimise concentration risk.
Who needs CBEST? It is mandatory and not voluntary, and only applies to a small number of systemically important financial institutions identified by the regulators in the UK. CREST manages a related scheme called STAR-FS (Simulated Targeted Attack and Response for the Finance Sector), which FCA-regulated businesses excluded from CBEST can access. It brings intelligence-led testing to a broader range of finance across the UK.
Not sure which testing regime your organisation needs? Qualysec offers manual penetration testing with easy-to-understand, standards-mapped reporting, and can assist you with the scope that meets your regulatory drivers. Talk to Qualysec about your requirements.
TIBER-EU: The European Threat-Led Framework
The European Central Bank (ECB) launched a framework for threat intelligence-based ethical red teaming (TIBER-EU). It represents the continental equivalent of CBEST and offers a coordinated approach to threat-led testing within the EU. It aligns directly with broader IT security compliance frameworks and regulatory technical standards. The centrality of regulatory frameworks like DORA makes this alignment possible.
Looking at the structure, the comparison between CBEST vs TIBER-EU reveals two very similar structures. Both are intelligence based and both are realistic threat actors on live systems. Each takes defined phases of threat intelligence, red teaming, and remediation. Mandatory purple teaming and updated terms were added in TIBER-EU 2025. It changed the name of the White Team to the Control Team to keep the naming consistent with DORA.
Geography and governance are the difference in the CBEST and TIBER-EU. CBEST is a United Kingdom-specific test, supervised by the Bank of England. TIBER-EU is a European project, led by the ECB and run by the national central banks. The Netherlands (DNB), Germany (Bundesbank and BaFin), France (Banque de France) and Luxembourg (BCL and CSSF) are also adopting authorities as of 2026. Directly supervised institutions are covered by the ECB.
Most importantly, TIBER-EU is not a law, but a framework. It is voluntary and adopted country by country when it is used on its own. The reason behind this change is DORA, which practically requires some entities to perform TIBER-EU-style testing. The voluntary – binding link between the two is the one that is the least understood of the entire CREST vs CHECK vs CBEST vs TIBER-EU vs DORA TLPT picture.
DORA TLPT: The Binding EU Requirement
DORA TLPT is at the top of the hierarchy. The provision of the Digital Operational Resilience Act that imposes Threat-Led Penetration Testing for financial entities entered into force on 17 January 2025. The detailed rules are contained in the RTS, Commission Delegated Regulation (EU) 2025/1190, which will apply directly across the EU from 8 July 2025 (SureCloud). This is no longer guidance; it is binding law.This is no longer voluntary guidance; it is binding law enforced through strict governance risk and compliance frameworks.
The first step in understanding DORA TLPT requirements is to know what the testing entails. We conduct TLPT as a comprehensive red-team engagement, using threat intelligence relevant to the entity and its industry. To ensure an authentic test of operational resilience, we do not inform the defensive Blue Team in advance, preventing a rehearsed response. We perform the assessment on live systems supporting critical functions rather than in staging environments, allowing us to evaluate the organisation’s real-world ability to detect, respond to, and withstand sophisticated threats.
DORA TLPT requirements are stringent and specific. The in-scope entities are required to carry out a TLPT at least once every three years. The engagement requires an independent threat intelligence provider and another red-team provider who are DORA-compliant. If you use internal testing, you must use an external threat intelligence provider. The competent authority must receive reporting, and you must obtain a certificate of completion. From procurement to attestation, it can take 9 to 14 months.
TIBER-EU Methodology for DORA TLPT
It is methodologically required to meet the DORA TLPT requirements that TIBER-EU is followed. DORA’s standards are based on the TIBER-EU framework. As such, TIBER-EU is the delivery method for a DORA TLPT. This is the pivotal link. Threat-Led Penetration Testing (TLPT) is a legal requirement under DORA, and TIBER-EU is the recognised method to fulfil the legal requirement. If you get that relationship right, the rest of DORA tests will fall into place.
Who Actually Needs DORA TLPT?

One myth is that DORA TLPT is a tool for all financial institutions. It does not. DORA makes a clear distinction between the two tiers, and it is crucial to know which tier you belong to and how much TLPT you will need.
Article 26 targets those whose collapse would really have a negative impact on the EU financial system. All GSIIs are automatically in scope, and other GSIEs are identified by competent authorities on the basis of risk (financialregulations.eu). If not designated by your national authority, you must not do TLPT, but are encouraged to do so.
However, all DORA-qualified entities must still meet basic security testing requirements. Application penetration testing, vulnerability assessments, cloud penetration testing, and network security reviews must still be conducted annually on all applications regardless of TLPT status. Regulators reserve Threat-Led Penetration Testing for systemically important entities, whereas they continue to require broad, traditional testing for the majority.
DORA still goes further than for non-EU organisations. Entities operating or having EU clients in the UK, such as banks, insurance and payment firms, may be in scope via their EU entities. This is the reason that a lot of financial institutions in the UK now have multi-year threat-driven programmes instead of annual point-in-time tests. The question of CREST vs CHECK vs CBEST vs TIBER-EU vs DORA TLPT cannot be considered only a national one anymore.
How to Decide Which Scheme Applies to You
Once you have explained all five schemes, it’s just a question of who you are and what you’re protecting. Answer the questions below to find where you fit in the CREST vs CHECK vs CBEST vs TIBER-EU vs DORA TLPT spectrum.
- Do you belong to a general commercial organisation? If that is the case, then CREST penetration testing accreditation is the minimum standard. If If you are already looking for a provider that CREST has accredited, you will have credible assurance for most purposes.
- Do you test systems owned by the UK government or public sector? If you need it, have CHECK on top of CREST. The essence of the CREST vs CHECK decision.
- Are you a systemically important UK financial institution? If that’s the case, then CBEST applies, as set forth by the regulators. Other companies that the FCA does not regulate could be subject to STAR-FS.
- Are you an EU financial institution or do you serve one? Then DORA applies. The need for full TLPT is dependent on designation, and the CBEST vs TIBER-EU and TIBER-EU-versus-DORA relationships then guide delivery.
- Do you have a significant role within DORA? In addition to annual baseline testing, TIBER-EU also requires Threat-Led Penetration Testing (TLPT) every 3 years.
Comparing the Applicable Testing Schemes
The table below provides an overview of the current CREST landscape, including CHECK, CBEST, TIBER-EU and DORA TLPT. Use it to help you determine which scheme (or combination of schemes) is applicable to your organisation.
| Scheme | Who Runs It | Who It Applies To | Nature |
| CREST | CREST (international body) | Any organisation buying testing | Voluntary quality accreditation |
| CHECK | NCSC (UK) | UK government and public-sector systems | Required for UK gov work; built on CREST |
| CBEST | Bank of England, PRA, FCA | Systemically important UK financial firms | Regulator-driven, threat-led |
| TIBER-EU | European Central Bank | EU financial entities (via national banks) | Framework; voluntary unless via DORA |
| DORA TLPT | EU law; national authorities | Designated significant EU financial entities | Mandatory, threat-led, every 3 years |
Be aware of the schemes in stack rather than conflict. Think about a significant UK institution that operates in the EU. It may include CREST penetration testing as its baseline, apply CHECK for government systems, apply CBEST internally and achieve DORA TLPT with TIBER-EU. The most regulated organisations aren’t about to pick one but rather several.
Does CREST Underpin DORA and TIBER-EU?
CREST accreditation often poses a question to the newer, threat-led regimes as to whether it will support them. It does, significantly. The accreditation of CREST is different to other schemes such as DORA TLPT. Nevertheless, those who wish to carry out threat-led testing will need the structured capabilities that CREST-accredited providers are able to provide, and CREST accredits the provider organisation (CREST) as well as the individual. They are complementary, not alternative.
In practice, the threat-led schemes are very much dependent on CREST. A CREST-qualified provider and specialist present all CBEST engagements. TIBER-EU and DORA TLPT demand the demonstration of capable threat intelligence and red team providers. One of the best certifications a firm can give is CREST. A CREST badge won’t necessarily make a DORA TLPT, but it will be a good starting point.
This rounds up the CREST vs CHECK vs CBEST vs TIBER-EU vs DORA TLPT association. Not all of them are as cheap as CREST in a competition. The accreditation layer is what provides the specialist, regulator-driven schemes with their credibility. The quality of the provider is what is important, regardless of the scheme involved. Evidence may often be seen in CREST and will help you know if the testing is meaningful or not.
Conclusion
The landscape of CREST vs CHECK vs CBEST vs TIBER-EU vs DORA TLPT is seemingly confusing until the hierarchy behind it is understood. Accreditation is the basic one, and it is called CREST. CHECK is an additional layer of the UK government. The UK and EU threat-led frameworks for financial institutions are CBEST and TIBER-EU, respectively. DORA TLPT is the EU binding law that TIBER-EU actually hands over. They do not compete with each other, but they complement one another.
This depends on identity and extent. General organisations need CREST penetration testing. Government Suppliers require CHECK. Systemically important UK financial firms face CBEST. DORA includes EU financial entities in the framework of TIBER-EU and, where relevant, in mandatory Threat-Led Penetration Testing (TLPT). A number of the large cross-border institutions have to meet several of them concurrently, at different times.
The bottom line is, you should chart your obligations ahead of you procure. Look for your regulators, your data and your footprint, and then find the matches with the schemes above. Check the accreditation of a provider independently from the relevant body. If you get this right, the question of CREST vs CHECK vs CBEST vs TIBER-EU vs DORA TLPT becomes clear and defensible testing plan for what matters.
Need penetration testing mapped to the right framework for your organisation? Qualysec offers manual, independent testing, severity-rated results, compliance reporting and retesting after remediation. Contact Qualysec to scope your assessment today.
Frequently Asked Questions
What is the difference between CREST, CHECK, CBEST, TIBER-EU, and DORA TLPT?
They are at various levels. Within the CREST vs CHECK vs CBEST vs TIBER-EU vs DORA TLPT hierarchy, CREST is a basic accreditation, CHECK is for UK government systems, and CBEST, TIBER-EU and DORA TLPT are enhanced threat-based regimes for financial institutions. CBEST is UK, TIBER-EU is EU, and DORA TLPT is the EU binding law provided by TIBER-EU.
Which penetration testing framework should my organisation follow?
This depends on who you are and what you are protecting. Commercial companies cannot afford to do without CREST penetration testing. Government suppliers need CHECK. The UK will apply CBEST to systemically important UK financial firms, and TIBER-EU may subject EU financial entities to DORA TLPT.. Map your regulators and data and match with the proper scheme.
Who needs DORA Threat-Led Penetration Testing (TLPT)?
Only those financial institutions which are systemically important to the EU, as designated by their competent authorities, and globally systemically important institutions automatically. The DORA TLPT requirements stipulate that testing must be conducted at least every three years. Other DORA-covered entities conduct annual conventional testing, but not complete Threat-Led Penetration Testing (TLPT) unless specified.
What is the relationship between TIBER-EU and DORA TLPT?
TIBER-EU is the framework, and DORA TLPT is the law. In February 2025, TIBER-EU updated to comply with DORA’s technical standards. A qualifying TIBER-EU test would meet the DORA obligation, and in practice, TIBER-EU is the accepted way to provide a DORA TLPT.
Does CREST accreditation support DORA TLPT assessments?
Yes. A completed DORA TLPT is not equivalent to CREST accreditation. Nonetheless, CREST-accredited providers offer the framework, audit and capability necessary when looking to undergo threat-led testing. The CBEST vs TIBER-EU and DORA context is a place where experts from CREST come to assist. Evidence of provider competence can be a credible way to identify certified threat intelligence and red team testers.






