Every penetration testing proposal arrives covered in acronyms, and most buyers nod at them without knowing which ones matter for their situation. Two of them are awarded to people. One is granted to companies. They are not interchangeable, and asking for the wrong one either costs you money you did not need to spend or leaves you with a test your customer will not accept.

Declared interest

I have worked at CREST accredited firms, and I hold Cyber Scheme certification. I have also been involved since the beginning as a technical assessor for The Cyber Scheme's professional titles. So I have a stake in one of the three schemes discussed below, and a view about tester quality that follows from it. Both are stated openly further down, clearly labelled as opinion, so you can weigh them accordingly. The factual sections are sourced and would read the same from anyone.

CHECKA scheme for companies, not a tester qualification
Two routesCREST and Cyber Scheme exams both lead into it
Most buyersDo not need CHECK, and are sold it anyway

The single most common misunderstanding

CHECK is not a qualification. No individual “is CHECK”. CHECK is a scheme operated by the National Cyber Security Centre under which approved companies may conduct authorised penetration tests of public sector and critical national infrastructure systems.

To hold that approval, a company must satisfy the NCSC’s requirements, which include employing suitably qualified staff, holding appropriate security clearance, following recognised methods, and reporting in the format government expects. The individuals working on those engagements hold qualifications, and it is those qualifications that come from CREST or The Cyber Scheme.

So the accurate way to read a proposal is: CHECK tells you the company is approved to test government systems; CREST or Cyber Scheme tells you what the person actually doing the testing has demonstrated.

The route into CHECK runs through either body

To work on CHECK engagements as a CHECK Team Member or CHECK Team Leader, an individual must hold the relevant qualification from either The Cyber Scheme or CREST. The NCSC treats both as evidence of technical competence for those roles; neither is a lesser route, and there is no third path that skips them.

Company accreditation works the same way. Both bodies accredit organisations, not just individuals. CREST has long accredited companies against standards covering policy, process, competence, insurance and quality management, and The Cyber Scheme now offers company accreditation as well. So “accredited company” on a proposal may reasonably come from either.

That is worth stating plainly because the market often implies otherwise. If someone tells you one of these routes is the only recognised path into CHECK, or the only way a company can be accredited, they are describing their own certification rather than the requirement.

What each one is

The Cyber Scheme. A UK certification body whose examinations are, like CREST’s, recognised by the NCSC. Its Cyber Scheme Team Member qualification maps to CHECK Team Member status, and Cyber Scheme Team Leader maps to CHECK Team Leader. Examinations are practical and taken in person at its examination centre, and the Team Leader assessment is built to replicate a real engagement: a scoping session, the technical assessment itself, and a client debrief. The Cyber Scheme also accredits companies, so an organisation can hold Cyber Scheme accreditation as well as its testers holding Cyber Scheme certifications.

CREST. An international not-for-profit membership body, recognised by the NCSC, that certifies individuals and accredits companies. Individual certifications run in tiers, from Practitioner through Registered to Certified, with the Certified level acting as the senior benchmark. CREST also accredits organisations against standards covering policy, process and competence, which is why you see it on company letterheads as well as on people.

CHECK. The NCSC’s own scheme, as above. Approved companies test systems processing information at OFFICIAL and above, testers typically require Security Check clearance, and reports follow the format government requires so that findings can be compared across departments.

Tiger Scheme. A fourth name you will occasionally see, administered through the University of South Wales, with technical requirements comparable to the others and recognised for the same purposes.

Side by side

CHECKCRESTThe Cyber Scheme
What it applies toCompaniesIndividuals and companiesIndividuals and companies
Run byNational Cyber Security CentreInternational membership body, NCSC recognisedUK certification body, NCSC recognised
Primary purposeApproving providers to test government and critical national infrastructureAssuring competence and company standards, internationallyAssuring tester competence, practically examined
LevelsTeam Member and Team Leader roles within an approved companyPractitioner, Registered, CertifiedTeam Member, Team Leader
ClearanceSecurity clearance normally requiredNot inherentlyNot inherently
Who needs itCentral government, public sector, critical national infrastructureWidely recognised across the private sector, and a route into CHECKRecognised for the same purposes, and equally a route into CHECK
Exam styleNot an exam. A scheme built on the qualifications either side of itWritten and practical, by tierPractical, in person, mirroring a real engagement

Which does your organisation actually need?

This is the part that saves money, and the government’s own guidance answers it plainly.

For an IT Health Check in central government, the Cabinet Office guidance is direct: central government customers should use the CHECK scheme and ensure their chosen partner is part of it.

For everyone else, the same guidance says non-central government customers may use Tiger Scheme, CREST approved services, or The Cyber Scheme.

Source: IT Health Check (ITHC): supporting guidance, Cabinet Office. Contains public sector information licensed under the Open Government Licence v3.0. © Crown copyright.

Read that carefully, because a great deal of unnecessary spend lives in the gap. CHECK approved providers generally charge a premium, and rightly so given the clearance, vetting and overhead they carry. If you are a manufacturing business in Wiltshire testing your own web application, that premium buys you nothing your customers will ever ask about.

The buying rule

If a contract, a framework or a government customer specifically requires CHECK, you need a CHECK provider and nothing else will do. If it does not, you need a competent tester with a recognised qualification, and CREST or Cyber Scheme certification tells you that. Paying CHECK rates when nobody has asked for CHECK is the most common avoidable cost in penetration testing procurement.

The part where I declare a preference

Everything above is factual and sourced. What follows is opinion, and I have an interest in it: I am a technical assessor for The Cyber Scheme’s professional titles, and I have previously worked at CREST accredited firms.

Both routes are recognised by the NCSC as evidence of competence, and nothing below changes that. Within that parity, my personal preference is The Cyber Scheme, and it is not a view I started with: I came to it from the other side, and the quality of the process won me over.

The reason is the format. Cyber Scheme examinations are practical and sat in person at their examination centre, under observation, against systems the candidate has not seen before. The Team Leader assessment goes further and mirrors the shape of a real engagement rather than isolated technical tasks: scoping the work with a client, carrying out the assessment, then explaining findings back to a client in a debrief. That last element matters more than the industry generally admits, because a tester who cannot explain what they found to a non-technical director has delivered half a service.

Realism is the other reason. Testing someone in a controlled centre, in person, on unfamiliar targets, produces a stronger signal about capability than most alternatives. It is harder to prepare for narrowly, and easier to trust as a proxy for whether someone can actually do the job on a client site.

The honest counterweight, because this is an opinion piece and not an advertisement: CREST is the more internationally recognised badge, its Certified level represents a genuinely senior technical standard, and its company accreditation covers organisational things individual certifications do not, such as process, insurance and quality management. Plenty of excellent testers hold CREST certifications and nothing else. If your customer’s procurement team asks for CREST specifically, CREST is the right answer regardless of my preference, and anyone telling you otherwise is selling rather than advising.

What to ask a provider, whichever badge they hold

  • "Who specifically will test us, and what do they hold?" Company accreditations are earned by organisations; the work is done by a person. Ask for that person's qualifications by name, not the company's.
  • "Do we actually need CHECK for this?" A provider willing to tell you that you do not is worth more than one who lets you assume you do.
  • "How much of this is manual?" A qualification tells you a tester can work by hand. It does not guarantee the engagement is priced to let them.
  • "Will the tester present the findings to us?" If the person who did the work is not in the debrief, something has been lost between the testing and the telling.
  • "Is retesting included?" Verification of fixes is where testing turns into improvement.

Where Malwise sits, stated plainly

Our penetration testing is delivered by testers certified through The Cyber Scheme. We are not a CHECK provider, and we will say so before you ask: if your requirement specifies CHECK, you need a CHECK approved company, and we will tell you that rather than talk you out of your own requirement.

For the great majority of UK businesses, that requirement never appears. What appears is a customer, an insurer or a board asking whether the testing was done properly by someone competent, and that is a question we can answer with a name and a certification rather than an acronym.

If you want a straight answer about which of these your situation actually calls for, including when the answer is “someone other than us”, get in touch or call 01722 445972. More detail on the service is on our penetration testing page, and we have written separately about what you are actually buying when you choose between assessment and testing.