If you’ve ever tried to hire a penetration testing firm, you’ll know how confusing it gets. CREST, OSCP, CHECK, Tiger Scheme, Cyber Scheme. Every provider throws a wall of acronyms at you, and most businesses have no idea which ones actually count for anything.
That’s a real problem, because picking the wrong provider usually means you’ll end up with a glorified vulnerability scan packaged as a pen test, complete with a padded report that tells you almost nothing useful about your actual risk. So let’s learn what CREST certification actually means, how testers earn it, what it does for the quality of your test, and what you should be asking before you sign on the dotted line.
What CREST Actually Is
CREST stands for the Council of Registered Ethical Security Testers. It’s a not-for-profit accreditation body that sets standards for companies and individual testers carrying out penetration testing, threat intelligence, vulnerability assessments, and incident response. It exists because the pen testing market had a serious quality problem.
Literally anyone could call themselves a pen tester, run an automated scanner, and hand over a report full of generic findings. CREST was created to sort that out by putting a proper framework around competence, ethics, accountability, and consistency.
For a company to become CREST-accredited, it’ll need to pass assessments covering data handling, methodology, quality assurance, and the qualifications of its testers. Those assessments get reviewed by GCHQ and the National Cyber Security Centre (NCSC), which gives them a level of authority that most commercial certifications simply can’t match.
How Testers Earn CREST Qualifications
The individual pen testers at a CREST-accredited firm will hold their own certifications too, and these aren’t easy to get. CREST’s professional-level qualifications, like the CREST Registered Penetration Tester (CRT) and CREST Certified Tester exams, include hands-on components. Candidates have to actually exploit vulnerabilities in live environments to pass.
That’s a big deal compared to certifications that rely purely on multiple-choice questions. Someone who’s passed a CREST exam has proven they can find and exploit real vulnerabilities, not just recognise them on paper. The exams also cover legal and ethical requirements, so you’ll know the person testing your systems understands their obligations around data handling and responsible disclosure.
What CREST Means for the Quality of Your Test
When a CREST-accredited firm runs a pen test, they’ll follow a defined methodology. That usually means proper scoping before anything starts, manual testing alongside automated tools, documented evidence for every finding, and a report that ranks vulnerabilities by actual business impact instead of just slapping a generic severity label on them.
This matters because the gap between a good pen test and a bad one is huge. A poor test might flag a hundred “medium” vulnerabilities pulled straight from scanner output, with zero context on which ones are genuinely exploitable or which ones would cause the most damage if someone got in. A CREST-accredited test will give you findings your team can actually do something with.
The report is covered by the same framework. Write-ups from accredited providers, like Equilibrium’s pen testing team, go through internal quality assurance before they’re issued, and that review is what catches recycled severity ratings, findings with no supporting evidence and remediation advice that’s too vague to act on. Without that layer, you’re reading whatever the tester typed up on the last day of the engagement, with no way of knowing what’s been checked.
Questions to Ask Before You Hire a Pen Testing Provider
When you’re reviewing proposals, a few pointed questions will quickly separate the qualified firms from those that aren’t up to standard:
- Are you CREST accredited, and can you provide your membership number? Any legitimate CREST member will be listed on the CREST website. If they can’t point you to their listing, that’s your first red flag.
- Which CREST qualifications do your testers hold? You want to know the individuals doing the work are qualified, not just the company name on the certificate.
- What’s your methodology? A credible provider will walk you through how they work, from scoping and reconnaissance through to exploitation and reporting. If the answer is vague, move on.
- How do you handle critical findings during a test? Good firms will have an escalation process for anything urgent found mid-test, instead of sitting on it until the report lands two weeks later.
- Can you share a sample report? This tells you a lot. Look for clear remediation steps, evidence of manual testing, and findings ranked by business risk.
Red Flags That Suggest a Provider Isn’t Up to Scratch
There are a few warning signs that should make you pause.
- If a provider quotes you a fixed price without scoping your environment first, they’re guessing.
- If their report is mostly automated scanner output with barely any manual analysis layered in, you haven’t really had a pen test.
- If they can’t name the certifications their individual testers hold, it’s a clear red flag.
- If they dodge questions about how they work, that’s a strong signal they’re not operating at a professional level.
One last one watch for: firms that promise to test everything in a day or two. A thorough pen test takes time. Rushed timelines almost always mean corners are being cut, and that defeats the whole purpose of testing in the first place.
A Certification You Can Verify Yourself
One of the best things about CREST accreditation is that you can check it yourself. You can look up a company’s membership status directly on the CREST website, and you can confirm whether individual testers hold valid qualifications.
That transparency sets CREST apart from certifications where there’s no easy way for a buyer to verify what they’re being told. When you’re trusting a firm with access to your systems and your data, that kind of accountability matters.









