CHECK (NCSC Penetration Testing)

How CHECK works

CHECK operates at two levels — the company and the individual tester.

Company approval: A CHECK-approved company must employ a minimum number of CHECK Team Leaders and Team Members, maintain documented testing methodologies, operate quality assurance processes for deliverables, and hold appropriate insurance and security clearances. The NCSC assesses companies through application, interview, and ongoing compliance monitoring.

Individual tester approval: CHECK recognises two roles. A CHECK Team Member has demonstrated competence in penetration testing through a combination of qualifications (typically CREST certifications) and practical experience. A CHECK Team Leader has additional experience and the authority to lead engagements and sign off reports. Both roles require security clearance to the level appropriate for the systems being tested — typically Security Check (SC) or Developed Vetting (DV).

Every CHECK engagement must be led by an approved CHECK Team Leader, who takes responsibility for the scope, methodology, and quality of the final report. This individual accountability is a distinguishing feature of the scheme.

CHECK vs CREST

CHECK and CREST are related but distinct:

CHECKCREST
Governed byNCSC (UK government)CREST (industry body)
ScopeUK government and public sector systems onlyAny organisation, any sector, internationally
VettingGovernment security clearance requiredNo government vetting
MandatoryRequired for testing HMG systemsVoluntary (but widely expected by procurement)
QualificationUses CREST exams as part of the pathwayIndependent certification scheme

CREST certifications form part of the pathway to CHECK approval — a tester typically holds CREST CRT or CCT before applying for CHECK status. However, holding a CREST certification alone does not make a tester CHECK-approved. The additional requirements are government security vetting and NCSC assessment.

Many penetration testing firms hold both CHECK approval and CREST membership. CHECK is required for government work; CREST is expected across private sector procurement, particularly in financial services and critical infrastructure.

When CHECK is required

CHECK penetration testing is required or expected in several contexts:

  • Government departments — all central government departments must use CHECK-approved companies for penetration testing of systems that process OFFICIAL, SECRET, or TOP SECRET data
  • Public sector procurement — the G-Cloud framework and other Crown Commercial Service procurement routes reference CHECK as a requirement for security testing services
  • Critical national infrastructure — organisations assessed under the NCSC CAF may need CHECK-level testing for their systems, particularly where they interface with government networks
  • Defence supply chain — MOD suppliers and defence contractors are typically required to use CHECK-approved testers for systems handling defence data
  • NHS and health — NHS Digital and health sector bodies increasingly require CHECK-approved testing for systems handling patient data connected to government networks

For private sector organisations with no government connection, CHECK is not required. CREST-certified penetration testing is the recognised standard for commercial environments.

Cyberfort and CHECK

We provide CHECK-approved penetration testing for government departments, public sector organisations, and critical national infrastructure operators. Our CHECK Team Leaders hold the security clearances and NCSC approval required to test systems processing HMG data. We deliver infrastructure, application, and network penetration testing through our penetration testing service, covering both CHECK-mandated government work and CREST-certified commercial engagements. For organisations on the G-Cloud framework, our services are available through Crown Commercial Service procurement routes.

Related glossary terms

  • CREST Certification — the industry certification scheme for penetration testers, which forms part of the CHECK qualification pathway
  • Red Teaming — adversarial testing that goes beyond standard penetration testing to simulate real-world attack scenarios
  • G-Cloud — the UK government procurement framework that references CHECK as a requirement for security testing services
  • CBEST — the Bank of England’s threat intelligence-led penetration testing framework for UK financial services

External references

Frequently asked questions

Is CHECK penetration testing mandatory?

CHECK is mandatory for penetration testing of UK government systems that process HMG data classified at OFFICIAL or above. It is also widely required by public sector procurement frameworks including G-Cloud and Crown Commercial Service agreements. For private sector organisations with no government connection, CHECK is not required — CREST certification is the recognised standard.

What is the difference between CHECK and CREST?

CHECK is a government scheme run by the NCSC that authorises companies and individual testers to assess HMG systems. CREST is an industry body that certifies penetration testers and companies for commercial work. CREST certifications form part of the pathway to CHECK approval, but CHECK additionally requires government security vetting and NCSC assessment. A CREST-certified tester is not automatically CHECK-approved.

How do I find a CHECK-approved company?

The NCSC maintains a list of CHECK-approved companies on its website. You can also find CHECK-approved providers through the G-Cloud framework on the Digital Marketplace. When commissioning a CHECK engagement, verify that the named Team Leader holds current CHECK approval and the appropriate security clearance for your data classification level.

Awards and Accreditations

blue light commercial logo

Contact Us

Cyberfort Ltd
Venture West,
Greenham Business Park, Thatcham,
Berkshire,
RG19 6HX

+44 (0)1304 814800

[email protected]


Cyberfort
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.