What is CREST accreditation? A buyer's guide to the badge
The CREST logo appears on a large number of cyber security supplier websites, usually somewhere near the bottom of the homepage, alongside ISO 27001 and Cyber Essentials. Most buyers read it as a single quality mark and assume that the provider has been independently assessed.
However, CREST operates several distinct things under one brand - three tiers of company status, six accreditation disciplines, a separate set of individual exams, and a group of government and regulator schemes it administers on behalf of others. "We're CREST accredited" can describe a provider that has had its methodologies independently reviewed for the exact service you are buying. But it can also describe a provider that has paid a registration fee and signed a code of conduct.
This article sets out what lies behind the badge and how to check a supplier's claim in about two minutes.
What CREST is
CREST is a not-for-profit body registered in the UK, operating internationally through regional councils covering the UK, Europe, Asia, Australasia, North America, and the Middle East and Africa. It has two separate jobs:
· It accredits companies. An organisation submits evidence about its processes, methodologies and data handling, CREST reviews it, and the company is awarded accreditation in one or more disciplines.
· It certifies individuals. Practitioners sit exams - CPSA, CRT, CCT and others - that test technical competence. These are personal qualifications that belong to the individual, not the employer.
The two are related but not interchangeable. A company can employ CREST-certified testers without holding company accreditation. A company can hold accreditation while a specific individual on your engagement holds no CREST certification at all. If the competence of the named delivery team is important to you, that is a separate question from whether the company logo is legitimate.
The six accreditation disciplines
CREST accreditation is not awarded to a company as a whole. It is awarded per discipline. The current list is:
- Penetration Testing
- Vulnerability Assessment
- Intelligence Led Penetration Testing (STAR)
- Threat Intelligence for Simulated Attack (STAR)
- Incident Response
- Security Operations Centres
Each is assessed against its own standard, with its own requirements and evidence. Existing members can apply to add further accreditations, at an application fee starting from £1,500 with no additional annual fee.
This is the point most likely to be missed during the procurement process. A provider accredited for Penetration Testing has been assessed on how it scopes, runs and reports tests. It has not been assessed on how it staffs a 24/7 monitoring rota, how it manages analyst fatigue, or how it transfers your data when the contract ends. Those are all part of the Security Operations Centres standard, which is a different assessment entirely. If you are buying a managed SOC from a company whose accreditation is in penetration testing, the badge on the proposal is telling you about a different service.
Ask which discipline. It is a fair question and a well-run supplier will answer it without hesitation.
The three tiers: Pathway, Pathway+ and Member
CREST runs an Accreditation Pathway with three stages, designed to bring less mature providers into the ecosystem and move them towards full accreditation. The stages differ in one respect that should matter enormously to a buyer - how much of the claim has been checked by somebody other than the supplier.
Stage one: Pathway.
A registration process. The organisation provides company details, meets basic company requirements and signs the CREST Code of Conduct. There is no assessment of methodology or capability. CREST issues a Pathway logo and lists the company on its website. The annual fee is £250 and organisations are expected to progress to Pathway+ within two years.
Stage two: Pathway+.
The organisation completes a self-assessment against the CREST organisational standards and at least one discipline standard, rating itself against a series of objectives, adding commentary and confirming that evidence exists. It then formally attests that the self-assessment is accurate and submits it. CREST does not independently review the results at this stage - the output is a development and gap-analysis tool. A Pathway+ logo is issued. The annual fee is £1,500, and organisations are expected to progress to membership within two years.
Stage three: Member.
This is the stage where accreditation is awarded. The organisation submits a full application for independent review, with evidence supporting it, covering the complete company requirements and the overall requirements of one or more disciplines. Employees delivering the service must be formally registered on the skilled persons register to demonstrate they are suitably competent and qualified. Accreditation is not guaranteed, and accredited companies undergo periodic reassessment to keep it.
CREST is explicit that Pathway and Pathway+ organisations must present themselves as Pathway or Pathway+ and not as CREST-accredited Members. The logos are visually distinct, but in a PDF proposal reduced to 40% and printed in greyscale, they are considerably less discrete.
None of this makes Pathway status worthless. A young provider working through the standards in public is doing something more honest than one that ignores them. But Pathway is a statement of intent, Pathway+ is a self-marked exam, and only Member status carries independent assessment.
How to verify a claim
Only CREST Members are searchable by buyers through the supplier selection functionality on the CREST Marketplace. Pathway and Pathway+ organisations are listed on the CREST website, but they do not appear in the buyer-facing supplier search.
That gives you a relatively easy test:
- Go to the CREST Marketplace supplier search
- Search for the supplier by name
- If they appear, open the profile and check which disciplines they are accredited in
- Compare that list against the service you are buying
If a supplier claiming accreditation does not appear in the supplier search, an explanation is needed. It may be a regional listing issue or a recent name change. It may also be that they hold Pathway or Pathway+ status rather than accreditation.
Do this before the shortlist, not after. It takes less time than reading a single page of the proposal.
CREST and the regulator schemes
For regulated buyers, particularly in financial services, CREST also underpins a set of government and regulator programmes. These are separate from CREST's own accreditations and carry their own requirements:
- CBEST - Bank of England threat-led penetration testing for UK financial services
- GBEST - the UK Cabinet Office equivalent for government
- TIBER-EU - the European Central Bank framework
- CHECK - the NCSC scheme for testing UK government, public sector and critical national infrastructure systems
- NCSC Cyber Incident Response and Cyber Incident Exercising - assured incident response and exercising providers
- ASSURE - the UK Civil Aviation Authority scheme
- iCAST (Hong Kong Monetary Authority) and Dubai DESC Cyber Force outside the UK
If a tender requires CHECK, CREST accreditation alone does not satisfy it. If it requires CBEST, the same applies. These are different qualifications with different assessment routes, and a supplier that holds one does not automatically hold the others. Where your regulator names a specific scheme, name that scheme in your requirements rather than writing "CREST accredited or equivalent" and expecting respondents to interpret it correctly.
What accreditation does not tell you
Accreditation assesses how a provider works. It does not assess how well the provider will work for you.
It tells you nothing about price, contract terms, cultural fit, whether the team has worked in your sector, whether their tooling integrates with your estate, or what happens on a Tuesday afternoon when something goes wrong and you need a human being to answer the phone. It is a baseline, not a ranking. Two accredited providers can deliver services of very different quality, and both remain compliant with the standard.
Used properly, accreditation narrows the field so that you can spend your evaluation effort on the things that differentiate. Used improperly, it becomes a box on a scoring matrix that lets a weak proposal through.
The most useful thing you can do with a CREST standard is read it and turn its requirements into your questions. For managed SOC specifically, we have set out the six domains of the CREST Security Operations standard and how to use them as a tender agenda in What is CREST SOC accreditation?
Talanos and CREST
Talanos has CREST accreditation for Security Operations. We put the badge on our proposals because buyers ask for it, and we would rather be assessed than assert. But we would also rather you interrogated it than took it on trust - including ours.
If you are building a specification for a managed SOC, third-party risk programme or security testing engagement and want a second opinion on what to require, we are happy to have that conversation without a proposal attached.
Ready to strengthen your cyber resilience?
Talk to one of our specialists about how Talanos can support your team.
Book a consultation →