A tender document names CHECK penetration testing as a hard requirement. The compliance team pulls up its usual supplier list, only to find most of those firms hold CREST accreditation, not CHECK. The two get treated as interchangeable in casual conversation, but a procurement officer checking credentials against a government contract will not accept one for the other.

CHECK is the UK’s official penetration testing scheme for assessing government systems, administered directly by the National Cyber Security Centre (NCSC). Under the current CHECK Scheme Standard v1.1, published in November 2024, only companies employing NCSC-approved testers can legally describe their work as CHECK testing. This guide explains what CHECK actually certifies, how it differs from CREST, and who needs it. It also covers what changed when the scheme moved its qualification requirements onto the UK Cyber Security Council’s framework in 2025 and 2026.

What Is CHECK Penetration Testing?

CHECK pen testing is the NCSC’s scheme for accrediting companies and individuals to carry out penetration testing on UK government and public sector systems. The scheme name itself is shorthand for the process: government customers commission an “IT Health Check.” CHECK-approved firms are the only ones licensed to deliver it under that name.

Unlike a general commercial penetration test, CHECK testing follows a formal standard covering three areas: company-level approval, individual tester qualifications, and reporting requirements. The CHECK Scheme Standard sets out exactly how a testing company must operate to keep its approval. Testers, in turn, must independently hold current qualifications before they can work on a CHECK engagement.

Crucially, CHECK pen testing is not a certification an individual organisation earns for its own systems. Instead, it certifies testing companies and testers as qualified to test other organisations’ systems. A government department doesn’t get CHECK certified. It commissions a CHECK-approved supplier to perform its ITHC.

source: https://qualysec.com/check- ...
पीछे आगे