SC cleared penetration testing is a mandatory requirement, not a nice-to-have. It applies whenever a test touches UK central government systems, public sector data classified at OFFICIAL or above, or critical national infrastructure. If your engagement sits outside that world, cleared testers are almost never necessary. Getting this distinction wrong costs money either way. You either pay a premium for clearance you don’t need, or discover mid-procurement that your shortlisted supplier can’t actually meet the requirement.
Here’s how to work out which situation you’re in, and what to check before you sign anything.
Table of Contents
Where SC clearance sits in the UK vetting system
UK vetting is layered. The Baseline Personnel Security Standard (BPSS) sits at the bottom: identity, right to work, employment history and an unspent criminal record check. It’s the foundation every higher clearance builds on. By itself, though, it only covers OFFICIAL information.
Counter Terrorist Check (CTC) sits above that. It covers roles near sensitive locations or public figures and is typically valid for ten years. Security Check (SC) is the level that matters most for penetration testing buyers. It permits frequent, unsupervised access to SECRET material, plus occasional supervised access to TOP SECRET, and runs on a roughly ten-year cycle. Developed Vetting (DV) goes further still. It covers uncontrolled TOP SECRET access and involves a considerably deeper, longer investigation.
SC is the clearance most commonly held across government contracting. That makes it the benchmark to check for when you’re scoping SC cleared penetration testing.
Why the CHECK scheme makes SC clearance non-negotiable
The NCSC runs the CHECK scheme so government bodies and CNI operators can trust that a provider’s staff meet a consistent standard. That covers both technical skill and personnel vetting. Every CHECK Team Member and Team Leader must hold at least SC clearance as a floor. This is what most people actually mean when they ask for SC cleared penetration testing on a government contract.
CHECK is mandatory for central government systems handling OFFICIAL data and above. STRAP-classified systems are the exception, and follow separate rules. The rest of the public sector is expected to use CHECK-assured suppliers too, unless a risk owner has specifically decided otherwise. Private-sector organisations are under no obligation to use CHECK providers at all.
CREST accreditation is not the same as CHECK approval
This is where buyers most often get caught out. CREST administers the professional qualifications that the CHECK scheme relies on. Holding CREST accreditation doesn’t automatically make a firm an NCSC CHECK provider, though. Team Leaders need a UK Cyber Security Council Professional Title at Principal level. Team Members need Practitioner level as a minimum. Both re-sit technical exams roughly every three years and log 75 hours of continuing professional development across that cycle.
A supplier can genuinely be CREST accredited and still not be registered as a CHECK provider. If your contract needs CHECK, ask that question directly rather than accepting “we’re CREST certified” as proof. It’s one of several red flags worth checking for when you’re comparing penetration testing companies. Vague scoping and thin reporting are two more.
Clearance is separate from testing methodology
It’s easy to conflate SC clearance with the technical side of a test, but they answer different questions. Clearance is about who is allowed to see your data and systems. Methodology, whether the engagement is run black box, grey box or white box, is about how much information the tester starts with. Even SC cleared penetration testing still needs proper methodology decisions made on their own merits. A good supplier walks you through both conversations separately, rather than bundling them into one line item.
The same logic applies when you’re judging a provider’s methodology more generally. Ask how they scope engagements, how findings get validated before they reach the report, and how remediation advice is prioritised. Those questions matter whether or not clearance is in play.
A quick checklist before you commission the work
Run through this before you commission SC cleared penetration testing:
- Do the named individuals hold current SC clearance today, rather than just being “clearance eligible”?
- Is the supplier registered as an NCSC CHECK provider, if your contract needs one?
- What Professional Title level does the proposed Team Leader hold?
- When do the assigned testers’ clearances expire relative to your contract end date?
- If clearance has to be arranged fresh, has that lead time been built into the schedule?
Building clearance timelines into your procurement
UKSV is upfront that it can’t guarantee a fixed processing time, because each case is different. Straightforward SC applications often complete in around six weeks in practice. Anyone with a complex residency or financial history should expect longer, and busy periods stretch timescales further too.
Treat this as a scheduling risk, not just a compliance box to tick. A supplier whose named testers don’t yet hold clearance may need weeks added to your start date. Ask when a proposed tester’s current clearance was last renewed too. SC runs on a ten-year cycle. A clearance nearing the end of that window can lapse partway through a longer engagement if nobody is watching the date.
What this means for your budget
Don’t assume SC cleared penetration testing will be priced the same as an unrestricted commercial test. Ask suppliers directly whether clearance, CHECK registration or on-site delivery requirements add anything to the quote. Get that broken out as a separate line, rather than folded into a single day rate.
If you’re already working out what to budget for a penetration test, use that as your baseline, then ask what changes once clearance is added to the scope.
Frequently asked questions
Is SC cleared penetration testing required for every government contract?
It’s mandatory for central government systems handling OFFICIAL data and above, through the CHECK scheme. Elsewhere in the public sector it’s strongly expected, unless a risk owner says otherwise.
Can a CREST-accredited firm supply CHECK penetration testing?
Only if it’s separately registered as an NCSC CHECK provider. CREST accreditation and CHECK approval are related but distinct, so ask the supplier directly which one they hold.
Do private companies ever need cleared testers?
Occasionally, usually where a business sits inside a defence or CNI supply chain and a client contract specifies it. Most commercial testing never requires it.
How long is SC clearance valid for?
Roughly ten years, though UKSV won’t promise that as a guarantee for every individual case. Check renewal dates against your contract length.
How long does it take to get SC clearance from scratch?
Straightforward cases often take around six weeks, though complex histories or high demand can push this out considerably. Build the lead time into your project plan rather than assuming it will be quick.
Does the testing methodology, black box, grey box or white box, affect the clearance requirement?
No. Clearance is about who can access your data and systems. Methodology is a separate scoping decision about how much information the tester starts with, and both should be agreed independently.
What is BPSS, and is it enough on its own?
BPSS is the baseline pre-employment check covering identity, right to work and criminal record. It’s the foundation SC and higher clearances build on, but by itself it doesn’t meet a CHECK scheme’s SC clearance requirement.

The underlying test doesn’t change: you still need testers who can find and explain real vulnerabilities. Clearance is a separate, additional control that applies when your data or systems genuinely demand it. Scope it correctly at the outset and you avoid both wasted spend and last-minute procurement headaches.
If you’re not sure whether your own contract needs SC cleared penetration testing or just a CREST-accredited team, Aardwolf Security can talk it through as part of scoping your engagement. Get in touch and we’ll help you work out what the requirement means for your project.
Subscribe to our newsletter
Honest updates, straight to your inbox. Unsubscribe any time.