Is penetration testing legal in the UK? Only just, and only because of a piece of paper. Strip away the reputation and the tooling, and what a penetration tester does technically matches the definition of a crime under the Computer Misuse Act 1990. The only thing standing between a legitimate security engagement and a Section 1 offence is written authorisation. Intent, skill and good judgement count for nothing in the eyes of the law.

That should concern anyone treating a pen test as a commodity purchase. It is worth understanding properly before you sign anything.
Table of Contents
Is penetration testing legal in the UK? The short answer
Yes, but only when the system owner has given clear, written authorisation first. That authorisation is the entire legal basis for the work. Without it, the same technical actions are a criminal offence rather than a security service, no matter how good the tester’s intentions are.
The uncomfortable truth about the Computer Misuse Act
The Computer Misuse Act 1990 was written before most of the internet existed. It has never been rewritten with penetration testing in mind. Section 1 criminalises causing a computer to perform a function with intent to secure unauthorised access to a program or data. The person must know the access is unauthorised. That is the whole test. Motive does not appear anywhere in it.
The Crown Prosecution Service’s guidance confirms the point bluntly. There is no mention of consent-based security testing anywhere in the framework. That means “I was trying to help” carries no legal weight if the access itself was not authorised.
There is no “ethical hacker” exemption, and there might not be one for a while
Plenty of people assume good intentions offer some kind of shield. They do not. The industry has been campaigning to fix that gap for years. The CyberUp Campaign has pushed for a statutory public interest defence for years. It argues the current law creates a chilling effect on legitimate research and leaves UK cyber professionals with less legal protection than counterparts in the US, France or Germany.
Movement is finally happening. The May 2026 King’s Speech confirmed the Act would be updated through a coming National Security Bill. Related amendments have also been tabled in the Crime and Policing Bill and the Cyber Security and Resilience Bill. Yet according to reporting on the reform, no draft legislation exists yet, and nothing is expected in Parliament before later in 2026. Anyone testing systems today is working entirely under the old rules. A future defence will not retroactively protect work done now.
Where testers actually get caught out
The risk rarely comes from a rogue actor pretending to be a legitimate tester. It comes from scope drift on genuine engagements. A tester finds a foothold on an authorised system. It connects to something interesting nearby. They follow the trail without checking whether that adjacent system was ever named in the agreement.
Or a client mentions offhand that a related subsidiary “probably has the same issue.” The tester takes a look without getting it added to the written scope first. Neither scenario involves malice. Both meet the legal definition of unauthorised access the moment the tester steps past what was actually signed off.
A supplier’s discipline around scope matters more than their marketing for exactly this reason. Ask how a provider handles the moment testing surfaces something interesting outside the agreed boundary, and watch for a vague answer. Our own guide on choosing a penetration testing company covers the wider red flags worth checking before you sign. Scope discipline sits near the top of that list.
Cross-border infrastructure adds another layer most people overlook. Systems hosted overseas add complexity, and so does a tester based outside the UK probing systems with a UK link. More than one country’s law can apply at once. A test that is comfortably authorised under a UK client’s letter can still fall foul of hosting terms or local law elsewhere. That is one more reason scope documents need to name infrastructure precisely rather than describing it loosely.
Why “the client said it was fine” is not a defence
Verbal permission feels reassuring in the moment. It means almost nothing afterwards. If an incident, dispute or audit ever puts an engagement under scrutiny, what matters is the documented authorisation on file. That means exact systems, exact dates, exact techniques, signed by someone with genuine authority over those systems.
Case law backs this up. In R v Bow Street Magistrates’ Court (ex parte Allison), the courts confirmed that even employees testing their own employer’s systems can be caught by the Act if they exceed access limits the employer clearly defined. Being on the payroll is not the same as being legally authorised, and neither is being trusted by a client contact.
What accredited providers do differently
This is where accreditation earns its keep. It is not a legal requirement for private-sector work, but it is evidence of a provider that treats authorisation as procedure rather than an afterthought. NCSC’s CHECK scheme is mandatory for testing UK government and critical national infrastructure systems, precisely because it enforces rigorous scoping and conduct standards. Many organisations outside that requirement still ask about CREST accreditation for the same reason. It signals a tester who will stop at the agreed boundary, document everything, and know exactly what they are and are not authorised to touch.
Frequently asked questions
Is penetration testing illegal without written permission?
Yes. Without documented authorisation from the genuine system owner, the actions involved meet the legal definition of unauthorised access under Section 1 of the Computer Misuse Act, regardless of the tester’s intent.
Can good intentions protect a tester who exceeds scope?
No. The Act does not include a good-faith or public interest defence. Intent is legally irrelevant if the access itself was not authorised in advance.
Is a statutory defence for ethical hackers coming?
Reform is in progress but not yet law. Updates to the Computer Misuse Act are expected via a National Security Bill, but no draft text has been published, and passage is not expected before later in 2026.
Does being an employee make internal testing automatically authorised?
No. Case law confirms employees can still commit an offence if they exceed the access limits their employer clearly set. Internal teams need a documented scope too, not just a job title.
Does CREST or CHECK accreditation guarantee a legal test?
Accreditation is not itself a legal requirement outside CHECK’s mandatory public sector scope. It is a strong signal that a provider takes authorisation and scope discipline seriously, and that is what actually keeps a test on the right side of the law.
What should worry a business more, an unlicensed tester or a vague scope?
A vague scope. Certifications matter, but a precisely written, signed authorisation is the document that actually determines whether the engagement is lawful. Even a highly qualified tester working from a loose or verbal scope carries real legal exposure for both sides, while a properly scoped engagement stays lawful regardless of which individual carries out the work.
Working with a provider that treats authorisation as non-negotiable removes the guesswork. Aardwolf Security builds proper scoping and sign-off into every engagement before testing starts. Get in touch if you want a test that stays firmly on the right side of the line.
Subscribe to our newsletter
Honest updates, straight to your inbox. Unsubscribe any time.