FCA Penetration Testing Requirements for Firms That Aren’t Tier-One

by Rebecca Sutton

Most firms searching for FCA penetration testing requirements are not the tier-one bank the headlines are about. They are a payments start-up, a wealth manager or an insurance intermediary. They just want to know what “regular testing” means for them. Here is the short answer. The FCA does not name penetration testing in a single rule. But its operational resilience regime, plus the Bank of England’s CBEST and STAR-FS frameworks for the biggest firms, add up to the same outcome. Almost every regulated business ends up needing a penetration test anyway.

Security tester working at a multi-monitor setup during a penetration test

Here is how that obligation breaks down by firm size. And what proportionate testing looks like if CBEST is not built for you.

FCA penetration testing requirements: where the obligation actually comes from

The rule behind most of this sits in SYSC 15A of the FCA Handbook. It tells an in-scope firm to identify its important business services. These are the services that could cause real harm to customers or the market if they broke. The firm then has to set an impact tolerance for each one: the maximum disruption it can absorb before real damage is done.

Once that tolerance is set, the firm has to map what supports each service: people, systems, processes and third parties. Then it has to run scenario testing to check it can stay within tolerance when something goes wrong. A cyber attack is one of the most obvious ways things go wrong. For most firms, penetration testing is the practical way to prove the scenario testing rule is more than paperwork.

Who has to follow SYSC 15A?

The chapter covers banks, building societies, designated investment firms and Solvency II insurers. It also covers enhanced scope SM&CR firms, Recognised Investment Exchanges, payment and e-money institutions, registered account information service providers and consolidated tape providers. Firms based outside the UK are not in scope.

Everyone on that list should already have passed the March 2025 deadline. By then, firms had to show they could operate within their impact tolerances. The FCA is now reviewing evidence, not intentions.

Why “CBEST” keeps coming up, and why it probably does not apply to you

CBEST is the Bank of England’s threat-intelligence-led penetration testing framework. The PRA and FCA deliver it jointly with the Bank. It targets a small group of institutions judged systemically important to UK financial stability: think major banks and core market infrastructure, not a 40-person fintech. A CBEST engagement starts with bespoke intelligence on the threat actors most likely to target that firm. Testers then reproduce those actors’ tactics against real production systems.

Participation is technically voluntary. But the Bank of England, PRA and FCA all treat it as an expectation for the firms it is built for. They also publish an annual thematic review of CBEST results, so participants can benchmark themselves against the wider sector.

STAR-FS: the framework built for everyone else at the top table

STAR-FS (Simulated Targeted Attack and Response for Financial Services) exists because CBEST could not scale to more firms. CREST built it with the Bank of England, PRA and FCA. It uses the same threat-led testing philosophy as CBEST, but with less regulatory and firm overhead. That opens it up to a wider range of banks, building societies, insurers and other regulated firms sitting just below CBEST’s tier-one threshold.

Both sides of a STAR-FS engagement, the threat intelligence and the technical testing, must come from CREST-accredited providers. Providers need specific certifications and real financial-sector experience. That bar exists for a reason: threat-led testing only works if the intelligence behind it is genuine.

If you are not tier-one: what proportionate testing looks like

Here is the part most guides skip. If your firm will never sit CBEST or STAR-FS, you are not off the hook. You are just working from a different standard. The FCA and PRA do not publish a fixed testing calendar for smaller regulated firms. Instead, they expect testing that is regular and matched to your risk profile. It has to show that your important business services would survive a realistic cyber incident.

In practice, that means a scoped penetration test of your internet-facing infrastructure and core applications. Use a provider whose methodology lines up with the standards behind CBEST and STAR-FS, even though the formal engagement itself is out of reach. Supervisors and auditors recognise that standard. It gives you evidence that stands up to scrutiny, not just a tick-box scan report.

That is the practical shape of FCA penetration testing requirements for firms below the tier-one threshold: no named rule, but a real expectation all the same. The best results come from scoping the test around the business services your operational resilience assessment already identified, rather than a generic infrastructure sweep. That way the findings map directly onto what the FCA actually wants to see. Aardwolf Security scopes tests this way for regulated firms as a matter of course, starting from the business services already mapped rather than from scratch.

How often should you actually test?

Once a year is the common floor. But SYSC 15A ties the requirement to risk and change, not a date on the calendar. If you ship new customer-facing features every few weeks, or you just onboarded a major new supplier, an annual cycle will miss what changed in between. Our guide to penetration test frequency covers how to set a schedule around your own pace of change. Retest after any material infrastructure, application or third-party change. Treat the annual test as a minimum, not the whole answer.

Three steps before you scope a test

  • Start from your important business services, not your server list. Map which systems, applications and third parties actually deliver each one. That mapping should already exist from your operational resilience work, and it tells the tester exactly where to focus.
  • Choose a provider on accreditation and sector experience, not price alone. A generic web app test will not satisfy a supervisor asking pointed questions about resilience. Look for genuine financial services references and recognised certifications instead.
  • Agree a remediation and retest plan before the test starts. A report full of findings nobody fixes is weaker evidence than no test at all. It can raise more questions with a supervisor than it answers.

What happens after the test matters just as much

SYSC 15A does not stop at running the test. Once testing, or a real disruption, exposes a weakness, the rule expects the firm to run a lessons-learned exercise. It then has to make the improvements that come out of it, not just file the report. A test that sits unread after delivery, with findings still open six months later, does not meet that bar. Not even if the test itself was thorough.

Build the retest into the original engagement rather than buying it separately later. Confirm that a critical finding is actually fixed, rather than assuming a development team closed it. That is what turns a test report into evidence a supervisor can rely on. If you want a second opinion on how your own testing programme lines up with FCA expectations, get in touch for a no-obligation conversation.

Frequently asked questions

Where do FCA penetration testing requirements actually come from?

Mainly from SYSC 15A’s operational resilience rules, which expect scenario testing of important business services. CBEST and STAR-FS add more specific, threat-led testing on top, but only for firms large enough to fall into their scope.

Does the FCA require every regulated firm to pass CBEST?

No. CBEST only targets systemically important firms. Most FCA-regulated businesses are expected to run regular, proportionate penetration testing instead, under the general operational resilience rules.

What is the difference between STAR-FS and CBEST?

Both use threat-led testing methods. STAR-FS was built to reach a wider range of firms with lower regulatory and firm overhead. CBEST stays reserved for tier-one institutions.

Can Cyber Essentials satisfy FCA operational resilience testing?

Not on its own. Cyber Essentials checks a set of baseline technical controls. Operational resilience testing has to show your important business services can withstand a realistic attack, and only a scoped penetration test can demonstrate that.

How much does an FCA-aligned penetration test cost?

It varies with scope. But a test built around your mapped important business services, delivered by a CREST-accredited provider, usually costs more than a generic infrastructure scan. It needs more preparation and a tighter methodology.

Subscribe to our newsletter

Honest updates, straight to your inbox. Unsubscribe any time.

You may also like