If a tender document or a public sector client has asked for a “CHECK penetration test”, they mean something specific. It is testing carried out by a company approved under the National Cyber Security Centre’s CHECK scheme, the UK government’s accreditation for penetration testers working on OFFICIAL-classified and critical national infrastructure systems. That is more specific than a standard pen test, and outside government work it usually is not the accreditation you need.

Here is what CHECK is, why it exists, and how to tell whether your organisation actually needs a CHECK penetration test.
Table of Contents
Why does the CHECK scheme exist?
Government departments buy penetration testing from the open market, the same way any business does. But they cannot easily verify a supplier’s competence for every procurement. CHECK solves that by having the NCSC vet the testers once, centrally, so any government buyer can trust the accreditation rather than re-checking a supplier’s credentials from scratch.
The NCSC describes penetration testing itself as “a method for gaining assurance in the security of an IT system by attempting to breach some, or all, of that system’s security, using the same tools and techniques as an adversary might.” CHECK sits on top of that definition. It is a quality gate on who is allowed to do the breaching, not a different kind of test.
Who is required to use a CHECK-approved tester?
The requirement narrows quickly the further you get from central government:
- Central government departments handling OFFICIAL-classified systems, where CHECK is generally required.
- Public sector bodies more broadly, where it is strongly recommended rather than universally mandatory.
- Critical national infrastructure operators, where regulators and sector frameworks often expect it.
- Everyone else, where CHECK is simply not part of the picture, and a commercially accredited tester is the norm.
A useful test: if nobody in your procurement or compliance chain has specifically asked for CHECK by name, you almost certainly do not need to source one.
CHECK vs CREST: same trust problem, two different answers
CHECK and CREST both exist to answer “can this tester be trusted with our systems”, but they were built for different buyers and work differently under the hood.
| CHECK | CREST | |
|---|---|---|
| Governing body | NCSC (UK government) | Independent international membership body |
| Primary market | Government, public sector, CNI | Commercial sector, globally |
| What gets accredited | Individual testers and team leaders | The testing company and its individual staff |
| Personnel vetting | Minimum SC clearance for all staff | Standard background checks, no mandated clearance level |
CHECK Team Leaders must hold the Security Testing title from the UK Cyber Security Council at Principal level as a minimum. Every member of a CHECK team also needs an NCSC-approved qualification plus SC clearance. That vetting overhead is a large part of why a CHECK penetration test costs more than a broadly equivalent commercial one.
What does a CHECK penetration test report contain?
A CHECK penetration test report follows a format the NCSC controls, rather than one the testing company sets independently. Vulnerabilities are rated High, Medium, Low or Informational, with CVSS scores permitted as a supplementary detail rather than a replacement for that rating. The value of this standardisation is comparability. A government buyer reviewing reports from several different CHECK suppliers over several years reads the same structure each time, which makes trend-spotting and audit far easier than a mix of proprietary report formats would.
It is also worth knowing what any penetration test does not tell you, whether it is a CHECK penetration test or a standard commercial one. It confirms your security posture at the moment the test was run, nothing more. A year or more can pass between engagements, and new weaknesses can appear well before the next one is scheduled. A test is a snapshot to act on, not a certificate that stays valid until the next renewal date.
Who keeps CHECK providers honest once they’re accredited?
The NCSC does not simply approve a company and move on. It reviews CHECK providers’ reports over time to make sure output continues to meet the scheme’s standard, and a provider that consistently underperforms can be removed from the list. That ongoing oversight is arguably the more valuable part of the scheme for buyers. It means the accreditation you see today reflects recent performance, not a qualification earned years ago and never revisited.
Day to day, though, the relationship is a normal commercial one. The buyer contracts directly with the CHECK provider, agrees scope and rules of engagement, and manages the engagement much as it would any other penetration test. The NCSC’s role is setting and policing the standard, not running individual projects.
Commissioning a CHECK penetration test: what to check first
A few checks make the procurement process considerably smoother if CHECK is genuinely what your contract requires:
- Verify current status on the NCSC’s own published list, not on the strength of a provider’s own claims.
- Confirm which staff hold Team Leader status, since sign-off at that level is a scheme requirement.
- Ask about experience with comparable government or CNI environments, including any legacy systems or unusual architecture your estate includes.
- Agree evidence-gathering and reporting timelines early, since the standard format does not remove variation in provider turnaround times.
Most of this checklist applies whether or not CHECK is in play. For broader guidance on vetting any supplier, see our guide on how to choose a penetration testing company.
So which one does your organisation need?
If you are bidding for central government work, supplying a CNI operator, or your contract names CHECK specifically, you need a CHECK penetration test provider and there is no substitute. For almost everyone else, a CREST-accredited test covers the same underlying assurance: vetted testers, a recognised methodology, and a report that clients, auditors and insurers will accept without question.
Paying for CHECK when your contract does not require it does not buy a better test. It buys a different accreditation, priced for a different threat model, sold to the wrong buyer.
If a CREST-accredited test is what your organisation actually needs, Aardwolf Security’s penetration testing team can scope an engagement around your systems and budget. Not sure which accreditation your contract requires? Get in touch and we will help you work it out before you request quotes.
Frequently asked questions
Is CHECK the same as an IT Health Check (ITHC)?
Yes, in practice the terms are used interchangeably. ITHC is the older name for testing carried out under the CHECK scheme, and you will still see it used in older government policy documents and contracts.
Do CHECK testers use different tools than commercial testers?
Not fundamentally. The tools and techniques mirror those an adversary might use, per the NCSC’s own definition. What differs is the personnel vetting, the qualification requirements, and the standardised reporting format the scheme imposes.
Can a small or mid-sized business request a CHECK penetration test?
Nothing legally prevents it, but most CHECK providers are structured around public sector procurement. The clearance overhead makes it a poor fit for a business that does not have a contractual reason to need it, and a CREST-accredited tester is the more practical route.
Does holding CHECK accreditation mean a company is better than a CREST-only provider?
Not automatically. It means the company can legally take on government work requiring CHECK. Many CREST-accredited firms deliver excellent commercial testing without ever needing CHECK status, because their client base does not require it.
How do I verify a provider genuinely holds CHECK status?
Check the NCSC’s own published list of assured CHECK companies rather than relying on a claim made in a proposal or on a website.
Can CHECK accreditation be lost?
Yes. The NCSC reviews report quality over time rather than granting a permanent badge. A provider whose standards slip can have its status withdrawn, which is exactly why checking current status matters more than checking a provider’s history.
Subscribe to our newsletter
Honest updates, straight to your inbox. Unsubscribe any time.