There Is No Penetration Testing Certificate. Here Is What You Actually Get

by Rebecca Sutton

Stop looking for a penetration testing certificate. It does not exist, no matter how many vendor websites show a shiny badge next to the word ‘certified’. A penetration test produces a report, and if you ask for it, an attestation letter. Neither is a certificate. Treating them as interchangeable with Cyber Essentials or ISO 27001 will trip you up the first time an auditor actually reads what you sent them.

An IT manager reviewing a penetration testing report dashboard on a laptop instead of a certificate

Where the penetration testing certificate confusion comes from

Some providers hand clients a completion badge as a marketing flourish. It looks official, often with a seal or a signature, but it is not a recognised credential anywhere. Nobody accredits it. Nobody checks it against a register. An auditor who knows the space will not treat it as evidence of anything beyond ‘we paid someone to run some scans’. If your provider leads with a badge instead of a proper report, that is worth noticing.

What genuinely happens at the end of a test

A test that was run properly ends with paperwork that actually holds up:

  • A technical report: findings, evidence, severity, and how to fix each issue
  • An executive summary a non-technical board member can follow
  • Confirmation of scope, dates, and the standard or methodology used
  • An attestation letter, if you asked for one, built for sharing outside your team

That is the whole list. There is no fifth item called a certificate, however much a sales page implies otherwise.

Attestation letter, not certificate: why the distinction matters

An attestation letter is one or two pages. It confirms what was tested, when, and how thoroughly, without the technical detail that would let someone reproduce an attack. It answers the actual question an insurer or a big customer is asking. Usually that question is ‘did independent testing happen recently, and can we trust the answer’. A certificate implies a pass or fail standard measured against a fixed bar. Penetration testing does not work that way. Findings get fixed, not ‘passed’.

What should be in the letter

  • The scope tested, named precisely enough that a reader knows what was and was not covered
  • Test dates and whether access was authenticated
  • Current remediation status, not just the original findings
  • The tester’s or firm’s relevant accreditation

Penetration testing certificate versus the schemes that do certify something

Cyber Essentials, Cyber Essentials Plus, ISO 27001, PCI DSS, and SOC 2 each produce a real document. None of them is generated by a penetration test on its own.

Scheme Real output Involves a pen test?
Cyber Essentials Certificate, IASME, annual No
Cyber Essentials Plus Certificate, IASME No, technical audit and scan instead
ISO 27001 Certificate, accredited body Supports it, not the whole picture
PCI DSS Attestation of Compliance Yes, required annually
SOC 2 Auditor’s report Expected in practice, not mandated

Even the scheme that mandates testing, PCI DSS, still calls its output an attestation, not a certificate. That should settle the argument the next time a vendor’s marketing page implies otherwise.

A common scenario

Picture a retailer whose acquiring bank asks for proof of testing under PCI DSS. There is no certificate to hand over, because none exists for this kind of testing. An attestation letter covers it instead, naming the scope, the dates, and the current remediation status. Banks and auditors generally accept that without a follow-up question, because it answers exactly what they were asking for.

CREST, CHECK and OSCP are credentials for people, not businesses

These accreditations sit with the tester or the testing firm. They tell you the person doing the work passed a proper exam and follows a defined methodology. That matters enormously when you are handing someone access to your systems. But they do not transfer to your organisation. A CREST-accredited firm cannot certify your business as CREST-anything. Keep that straight before it ends up in a board pack by mistake.

What if you already sent a badge to a client

It happens. If a badge or completion certificate from a previous test has already gone out to a client or an auditor, follow it up with a proper attestation letter rather than leaving it as the only record. Most auditors will not object to the correction. Few will thank you for staying quiet about it, especially if the badge gets questioned later during a renewal.

What to actually ask for next time

  • An attestation letter as a named deliverable, agreed before the test starts
  • Wording that matches what your auditor or insurer specifically requires
  • Evidence of the tester’s accreditation, not just a claim on a website
  • A plan for retesting so the letter stays current

None of this costs much to arrange. It just has to be agreed before the testers start, not chased afterwards when someone urgently wants a penetration testing certificate that was never going to exist.

Make it part of your standard scope, not an afterthought

The cleanest fix is procedural. Add the attestation letter to your statement of work every time you commission a penetration test, alongside the report and any agreed retest. It rarely adds meaningful cost, and it means nobody is hunting for a penetration testing certificate that was never going to turn up when a deadline is already close.

If you are not confident your current provider would produce a proper attestation letter without a fuss, that is worth raising before your next renewal. Aardwolf Security’s penetration testing engagements include a full report and, where needed, a signed letter your auditor or insurer can actually use. Get in touch if you want to talk through what your next questionnaire is likely to ask for.

Frequently asked questions

Is there an official penetration testing certificate?

No. What exists is a report and, on request, an attestation letter. Neither is issued by an accrediting body the way Cyber Essentials or ISO 27001 certificates are.

Why do some providers give out a “certificate of testing” anyway?

It is usually a marketing document rather than a recognised credential. It can look reassuring on a wall or a website, but it carries no formal standing with auditors, insurers, or regulators, and nobody outside the firm that issued it will recognise the design.

What do I send when a client’s security questionnaire asks for a certificate?

Send the attestation letter. It confirms the testing happened, when, and how thoroughly. It does this without exposing the technical findings.

Does passing Cyber Essentials mean I do not need a penetration test?

No. Standard Cyber Essentials does not involve one at all. Even Cyber Essentials Plus relies on a technical audit and vulnerability scan rather than adversarial testing. Many businesses run both anyway, since they serve different purposes and different audiences.

How current does an attestation letter need to be?

Most auditors and insurers expect testing within the last 12 months. Sooner if your systems have changed materially since the last test.

Can a penetration testing certificate ever become an official thing?

Nothing rules it out in theory, but no accrediting body currently offers one, and none of the major UK or international standards bodies has proposed it. Until that changes, the attestation letter remains the practical answer.

Should I trust a provider who offers a certificate as standard?

Not on its own. A badge is not disqualifying if the underlying report is thorough and the firm can also produce a proper attestation letter on request. Treat the badge as marketing, judge the provider on the report, the methodology, and whether their testers hold a recognised accreditation such as CREST or CHECK.

Subscribe to our newsletter

Honest updates, straight to your inbox. Unsubscribe any time.

You may also like