Offensive Security

CREST Penetration Testing (CREST-member Partner)

CREST penetration testing for the frameworks and buyers that require it. Delivered through our CREST-member partner, with Onyx Security Labs scoping and coordinating the engagement.

Overview

Some regulators, assurance schemes, and enterprise procurement processes require penetration testing performed by a CREST-certified provider. CREST (the Council of Registered Ethical Security Testers) is an international not-for-profit certification body for the technical information security industry. CREST certification gives organisations and buyers confidence that the methodology, penetration tester qualifications, and reporting quality meet a recognised standard aligned to the cyber security industry's code of conduct.

Onyx Security Labs delivers CREST penetration testing through our CREST-member partner. We scope the engagement, define the rules of engagement, and manage delivery from start to finish. The security testing is performed by CREST certified penetration testers working under the CREST framework, so the assurance your stakeholders expect is there on the report. CREST certification carries weight with the National Cyber Security Centre and regulated sectors where security risk must be managed to a demonstrable standard.

If you do not have a specific CREST requirement from a regulator, scheme, or buyer, our standard penetration testing covers the same technical ground. We will tell you which applies during scoping.

What’s included

  • Scoping and requirements confirmation aligned to your CREST assurance need
  • Penetration testing performed by CREST Certified Penetration Testers (via our partner)
  • CREST-recognised methodology and structured reporting
  • CVSS-aligned, evidence-backed findings
  • Remediation guidance and re-test
  • Engagement coordination and project management by Onyx Security Labs

How we work

  1. 01
    Confirm the requirement

    We confirm why CREST is required, whether by a regulator, an assurance scheme, or a buyer, and scope the engagement accordingly.

  2. 02
    Engage the partner

    Our CREST-member partner is engaged to perform security testing under the CREST framework with CREST Certified Penetration Testers.

  3. 03
    Test and report

    CREST certified penetration testers conduct the engagement and produce CREST-recognised reporting with evidence-backed findings covering security vulnerabilities across the agreed scope.

  4. 04
    Remediate and re-test

    We guide your team through remediation and coordinate the re-test with the partner.

What you get

  • CREST-recognised penetration test report (issued by our CREST-member partner)
  • Executive summary and detailed technical findings
  • Remediation guidance and re-test

Certification comes from the partner

CREST testing is performed by our CREST-member partner under their certification. Onyx Security Labs scopes, coordinates, and manages the engagement. If you do not specifically require CREST, our standard penetration testing covers the same technical ground at a faster scoping pace and includes application security and web application testing as needed.

Frequently asked questions

When do we actually need CREST rather than standard penetration testing?

When a regulator, an assurance scheme, or a customer's procurement process names CREST as a requirement. Regulated sectors such as financial services, critical infrastructure operators, and some government supply chains frequently require a CREST pen test specifically. If none of those apply to you, standard penetration testing usually meets the security operations need and the technical scope is comparable.

Who carries out the CREST testing?

CREST Certified Penetration Testers from our CREST-member partner conduct the engagement. Onyx Security Labs scopes the work, manages the project, and supports your team through remediation. CREST certification means testers have passed rigorous examinations across their technical information security discipline.

How do we know which type of penetration test is right for us?

We ask about your regulatory and contractual obligations during the initial scoping call. If CREST is not required, we recommend standard penetration testing and advise on the right scope for your cyber security posture. If it is required, we engage our partner and manage the process end to end.

What does CREST stand for, and why does it matter?

CREST stands for the Council of Registered Ethical Security Testers. It is an internationally recognised certification body for cyber security and penetration testing engagements. Where a buyer or regulator names CREST by name, a CREST-certified provider is required. Without it, the engagement does not satisfy the requirement regardless of technical quality.

See the kind of report you get

Every engagement ends with a report you can act on: an executive summary, CVSS-aligned findings, reproduction evidence, and prioritised fixes. Ask for a redacted sample and we will share one.

Credentials held by our team

ISO/IEC 27001 Lead Auditor
CISM
CISA
COBIT 2019
CEH
CRTP
eCPPT
CSA
CCNA
ITIL
Free tool · about 3 minutes · instant score

How ready is your security and compliance?

Answer 15 quick questions across the controls auditors actually check, and get an instant readiness score with tailored next steps. No call required.

Start the free assessment

Ready to simplify security and compliance?

Pick a service, book a scope call, or ask a question. Whatever order works.