What is CREST accreditation, and why do buyers ask for it?
When you hire a company to attack your systems on purpose, you trust it with your weaknesses and often with your data. Most buyers cannot judge a tester’s skill from a sales meeting. CREST accreditation gives you an independent way to check.
It matters most when the test supports an audit (ISO/IEC 27001, SOC 2 or PCI DSS), a funding round or a customer’s security questionnaire. Choosing the right provider early saves you from paying for a second test.
The short answer
CREST is an international not-for-profit body. It accredits companies that provide technical security services such as penetration testing (an authorized, controlled attack that finds weaknesses before criminals do). It also certifies individual testers.
Companies are assessed on how they operate: their procedures, how they handle client data and how they check the quality of their work. They must keep meeting these requirements to stay accredited. Individual testers earn certifications such as CREST Registered Penetration Tester (CRT) and CREST Certified Tester (CCT) by passing practical exams.
CREST is not a way of testing, and it does not tell a provider how to test. Each accredited company writes and follows its own documented approach. That approach is usually built on public standards such as NIST SP 800-115, PTES and the OWASP Web Security Testing Guide (WSTG).
How is this different from ISO/IEC 27001?
ISO/IEC 27001 certifies how a company manages security in its own business. CREST accreditation tells you about the people who will test you, how they work and how they will treat your data. Some financial regulators and many large buyers look for it when they assess testing providers.
What accreditation tells you about a provider
| Area | What it tells you | What can go wrong without it |
|---|---|---|
| People | Testers have passed practical exams and can combine small weaknesses into a realistic attack | Theoretical findings and false alarms that lead to a retest |
| Process | Scoping, rules of engagement and a repeatable testing approach are written down | Coverage varies from test to test, and reports lack evidence |
| Data handling | Test evidence is handled, kept and destroyed under agreed controls and an NDA | Your customers’ data leaks through the vendor |
| Quality assurance | Work is reviewed before the report is released | The board asks “what does this mean for us?” and the report has no answer |
What skipping it can cost
Many banks, insurers and large companies ask for CREST accreditation in tenders and vendor questionnaires. A provider without it may be screened out, which slows your project or your deal.
Auditors and PCI DSS assessors look for a defined testing approach, qualified testers and proof that findings were checked by hand. A thin report can mean more testing before sign-off, so you end up paying twice.
The quieter cost is false confidence. Automated scans miss flaws in business logic and chains of small weaknesses. Those are the routes ransomware groups often use.
Where Snipeyes fits
Snipeyes is a CREST-accredited company, certified to ISO/IEC 27001:2022, and our testers hold CREST certifications. Each engagement follows our documented approach, based on OWASP WSTG and ASVS, PTES, NIST SP 800-115 and MITRE ATT&CK. It covers a scoping workshop, threat modeling, manual validation, a risk-rated report with compliance mapping, and a retest. The work is done under NDA. You receive the report within 10 business days of testing, and the retest is included at no extra cost.
Free checklist: if you are comparing providers, download our CISO/CTO Checklist: 12 Questions to Validate a Penetration Testing Provider (PDF) and use it on your next vendor call.
P.S. Not sure whether you need a penetration test or a broader vulnerability assessment and penetration test (VAPT)? Our short OWASP Risk Calculator gives you a first risk rating.