Assesses organizational and service-specific capability.
CREST provides independent accreditation for cybersecurity service providers and their service capabilities. It is distinct from individual professional qualifications and can be relevant to penetration testing, security operations, incident response and threat intelligence providers.

Company accreditation is not the same as an individual CREST qualification. CREST states that individuals are not generally required to hold CREST qualifications for a company to achieve accreditation; teams can be assessed through skills, experience and qualifications held.
Assesses organizational and service-specific capability.
Multiple accreditation standards are available.
Company requirements and AI-enabled penetration testing were updated.
Individual exams should not be confused with company accreditation.
CREST operates accreditation, professional qualification and community programs intended to build trust in cybersecurity services. Company accreditation looks at governance, quality, ethics, people, processes and delivery rather than a tool checklist alone.
A customer requirement for a CREST-accredited provider is therefore different from requiring one staff member to hold an individual certification.
CREST currently publishes company general requirements and service standards covering Cyber Threat Intelligence, Incident Exercising, Incident Response, Penetration Testing, Security Architecture, Security Operations, Threat Intelligence for Simulated Attacks, Threat-led Penetration Testing and Vulnerability Assessment.
This means CREST is not limited to penetration testing.
| Service | Focus | Typical provider |
|---|---|---|
| Penetration Testing | Quality of pentest delivery | Pentest/red-team firm |
| Security Operations | Security operations services | SOC/MDR provider |
| Incident Response | Incident-response capability | DFIR/IR team |
| Cyber Threat Intelligence | Threat-intelligence service | CTI provider |
| Vulnerability Assessment | Vulnerability assessment | Security consultancy |
Cybersecurity service providers are assessed against organizational and relevant service-specific standards. The business, team, quality system and real delivery capability should match the accreditation sought.
A generic software company cannot treat accreditation as a decorative badge; it must demonstrate the relevant cybersecurity service capability.
Individual CREST qualifications assess a professional’s knowledge and skill. Company accreditation assesses organizational delivery, people, quality and governance.
CREST states there is no general mandatory requirement for individuals to be CREST-qualified for company accreditation; skills, experience and other qualifications can be considered.
Start by selecting the service standard that reflects the services actually sold. Prepare evidence against company general requirements and the relevant service standard, including team capability, QA, data handling, methodology and customer delivery.
Because membership and application flows can change, the current CREST membership and accreditation pages should be treated as authoritative.
Accreditation considers scoping, authorization, methodology, safe testing, quality review, reporting, customer-data protection and staff competence—not merely running scanners.
It provides customers with assurance about repeatable professional service delivery.
On 28 July 2026, CREST announced new accreditation requirements addressing Responsible AI Use in Company General Requirements and an AI-Enabled Penetration Testing annex.
The focus includes governance, oversight, transparency and preserving professional judgment while AI is used in service delivery.
Membership tier, service accreditation and individual qualifications should not be described as interchangeable. CREST updated its membership model in 2026, so current rights and terminology should be checked directly.
If a buyer asks for a specific CREST-accredited service, confirm the actual service accreditation rather than a generic membership status.
CREST operates internationally. Eligibility for a company in Türkiye should be checked against current service, membership and regional application arrangements.
Market acceptance can also vary by customer and procurement requirement, so direct confirmation is prudent.
Useful readiness work includes governance policies, ethics, customer authorization, competence matrices, QA, example deliverables, retention/deletion, complaints, secure communications and escalation processes.
Tool inventory, licensed software, testing-environment security, customer-data locations, access controls and secure report delivery support operational credibility.
CREST focuses on cybersecurity service-provider capability. ISO 27001 is an ISMS certification, SOC 2 is an attestation report over service controls and PCI DSS protects payment account data.
| Framework | Primary output | Typical target |
|---|---|---|
| CREST | Company/service accreditation | Pentest/SOC/IR/CTI providers |
| ISO 27001 | ISMS certificate | Any sector |
| SOC 2 | Attestation report | SaaS/B2B services |
| PCI DSS | Payment-security validation | Merchants/payment providers |
| FedRAMP | Federal cloud certification | CSPs serving US federal agencies |
No. CREST also offers company and service accreditations.
CREST states there is no general mandatory individual qualification requirement for company accreditation; skills and experience can be assessed.
No. Standards also cover Security Operations, Incident Response, CTI, Vulnerability Assessment and other services.
Yes. CREST added Responsible AI and AI-enabled penetration testing requirements.
Eligibility should be confirmed against current CREST service and membership arrangements.
No. They assess different objectives.
We do not claim to be a certification body or independent auditor. We can assist with technical readiness around servers, hosting, access, logging, backups and baseline security controls.