CREST
CREST is a UK-based not-for-profit accreditation and certification body for the cybersecurity industry, accrediting 500+ service-provider members and certifying 3,000+ practitioners across penetration testing, incident response, SOC, and threat intelligence, serving providers, regulators, and enterprise buyers.
- Company typePrivate
- Founded2006
- HeadquartersSlough, United Kingdom
- Headcount251–500
- GTM typeB2B
- OfferingServices
What CREST does
CREST (International) is a UK-registered not-for-profit accreditation and certification body serving the technical information security industry. Founded in 2006 and registered in Coventry, United Kingdom (company number 09805375), it accredits cybersecurity service providers and certifies individual practitioners across seven disciplines: penetration testing, vulnerability assessment, threat intelligence, incident response, security operations centres (SOC), security architecture, and threat-led penetration testing (STAR/STAR-FS). Its core "product" is not software but a body of published accreditation standards, professional certification exams (e.g., CPSA, CRT, CCT INF, CCT APP, CPIA, CCIM, CCSAM), maturity assessment tools (spreadsheet-based, scored 1–5), and the CREST Marketplace, a searchable online directory of accredited suppliers filterable by service, region, industry, and government scheme.
CREST serves three primary buyer groups—cybersecurity service providers seeking independent quality assurance, governments and regulators requiring standardized providers, and enterprise buyers procuring vetted services—plus individual practitioners pursuing credentials. Its accreditations are embedded in numerous regulated schemes, including UK Bank of England CBEST, NCSC CHECK/CIR/CIE, UK CAA ASSURE, UK Cabinet Office GBEST, Dubai DESC Cyber Force, EU ECB TIBER-EU, and HKMA iCAST. The organization reports over 500 member companies worldwide and more than 3,000 individuals holding CREST certifications, operating through regional councils across Asia, Australasia, Europe, Middle East & Africa, North America, and the UK.
The business model is member-funded and recurring. Revenue streams include annual membership subscriptions (£26,500 global / £7,500 regional), tiered entry statuses (Pathway at £250/year, Pathway+ at £1,500/year), one-time joining fees (£1,500–£25,000 by revenue tier), non-refundable application fees (£500–£1,200), professional certification exam fees, and additional accreditation subscriptions (e.g., OVS at £2,000/year, CIS Controls at £1,200/year). Go-to-market is consultative and relationship-based via membership applications, the marketplace, regional subscriptions, government/regulator programs, industry events (CRESTCon, BSides), and discipline communities. Discounts (50%) apply for low-income-country providers.
CREST firmographics
Firmographics- Name
- CREST
- Legal name
- CREST (International)
- Website
- https://crest-approved.org
- Company type
- Private
- Founded year
- 2006
- Operating status
- Operating
- Headcount range
- 251–500 employees
- Short description
- CREST is a UK-based not-for-profit accreditation and certification body for the cybersecurity industry, accrediting 500+ service-provider members and certifying 3,000+ practitioners across penetration testing, incident response, SOC, and threat intelligence, serving providers, regulators, and enterprise buyers.
- Ownership category
- akta.pro rank
CREST industry classification
Industry- Product category
- Cybersecurity Accreditation Services
- NAICS
- Educational Support Services (611710), Business Associations (813910), Testing Laboratories and Services (54138)
- SIC
- Services-Testing Laboratories (8734)
- akta.pro primary industry
- Information Technology (IT) & Cybersecurity Certifications (EDAAANAA)
- akta.pro secondary industries
- Penetration Testing, Red Team & Ethical Hacking (EDAOAIAH), Digital Assessment Platforms & Computer-Based Testing Authorities (EDADAFAK), Credential, Education & Professional License Verification (BPAKAEAI), Certification & Licensing Exam Management Platforms (EDAFADAG)
Keywords
Where CREST is headquartered
LocationHeadquarters
- HQ city
- Slough
- HQ country
- United Kingdom
- HQ region
- Europe
Offices1 record
Markets served
CREST business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Operations, Technology or R&D, Marketing or Sales
Revenue model
- Membership Subscriptions: Annual subscription fees charged to member companies. Global subscription covers all regions; regional subscriptions cover specific geographic areas (Americas, Asia, Australasia, EMEA). Fees are required to maintain CREST membership and access accreditation benefits.
- Accreditation Application Fees: Non-refundable fees charged when organizations submit accreditation applications. Covers assessment of application, one resubmission if initial application fails, and administrative processing. Fees vary by accreditation type from £500 to £1,200 depending on discipline.
- Joining Fees: One-time joining fees for new members based on annual revenue tiers. Revenue thresholds determine fees ranging from £1,500 for revenue below £1m to £25,000 for revenue above £50m. Applied only at initial membership, not for renewals or additional accreditations.
- Professional Certifications: Revenue from CREST professional certification exams including CPSA, CRT, CCT INF, CCT APP, CPIA, CRIA, CCIM, CPTIA, CRTIA, CCTIM, CCRTS, CCSAM. Discounts available for Pathway/Pathway+ members and low-income countries.
- Additional Accreditation Subscription Fees: Annual fees for specific accreditations beyond base membership: Mobile & Web Application Testing (OVS) at £2,000/year and CIS Controls Accreditation at £1,200/year.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | Pathway Status - Entry-level registration for early-stage cyber service providers |
| Subscription | Annual | Pathway+ Status - Self-assessment stage for organizations progressing toward accreditation |
| Subscription | Annual | CREST Membership - Full accreditation with independent review |
| Subscription | Annual | Pathway/Pathway+ Bundle |
| Subscription | Annual | Low-Income Country Discount |
Go-to-market motion3 records
Distribution channels4 records
Marketing channels6 records
CREST product offering
Product offeringCore offering
CREST is an international not-for-profit accreditation and certification body for the cybersecurity industry. It accredits cybersecurity service provider companies across multiple technical disciplines (penetration testing, incident response, SOC, threat intelligence, security architecture) and certifies individual practitioners through professional examinations. CREST also operates a marketplace that connects organizations seeking cyber services with its community of accredited suppliers.
Product overview
CREST is a global accreditation and certification body for the cyber security industry, offering a multi-layered portfolio of accreditation programmes for organizations and professional certifications for individuals. The core offering consists of organizational accreditation across seven cyber security disciplines: Penetration Testing, Vulnerability Assessment, Threat Intelligence, Incident Response, Security Operations Centres (SOC), Security Architecture, and Threat-Led Penetration Testing (STAR/STAR-FS). Supporting the accreditation programmes are professional certifications for individuals at various career stages (Practitioner, Registered, and Certified levels) spanning penetration testing, intrusion analysis, incident management, red teaming, and threat intelligence. The portfolio also includes maturity assessment tools, an online marketplace for finding accredited suppliers, and the CREST CAMP capacity-building programme for developing markets. CREST serves over 500 member companies worldwide and manages government/regulator schemes including CBEST, TIBER-EU, ASSURE, NCSC CHECK, and Dubai Cyber Force.
Differentiator
Problem solved
Functional benefit
Brands
- CREST AI Charter: Industry framework establishing principles for the responsible use of artificial intelligence in cyber security services covering governance, transparency, accountability, and data protection.
- CREST CAMP
- CREST Marketplace
Products and services
- Organizational Accreditation Programme
- Professional Practitioner Certifications
- CREST Marketplace
Quantifiable outcome
- Over 500 member companies quality assured and accredited globally
- +2 more outcomes
Companies that use CREST
Customer profileNamed customers5 records
Segments4 records
Ideal customer profiles3 records
CREST technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature3 records
CREST partnerships and signals
Strategic signalPartnerships
17 partnerships are on record, tiered flagship and core.
- NCC GroupflagshipNCC Group became a founding signatory of the CREST AI Charter, an industry framework establishing nine principles for the responsible use of artificial intelligence in cybersecurity services covering governance, transparency, accountability, and data protection.
- SynackcoreSynack expanded its partnership with CREST by adding two new certifications (CREST Certified Tester Infrastructure and CREST Certified Tester Application) to its Synack Red Team Pathways program. This gives CREST-certified security researchers a direct route to join the SRT community and adds third-party credentialing important for DORA, NIS2, and TIBER-EU compliance.
- AbacuscoreAbacus achieved CREST accreditation for its penetration testing services following independent audit between October 2025 and February 2026. The accreditation validates that Abacus meets technical, ethical, and legal standards for penetration testing, placing it among rare MSPs with this benchmark.
- UK Foreign, Commonwealth & Development Office (FCDO)flagshipCREST CAMP (Cyber Accelerated Maturity Programme) is funded by UK FCDO, targeting 11 countries from September 2024 to March 2025 to improve cybersecurity maturity and private sector involvement through mentoring, training, and accreditation pathways.
- UK Department of Foreign Affairs and Trade (DFAT)flagshipCREST CAMP supported by DFAT alongside FCDO and EBRD as international donor partners funding capacity-building programs across 14+ countries.
- European Bank for Reconstruction and Development (EBRD)flagshipCREST CAMP supported by EBRD as international donor partner alongside FCDO and DFAT, funding cybersecurity capacity building globally.
- UK Bank of EnglandflagshipCREST developed CBEST framework with UK Bank of England to deliver controlled, bespoke, intelligence-led cyber security tests for systemically important financial institutions. CREST helps develop accreditation standards for CBEST penetration testing.
- UK National Cyber Security Centre (NCSC)flagshipCREST delivers CHECK scheme (approved penetration tests for public sector and CNI), NCSC CIR Standard Level scheme, and Cyber Incident Exercising (CIE) scheme in partnership with NCSC.
- UK Civil Aviation Authority (CAA)coreCREST developed ASSURE scheme with UK CAA for cyber security audits of aviation organizations under CAP 1753 framework.
- Dubai Electronic Security Center (DESC)coreDESC Cyber Force program enables CREST-qualified individuals and accredited companies to register as cybersecurity service providers for Dubai government, semi-government, and critical information infrastructure sectors.
- European Central Bank (ECB)coreCREST supports TIBER-EU framework enabling European and national authorities to test financial sector resilience against sophisticated cyber attacks.
- Hong Kong Monetary Authority (HKMA)coreCREST supports iCAST framework introduced by HKMA for threat intelligence-led security testing of banks under Cyber Resilience Assessment Framework.
- UK Cabinet OfficecoreCREST developed GBEST scheme based on CBEST model, being rolled out across UK Government Departments with NCSC providing technical assurance.
- UK Cyber Security CouncilcoreCREST certifications align with UK CSC professional titles framework. CHECK scheme requires CTLs and CTMs to hold UK CSC professional titles at Practitioner and Principal levels respectively.
- OWASPcoreCREST OVS quality assurance standard is aligned to OWASP's Application Security Verification Standard (ASVS) and Mobile Application Security Verification Standard (MASVS).
- Center for Internet Security (CIS)coreCREST offers CIS Controls Accreditation for organizations assessing client implementation of CIS Critical Controls.
- UK CAA (ASSURE)coreCREST and UK CAA collaborated to develop the ASSURE scheme for third-party cyber security audits of aviation organizations.
Scale indicators5 records
Recent moves6 records
Expansion highlights6 records
CREST competitors and assessment
Company assessmentBroad incumbents
- CompTIA: CompTIA is a large, established provider of vendor-neutral IT certifications (Security+, PenTest+, CySA+) that overlaps with CREST's entry- and mid-tier cybersecurity certification portfolio and is widely recognized by employers and governments.
- PCI Security Standards Council: PCI SSC is an industry-led standards body that qualifies security assessors (QSAs) and approves scanning vendors for the payments ecosystem, operating an analogous accreditation model in the adjacent payments-cyber segment.
- IAPP (International Association of Privacy Professionals): IAPP is a global non-profit certification and membership body for privacy professionals (CIPP, CIPM, CIPT), adjacent in mission and member-funded business model to CREST's privacy- and security-accreditation role.
Direct peers
- EC-Council: EC-Council issues the Certified Ethical Hacker (CEH) and other offensive security credentials, competing for the same individual certification and training demand that CREST addresses via CRT, CCT, and CCSAM/CCRTS.
- ISACA: ISACA is a global non-profit membership body that issues widely recognized cybersecurity and IT governance certifications (CISA, CISM, CGEIT, CRISC) and serves as a direct peer in professional credentialing for the cybersecurity workforce.
- APMG International: APMG accredits and manages professional certification schemes (e.g., ISO/IEC 27001, cyber resilience schemes), operating the same accreditation-and-certification business model as CREST across adjacent standards.
- Offensive Security: Offensive Security issues the OSCP and other hands-on penetration testing certifications, positioning it as a direct peer for offensive-security individual credentials that overlap with CREST's CCT INF and CCT APP certifications.
- (ISC)²: (ISC)² is a global non-profit cybersecurity professional certification body best known for the CISSP credential, making it the most direct peer to CREST's role as an accreditation and certification body for cybersecurity professionals and organizations.
- SANS Institute: SANS Institute delivers cybersecurity training and awards the GIAC family of certifications, overlapping directly with CREST's penetration testing, incident response, and SOC certification offerings.
Others
- NCSC (UK National Cyber Security Centre): UK NCSC is the regulator that delegates delivery of CHECK, CIR, and CIE schemes to CREST and licenses other accreditors; it is a key ecosystem partner and the source of CREST's strongest UK regulatory moat.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat4 records
Key risks6 records
Key highlights7 records
Customer concentration
CREST social profiles
Digital presenceCREST financial estimates
Financial estimateRevenue estimate
Valuation estimate
CREST leadership team
Management profileNumber of profiles
Profiles3 records
CREST funding detail
Funding detailFunding overview
Funding rounds1 record
Investors1 record
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
CREST M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about CREST
What does CREST do?
CREST is an international not-for-profit accreditation and certification body for the cybersecurity industry. It accredits cybersecurity service provider companies across multiple technical disciplines (penetration testing, incident response, SOC, threat intelligence, security architecture) and certifies individual practitioners through professional examinations. CREST also operates a marketplace that connects organizations seeking cyber services with its community of accredited suppliers.
Is CREST a public or private company?
CREST is a private company. It is classified as nonprofit foundation owned and is currently operating.
When was CREST founded?
CREST was founded in 2006. It employs 251 to 500 people.
Where is CREST based?
CREST is headquartered in Slough, United Kingdom, in the Europe region.
How does CREST make money?
Five revenue lines are on record. Membership Subscriptions are the primary driver. The others are accreditation Application Fees, joining Fees, professional Certifications and additional Accreditation Subscription Fees.
Who are CREST's main competitors?
Broad incumbents on record are CompTIA, PCI Security Standards Council and IAPP (International Association of Privacy Professionals). Direct peers are EC-Council, ISACA, APMG International, Offensive Security, (ISC)² and SANS Institute. NCSC (UK National Cyber Security Centre) is listed as an others.
Does CREST have an API?
No public API is recorded for CREST.
What industry is CREST in?
CREST's product category is Cybersecurity Accreditation Services. Its primary akta.pro industry code is EDAAANAA, Information Technology (IT) & Cybersecurity Certifications, with a secondary code of EDAOAIAH, Penetration Testing, Red Team & Ethical Hacking. Its NAICS code is 611710 and its SIC code is 8734.