Developer docs
API playgroundTry for free, no card

Search company profiles

CREST

Full company profile

uuid00054sz

Namestring
CREST
Legal namestring
CREST (International)
Company typeenum
Private
Founded yearint
2006
Descriptiontext

CREST (International) is a UK-registered not-for-profit accreditation and certification body serving the technical information security industry. Founded in 2006 and registered in Coventry, United Kingdom (company number 09805375), it accredits cybersecurity service providers and certifies individual practitioners across seven disciplines: penetration testing, vulnerability assessment, threat intelligence, incident response, security operations centres (SOC), security architecture, and threat-led penetration testing (STAR/STAR-FS). Its core "product" is not software but a body of published accreditation standards, professional certification exams (e.g., CPSA, CRT, CCT INF, CCT APP, CPIA, CCIM, CCSAM), maturity assessment tools (spreadsheet-based, scored 1–5), and the CREST Marketplace, a searchable online directory of accredited suppliers filterable by service, region, industry, and government scheme.

CREST serves three primary buyer groups—cybersecurity service providers seeking independent quality assurance, governments and regulators requiring standardized providers, and enterprise buyers procuring vetted services—plus individual practitioners pursuing credentials. Its accreditations are embedded in numerous regulated schemes, including UK Bank of England CBEST, NCSC CHECK/CIR/CIE, UK CAA ASSURE, UK Cabinet Office GBEST, Dubai DESC Cyber Force, EU ECB TIBER-EU, and HKMA iCAST. The organization reports over 500 member companies worldwide and more than 3,000 individuals holding CREST certifications, operating through regional councils across Asia, Australasia, Europe, Middle East & Africa, North America, and the UK.

The business model is member-funded and recurring. Revenue streams include annual membership subscriptions (£26,500 global / £7,500 regional), tiered entry statuses (Pathway at £250/year, Pathway+ at £1,500/year), one-time joining fees (£1,500–£25,000 by revenue tier), non-refundable application fees (£500–£1,200), professional certification exam fees, and additional accreditation subscriptions (e.g., OVS at £2,000/year, CIS Controls at £1,200/year). Go-to-market is consultative and relationship-based via membership applications, the marketplace, regional subscriptions, government/regulator programs, industry events (CRESTCon, BSides), and discipline communities. Discounts (50%) apply for low-income-country providers.

Short descriptiontext

CREST is a UK-based not-for-profit accreditation and certification body for the cybersecurity industry, accrediting 500+ service-provider members and certifying 3,000+ practitioners across penetration testing, incident response, SOC, and threat intelligence, serving providers, regulators, and enterprise buyers.

Operating statusenum
Operating
Ownership categoryenum
Headcount rangeband
251–500
akta.pro rankint
HeadquartersSlough, United Kingdom
HQ citystring
Slough
HQ countrystring
United Kingdom
HQ regionstring
Europe
Markets served

Serves global market

Offices1 record

Each record includes

City, Country, Type, Description, Source

Keyword5 values
cybersecurity accreditation services, penetration testing certification, incident response accreditation, threat intelligence certification, cyber service standards
Industry5 codes
1Information Technology (IT) & Cybersecurity Certifications
CodeEDAAANAAPrimaryYes
2Penetration Testing, Red Team & Ethical Hacking
CodeEDAOAIAHPrimaryNo
3Digital Assessment Platforms & Computer-Based Testing Authorities
CodeEDADAFAKPrimaryNo
4Credential, Education & Professional License Verification
CodeBPAKAEAIPrimaryNo
5Certification & Licensing Exam Management Platforms
CodeEDAFADAGPrimaryNo
NAICS code3 codes
  • Educational Support Services611710
  • Business Associations813910
  • Testing Laboratories and Services54138
SIC code1 code
  • Services-Testing Laboratories8734
Product category
Cybersecurity Accreditation Services
GTM motion3 records

Each record includes

Type, Description, Source

Revenue model5 records
1Membership Subscriptions
TypeSubscription Recurring
Description

Annual subscription fees charged to member companies. Global subscription covers all regions; regional subscriptions cover specific geographic areas (Americas, Asia, Australasia, EMEA). Fees are required to maintain CREST membership and access accreditation benefits.

crest-approved.org
2Accreditation Application Fees
TypeOne Time License
Description

Non-refundable fees charged when organizations submit accreditation applications. Covers assessment of application, one resubmission if initial application fails, and administrative processing. Fees vary by accreditation type from £500 to £1,200 depending on discipline.

crest-approved.org
3Joining Fees
TypeOne Time License
Description

One-time joining fees for new members based on annual revenue tiers. Revenue thresholds determine fees ranging from £1,500 for revenue below £1m to £25,000 for revenue above £50m. Applied only at initial membership, not for renewals or additional accreditations.

crest-approved.org
4Professional Certifications
TypeSubscription Recurring
Description

Revenue from CREST professional certification exams including CPSA, CRT, CCT INF, CCT APP, CPIA, CRIA, CCIM, CPTIA, CRTIA, CCTIM, CCRTS, CCSAM. Discounts available for Pathway/Pathway+ members and low-income countries.

crest-approved.org
5Additional Accreditation Subscription Fees
TypeSubscription Recurring
Description

Annual fees for specific accreditations beyond base membership: Mobile & Web Application Testing (OVS) at £2,000/year and CIS Controls Accreditation at £1,200/year.

crest-approved.org
Marketing channels6 records

Each record includes

Title, Type, Stage, Description, Source

Distribution channels4 records

Each record includes

Title, Type, Scope, Target buyer, Description, Source

Cost components4 values
Personnel, Operations, Technology or R&D, Marketing or Sales
Pricing details5 tiers
1Pathway Status - Entry-level registration for early-stage cyber service providers
ModelSubscriptionBilling cadenceAnnual
Notes

Annual fee: £250. Includes basic company registration, Code of Conduct sign-up, CREST Pathway logo, website listing, and 10% exam discount.

crest-approved.org
2Pathway+ Status - Self-assessment stage for organizations progressing toward accreditation
ModelSubscriptionBilling cadenceAnnual
Notes

Annual fee: £1,500. Includes self-assessment against CREST standards, gap analysis report, mentoring access, and 15% exam discount. Organizations must advance to full membership within two years.

crest-approved.org
3CREST Membership - Full accreditation with independent review
ModelSubscriptionBilling cadenceAnnual
Notes

Application fee: £1,200. Joining fee: £1,500-£25,000 based on annual revenue. Annual subscription: £26,500 (Global) or £7,500 (Regional). 30% exam discount. Includes full accreditation logos and searchable marketplace listing.

crest-approved.org
4Pathway/Pathway+ Bundle
ModelSubscriptionBilling cadenceAnnual
Notes

Combined annual fee: £1,500. Enables organizations to achieve both Pathway and Pathway+ statuses simultaneously at the cost of Pathway+ alone, removing financial barriers for fast-track development.

crest-approved.org
5Low-Income Country Discount
ModelSubscriptionBilling cadenceAnnual
Notes

50% discount on Pathway fees, membership application fee, joining fee, and annual subscription for companies headquartered in World Bank-classified low or lower-middle income economies with revenue below £5m.

crest-approved.org
GTM typeB2B
B2B
Offering typeServices
Services
Brand1 of 3 records shown
1CREST AI Charter
Description

Industry framework establishing principles for the responsible use of artificial intelligence in cyber security services covering governance, transparency, accountability, and data protection.

crest-approved.org
+2 more records
Core offering1 text field

CREST is an international not-for-profit accreditation and certification body for the cybersecurity industry. It accredits cybersecurity service provider companies across multiple technical disciplines (penetration testing, incident response, SOC, threat intelligence, security architecture) and certifies individual practitioners through professional examinations. CREST also operates a marketplace that connects organizations seeking cyber services with its community of accredited suppliers.

Differentiator
Functional benefit
Problem solved
Quantifiable outcome1 of 3 values shown
  • Over 500 member companies quality assured and accredited globally
+2 more records
Product overview1 text field

CREST is a global accreditation and certification body for the cyber security industry, offering a multi-layered portfolio of accreditation programmes for organizations and professional certifications for individuals. The core offering consists of organizational accreditation across seven cyber security disciplines: Penetration Testing, Vulnerability Assessment, Threat Intelligence, Incident Response, Security Operations Centres (SOC), Security Architecture, and Threat-Led Penetration Testing (STAR/STAR-FS). Supporting the accreditation programmes are professional certifications for individuals at various career stages (Practitioner, Registered, and Certified levels) spanning penetration testing, intrusion analysis, incident management, red teaming, and threat intelligence. The portfolio also includes maturity assessment tools, an online marketplace for finding accredited suppliers, and the CREST CAMP capacity-building programme for developing markets. CREST serves over 500 member companies worldwide and manages government/regulator schemes including CBEST, TIBER-EU, ASSURE, NCSC CHECK, and Dubai Cyber Force.

Product and service3 records
1Organizational Accreditation Programme
CategoryOrganizational Accreditation
2Professional Practitioner Certifications
CategoryIndividual Certification
3CREST Marketplace
CategoryBuyer-Provider Marketplace
Scale indicator5 records

Each record includes

Type, Value, Description, Source

Partnership17 partners
Strategic tierFlagshipTypeStrategic or Co-development PartnerAnnounced on2026-06-24
Description

NCC Group became a founding signatory of the CREST AI Charter, an industry framework establishing nine principles for the responsible use of artificial intelligence in cybersecurity services covering governance, transparency, accountability, and data protection.

Strategic tierCoreTypeStrategic or Co-development PartnerAnnounced on2026-06-04
Description

Synack expanded its partnership with CREST by adding two new certifications (CREST Certified Tester Infrastructure and CREST Certified Tester Application) to its Synack Red Team Pathways program. This gives CREST-certified security researchers a direct route to join the SRT community and adds third-party credentialing important for DORA, NIS2, and TIBER-EU compliance.

Strategic tierCoreTypeStrategic or Co-development PartnerAnnounced on2026-04-07
Description

Abacus achieved CREST accreditation for its penetration testing services following independent audit between October 2025 and February 2026. The accreditation validates that Abacus meets technical, ethical, and legal standards for penetration testing, placing it among rare MSPs with this benchmark.

Strategic tierFlagshipTypeStrategic or Co-development PartnerAnnounced on2024-09-01
Description

CREST CAMP (Cyber Accelerated Maturity Programme) is funded by UK FCDO, targeting 11 countries from September 2024 to March 2025 to improve cybersecurity maturity and private sector involvement through mentoring, training, and accreditation pathways.

5UK Department of Foreign Affairs and Trade (DFAT)
Strategic tierFlagshipTypeStrategic or Co-development Partner
Description

CREST CAMP supported by DFAT alongside FCDO and EBRD as international donor partners funding capacity-building programs across 14+ countries.

crest-approved.org
Strategic tierFlagshipTypeStrategic or Co-development Partner
Description

CREST CAMP supported by EBRD as international donor partner alongside FCDO and DFAT, funding cybersecurity capacity building globally.

Strategic tierFlagshipTypeStrategic or Co-development Partner
Description

CREST developed CBEST framework with UK Bank of England to deliver controlled, bespoke, intelligence-led cyber security tests for systemically important financial institutions. CREST helps develop accreditation standards for CBEST penetration testing.

Strategic tierFlagshipTypeStrategic or Co-development Partner
Description

CREST delivers CHECK scheme (approved penetration tests for public sector and CNI), NCSC CIR Standard Level scheme, and Cyber Incident Exercising (CIE) scheme in partnership with NCSC.

Strategic tierCoreTypeStrategic or Co-development Partner
Description

CREST developed ASSURE scheme with UK CAA for cyber security audits of aviation organizations under CAP 1753 framework.

Strategic tierCoreTypeStrategic or Co-development Partner
Description

DESC Cyber Force program enables CREST-qualified individuals and accredited companies to register as cybersecurity service providers for Dubai government, semi-government, and critical information infrastructure sectors.

Strategic tierCoreTypeStrategic or Co-development Partner
Description

CREST supports TIBER-EU framework enabling European and national authorities to test financial sector resilience against sophisticated cyber attacks.

Strategic tierCoreTypeStrategic or Co-development Partner
Description

CREST supports iCAST framework introduced by HKMA for threat intelligence-led security testing of banks under Cyber Resilience Assessment Framework.

Strategic tierCoreTypeStrategic or Co-development Partner
Description

CREST developed GBEST scheme based on CBEST model, being rolled out across UK Government Departments with NCSC providing technical assurance.

Strategic tierCoreTypeStrategic or Co-development Partner
Description

CREST certifications align with UK CSC professional titles framework. CHECK scheme requires CTLs and CTMs to hold UK CSC professional titles at Practitioner and Principal levels respectively.

Strategic tierCoreTypeTechnology or Integration
Description

CREST OVS quality assurance standard is aligned to OWASP's Application Security Verification Standard (ASVS) and Mobile Application Security Verification Standard (MASVS).

Strategic tierCoreTypeStrategic or Co-development Partner
Description

CREST offers CIS Controls Accreditation for organizations assessing client implementation of CIS Critical Controls.

17UK CAA (ASSURE)
Strategic tierCoreTypeStrategic or Co-development Partner
Description

CREST and UK CAA collaborated to develop the ASSURE scheme for third-party cyber security audits of aviation organizations.

crest-approved.org
Recent move6 records

Each record includes

Date, Type, Title, Description, Source

Expansion highlight6 records

Each record includes

Type, Description

Peers10 records
TypeBroad incumbent
Description

CompTIA is a large, established provider of vendor-neutral IT certifications (Security+, PenTest+, CySA+) that overlaps with CREST's entry- and mid-tier cybersecurity certification portfolio and is widely recognized by employers and governments.

TypeDirect peer
Description

EC-Council issues the Certified Ethical Hacker (CEH) and other offensive security credentials, competing for the same individual certification and training demand that CREST addresses via CRT, CCT, and CCSAM/CCRTS.

TypeDirect peer
Description

ISACA is a global non-profit membership body that issues widely recognized cybersecurity and IT governance certifications (CISA, CISM, CGEIT, CRISC) and serves as a direct peer in professional credentialing for the cybersecurity workforce.

TypeDirect peer
Description

APMG accredits and manages professional certification schemes (e.g., ISO/IEC 27001, cyber resilience schemes), operating the same accreditation-and-certification business model as CREST across adjacent standards.

TypeDirect peer
Description

Offensive Security issues the OSCP and other hands-on penetration testing certifications, positioning it as a direct peer for offensive-security individual credentials that overlap with CREST's CCT INF and CCT APP certifications.

TypeBroad incumbent
Description

PCI SSC is an industry-led standards body that qualifies security assessors (QSAs) and approves scanning vendors for the payments ecosystem, operating an analogous accreditation model in the adjacent payments-cyber segment.

TypeDirect peer
Description

(ISC)² is a global non-profit cybersecurity professional certification body best known for the CISSP credential, making it the most direct peer to CREST's role as an accreditation and certification body for cybersecurity professionals and organizations.

TypeDirect peer
Description

SANS Institute delivers cybersecurity training and awards the GIAC family of certifications, overlapping directly with CREST's penetration testing, incident response, and SOC certification offerings.

TypeOthers
Description

UK NCSC is the regulator that delegates delivery of CHECK, CIR, and CIE schemes to CREST and licenses other accreditors; it is a key ecosystem partner and the source of CREST's strongest UK regulatory moat.

TypeBroad incumbent
Description

IAPP is a global non-profit certification and membership body for privacy professionals (CIPP, CIPM, CIPT), adjacent in mission and member-funded business model to CREST's privacy- and security-accreditation role.

Market position
Strengths5 records

Each record includes

Headline, Details, Source

Weaknesses5 records

Each record includes

Headline, Details, Source

Competitive moat4 records

Each record includes

Type, Details

Key risks6 records

Each record includes

Headline, Details, Source

Key highlights7 records

Each record includes

Headline, Details, Source

Customer concentration

Classification, Details

Named customers5 records

Each record includes

Name, Industry, Type, Use case, Source, UUID

Segment4 records

Each record includes

Title, Type, Primary, Description, Pain point addressed, Use case, Source

Ideal customer profile3 records

Each record includes

Profile, Firmographic size, Sales motion, Sales cycle length, Buying structure, Purchase trigger, Buyer persona, Geography, Industry vertical, Primary use case, Description, Pain points, Evidence proof points, Target buyer

Technology focused
No
API detail
Has APIbool
No

Docs URL, Description

AI maturity
App detail

Has app

Feature3 records

Each record includes

Title, Differentiator, Description, Source

Core technology
Revenue estimate
Valuation estimate
Number of profiles
Profiles3 records

Each record includes

Name, Designation, Designation category, Overview, Profile commentary, Source

No data
No data
Funding overview

Funding stage, Last funding date, Total funding USD

Funding rounds1 record

Each record includes

Round, Amount USD, Date, Pre money valuation, Total investors, Investors, News

Investors1 record

Each record includes

Name, Type, Date of entry, Rounds participated, Website

Funding detail is available on the Subscription and Enterprise plan.Contact sales →

M&A

Each record includes

Name, Acquisition type, Announced date, Completed date, Status, Website, News

Investment

Each record includes

Name, Round, Announced date, Lead investor, Website, News

M&A and investment is available on the Subscription and Enterprise plan.Contact sales →

CREST

Cybersecurity Accreditation Servicescrest-approved.org

CREST is a UK-based not-for-profit accreditation and certification body for the cybersecurity industry, accrediting 500+ service-provider members and certifying 3,000+ practitioners across penetration testing, incident response, SOC, and threat intelligence, serving providers, regulators, and enterprise buyers.

What CREST does

CREST (International) is a UK-registered not-for-profit accreditation and certification body serving the technical information security industry. Founded in 2006 and registered in Coventry, United Kingdom (company number 09805375), it accredits cybersecurity service providers and certifies individual practitioners across seven disciplines: penetration testing, vulnerability assessment, threat intelligence, incident response, security operations centres (SOC), security architecture, and threat-led penetration testing (STAR/STAR-FS). Its core "product" is not software but a body of published accreditation standards, professional certification exams (e.g., CPSA, CRT, CCT INF, CCT APP, CPIA, CCIM, CCSAM), maturity assessment tools (spreadsheet-based, scored 1–5), and the CREST Marketplace, a searchable online directory of accredited suppliers filterable by service, region, industry, and government scheme.

CREST serves three primary buyer groups—cybersecurity service providers seeking independent quality assurance, governments and regulators requiring standardized providers, and enterprise buyers procuring vetted services—plus individual practitioners pursuing credentials. Its accreditations are embedded in numerous regulated schemes, including UK Bank of England CBEST, NCSC CHECK/CIR/CIE, UK CAA ASSURE, UK Cabinet Office GBEST, Dubai DESC Cyber Force, EU ECB TIBER-EU, and HKMA iCAST. The organization reports over 500 member companies worldwide and more than 3,000 individuals holding CREST certifications, operating through regional councils across Asia, Australasia, Europe, Middle East & Africa, North America, and the UK.

The business model is member-funded and recurring. Revenue streams include annual membership subscriptions (£26,500 global / £7,500 regional), tiered entry statuses (Pathway at £250/year, Pathway+ at £1,500/year), one-time joining fees (£1,500–£25,000 by revenue tier), non-refundable application fees (£500–£1,200), professional certification exam fees, and additional accreditation subscriptions (e.g., OVS at £2,000/year, CIS Controls at £1,200/year). Go-to-market is consultative and relationship-based via membership applications, the marketplace, regional subscriptions, government/regulator programs, industry events (CRESTCon, BSides), and discipline communities. Discounts (50%) apply for low-income-country providers.

CREST firmographics

Firmographics
Name
CREST
Legal name
CREST (International)
Website
https://crest-approved.org
Company type
Private
Founded year
2006
Operating status
Operating
Headcount range
251–500 employees
Short description
CREST is a UK-based not-for-profit accreditation and certification body for the cybersecurity industry, accrediting 500+ service-provider members and certifying 3,000+ practitioners across penetration testing, incident response, SOC, and threat intelligence, serving providers, regulators, and enterprise buyers.
Ownership category
akta.pro rank

CREST industry classification

Industry
Product category
Cybersecurity Accreditation Services
NAICS
Educational Support Services (611710), Business Associations (813910), Testing Laboratories and Services (54138)
SIC
Services-Testing Laboratories (8734)
akta.pro primary industry
Information Technology (IT) & Cybersecurity Certifications (EDAAANAA)
akta.pro secondary industries
Penetration Testing, Red Team & Ethical Hacking (EDAOAIAH), Digital Assessment Platforms & Computer-Based Testing Authorities (EDADAFAK), Credential, Education & Professional License Verification (BPAKAEAI), Certification & Licensing Exam Management Platforms (EDAFADAG)

Keywords

  • Cybersecurity accreditation services
  • Penetration testing certification
  • Incident response accreditation
  • Threat intelligence certification
  • Cyber service standards

Where CREST is headquartered

Location

Headquarters

HQ city
Slough
HQ country
United Kingdom
HQ region
Europe

Offices1 record

Markets served

CREST business model

Business model
GTM type
B2B
Offering type
Services
Cost components
Personnel, Operations, Technology or R&D, Marketing or Sales

Revenue model

  1. Membership Subscriptions: Annual subscription fees charged to member companies. Global subscription covers all regions; regional subscriptions cover specific geographic areas (Americas, Asia, Australasia, EMEA). Fees are required to maintain CREST membership and access accreditation benefits.
  2. Accreditation Application Fees: Non-refundable fees charged when organizations submit accreditation applications. Covers assessment of application, one resubmission if initial application fails, and administrative processing. Fees vary by accreditation type from £500 to £1,200 depending on discipline.
  3. Joining Fees: One-time joining fees for new members based on annual revenue tiers. Revenue thresholds determine fees ranging from £1,500 for revenue below £1m to £25,000 for revenue above £50m. Applied only at initial membership, not for renewals or additional accreditations.
  4. Professional Certifications: Revenue from CREST professional certification exams including CPSA, CRT, CCT INF, CCT APP, CPIA, CRIA, CCIM, CPTIA, CRTIA, CCTIM, CCRTS, CCSAM. Discounts available for Pathway/Pathway+ members and low-income countries.
  5. Additional Accreditation Subscription Fees: Annual fees for specific accreditations beyond base membership: Mobile & Web Application Testing (OVS) at £2,000/year and CIS Controls Accreditation at £1,200/year.

Pricing tiers

ModelBillingPrice
SubscriptionAnnualPathway Status - Entry-level registration for early-stage cyber service providers
SubscriptionAnnualPathway+ Status - Self-assessment stage for organizations progressing toward accreditation
SubscriptionAnnualCREST Membership - Full accreditation with independent review
SubscriptionAnnualPathway/Pathway+ Bundle
SubscriptionAnnualLow-Income Country Discount

Go-to-market motion3 records

Distribution channels4 records

Marketing channels6 records

CREST product offering

Product offering

Core offering

CREST is an international not-for-profit accreditation and certification body for the cybersecurity industry. It accredits cybersecurity service provider companies across multiple technical disciplines (penetration testing, incident response, SOC, threat intelligence, security architecture) and certifies individual practitioners through professional examinations. CREST also operates a marketplace that connects organizations seeking cyber services with its community of accredited suppliers.

Product overview

CREST is a global accreditation and certification body for the cyber security industry, offering a multi-layered portfolio of accreditation programmes for organizations and professional certifications for individuals. The core offering consists of organizational accreditation across seven cyber security disciplines: Penetration Testing, Vulnerability Assessment, Threat Intelligence, Incident Response, Security Operations Centres (SOC), Security Architecture, and Threat-Led Penetration Testing (STAR/STAR-FS). Supporting the accreditation programmes are professional certifications for individuals at various career stages (Practitioner, Registered, and Certified levels) spanning penetration testing, intrusion analysis, incident management, red teaming, and threat intelligence. The portfolio also includes maturity assessment tools, an online marketplace for finding accredited suppliers, and the CREST CAMP capacity-building programme for developing markets. CREST serves over 500 member companies worldwide and manages government/regulator schemes including CBEST, TIBER-EU, ASSURE, NCSC CHECK, and Dubai Cyber Force.

Differentiator

Problem solved

Functional benefit

Brands

  • CREST AI Charter: Industry framework establishing principles for the responsible use of artificial intelligence in cyber security services covering governance, transparency, accountability, and data protection.
  • CREST CAMP
  • CREST Marketplace

Products and services

  • Organizational Accreditation Programme
  • Professional Practitioner Certifications
  • CREST Marketplace

Quantifiable outcome

  • Over 500 member companies quality assured and accredited globally
  • +2 more outcomes

Companies that use CREST

Customer profile

Named customers5 records

Segments4 records

Ideal customer profiles3 records

CREST technology and API

Technology

Technology focussed No

API detail

Has API
No
API docs
API detail

Core technology

AI maturity

App detail

Feature3 records

CREST partnerships and signals

Strategic signal

Partnerships

17 partnerships are on record, tiered flagship and core.

  • NCC GroupflagshipStrategic or Co-development Partner · 24 June 2026NCC Group became a founding signatory of the CREST AI Charter, an industry framework establishing nine principles for the responsible use of artificial intelligence in cybersecurity services covering governance, transparency, accountability, and data protection.
  • SynackcoreStrategic or Co-development Partner · 4 June 2026Synack expanded its partnership with CREST by adding two new certifications (CREST Certified Tester Infrastructure and CREST Certified Tester Application) to its Synack Red Team Pathways program. This gives CREST-certified security researchers a direct route to join the SRT community and adds third-party credentialing important for DORA, NIS2, and TIBER-EU compliance.
  • AbacuscoreStrategic or Co-development Partner · 7 April 2026Abacus achieved CREST accreditation for its penetration testing services following independent audit between October 2025 and February 2026. The accreditation validates that Abacus meets technical, ethical, and legal standards for penetration testing, placing it among rare MSPs with this benchmark.
  • UK Foreign, Commonwealth & Development Office (FCDO)flagshipStrategic or Co-development Partner · 1 September 2024CREST CAMP (Cyber Accelerated Maturity Programme) is funded by UK FCDO, targeting 11 countries from September 2024 to March 2025 to improve cybersecurity maturity and private sector involvement through mentoring, training, and accreditation pathways.
  • UK Department of Foreign Affairs and Trade (DFAT)flagshipStrategic or Co-development PartnerCREST CAMP supported by DFAT alongside FCDO and EBRD as international donor partners funding capacity-building programs across 14+ countries.
  • European Bank for Reconstruction and Development (EBRD)flagshipStrategic or Co-development PartnerCREST CAMP supported by EBRD as international donor partner alongside FCDO and DFAT, funding cybersecurity capacity building globally.
  • UK Bank of EnglandflagshipStrategic or Co-development PartnerCREST developed CBEST framework with UK Bank of England to deliver controlled, bespoke, intelligence-led cyber security tests for systemically important financial institutions. CREST helps develop accreditation standards for CBEST penetration testing.
  • UK National Cyber Security Centre (NCSC)flagshipStrategic or Co-development PartnerCREST delivers CHECK scheme (approved penetration tests for public sector and CNI), NCSC CIR Standard Level scheme, and Cyber Incident Exercising (CIE) scheme in partnership with NCSC.
  • UK Civil Aviation Authority (CAA)coreStrategic or Co-development PartnerCREST developed ASSURE scheme with UK CAA for cyber security audits of aviation organizations under CAP 1753 framework.
  • Dubai Electronic Security Center (DESC)coreStrategic or Co-development PartnerDESC Cyber Force program enables CREST-qualified individuals and accredited companies to register as cybersecurity service providers for Dubai government, semi-government, and critical information infrastructure sectors.
  • European Central Bank (ECB)coreStrategic or Co-development PartnerCREST supports TIBER-EU framework enabling European and national authorities to test financial sector resilience against sophisticated cyber attacks.
  • Hong Kong Monetary Authority (HKMA)coreStrategic or Co-development PartnerCREST supports iCAST framework introduced by HKMA for threat intelligence-led security testing of banks under Cyber Resilience Assessment Framework.
  • UK Cabinet OfficecoreStrategic or Co-development PartnerCREST developed GBEST scheme based on CBEST model, being rolled out across UK Government Departments with NCSC providing technical assurance.
  • UK Cyber Security CouncilcoreStrategic or Co-development PartnerCREST certifications align with UK CSC professional titles framework. CHECK scheme requires CTLs and CTMs to hold UK CSC professional titles at Practitioner and Principal levels respectively.
  • OWASPcoreTechnology or IntegrationCREST OVS quality assurance standard is aligned to OWASP's Application Security Verification Standard (ASVS) and Mobile Application Security Verification Standard (MASVS).
  • Center for Internet Security (CIS)coreStrategic or Co-development PartnerCREST offers CIS Controls Accreditation for organizations assessing client implementation of CIS Critical Controls.
  • UK CAA (ASSURE)coreStrategic or Co-development PartnerCREST and UK CAA collaborated to develop the ASSURE scheme for third-party cyber security audits of aviation organizations.

Scale indicators5 records

Recent moves6 records

Expansion highlights6 records

CREST competitors and assessment

Company assessment

Broad incumbents

  • CompTIA: CompTIA is a large, established provider of vendor-neutral IT certifications (Security+, PenTest+, CySA+) that overlaps with CREST's entry- and mid-tier cybersecurity certification portfolio and is widely recognized by employers and governments.
  • PCI Security Standards Council: PCI SSC is an industry-led standards body that qualifies security assessors (QSAs) and approves scanning vendors for the payments ecosystem, operating an analogous accreditation model in the adjacent payments-cyber segment.
  • IAPP (International Association of Privacy Professionals): IAPP is a global non-profit certification and membership body for privacy professionals (CIPP, CIPM, CIPT), adjacent in mission and member-funded business model to CREST's privacy- and security-accreditation role.

Direct peers

  • EC-Council: EC-Council issues the Certified Ethical Hacker (CEH) and other offensive security credentials, competing for the same individual certification and training demand that CREST addresses via CRT, CCT, and CCSAM/CCRTS.
  • ISACA: ISACA is a global non-profit membership body that issues widely recognized cybersecurity and IT governance certifications (CISA, CISM, CGEIT, CRISC) and serves as a direct peer in professional credentialing for the cybersecurity workforce.
  • APMG International: APMG accredits and manages professional certification schemes (e.g., ISO/IEC 27001, cyber resilience schemes), operating the same accreditation-and-certification business model as CREST across adjacent standards.
  • Offensive Security: Offensive Security issues the OSCP and other hands-on penetration testing certifications, positioning it as a direct peer for offensive-security individual credentials that overlap with CREST's CCT INF and CCT APP certifications.
  • (ISC)²: (ISC)² is a global non-profit cybersecurity professional certification body best known for the CISSP credential, making it the most direct peer to CREST's role as an accreditation and certification body for cybersecurity professionals and organizations.
  • SANS Institute: SANS Institute delivers cybersecurity training and awards the GIAC family of certifications, overlapping directly with CREST's penetration testing, incident response, and SOC certification offerings.

Others

  • NCSC (UK National Cyber Security Centre): UK NCSC is the regulator that delegates delivery of CHECK, CIR, and CIE schemes to CREST and licenses other accreditors; it is a key ecosystem partner and the source of CREST's strongest UK regulatory moat.

Market position

Strengths5 records

Weaknesses5 records

Competitive moat4 records

Key risks6 records

Key highlights7 records

Customer concentration

CREST social profiles

Digital presence

CREST financial estimates

Financial estimate

Revenue estimate

Valuation estimate

CREST leadership team

Management profile

Number of profiles

Profiles3 records

CREST funding detail

Funding detail

Funding overview

Funding rounds1 record

Investors1 record

Funding detail is available on the Subscription and Enterprise plan.Contact sales →

CREST M&A and investment

M&A and investment

M&A

Investments

M&A and investment is available on the Subscription and Enterprise plan.Contact sales →

Frequently asked questions about CREST

What does CREST do?

CREST is an international not-for-profit accreditation and certification body for the cybersecurity industry. It accredits cybersecurity service provider companies across multiple technical disciplines (penetration testing, incident response, SOC, threat intelligence, security architecture) and certifies individual practitioners through professional examinations. CREST also operates a marketplace that connects organizations seeking cyber services with its community of accredited suppliers.

Is CREST a public or private company?

CREST is a private company. It is classified as nonprofit foundation owned and is currently operating.

When was CREST founded?

CREST was founded in 2006. It employs 251 to 500 people.

Where is CREST based?

CREST is headquartered in Slough, United Kingdom, in the Europe region.

How does CREST make money?

Five revenue lines are on record. Membership Subscriptions are the primary driver. The others are accreditation Application Fees, joining Fees, professional Certifications and additional Accreditation Subscription Fees.

Who are CREST's main competitors?

Broad incumbents on record are CompTIA, PCI Security Standards Council and IAPP (International Association of Privacy Professionals). Direct peers are EC-Council, ISACA, APMG International, Offensive Security, (ISC)² and SANS Institute. NCSC (UK National Cyber Security Centre) is listed as an others.

Does CREST have an API?

No public API is recorded for CREST.

What industry is CREST in?

CREST's product category is Cybersecurity Accreditation Services. Its primary akta.pro industry code is EDAAANAA, Information Technology (IT) & Cybersecurity Certifications, with a secondary code of EDAOAIAH, Penetration Testing, Red Team & Ethical Hacking. Its NAICS code is 611710 and its SIC code is 8734.

Unlock the full company data

50 free credits on sign-up, no credit card required.

Contact sales
Live signals
Security BoulevardAI Penetration Testing: Will AI replace human pen testers?AI penetration testing tools are being adopted, with a Stanford study showing an AI agent outperforming 9 of 10 humans in speed and cost. However, humans still excel at complex business logic and access control, and CREST has launched AI-focused accreditations. The role is shifting toward human judgment rather than full replacement.SecuritybriefCREST launches AI testing standard for cyber firmsCREST International has launched a Security Testing of AI standard and accreditation for cybersecurity service providers, assessing technical expertise, methodologies, governance, tooling and AI-specific risk identification. Providers must already hold Penetration Testing Accreditation. CREST cited research showing 69% of penetration testing providers use AI and 76% increased use over the past year.FinancialContent Business PageQualysec Technologies Earns CREST Accreditation for Penetration TestingQualysec Technologies has received CREST accreditation for its penetration testing practice, providing independent recognition of its technical capabilities and professional standards. The company reports over five years of experience, having completed more than 2,500 security assessments for clients in over 38 countries. This accreditation supports Qualysec's strategy to expand its enterprise and international presence in regulated industries.SourcesecurityCREST launches AI security testing accreditationCREST, a global cybersecurity non-profit, has launched a new accreditation standard for the security testing of Generative AI and Large Language Model-enabled systems. This initiative aims to provide independent assurance that service providers possess the necessary technical expertise and methodologies to assess AI-specific security risks effectively. The standard covers the entire AI system attack surface, including applications, data sources, and orchestration layers, addressing market needs for verified competence.Security BoulevardWhat is Penetration Testing?The article provides a comprehensive overview of penetration testing, defining it as an authorized ethical hacking process used to identify and exploit security weaknesses in digital systems before malicious actors can. It outlines various testing types, including web application, mobile, network infrastructure, API, and social engineering assessments, while emphasizing their role in meeting regulatory standards like GDPR and ISO 27001. The text also details the operational lifecycle of a pen test and highlights Sencode as a CREST-accredited provider offering these services in the UK.Indian Economic ObserverNuSummit Joins CREST AI Charter Founding Signatories to Advance Trusted AI in CybersecurityNuSummit Cybersecurity announced it has become a Founding Signatory of the CREST AI Charter, joining a group of leading cybersecurity organizations committed to promoting responsible AI use across the industry. Through this commitment, NuSummit Cybersecurity supports CREST's Nine Principles for AI-Enabled Activities, ensuring its AI-enabled services incorporate strong governance, security, human oversight and accountability. The company stated that clients increasingly demand accountable AI solutions, positioning this membership as a reflection of its standards for trustworthy AI-enabled cybersecurity offerings.The TribuneNuSummit Joins CREST AI Charter Founding Signatories to Advance Trusted AI in CybersecurityNuSummit Cybersecurity announced it has become a Founding Signatory of the CREST AI Charter, joining a group of leading cybersecurity organizations committed to promoting responsible AI use across the industry. Through this commitment, NuSummit supports CREST's Nine Principles for AI-Enabled Activities, ensuring its AI-enabled services are built with strong governance, security, human oversight and accountability. The company stated that this move reflects its commitment to helping shape a trusted future for AI-enabled cybersecurity while upholding professional standards.BusinessLineNuSummit Joins CREST AI Charter Founding Signatories to Advance Trusted AI in CybersecurityNuSummit Cybersecurity announced it has become a Founding Signatory of the CREST AI Charter, joining a group of leading cybersecurity organizations committed to promoting responsible AI use in the industry. Through this commitment, NuSummit supports CREST's Nine Principles for AI-Enabled Activities, committing to deliver AI-enabled services with strong governance, security, human oversight, and accountability. The company stated this reflects its commitment to shaping a trusted future for AI-enabled cybersecurity as AI adoption accelerates across the cybersecurity sector.The HinduNuSummit Joins CREST AI Charter Founding Signatories to Advance Trusted AI in CybersecurityNuSummit Cybersecurity announced it has become a Founding Signatory of the CREST AI Charter, joining a group of leading cybersecurity organizations committed to responsible AI use in the industry. Through this commitment, NuSummit supports CREST's Nine Principles for AI-Enabled Activities, which focus on governance, security, human oversight, and accountability in AI-enabled services. The company stated that this reflects its standard of treating governance and human oversight as non-negotiable as it embeds AI deeper into its cybersecurity offerings.TechTrendsKECREST creates AI accreditation for penetration testing servicesCREST introduced AI accreditation standards for cybersecurity service providers, becoming one of the first to offer independently verified requirements for responsible AI use in penetration testing. Applications for the optional accreditation are now open to existing CREST members and other providers. The standards are incorporated into CREST's existing accreditation framework, allowing enforcement of compliance.