Iterasec Is Now a CREST-Accredited Penetration Testing Provider

Iterasec Is Now a CREST-Accredited Penetration Testing Provider

Choosing a pentest provider requires more than comparing service lists and certifications. Almost any company can claim to follow best practices or employ experienced ethical hackers. The harder question is whether its methodology, internal controls, quality assurance, and technical capability have been independently assessed.

Iterasec has achieved CREST accreditation in the Penetration Testing and Vulnerability Assessment disciplines. For our clients, this adds independent assurance to the security testing services they already receive from Iterasec.

This article explains what CREST is, what the assessment involves, and what working with a CREST-accredited provider means in practice.

CREST approved provider

What Is CREST Accreditation?

CREST is an international not-for-profit membership and accreditation body representing the global cybersecurity industry. Established in 2006, it develops standards for cybersecurity service providers and professional certifications for individuals. Its accredited disciplines include security testing, incident response, threat intelligence, and security operations.

Company-level accreditation assesses whether a provider has the organizational controls, service-delivery processes, technical capability, and governance required to deliver consistently professional work. For pen testing, that means more than demonstrating an ability to find vulnerabilities. CREST also examines how a provider scopes and authorizes tests, protects client information, assures report quality, communicates with stakeholders, and manages legal and ethical responsibilities.

CREST accreditation vs CREST certification

A CREST member company is assessed as an organization. The review covers its methodologies, processes, security practices, and the collective competence of the team delivering the accredited service.

Individual CREST certifications, including CPSA, CRT, and CCT, assess a professional’s knowledge and technical skills through examinations. CREST does not require every specialist at an accredited company to hold one of these qualifications. The company assessment considers the team’s skills, experience, relevant certifications, and staffing as a whole.

Iterasec’s specialists hold a broad range of professional credentials and continually develop their skills through research, internal knowledge sharing, and practical project work. Those credentials support the team’s expertise; the company-level assessment validates the system through which that expertise is delivered.

CREST accreditation standards: what is required to become a CREST-accredited company

Providers must present evidence against CREST’s general company requirements and the standards for each service they want to be accredited. For Iterasec, this meant demonstrating how our assessments are planned, performed, reviewed, secured, and improved.

Documented and repeatable testing methodology

A reliable assessment must be repeatable without becoming a checklist exercise. Testers need enough structure to cover the agreed scope consistently, while retaining the freedom to investigate non-obvious attack paths and vulnerability chains.

The review considers documented processes for scoping, authorization, delivery, communication, reporting, and remediation support. At Iterasec, project-specific work is informed by OWASP, NIST, OSSTMM, MITRE ATT&CK, CIS Benchmarks, and relevant cloud-provider guidance. These resources establish coverage, but they do not replace manual analysis or professional judgment.

Proven technical competence and certified consultants

The assessment evaluates whether the provider has enough suitably skilled professionals to deliver the accredited services. Qualifications contribute to this evaluation, but practical experience, technical depth, supervision, and the ability to handle different environments also matter.

A scanner can detect known exposures. It cannot reliably understand business logic, combine several weaknesses into a critical attack path, or determine whether an apparent vulnerability is genuinely exploitable in the client’s environment.

Quality assurance, reporting and data handling

A security assessment gives an external team access to sensitive systems and information. Technical skill without disciplined handling of that access creates its own risk.

CREST examines legal and regulatory requirements, data protection, test-data security, logging and auditing, stakeholder communication, and quality assurance. Accredited companies also commit to CREST codes of conduct and remain subject to renewal and oversight.

For clients, this means findings should be technically verified, evidence handled securely, and reports reviewed before they become the basis for remediation, audit evidence, or a risk decision.

What CREST penetration testing accreditation means for Iterasec clients

Independently Validated Quality

Vendor selection often relies on information supplied by the vendor itself: website claims, sales materials, references, sample reports, and individual credentials. These inputs are useful, but they are not independent validation.

The accreditation reduces that uncertainty. It shows that an external industry body has assessed the provider’s methodologies, processes, and skills against a defined standard. It does not guarantee that no vulnerability will remain undiscovered. It gives buyers a stronger basis for trusting how the work will be conducted, reviewed, and reported.

Stronger Assurance for Enterprise Customers

For many software and technology companies, a penetration test is not only an internal security measure. It is also evidence that prospective customers expect to see during procurement and security due diligence.

Large enterprises, financial institutions, telecom operators, and other regulated organizations often examine how a product was tested, who performed the assessment, and whether the provider has recognized external accreditation. In some procurement processes, using a CREST-accredited penetration testing company is required. In others, it provides stronger assurance than a report from an unknown or self-declared security vendor.

Working with a CREST-accredited provider gives Iterasec clients more credible evidence to present to their own customers. The final report can support security questionnaires, vendor assessments, procurement reviews, and discussions with internal security teams.

This can make it easier to:

  • Demonstrate that the product was tested by an independently assessed security provider
  • Respond to enterprise security and procurement requirements
  • Reduce concerns around the quality and reliability of the assessment
  • Support customer due diligence with clear, professionally reviewed findings
  • Move enterprise sales discussions forward without repeating the same security validation for every prospect

The accreditation does not replace the need for a properly scoped assessment or timely remediation. It strengthens the credibility of the testing evidence and helps clients demonstrate that product security has been evaluated to a recognized professional standard.

Safe, Risk-Aware Testing of Production Systems

Some weaknesses can only be validated in the environment where access controls, integrations, cloud permissions, network paths, and business logic interact. Production testing, however, must be controlled carefully.

A professional engagement starts with explicit scope, authorization, rules of engagement, escalation contacts, and agreement on potentially disruptive techniques. Critical findings should be communicated immediately. Evidence collection, retention, and retesting must also follow defined processes.

CREST accreditation provides assurance around these organizational and delivery controls. The exact approach remains risk-based and must be agreed for each environment.

“CREST accreditation validates the way we have built Iterasec from the beginning: strong technical teams, careful delivery, and testing that goes beyond automated checks. It confirms that the processes behind our work – from scoping and secure data handling to technical review and reporting – meet a recognized international standard. For clients, it provides another objective reason to trust the depth and consistency of our assessments.”

Igor Kantor
Co-founder and CEO, Iterasec

Why Choose a CREST-Accredited Penetration Testing Provider?

Poor-quality testing can create false confidence. A checklist-only engagement may produce many low-value findings while missing the attack path that actually matters. Vague remediation advice can also make the report difficult to use.

A CREST-approved provider offers additional assurance around:

  • Documented and controlled testing processes
  • Appropriate technical competence and supervision
  • Secure handling of client systems, evidence, and test data
  • Reviewed, actionable reporting rather than raw scanner output
  • Legal, ethical, and professional accountability

Accreditation should still be considered alongside relevant experience, communication, and evidence from similar projects. The right provider also understands the system, threat model, and business risk behind the scope.

Iterasec’s CREST-Accredited Penetration Testing Services

Iterasec provides manual-first testing across applications, infrastructure, cloud environments, and connected technologies:

These services correspond to Iterasec’s current application, network, cloud, container, AI, embedded, IoT, compliance-driven, and adversary-simulation capabilities.

Each engagement is scoped around the client’s architecture, threat model, compliance requirements, and operational constraints. Automated tools may support coverage and efficiency, but experienced specialists perform and interpret the core work.

Clients receive validated findings, evidence, risk context, practical remediation guidance, and a technical debrief – not simply a vulnerability list. Retesting can then confirm whether the issues were addressed correctly.

Contact Iterasec to scope a CREST-accredited penetration test for your applications, infrastructure, cloud environment, or connected product.

 

FAQ

Search for Iterasec in the official CREST Marketplace , which lists CREST accredited providers and their approved disciplines. CREST describes the Marketplace as a sourcing platform for providers independently assessed against its professional standards.

It provides independent assurance that a provider has been assessed against recognized requirements for methodology, technical capability, quality assurance, data security, and professional conduct. It helps buyers distinguish assessed companies from vendors relying only on self-reported expertise.

Accreditation applies to a company and evaluates how it delivers a cybersecurity service. Certification applies to an individual and assesses that professional’s knowledge and technical skills through an examination.

A properly scoped assessment can provide credible evidence for risk management, vulnerability assessment, control testing, and remediation. It does not automatically establish compliance; the work must match the systems, scope, frequency, and evidence required by the framework.

The process starts with scoping and a kickoff meeting to confirm assets, access, constraints, communication, and rules of engagement. Iterasec then performs the agreed work, communicates critical findings during the project, delivers a reviewed report, and holds a technical debrief. Most engagements take approximately two to five weeks depending on scope and complexity, with retesting available after remediation.

Contacts

Please tell us what are you looking for and we will happily support you in that. Feel free to use our contact form or contact us directly.

    Thank you for submission!

    We’ve received your request and will get back to you shortly. If you have any urgent questions, feel free to contact us at [email protected]