CHECK penetration testing

Information for CHECK buyers
About the CHECK penetration testing scheme
If you’re part of central government or the critical national infrastructure (CNI), it is imperative that you have the utmost level of trust in the testers accessing your systems. The CHECK scheme is intended to give you that confidence.
The NCSC assesses all companies offering CHECK services to make sure they follow our methodology.
Who is it for?
If you operate in one of the following areas, the CHECK scheme gives you confidence in the testers accessing your systems and networks:
- central government departments
- public sector bodies
- UK critical national infrastructure (CNI)
You gain this confidence through the assurance that every company offering CHECK services has been rigorously assessed to make sure their methodology meets our standard.
All CHECK Team Leaders must hold and maintain, as a minimum, a ‘Principal’ Cyber Security Professional (Security Testing) title awarded by the UK Cyber Security Council. All CHECK Team Members must hold and maintain, as a minimum, a ‘Practitioner’ Cyber Security Professional (Security Testing) title awarded by the UK Cyber Security Council. Both CHECK Team Leaders and CHECK Team members must hold a valid SC clearance as a minimum. We regularly audit CHECK reports to ensure they are meeting CHECK standards.
If your organisation is not public sector, penetration testing does not need to be conducted by a CHECK service provider. There is useful information on how to commission a penetration test on the NCSC website.
How to select a CHECK penetration test provider
CHECK Service Providers are all listed on our website.
Any contract for penetration testing work is made between you and your selected CHECK service provider.
For government and wider public sector, the NCSC has worked in partnership with Crown Commercial Services (CCS) to establish a central route to procure CHECK services.
Full details on using their Dynamic Purchasing System to invite suppliers to a mini competition tender can be found on the CCS website.
When you are buying a penetration test from a CHECK provider, they will give you this letter which contains useful information to make your experience as smooth as possible.
Considerations for using a CHECK provider
For central government departments and their associated agencies:
- All systems processing data protectively marked OFFICIAL and above (up to Top Secret but excluding STRAP systems) should be assessed by companies assured under CHECK
For other public sector bodies:
- We strongly recommend that all systems be assessed by a CHECK company, unless the system's risk owner explicitly advises otherwise
Planning and commissioning a penetration test on your network should be done with care and we have some guidance on this to help you.
Provide feedback on a penetration test conducted under the CHECK scheme
Feedback helps us to make improvements to the scheme and ensure that CHECK service providers remain effective. Please send your feedback via the Customer Feedback form.
For CHECK-related complaints or breaches of contract, please email the CHECK team