01Introduction
In the UK, the Middle East and parts of Asia-Pacific, procurement teams often require that a penetration test be performed by a CREST-accredited provider. It's an accreditation for testers, not a framework for your controls.
02What is CREST?
CREST is an international not-for-profit body that accredits companies providing penetration testing, threat intelligence, incident response and SOC services, and certifies individual practitioners through exams. Accredited companies must meet requirements for methodology, data handling and staff qualifications.
03How CREST works
For buyers, CREST works as a supplier filter.
- 1.
Check the requirement
Confirm whether a regulator, contract or customer requires a CREST-accredited provider.
- 2.
Select a provider
Choose from CREST's member directory for the service type needed.
- 3.
Scope and test
The provider runs a penetration test or red team engagement to CREST methodology.
- 4.
Report
Receive a report that satisfies the procurement or regulatory requirement.
04Threats and risks
The risk is treating an accredited test as the whole program.
Point-in-time assurance
An annual accredited test says little about releases shipped afterward.
Narrow scope
Budget limits which applications get tested.
Procurement delays
Scheduling accredited testers can take weeks.
Unfixed findings
Reports that satisfy procurement but don't lead to remediation.
05How Parameter helps
Parameter doesn't replace a CREST-accredited provider where one is required. It covers the continuous testing between those engagements.
Test between engagements
The pentesting agents test every release, so the accredited test finds less.
Arrive prepared
Fix proven findings before the formal engagement starts.
Retest on fix
Verify remediation of accredited-test findings immediately.

