About this Framework
CREST is an international non-profit accreditation and certification body for the technical security industry, providing rigorous examinations for penetration testers (CRT, CCT, CCSAS, CCSAM) and organisational accreditation for security testing firms. CREST-accredited assessments are required or recognised by the Bank of England (CBEST), European Central Bank (TIBER-EU), DORA for Threat-Led Penetration Testing (TLPT), PCI SSC for ASV scanning, and financial and government regulators across Asia-Pacific. CREST accreditation assures buyers of tester technical competence and ethical conduct.
Key Control Domains
Who Needs This?
- Financial institutions required to conduct CBEST or TIBER-EU/DORA TLPT
- Organisations requiring PCI DSS qualified penetration testing
- Government and critical infrastructure agencies
- Healthcare organisations requiring accredited security testing
- Enterprises conducting annual external and internal penetration testing
Compliance Benefits
- Internationally recognised quality assurance for security testing services
- Required for CBEST, TIBER-EU and DORA Threat-Led Penetration Testing
- Assures buyers of technical qualifications, ethics and professional standards
- Regulatory acceptance across financial services in UK, EU, Asia-Pacific and Middle East
Official Reference
Assessment Details
Share this Assessment
Share this permanent link with your team, clients or auditors.
https://grcopilot.app/frameworks/crest-penetration-testing-assessment