Key Takeaways
- CREST is a company level accreditation, not an individual certification, it verifies that a testing firm meets defined standards for methodology, quality control, and data handling.
- CREST penetration testing is most often required by UK based buyers, financial services companies, and government adjacent organizations, it is rarely a requirement for US SaaS or HealthTech startups.
- OSCP, CRTP, and CARTP are individual tester certifications, a different thing entirely, and just as relevant a signal of tester skill for buyers who are not asking for CREST specifically.
- Ask what your actual buyer or auditor requires before assuming you need a CREST accredited vendor, the requirement is buyer specific, not universal.
CREST penetration testing means the testing firm itself, not just the individual tester, has been accredited by CREST, an international not for profit that certifies companies and individuals against defined technical and quality standards. If a prospect, auditor, or security questionnaire has asked whether your pentest vendor is CREST accredited and you are not sure what that actually means, this covers what the accreditation does and does not guarantee, and when it genuinely matters.
What CREST Accreditation Actually Certifies
CREST accreditation applies at two levels, and the distinction matters. Company accreditation verifies that the firm follows defined methodology, maintains quality assurance processes, handles client data according to specific standards, and carries appropriate insurance and legal safeguards. Individual accreditation, separate from the company level, certifies that a specific tester has passed CREST’s own technical examinations.
A firm can be CREST accredited at the company level without every individual tester holding a CREST personal certification, and a tester can hold an individual CREST certification while working at a firm that is not itself accredited. Buyers asking about CREST usually mean the company level accreditation, since that is what shows up in vendor security questionnaires and procurement checklists.
When CREST Actually Gets Required
CREST accreditation originated in the UK and remains most heavily weighted there. It shows up as a genuine requirement in a few specific contexts: UK financial services firms operating under frameworks like CBEST, UK government and public sector procurement, and larger UK or EU enterprise buyers whose security teams have standardized on CREST as their vendor bar.
For a US based SaaS or HealthTech startup, CREST is far less commonly a hard requirement. SOC 2 auditors do not require it. HIPAA risk assessments do not require it. Most US enterprise security questionnaires ask about testing methodology, tester experience, and report quality rather than a specific accreditation body. CREST becomes relevant mainly when your buyer base includes UK companies, or when you are pursuing a market where CREST has become the default expectation.
Not sure whether your specific buyer or auditor actually requires CREST, or just assumes it might help? Book a scoping call and we will help you figure out what is actually being asked for.
CREST vs OSCP: Two Different Things Entirely
This comparison comes up often enough that it is worth addressing directly. CREST and OSCP are not competing standards, they certify different things. CREST, at the individual level, is one path to demonstrating tester competency, weighted toward UK based methodology and typically pursued by testers at CREST member firms. OSCP, the Offensive Security Certified Professional, is a vendor neutral, hands on certification widely respected across the US and international security industry, earned by compromising live systems in a proctored exam rather than answering multiple choice questions.
Neither certification is objectively superior, they serve different markets and testing traditions. A buyer specifically requiring CREST company accreditation is asking for something OSCP does not provide, since OSCP certifies individuals, not firms. A buyer asking whether your testers are qualified, without specifying CREST by name, is usually satisfied by strong individual certifications regardless of which body issued them.
Where This Leaves a Vendor Evaluation
If you are evaluating a pentest vendor and CREST penetration testing has come up as a requirement, the right first step is confirming whether your specific buyer or auditor actually requires it by name, or whether they are asking a broader question about tester qualifications that a range of certifications can answer. Requiring CREST specifically narrows your vendor pool considerably, and for a US focused SaaS or HealthTech startup, that narrower pool is often solving for a requirement nobody actually asked for.
Our own delivery team holds OSCP, CRTP, and CARTP certifications rather than CREST, a deliberate fit for our primarily US and Canadian client base, where these certifications carry the same weight CREST carries in the UK market. For SaaS penetration testing specifically, individual tester certification and manual testing depth tend to matter more to US buyers than which accreditation body issued the credential.
Frequently Asked Questions
Does my startup need a CREST accredited pentest vendor? Most US based SaaS and HealthTech startups do not need CREST specifically, unless a UK buyer, UK regulator, or a specific enterprise security questionnaire names it directly. Check what is actually being asked before narrowing your vendor search to CREST accredited firms only.
Is OSCP equivalent to CREST? Not exactly. OSCP certifies individual testers on hands on technical skill, while CREST accredits firms on methodology and quality process, with a separate individual certification track. They are different types of credentials rather than direct substitutes.
Can a non CREST accredited firm still be a strong choice? Yes. Certification and accreditation are one signal among several. Manual testing depth, report quality, tester experience, and relevant compliance framework knowledge often matter more to a US buyer than which accreditation body a firm holds.
If you want a pentest team with certifications suited to your actual buyer base rather than a generic accreditation checklist, book a scoping call and we will walk through what your specific requirements actually are.
Packet33 is a penetration testing and compliance advisory firm serving SaaS and HealthTech startups in the US, Canada, and UK.
Mohamed is the founder of Packet33. He worked as a cybersecurity analyst before launching the firm and now leads an OSCP-certified team serving SaaS and HealthTech startups in the US, Canada, and UK.
