arrow_backBack to field notes
CERTIFICATIONS Published 4 Aug 2026

What Are CREST Certifications and Do You Need One?

A practical breakdown of CREST's UK pentest certifications, who requires them, and how they compare to CEH and OSCP.

If you're aiming to work as a penetration tester in the UK, or for any company that does business with UK government or financial institutions, you'll run into CREST sooner or later. It's not a single exam but a whole certification body with several tiers, and understanding which one matters for your career path saves a lot of wasted study time.

What CREST actually is

CREST (the Council of Registered Ethical Security Testers) is a non-profit accreditation body based in the UK that certifies both individuals and the companies they work for. That second part matters a lot more than it does with something like OSCP. A UK company can't legally bid on certain government or NHS-related security testing contracts unless it holds CREST company accreditation, and that accreditation depends on employing a minimum number of CREST-certified individuals. So the certification isn't just a personal credential — it's tied directly to which contracts your employer can win.

The main individual certifications

CREST offers a ladder of exams rather than one-size-fits-all testing:

  • CPSA (CREST Practitioner Security Analyst) — entry-level, multiple choice, covers networking fundamentals, common vulnerabilities, and methodology. Good for someone one or two years into a security role.
  • CRT (CREST Registered Tester) — the exam most working pentesters aim for first. It's a mix of theory and a hands-on practical component testing infrastructure.
  • CCT (CREST Certified Tester) — split into Infrastructure and Application streams. This is the senior-level credential, roughly comparable in difficulty and reputation to OSCE or GXPN, and it's what's typically required to lead engagements or sign off reports as the accredited tester.

There are also specialist tracks: CCSAS for simulated attack work (used in CBEST-style engagements against UK financial institutions), and certifications for web application testing specifically.

How the exams work

CPSA is computer-based multiple choice, sat at a Pearson VUE center. CRT and CCT involve a practical lab component where you're given a network or application to assess within a fixed time window and have to produce findings that meet CREST's technical bar — not just "I found a vulnerability" but proper identification, exploitation where appropriate, and clear write-up. The CCT practical exams run considerably longer than CRT and expect a much higher exploitation success rate against harder-configured targets.

One detail that trips people up: CREST exams assume UK-centric context. Expect references to UK data protection law, the National Cyber Security Centre (NCSC), and testing methodologies aligned with CHECK (the NCSC's own scheme, which itself requires CREST or equivalent certification for testers).

CREST vs OSCP vs CEH — how they actually compare

CEH is broad and largely theoretical; it's a decent HR checkbox but doesn't carry much weight with practitioners. OSCP is hands-on and internationally respected, especially in the US market. CREST sits in between in terms of raw technical depth but wins on UK-specific market recognition — if you want to work for a CHECK-approved company or bid on UK public sector pentest work, CREST (or NCSC's own scheme) isn't optional, it's a contractual requirement.

If you're building a career outside the UK, OSCP or the newer OSCP+ generally opens more doors. If you're targeting UK consultancies like NCC Group, Context Information Security, or similar CHECK-accredited firms, CRT is usually the first credential recruiters ask about.

Cost and practical planning

CREST exams aren't cheap — expect the CRT practical to run several hundred pounds, with CCT costing considerably more given its length and complexity. Many candidates study using CREST's own syllabus documents (freely published on their site) combined with practice on platforms like HackTheBox or TryHackMe to build the hands-on speed the practical exams demand. Give yourself real lab time before booking — the practical components are unforgiving of shaky enumeration habits, and re-sit fees add up fast.

Who should actually pursue it

If you're already working (or want to work) for a UK-based pentest consultancy, CRT is worth the investment early in your career, with CCT as a multi-year goal once you've got real engagement experience. If you're a generalist security professional outside consultancy — say, in an internal blue team or SOC role — CREST is far less relevant than something like GCIH or a SANS credential.

For more on building the hands-on skills these exams actually test, check out Korra Studio's segments on offensive security fundamentals and web application testing methodology.

Written with AI assistance, reviewed and published by Michal Pilch (CISSP), Korra Studio.

Ready to go further?

This is one note from the Korra Studio knowledge base — the platform pairs every topic with 1-to-1 mentoring.

Get started freearrow_forward