Service

NCSC CHECK Penetration Testing

Expert-led penetration testing that goes beyond automated scanning to identify, validate and demonstrate the vulnerabilities and attack paths that could put your organisation, data and services at risk.

Understanding NCSC CHECK penetration testing

Meet your penetration testing requirements with NCSC CHECK.

CHECK penetration testing provides controlled, expert-led testing against the NCSC CHECK scheme, which sets standards for penetration testing trusted by government, public sector and UK critical national infrastructure organisations.

We combine automated tooling, manual investigation and real-world attack techniques to validate vulnerabilities, assess their impact and identify attack paths. CHECK provides additional assurance through NCSC-assessed methodologies and defined professional and security clearance requirements for CHECK personnel.

Learn more about CHECK for buyers

Benefits of NCSC CHECK penetration testing

Independent penetration testing with recognised assurance.

When the security of critical systems, sensitive information or important services is at stake, the quality and independence of your penetration testing matter. NCSC CHECK provides assurance that the provider, its methodology and the personnel delivering CHECK services meet defined requirements set by the NCSC.

01

Choose NCSC-assured testing

CHECK is an NCSC assurance scheme for authorised penetration testing of public sector and UK critical national infrastructure systems and networks. The NCSC assesses companies providing CHECK services to ensure their methodology meets the scheme standard.

See the NCSC guidance for buyers

02

Work to an established standard

CHECK providers operate against defined NCSC requirements covering the delivery of penetration testing. The scheme includes requirements around methodology, testing, evidence and reporting, giving customers a defined standard against which CHECK engagements are delivered.

View the CHECK scheme documents

03

Test beyond automated scanning

Effective penetration testing is about more than identifying potential vulnerabilities. We combine automated tooling with manual investigation, exploitation and experienced security judgement to establish whether weaknesses are genuinely exploitable and what an attacker could achieve.

Read how the NCSC defines penetration testing

04

Use qualified CHECK personnel

CHECK has defined requirements for the personnel delivering CHECK engagements. Team Leaders must hold the required professional qualification and CHECK team members must meet the scheme's competency and security clearance requirements. The NCSC also provides a facility for buyers to verify CHECK professionals.

View CHECK personnel requirements

05

Get evidence you can act on

CHECK reporting requirements are designed to give customers a clear record of the assessment, its scope, findings and supporting evidence. Our reports explain what was tested, what was identified, what could be exploited and why it matters, giving technical teams evidence they can use to plan remediation.

Review the CHECK scheme standard

06

Maintain confidence after remediation

Once vulnerabilities have been addressed, focused or full retesting can independently verify the changes. This provides evidence that identified weaknesses have been remediated and helps maintain confidence in the security of your systems over time.

Who needs NCSC CHECK testing?

When your customer, contract or environment requires CHECK.

NCSC CHECK is particularly relevant when penetration testing forms part of the assurance requirements for government, public sector or UK critical national infrastructure. If you are a supplier to government or CNI, or your contract specifically requires testing by an NCSC CHECK provider, we can help you determine what testing is required and deliver the appropriate assessment.

  • Suppliers and third parties supporting UK government organisations
  • Organisations providing services to UK critical national infrastructure
  • Contracts or procurement requirements that explicitly specify NCSC CHECK
  • Organisations requiring infrastructure or web application penetration testing with CHECK assurance

Not sure whether CHECK applies to your requirement? We can help you understand the scope, identify whether infrastructure or web application testing is appropriate, and define an assessment that meets the relevant requirement.

NCSC guidance for CHECK buyers

When NCSC CHECK scheme applies

Choose CHECK when the requirement calls for it.

NCSC CHECK is an assurance scheme for penetration testing, particularly relevant to UK government, public sector and critical national infrastructure environments. If your organisation, customer or contract requires testing by an NCSC CHECK provider, we can help define and deliver the appropriate assessment.

What NCSC CHECK tests cover

Infrastructure and web applications, tested properly.

Our NCSC CHECK penetration testing covers the two core testing areas of the scheme: infrastructure and web applications. We combine automated tooling, manual techniques and experienced security testing to identify vulnerabilities, validate their impact and understand how they could be exploited.

How we test

Methodology, expertise and CHECK assurance.

Our CHECK penetration tests use the same expert-led approach as our wider penetration testing, combining established methodologies, automated tooling and manual investigation, with testing aligned to the applicable NCSC CHECK requirements.

At a glance

Testing approach
Same expert-led methodology, aligned to CHECK requirements
Testing techniques
Automated tooling, manual testing and expert analysis
CHECK scope
Infrastructure and web application testing
Communication
Regular updates, with immediate escalation of serious findings
Scope control
Agreed boundaries with hard stops for out-of-scope systems
Handover
CHECK-compliant report, findings walkthrough and technical debrief

Our deliverables

Evidence your organisation can stand behind.

CHECK reporting follows the NCSC's defined requirements, providing clear evidence of the assessment, findings, risk and recommendations. CHECK reports are also subject to specific NCSC reporting and information-sharing requirements.

01

Technical Report

The formal CHECK report documents the scope, methodology, testing and limitations, with detailed findings, risk, evidence, impact, attack-path context and remediation recommendations. For systems below SECRET, CHECK reports are submitted to the NCSC through its secure portal. For SECRET and above, the customer retains the report for NCSC inspection on request.

NCSC CHECK requirements

02

Executive Summary Report

A concise summary of the assessment, overall security posture, highest-risk findings, key impacts and recommendations. We can also provide a separate customer-facing executive summary where required.

03

Custom Spreadsheet Reports

Where required, findings can also be supplied in your own spreadsheet or structured format, with fields such as affected assets, finding references, risk and remediation status. This can support internal vulnerability management or customer reporting processes alongside the formal CHECK report.

Need NCSC CHECK testing?

Tell us what you need to test and we’ll help define the right CHECK assessment for your environment, requirements and scope.

Discuss CHECK testing