Home / Blog / Security
Security Approximate reading time: 15 min · 09.09.2026

CHECK Penetration Testing, ITHC and PTaaS: What a Tender Spec Asks For

CHECK, ITHC, PTaaS, CREST and Cyber Essentials are not five levels of one job, but five different objects. How to tell which a specification actually requires, and whether it applies to you at all.

A tender specification’s technical requirements, with a security-requirements section

CHECK, ITHC, PTaaS, CREST and Cyber Essentials are not five levels of one job, but five different objects. How to tell which a specification actually requires, and whether it applies to you at all.

You open a tender specification, find the security section of the technical specification and read five names: CHECK penetration testing, ITHC, PTaaS, CREST and Cyber Essentials Plus. Beside them stand the words “security audit” and “penetration test”, and the whole is written as if they were grades of the same job — from the cheapest to the dearest.

They are not grades, but five different objects, which answer five different questions: who may test, what is done to a particular network, how the test is billed, whether the supplier has put their own infrastructure in order, and whether the system meets a norm. A bid that mixes two of them either promises what it must not promise, or pays for what was not asked.

This article does not sell CHECK, and that is worth saying at once: we are not CHECK scheme members, and this text does not claim it. The article explains what the specification actually requires, so that you can see whether it applies to you at all — and only in the case where the requirement turns out to be an ordinary website security check does it point to our website security audit.

Price here differs not by percentages but by multiples, because a bid that answers a Cyber Essentials requirement, and a bid that answers a full penetration test of a multi-role system, are two different budgets, and a buyer who puts them in one table is comparing the incomparable. Likewise a bidder who reads the requirement one grade higher than it is written loses the tender with a perfectly correct, only unnecessarily expensive, bid.

Five names that are not five levels of one job

  • CHECK — the UK National Cyber Security Centre’s (NCSC) company scheme. It determines who may test public-sector and CNI systems and in what form the report is prepared.
  • ITHC — a specific assessment with a specific scope, required for a connection to the UK Public Services Network. It is a task, not a scheme.
  • CREST — an international industry body with its own exams. It is not a synonym of CHECK, and this confusion is the one that appears most often in bids.
  • PTaaSpenetration testing as a service, that is, a delivery and billing model: a platform, a subscription, more frequent findings. It says nothing about who tests and against which standard.
  • Cyber Essentials and Cyber Essentials Plus — a certification of the supplier’s own five baseline controls, not of the system being delivered.

All five are UK or international instruments, and none of them is created by public procurement law, and that is the first thing to keep in mind when reading a specification in which one of them has been written.

CHECK penetration testing is a company scheme, not a test method

CHECK is an NCSC-run scheme into which a company is admitted, not a method any contractor could apply. NCSC buyers’ guidance provides that the work is done by a scheme member, that the team is led by a CHECK Team Leader and includes CHECK Team Members, that these people hold UK personnel security clearance, and that the report is prepared in the scheme format, and that below a given classification level a copy of it goes to NCSC. That means CHECK is not something you could “fulfil” with a test of sufficiently good quality, because a company is either in the scheme or it is not, and no description of methodology in a bid replaces that fact. CHECK is also not a statute: NCSC writes it as scheme guidance, and in the case of the Public Services Network it is one of the recognised routes, not a requirement in an Act.

More important than the content of the scheme itself is who CHECK is even for, and NCSC writes that without hedging: the scheme is built for central government, public-sector bodies and CNI. For central-government systems that process data at a given marking and above, NCSC advises that the assessment be entrusted to a scheme member, for other public-sector bodies it strongly recommends it, but for an organisation that is neither public sector nor CNI, NCSC itself points to ordinary commissioning guidance, not to CHECK. For a private company preparing a bid for a commercial buyer, that means CHECK is not a target to aim at. It is the UK public sector’s own internal order, and naming it in a commercial bid is more likely evidence that the name has been copied than that the work will be of higher quality.

ITHC is a task for a particular network

ITHC — IT Health Check — is what a UK public body needs in order to connect to, or stay connected to, the Public Services Network. Cabinet Office’s 2022 supporting guidance, which the connection process still points to, describes the minimum scope: assessment both from the outside and from the inside, internally with scanning and manual analysis across the estate, but in large estates sample testing is allowed, and in that case the sample is not less than a tenth. The connection-compliance process itself requires that the report submitted is not older than a year and has not already been used in the previous connection-compliance submission. The English name is a doctor’s metaphor, and minting a second noun from it explains nothing; it is more precise to keep ITHC and explain once that it is a security assessment of a particular network connection.

The scope itself is described in considerably more detail than usually survives into a bid, because the external part tests internet-reachable services (mail, web, firewalls), remote access and third-party connections. Internally, alongside scanning, manual analysis is required, as well as workstation and server configuration, patch status, wireless networks and the connection gateway. In large estates sample testing is allowed, and that is exactly where the tenth appears that tends to disappear from bids. The result has requirements too: the number, type and severity of findings in a readable summary, with a CVSS base score where possible. These figures are a Cabinet Office ITHC requirement for a particular network — it is neither a CHECK rule nor a general quality yardstick — and it is not correct to carry them into a commercial specification as a universal measure of quality.

Three names most often confused with CHECK

The other three names appear in specifications next to CHECK as if they were variants of it, and each of them in fact answers a different question: one about who examined the person, another about how the work is delivered and paid for, the third about whether the supplier has put their own infrastructure in order. It is these three that produce most of the badly prepared bids.

CREST is not CHECK

This is the most common error and at the same time the most useful distinction this article can make, because it changes the content of the bid: CREST is a body with membership and exams, whereas CHECK is an NCSC scheme with its own membership and its own roles. CREST itself describes it as a separate path — its certificate can be one way a person evidences competence, but it does not automatically follow that the company is a CHECK member. The practical consequence when bids are compared is simple: if the specification requires CHECK, a CREST certificate does not meet the requirement, and conversely — if the specification requires CREST, then CHECK membership is more than was asked, and too much has probably been paid for it.

PTaaS is a billing model, not a scheme

PTaaS describes how the service is delivered and paid for: a platform with a dashboard, a subscription, findings that appear continuously, and retesting after the fixes. Industry descriptions put it exactly as a delivery model, and there is no qualification requirement there, nor an authority that would confirm it. So the question “does PTaaS satisfy a CHECK or ITHC requirement” is not answered by “yes” or “no” — it is a question about two different objects. A billing model simply cannot satisfy a requirement about who may test and to what methodology, so if both stand in the specification they have to be read separately: one states a competence requirement, the other how the work is organised in time.

Cyber Essentials checks the supplier, not the deliverable

Cyber Essentials is a certification of five baseline controls on the supplier’s own infrastructure, and the Plus version adds a check of those controls with commodity tools. The certificate is renewed once a year, and procurement policy note PPN 014 ties it to supply-chain security. From that follows a boundary that bids often cross: Cyber Essentials Plus is not the penetration test the specification asked for of the system being built. It is an attestation about the supplier’s own computers and accounts, so a company can be Cyber Essentials Plus certified and deliver a system that has never been tested.

Three claims that should not be believed

Around these names a layer of claims has formed that is copied from one service description to another, and all three of the most common are either untrue or out of date, so they are worth reading next to what the relevant source actually says.

“CHECK is required by UK law.” No statute names CHECK, and NCSC in its guidance uses the words “should” and “strongly recommend”, and the GOV.UK Service Manual also allows an equivalent level. The only place where the requirement is strict is the connection conditions of a particular network, and even there the scheme is one of several recognised routes.

“To become a CHECK member, a company must first be CREST-accredited.” That was true of an older entry path and is still repeated in providers’ articles, but the latest scheme standard requires something else at company level. It remains partly true of people, because a CREST exam can be one of the competence attestations under the relevant professional title. It is exactly this difference between company level and person level that advertisements leave unsaid.

“Without CHECK you may not test UK government systems.” The legal boundary is drawn not by the scheme but by authorisation: unauthorised access to a computer system is an offence under the Computer Misuse Act 1990, whether or not the tester is in the scheme. CHECK is the buyer’s policy about whom to trust with the work, not a substitute for authorisation, and these two questions are worth keeping apart. The practical point is that written authorisation is always needed, even when no scheme and no statute requires that form.

What a UK tender specification actually requires

In the United Kingdom it is worth establishing first where such a requirement even comes from, because the answer is not where it is usually sought: the Procurement Act 2023 sets the procedure, transparency, equal treatment and what belongs in a technical specification, but it does not name a penetration test, CHECK, ITHC or PTaaS. Cabinet Office guidance on technical specifications, which explains what a specification is for, likewise does not prescribe a particular kind of security test. That means the security requirement is in the specification because the buyer wrote it — usually because they themselves have a duty that comes from elsewhere. So the right question is not “what does procurement law require”, but “what duty does the buyer have, and is this contract passing it to me”.

In the United Kingdom that duty, when it exists, comes from NCSC CHECK scheme guidance together with the Public Services Network connection-compliance process and the GOV.UK Service Manual. The Service Manual is the instrument that names a penetration test in those words: it requires both a penetration test and a vulnerability assessment, before public beta or the use of real user data, and it allows a CHECK-certified team or staff accredited to equivalent CHECK levels. The PSN process requires an ITHC, not CHECK as such, and lists several recognised schemes. More on the work itself and its boundaries is in a separate article on what a penetration test is.

CHECK qualifies companies; commercial work qualifies people

This is the difference that explains most of the confusion around CHECK, and it is written into the instruments themselves: CHECK determines who may test a public-sector or CNI system, and it formulates that through the company. The first path is a scheme member, with a CHECK Team Leader and CHECK Team Members who hold UK personnel security clearance. The second path, for work that is not CHECK work, is a named person — a tester with a CREST exam or comparable experience — and that person too is usually asked to be independent of building and maintaining the system under test.

The second path, however, still splits by who the buyer is. For a commercial buyer who is not central government, public sector or CNI, NCSC itself says a CHECK provider is not needed. If the system is being connected to the Public Services Network, the 2022 Cabinet Office guidance adds a further split: central government should use a CHECK partner, while non-central government may use CREST-approved ITHC services or the Cyber Scheme. There is no statutory company scheme, no official membership register and no list of accredited firms you must join for ordinary commercial website work. There is no commercial CHECK to join, and a specification that names CHECK for a commercial website is borrowing a public-sector instrument. For a company preparing a bid against a commercial specification, that means what has to be evidenced is the qualification and independence of the people named, not a firm’s status in a scheme that does not apply.

What to put in the bid about that

From the fact that CHECK qualifies a company, and commercial work a person, it also follows what has to be proved in the bid, and a general company description does not help here; what helps is, for CHECK, evidence of scheme membership and the named Team Leader and Team Members, and for everything else a particular person’s certificate or experience and an attestation of independence from building and maintaining this system in recent years. If the team has several testers, it is worth naming which of them meets which condition, because the buyer has to be able to check it without reading between the lines.

It is also worth not mistaking an example list for a closed requirement, because the certificates named in a specification are often exactly examples, and that means another internationally recognised penetration-testing certificate meets the requirement just as well, where the specification allows an equivalent. A bid that explains this in one paragraph makes evaluation easier for the buyer than a pile of certificate copies with no explanation.

A compliance audit is not a penetration test in the United Kingdom either

Next to a penetration test, specifications also name a compliance audit, and they are two different jobs with two different yardsticks. A penetration test looks at how far an attacker gets; a compliance audit checks whether the system and the processes meet a norm, and its result is a verdict on conformity, not a list of technical weaknesses.

That is shown most clearly by the qualification requirements, which in the two cases are written differently: for the person who carries out a penetration test the examples named are certificates such as CEH and OSCP, that is, attack-technique certificates; for a compliance audit, entirely different ones are named — management and audit certificates. If the specification has asked for one set of certificates but described the content of the other job, that is a contradiction, which is worth noticing before the bid, because it usually means the buyer themselves has not yet decided what they are buying.

Other countries have their own instruments

The United Kingdom has CHECK, but several European countries have their own answers to the same question, and if you are reading a specification in another language, finding CHECK there would be as suspicious as finding a foreign scheme in an English one. In France the National Cybersecurity Agency (ANSSI) qualifies providers of security-audit services, and this qualification covers five audit activities, among which penetration tests are one separate activity alongside architecture, configuration, source-code and organisational audit. A French specification therefore tends to name a particular activity, not the whole qualification at once, and the bidder has to read which of the five is required.

In Spain the National Security Scheme requires a security audit at least every two years for systems of a higher category, and the methodological guidance in it separately distinguishes a technical audit, in which the team actually works with the system, from a compliance audit, which rests on interviews and evidence. A compliance audit may ask to see an earlier penetration-test report, but it does not itself become one. In both cases the conclusion is the same as in the United Kingdom: the name belongs to a particular country, and carried across to another market it no longer means anything.

If the specification nevertheless says “CHECK”

If CHECK, ITHC or Cyber Essentials appears in a commercial specification, there are two plausible explanations, and they are worth distinguishing before the bid is written. The first is that the buyer really is a UK public-sector or CNI buyer, or is working with a UK government system, and in that case the requirement is genuine, it applies to a scheme member, and for most commercial web agencies it is simply not meetable. The second — and in practice the more common in commercial specifications — is that the specification has been taken from a public-sector template, and its author has not noticed that they have copied another sector’s instrument.

You can tell them apart from the rest of the document: if references to the Public Services Network, to NCSC CHECK guidance or to the GOV.UK Service Manual stand beside it, then the talk is of a public-sector duty and CHECK is there for a reason. If it sits in a commercial website build with no such duty, CHECK has arrived there by mistake. This is worth putting as a question to the buyer in the tender clarification process, rather than guessing in the bid, because the answer changes both the price and whether you can bid at all.

What the word “equivalent” means

In many specifications a reservation “or equivalent” stands beside the scheme name, and that is the most important paragraph in the whole security section, because it is exactly what decides whether you can bid. The problem is that the word “equivalent” itself is rarely defined in specifications, and so it means different things depending on who reads it.

In practice that means the burden of proof passes to the bidder: you have to show in what respect what is offered is equivalent. So the answer is not the name of a certificate, but a comparison by features — who tests and with what qualification, whether the vulnerabilities found are exploited, what the scope is, what the report format is and whether retesting happens after the fixes. If these features match, equivalence can be described; if even one material feature differs, it is more honest to say so than to hope that nobody will compare. The absence of an “or equivalent” reservation is an equally clear signal in the opposite direction, because a specification that requires one particular scheme with no alternative narrows the field of bidders to a handful of companies, and that is a question worth putting to the buyer before it is assumed that taking part is impossible.

How long a report remains valid

Deadlines appear in specifications in three forms, which come from entirely different places and so are not interchangeable: in the case of a UK network connection the report must not be older than a year and cannot be reused in the next connection-compliance submission. For a government digital service the GOV.UK Service Manual ties the test to going live, requiring it before public beta or the use of real user data, whereas in a commercial contract the deadline is simply whatever the parties have written, and that means it can be agreed.

In all three cases a calendar deadline alone is not enough, because a penetration-test report describes a particular system on a particular date, so after a material change, such as a new integration, a new role model or a rebuild of the payment flow, the report goes stale faster than time does. That is exactly why both official intervals and industry standards usually name the change alongside the interval.

In practice that means two things that are worth writing separately in the bid. First, it is worth stating clearly which version or release of the system the report applies to, because that is exactly what later decides a dispute about whether a finding is new. Second, it is worth agreeing separately on retesting after the fixes, because a finding that has been fixed, and a finding someone thinks has been fixed, differ.

How to read the requirement before preparing a bid

In practice four questions, asked in a set order, are enough, because each next one only makes sense once the previous has been answered. The first is which system is being tested — the one being delivered, or the supplier’s own, and this one question separates Cyber Essentials from everything else, so it is worth starting there. The second is whether the requirement names the provider’s status or a particular person’s qualification: status almost always points to CHECK company membership, while a person’s qualification points to a named exam or experience, and that is the boundary between a requirement a commercial firm can meet and one it cannot. The third is whether the vulnerabilities found have to be exploited, because if they do, the talk is of a penetration test, but if a list of findings is enough, that is a scan, which costs entirely different money. The fourth is which norm the buyer is citing, and if none, then the requirement is their own choice, which means the scope can be discussed.

What this looks like in practice is seen most clearly in one entirely typical formulation that tends to stand in a specification: “The tenderer shall provide a system security audit in accordance with CHECK or an equivalent methodology.” The first question answers at once — the system under test is the one being delivered, so Cyber Essentials falls away. The second shows that the provider’s status has been named, and that is CHECK. The third remains unanswered, because the word “audit” does not say whether vulnerabilities will be exploited. The fourth is decisive: if further on in the document there is no reference to any norm, then the requirement is the buyer’s choice, the reservation “or equivalent” is an open door, and the question that has to be asked is only one — whether the vulnerabilities found have to be exploited. If the specification does not answer these questions, they are worth asking in writing, and that is not a formality: a specification that names a scheme but does not state the scope produces entirely incomparable bids, and that is the buyer’s loss, not the bidder’s.

When it turns out to be an ordinary website security check

In some cases, especially in smaller tenders, behind all these names stands a much simpler need: the buyer wants to know whether their website or application is secure before handover. There is no CNI system, no Public Services Network, no supply-chain requirement — there is only a wish not to put into production something that is broken into in the first month.

This boundary is worth recognising honestly from the contractor’s side as well, not only from the buyer’s. If the specification really requires membership of a public-sector scheme, then the right answer is not to take part, or to take part in partnership with someone who has membership — not to describe your methodology so that it looks similar. An evaluation board notices that, and the reputational price is larger than one lost tender.

It is exactly in this case that our website security audit belongs, in which there is also room for a manual check with written authorisation. It is not CHECK, it is not an ITHC and it is not issued as one; it is the work that answers the question that was actually asked. If you have a specification on the table and it is not clear which of these categories it falls into, send us the security section of the specification, and we will say which instrument is named there — even if the answer is that it is not work for us.

ES
Edijs Stikuts
Owner · Webmasters
Drafted with AI assistance; fact-checked and approved by Edijs Stikuts.
Get in touch →
FAQ

Frequently asked questions.

Do you need CHECK membership to bid on a UK tender?

Only when the specification is actually asking for CHECK penetration testing of a public-sector or CNI system. CHECK is the NCSC scheme for those systems, and it is scheme guidance, not an Act. For a commercial buyer, NCSC itself says penetration testing does not need to be conducted by a CHECK provider. If a commercial specification still names CHECK, that is worth a clarification question before you bid.

How does CHECK penetration testing differ from CREST?

CHECK is an NCSC-run company scheme with its own roles, personnel security clearances and report format. CREST is an international industry body that grants membership and runs exams. A CREST certificate can be one way a person evidences competence, but it does not follow that the company is a CHECK member. So a CREST certificate does not satisfy a CHECK requirement, and if the specification asked only for CREST, CHECK membership is more than was asked.

Does Cyber Essentials Plus replace a penetration test?

No, because they check different things. Cyber Essentials and its Plus version attest that the supplier themselves has put five baseline controls in order on their own infrastructure, and Plus checks that with commodity tools. A penetration test applies to the system being delivered. A company can be certified and at the same time deliver a system that has never been tested, so in a specification these two requirements have to be read separately.

Who may carry out a penetration test in the United Kingdom?

For a CHECK test of a public-sector or CNI system, the work is done by a scheme member. The team is led by a CHECK Team Leader, with CHECK Team Members who hold UK personnel security clearance. For an ITHC on a Public Services Network connection, central government should use a CHECK partner; non-central government may use CREST-approved ITHC services or the Cyber Scheme. For ordinary commercial work no statute names who may test; the bar is the owner’s written authorisation.

What should you do if the specification names a requirement you cannot meet?

Raise it as a clarification question in the tender Q&A, rather than guessing in the bid. If the requirement names a public-sector scheme but the rest of the document is a commercial website build, it is most likely a copied template, and the buyer can clarify. The answer changes both the price and whether you can bid at all, so it has to arrive before the bid is written, not after.

RELATED SERVICE
Website security audit

Security audit. We find the holes before hackers do — OWASP Top 10, a manual penetration test, a report with priorities.

Learn more →