Best Public Sector Penetration Testing Companies (2026)

Public sector penetration testing in the UK runs on the NCSC CHECK scheme. Central government departments, many local authorities, NHS bodies, and anyone connecting to the Public Services Network are expected to use a CHECK Green Light company, staffed by CHECK Team Leaders and Team Members, for penetration tests and IT Health Checks. The providers below hold CHECK accreditation in our directory. The list opens with our Featured partner, clearly labelled, followed by the wider set.

Related: CHECK pen testing companies · UK penetration testing companies · Cyber Essentials pen testing

What does public sector penetration testing involve?

The CHECK scheme is NCSC's assurance framework for penetration testing of government and critical systems. A CHECK Green Light company has been assessed by NCSC and employs CHECK Team Leaders and Team Members who have passed CREST or Cyber Scheme examinations and hold the necessary security clearance. Testing follows NCSC's CHECK methodology and produces reports in a format accepted by government accreditors.

The most common engagement is the IT Health Check (ITHC), required for PSN connection compliance and widely used across the NHS, local government, and arms-length bodies. ITHCs cover external and internal infrastructure, web applications, build reviews, and remote access, with findings mapped to the accreditor's risk appetite. Beyond ITHCs, CHECK companies deliver application testing, cloud testing, and red teaming for departments with higher threat profiles.

When shortlisting, confirm the provider's current CHECK Green Light status on the NCSC website, ask how many CHECK Team Leaders it employs, and check experience with your specific accreditation route, whether PSN, NHS DSPT, or a departmental accreditor. Public sector frameworks such as G-Cloud and the Crown Commercial Service cyber security DPS are worth asking about, since many providers can be procured through them directly.

Top PickFeatured
WorkNest Secure logo

WorkNest Secure

Our top recommendation on this page.

CREST and CHECK-accredited UK penetration testing and managed security provider formed in 2026 from Pentest People, Bulletproof, and Target Defense, with CREST STAR/TLPT-FS capability and the GuardNest vulnerability management platform.

CRESTCHECKSTARNCSC AssuredISO 27001
  • Launched in May 2026, combining Pentest People, Bulletproof, and Target Defense under the WorkNest Secure brand.
  • CREST member of eleven years, listed as WorkNest Cyber, with accreditation for penetration testing, vulnerability assessment, application testing, STAR/TLPT-FS, and incident response.
  • NCSC CHECK Green Light company covering the whole of the UK.
  • NCSC Assured provider for Cyber Incident Exercising and Cyber Advisor services.
View WorkNest Secure
12 providers found
11 providers
PwC Cyber Security logo

PwC Cyber Security

Global Big Four professional services firm delivering CREST, CHECK, and CBEST-accredited penetration testing and red teaming services from London, serving the UK's largest enterprises and regulated organisations.

London, United KingdomEnterprise
Web ApplicationNetworkIoT+9
CRESTCHECKCBEST+3
Verified Apr 2026
Dionach logo

Dionach

Global enterprise cybersecurity consultancy founded in 1999 in Oxford, holding rare CREST STAR-FS accreditation and delivering penetration testing, red and purple teaming, and PCI QSA services across five international offices.

Oxford, United KingdomPremium
Web ApplicationNetworkRed Teaming+8
CRESTCHECKSTAR+3
Verified Apr 2026
MDSec logo

MDSec

Elite UK offensive security consultancy specialising in CBEST/STAR/TIBER red teaming, advanced adversary simulation, and CREST-accredited penetration testing for FTSE 100 clients.

Southam, United KingdomPremium
Web ApplicationNetworkCloud+7
CRESTCHECKCBEST+4
Verified Apr 2026
Secarma logo

Secarma

Manchester-based independent cybersecurity consultancy with over 20 years of experience delivering CREST and CHECK-accredited penetration testing, red teaming, and compliance certification services.

Manchester, United KingdomMid-Range
Web ApplicationNetworkMobile App+6
CRESTCHECKISO 27001+3
Verified Apr 2026
Cyberis logo

Cyberis

CREST and CHECK-accredited UK penetration testing consultancy with CBEST approval, specialising in infrastructure, application, and simulated attack assessments across the public and private sectors.

Worcester, United KingdomMid-Range
Web ApplicationNetworkMobile App+5
CRESTCHECKCBEST+5
Verified Apr 2026
Aristi logo

Aristi

CHECK and CREST-accredited Birmingham-based cyber security consultancy with over 15 years of experience delivering penetration testing, red teaming, and OT security assessments for government and private sector clients.

Birmingham, United KingdomMid-Range
Web ApplicationNetworkMobile App+8
CRESTCHECKISO 27001+3
Verified May 2026
Bridewell logo

Bridewell

Fast-growing CREST and CHECK-accredited UK cybersecurity consultancy with deep expertise in critical national infrastructure sectors.

Bristol, United KingdomMid-Range
Web ApplicationNetworkCloud+7
CRESTCHECKISO 27001+1
Verified Apr 2026
JUMPSEC logo

JUMPSEC

Full-service London-based cybersecurity consultancy with CREST, CHECK, and NCSC accreditations delivering offensive testing, managed detection, and strategic advisory services.

London, United KingdomMid-Range
Web ApplicationNetworkCloud+6
CRESTCHECKISO 27001+3
Verified May 2026
Salus Cyber logo

Salus Cyber

Award-winning Cheltenham-based cybersecurity consultancy with NCSC CHECK Green Light status and CREST approval, specialising in defence, government, and critical national infrastructure security.

Cheltenham, United KingdomMid-Range
Web ApplicationNetworkCloud+6
CRESTCHECKISO 27001+3
Verified Apr 2026
Claranet logo

Claranet

CREST and CHECK-accredited European managed services provider delivering penetration testing with deep infrastructure and cloud hosting expertise.

London, United KingdomMid-Range
Web ApplicationNetworkMobile App+5
CRESTCHECKISO 27001+1
Verified Apr 2026
CyberLab logo

CyberLab

Cardiff-based CREST and CHECK-accredited cyber security company delivering penetration testing, red teaming, and OT security assessments as part of the Chess Group.

Cardiff, United KingdomBudget
Web ApplicationNetworkCloud+5
CRESTCHECKNCSC Assured+1
Verified May 2026

Best Public Sector Penetration Testing Companies (2026), FAQs

What is CHECK and why does the public sector require it?+

CHECK is the NCSC scheme that assures penetration testing companies for government work. Public sector bodies handling OFFICIAL data, and anyone connecting to the PSN, are expected to use a CHECK Green Light company so that testing is performed by cleared, examined testers to an NCSC-recognised methodology.

What is an IT Health Check?+

An IT Health Check (ITHC) is the penetration test required for PSN connection compliance and common across the NHS and local government. It covers external and internal infrastructure, web applications, build configuration, and remote access, and produces a report accepted by government accreditors.

Can a non-CHECK company test a public sector organisation?+

For systems that do not require CHECK, yes, and many public bodies use CREST-accredited providers for lower-sensitivity work. For OFFICIAL systems, PSN compliance, and anything an accreditor designates as requiring CHECK, a CHECK Green Light company is expected.

How do I verify a provider's CHECK status?+

NCSC publishes the list of CHECK Green Light companies on its website, with the scope of each company's approval. Check it directly before appointing a provider, since accreditation is reviewed and companies can lapse.