Best Public Sector Penetration Testing Companies (2026)

Public sector penetration testing in the UK runs on the NCSC CHECK scheme. Central government departments, many local authorities, NHS bodies, and anyone connecting to the Public Services Network are expected to use a CHECK Green Light company, staffed by CHECK Team Leaders and Team Members, for penetration tests and IT Health Checks. The providers below hold CHECK accreditation in our directory. The list opens with our Featured partner, clearly labelled, followed by the wider set.

Related: CHECK pen testing companies · UK penetration testing companies · Cyber Essentials pen testing

What does public sector penetration testing involve?

The CHECK scheme is NCSC's assurance framework for penetration testing of government and critical systems. A CHECK Green Light company has been assessed by NCSC and employs CHECK Team Leaders and Team Members who have passed CREST or Cyber Scheme examinations and hold the necessary security clearance. Testing follows NCSC's CHECK methodology and produces reports in a format accepted by government accreditors.

The most common engagement is the IT Health Check (ITHC), required for PSN connection compliance and widely used across the NHS, local government, and arms-length bodies. ITHCs cover external and internal infrastructure, web applications, build reviews, and remote access, with findings mapped to the accreditor's risk appetite. Beyond ITHCs, CHECK companies deliver application testing, cloud testing, and red teaming for departments with higher threat profiles.

When shortlisting, confirm the provider's current CHECK Green Light status on the NCSC website, ask how many CHECK Team Leaders it employs, and check experience with your specific accreditation route, whether PSN, NHS DSPT, or a departmental accreditor. Public sector frameworks such as G-Cloud and the Crown Commercial Service cyber security DPS are worth asking about, since many providers can be procured through them directly.

Featured partnerFeatured
WorkNest Secure logo

WorkNest Secure

CREST and CHECK-accredited UK penetration testing and managed security provider formed in 2026 from Pentest People, Bulletproof, and Target Defense, with CREST STAR/TLPT-FS capability and the GuardNest vulnerability management platform.

CRESTCHECKSTARNCSC AssuredISO 27001
  • Holds CREST, CHECK, STAR, NCSC Assured, ISO 27001, and ISO 9001 accreditations.
  • Launched in May 2026, combining Pentest People, Bulletproof, and Target Defense under the WorkNest Secure brand.
  • Specialises in enterprise red teaming, including threat-led penetration testing for financial services under the Bank of England STAR-FS framework.
  • CREST member of eleven years, listed as WorkNest Cyber, with accreditation for penetration testing, vulnerability assessment, application testing, STAR/TLPT-FS, and incident response.
View WorkNest Secure
11 providers
London, United Kingdom · Checked Sept 2026

Global Big Four professional services firm delivering CREST, CHECK, and CBEST-accredited penetration testing and red teaming services from London, serving the UK's largest enterprises and regulated organisations.

Accreditations: CREST, CHECK, CBEST, STAR, ISO 27001 +1
Services: Web Application, Network, IoT, Cloud +9
Oxford, United Kingdom · Checked Sept 2026

Global enterprise cybersecurity consultancy founded in 1999 in Oxford, holding rare CREST STAR-FS accreditation and delivering penetration testing, red and purple teaming, and PCI QSA services across five international offices.

Accreditations: CREST, CHECK, STAR, ISO 27001, PCI QSA +1
Services: Web Application, Network, Red Teaming, Purple Teaming +7
Southam, United Kingdom · Checked Oct 2026

Elite UK offensive security consultancy specialising in CBEST/STAR/TIBER red teaming, advanced adversary simulation, and CREST-accredited penetration testing for FTSE 100 clients.

Accreditations: CREST, CHECK, CBEST, STAR, ISO 27001 +2
Services: Web Application, Network, Cloud, Red Teaming +6
London, United Kingdom · Checked Sept 2026

Full-service London-based cybersecurity consultancy with CREST, CHECK, and NCSC accreditations delivering offensive testing, managed detection, and strategic advisory services.

Accreditations: CREST, CREST AI Penetration Testing, CHECK, ISO 27001, Cyber Essentials +2
Services: Web Application, Network, Cloud, API +5
Manchester, United Kingdom · Checked Sept 2026

Manchester-based independent cybersecurity consultancy with over 20 years of experience delivering CREST and CHECK-accredited penetration testing, red teaming, and compliance certification services.

Accreditations: CREST, CHECK, ISO 27001, Cyber Essentials, Cyber Essentials Plus +1
Services: Web Application, Network, Mobile App, Cloud +5
Worcester, United Kingdom · Checked Apr 2026

CREST and CHECK-accredited UK penetration testing consultancy with CBEST approval, specialising in infrastructure, application, and simulated attack assessments across the public and private sectors.

Accreditations: CREST, CHECK, CBEST, STAR, ISO 27001 +3
Services: Web Application, Network, Mobile App, Cloud +4
Birmingham, United Kingdom · Checked Sept 2026

CHECK and CREST-accredited Birmingham-based cyber security consultancy with over 15 years of experience delivering penetration testing, red teaming, and OT security assessments for government and private sector clients.

Accreditations: CREST, CHECK, ISO 27001, Cyber Essentials, Cyber Essentials Plus +1
Services: Web Application, Network, Mobile App, Cloud +7
Bristol, United Kingdom · Checked Sept 2026

Fast-growing CREST and CHECK-accredited UK cybersecurity consultancy with deep expertise in critical national infrastructure sectors.

Accreditations: CREST, CHECK, ISO 27001, Cyber Essentials Plus
Services: Web Application, Network, Cloud, API +6
Cheltenham, United Kingdom · Checked Sept 2026

Award-winning Cheltenham-based cybersecurity consultancy with NCSC CHECK Green Light status and CREST approval, specialising in defence, government, and critical national infrastructure security.

Accreditations: CREST, CHECK, ISO 27001, Cyber Essentials, Cyber Essentials Plus +1
Services: Web Application, Network, Cloud, API +5
London, United Kingdom · Checked Sept 2026

CREST and CHECK-accredited European managed services provider delivering penetration testing with deep infrastructure and cloud hosting expertise.

Accreditations: CREST, CHECK, ISO 27001, Cyber Essentials Plus
Services: Web Application, Network, Mobile App, API +4
Cardiff, United Kingdom · Checked Sept 2026

Cardiff-based CREST and CHECK-accredited cyber security company delivering penetration testing, red teaming, and OT security assessments as part of the Chess Group.

Accreditations: CREST, CHECK, NCSC Assured, Cyber Essentials
Services: Web Application, Network, Cloud, Red Teaming +4

Best Public Sector Penetration Testing Companies (2026), FAQs

What is CHECK and why does the public sector require it?+

CHECK is the NCSC scheme that assures penetration testing companies for government work. Public sector bodies handling OFFICIAL data, and anyone connecting to the PSN, are expected to use a CHECK Green Light company so that testing is performed by cleared, examined testers to an NCSC-recognised methodology.

What is an IT Health Check?+

An IT Health Check (ITHC) is the penetration test required for PSN connection compliance and common across the NHS and local government. It covers external and internal infrastructure, web applications, build configuration, and remote access, and produces a report accepted by government accreditors.

Can a non-CHECK company test a public sector organisation?+

For systems that do not require CHECK, yes, and many public bodies use CREST-accredited providers for lower-sensitivity work. For OFFICIAL systems, PSN compliance, and anything an accreditor designates as requiring CHECK, a CHECK Green Light company is expected.

How do I verify a provider's CHECK status?+

NCSC publishes the list of CHECK Green Light companies on its website, with the scope of each company's approval. Check it directly before appointing a provider, since accreditation is reviewed and companies can lapse.