Best Public Sector Penetration Testing Companies (2026)
Public sector penetration testing in the UK runs on the NCSC CHECK scheme. Central government departments, many local authorities, NHS bodies, and anyone connecting to the Public Services Network are expected to use a CHECK Green Light company, staffed by CHECK Team Leaders and Team Members, for penetration tests and IT Health Checks. The providers below hold CHECK accreditation in our directory. The list opens with our Featured partner, clearly labelled, followed by the wider set.
Related: CHECK pen testing companies · UK penetration testing companies · Cyber Essentials pen testing
What does public sector penetration testing involve?
The CHECK scheme is NCSC's assurance framework for penetration testing of government and critical systems. A CHECK Green Light company has been assessed by NCSC and employs CHECK Team Leaders and Team Members who have passed CREST or Cyber Scheme examinations and hold the necessary security clearance. Testing follows NCSC's CHECK methodology and produces reports in a format accepted by government accreditors.
The most common engagement is the IT Health Check (ITHC), required for PSN connection compliance and widely used across the NHS, local government, and arms-length bodies. ITHCs cover external and internal infrastructure, web applications, build reviews, and remote access, with findings mapped to the accreditor's risk appetite. Beyond ITHCs, CHECK companies deliver application testing, cloud testing, and red teaming for departments with higher threat profiles.
When shortlisting, confirm the provider's current CHECK Green Light status on the NCSC website, ask how many CHECK Team Leaders it employs, and check experience with your specific accreditation route, whether PSN, NHS DSPT, or a departmental accreditor. Public sector frameworks such as G-Cloud and the Crown Commercial Service cyber security DPS are worth asking about, since many providers can be procured through them directly.
WorkNest Secure
Our top recommendation on this page.
CREST and CHECK-accredited UK penetration testing and managed security provider formed in 2026 from Pentest People, Bulletproof, and Target Defense, with CREST STAR/TLPT-FS capability and the GuardNest vulnerability management platform.
- Launched in May 2026, combining Pentest People, Bulletproof, and Target Defense under the WorkNest Secure brand.
- CREST member of eleven years, listed as WorkNest Cyber, with accreditation for penetration testing, vulnerability assessment, application testing, STAR/TLPT-FS, and incident response.
- NCSC CHECK Green Light company covering the whole of the UK.
- NCSC Assured provider for Cyber Incident Exercising and Cyber Advisor services.
PwC Cyber Security
Global Big Four professional services firm delivering CREST, CHECK, and CBEST-accredited penetration testing and red teaming services from London, serving the UK's largest enterprises and regulated organisations.
Dionach
Global enterprise cybersecurity consultancy founded in 1999 in Oxford, holding rare CREST STAR-FS accreditation and delivering penetration testing, red and purple teaming, and PCI QSA services across five international offices.
MDSec
Elite UK offensive security consultancy specialising in CBEST/STAR/TIBER red teaming, advanced adversary simulation, and CREST-accredited penetration testing for FTSE 100 clients.
Secarma
Manchester-based independent cybersecurity consultancy with over 20 years of experience delivering CREST and CHECK-accredited penetration testing, red teaming, and compliance certification services.
Cyberis
CREST and CHECK-accredited UK penetration testing consultancy with CBEST approval, specialising in infrastructure, application, and simulated attack assessments across the public and private sectors.
Aristi
CHECK and CREST-accredited Birmingham-based cyber security consultancy with over 15 years of experience delivering penetration testing, red teaming, and OT security assessments for government and private sector clients.
Bridewell
Fast-growing CREST and CHECK-accredited UK cybersecurity consultancy with deep expertise in critical national infrastructure sectors.
JUMPSEC
Full-service London-based cybersecurity consultancy with CREST, CHECK, and NCSC accreditations delivering offensive testing, managed detection, and strategic advisory services.
Salus Cyber
Award-winning Cheltenham-based cybersecurity consultancy with NCSC CHECK Green Light status and CREST approval, specialising in defence, government, and critical national infrastructure security.
Claranet
CREST and CHECK-accredited European managed services provider delivering penetration testing with deep infrastructure and cloud hosting expertise.
Best Public Sector Penetration Testing Companies (2026), FAQs
What is CHECK and why does the public sector require it?+
CHECK is the NCSC scheme that assures penetration testing companies for government work. Public sector bodies handling OFFICIAL data, and anyone connecting to the PSN, are expected to use a CHECK Green Light company so that testing is performed by cleared, examined testers to an NCSC-recognised methodology.
What is an IT Health Check?+
An IT Health Check (ITHC) is the penetration test required for PSN connection compliance and common across the NHS and local government. It covers external and internal infrastructure, web applications, build configuration, and remote access, and produces a report accepted by government accreditors.
Can a non-CHECK company test a public sector organisation?+
For systems that do not require CHECK, yes, and many public bodies use CREST-accredited providers for lower-sensitivity work. For OFFICIAL systems, PSN compliance, and anything an accreditor designates as requiring CHECK, a CHECK Green Light company is expected.
How do I verify a provider's CHECK status?+
NCSC publishes the list of CHECK Green Light companies on its website, with the scope of each company's approval. Check it directly before appointing a provider, since accreditation is reviewed and companies can lapse.