What Does a CREST Penetration Test Include? A Complete Guide

A penetration test is designed to answer a practical cybersecurity question: could an attacker exploit weaknesses in your systems, and what could they achieve if they did?

For UK organisations, a CREST penetration test can provide structured, independent security testing performed by appropriately accredited professionals. Rather than relying only on automated vulnerability scanners, penetration testing combines automated tools with manual investigation and controlled exploitation to identify realistic attack paths.

A well-planned assessment can help organisations discover vulnerabilities, understand their potential business impact and prioritise remediation before attackers have an opportunity to exploit them.

What You’ll Learn

In this guide, you’ll learn:

  • What a CREST penetration test includes
  • How the testing process works from scoping to reporting
  • Which systems and technologies can be tested
  • Why manual testing matters
  • What a penetration testing report should contain
  • What happens after vulnerabilities are discovered
  • How to decide whether your organisation needs testing
  • How to select a CREST penetration testing provider

What Is a CREST Penetration Test?

A CREST penetration test is an authorised security assessment designed to identify and, where appropriate, exploit vulnerabilities within an agreed scope.

The objective is not simply to generate a list of technical weaknesses. Experienced penetration testers investigate whether vulnerabilities can be chained together or exploited to achieve meaningful objectives, such as accessing sensitive information, bypassing authentication or escalating privileges.

CREST accreditation provides a recognised benchmark for organisations delivering cybersecurity services and is intended to provide assurance around professional processes, technical capability and quality.

However, accreditation should be considered alongside the provider’s experience, testing methodology and ability to assess the technologies relevant to your organisation.

What Does a CREST Penetration Test Include?

The exact scope varies according to the organisation’s objectives, but a professional penetration test typically includes several key stages.

1. Scoping and Rules of Engagement

Every penetration test should begin with clearly defined objectives and boundaries.

The provider and client establish which systems are included, which systems are excluded, what testing techniques are permitted and how potential security incidents should be handled.

The scope might include:

  • Domains and IP addresses
  • Web applications
  • APIs
  • Mobile applications
  • Internal networks
  • External infrastructure
  • Cloud environments
  • Specific applications or services

Clear rules of engagement help ensure testing remains controlled and authorised.

2. Reconnaissance and Information Gathering

Once the scope has been established, testers gather information about the target environment.

This can involve identifying technologies, services, endpoints, application functionality, authentication mechanisms and potential entry points.

Depending on the assessment, testers may use both passive reconnaissance and authorised active techniques.

The goal is to understand the attack surface before attempting exploitation.

3. Automated Vulnerability Assessment

Automated tools can help testers identify common vulnerabilities efficiently.

These tools may detect issues such as outdated software, insecure configurations, exposed services or known vulnerabilities.

However, automated scanning is only one component of a professional penetration test.

A scan may identify a potential weakness without understanding its context or determining whether it can actually be exploited. This is why manual analysis remains an important part of penetration testing.

4. Manual Security Testing

Experienced testers investigate the environment manually to identify weaknesses that automated tools may overlook.

Manual testing can examine areas such as:

  • Authentication
  • Authorisation
  • Access controls
  • Session management
  • Input validation
  • Business logic
  • Privilege escalation
  • Security configurations
  • Trust relationships
  • API functionality

This human-led analysis can be particularly important for modern applications where vulnerabilities depend on how different functions interact.

5. Controlled Exploitation

Where authorised by the agreed rules of engagement, testers attempt to exploit vulnerabilities in a controlled manner.

The purpose is to demonstrate the practical consequences of a weakness rather than simply reporting that a vulnerability exists.

For example, a tester might determine whether an authentication weakness could allow access to another user’s account or whether a low-level vulnerability could ultimately lead to access to sensitive systems.

Testing should be conducted carefully to minimise unnecessary disruption to business operations.

6. Attack Path Analysis

One of the most valuable aspects of penetration testing is understanding how vulnerabilities can be combined.

An individual vulnerability might appear relatively low risk when viewed in isolation. However, an attacker could potentially combine several weaknesses to move from an initial foothold to sensitive resources.

Attack-path analysis helps organisations understand this broader risk.

Instead of asking only:

“What vulnerabilities exist?”

the more useful question becomes:

“What could an attacker realistically achieve by combining these weaknesses?”

7. Risk and Business Impact Assessment

A professional penetration test should explain why identified vulnerabilities matter.

Technical severity is important, but businesses also need to understand potential consequences.

Depending on the environment, impact could include:

  • Unauthorised access to customer data
  • Theft of confidential information
  • Account compromise
  • Privilege escalation
  • Operational disruption
  • Financial loss
  • Reputational damage
  • Regulatory or contractual consequences

Connecting technical findings to business impact makes the results easier for decision-makers to prioritise.

8. Detailed Penetration Testing Report

The final report is one of the most important deliverables.

A useful report should clearly explain:

  • What was tested
  • How the assessment was conducted
  • Vulnerabilities identified
  • Evidence supporting the findings
  • Severity and potential impact
  • Attack paths where relevant
  • Recommended remediation
  • Areas requiring further investigation

Technical teams need enough detail to understand and fix vulnerabilities, while management needs a clear overview of the organisation’s overall security risk.

9. Remediation Recommendations

Finding vulnerabilities is only the first step.

The penetration testing provider should provide practical recommendations that help the organisation address the identified weaknesses.

Recommendations may involve software updates, configuration changes, access-control improvements, application-code changes, architectural modifications or additional security controls.

The objective should be to address the underlying cause rather than simply applying a temporary fix.

10. Retesting

After vulnerabilities have been remediated, retesting can confirm whether the fixes are effective.

This is particularly important for significant vulnerabilities that were successfully exploited during the original assessment.

Retesting can establish whether:

  • The vulnerability has been removed
  • The original attack technique is no longer successful
  • The remediation has introduced another weakness
  • Additional security improvements are required

This creates a valuable cycle of testing, remediation and verification.

What Systems Can Be Included in a CREST Penetration Test?

The answer depends on the provider’s capabilities and the agreed scope.

Web Applications

Testing can examine authentication, access controls, business logic, input validation, session management and other application security issues.

APIs

API testing can identify weaknesses in authentication, authorisation, data exposure, input handling and business logic.

Networks and Infrastructure

Network penetration testing can assess externally exposed systems and, where authorised, internal environments to identify potential routes for unauthorised access and lateral movement.

Cloud Environments

Cloud penetration testing can examine aspects such as identity management, permissions, configurations and attack paths involving cloud-hosted services.

Mobile Applications

Mobile testing can assess application functionality, authentication, data storage and interactions with backend APIs.

AI and LLM Applications

As businesses increasingly deploy AI-powered applications, security assessments may also need to consider risks specific to AI systems, including prompt injection, sensitive data exposure and unsafe interactions with external tools.

CREST Penetration Test vs Vulnerability Scan

A vulnerability scan and penetration test serve different purposes.

A vulnerability scan primarily uses automated tools to identify known vulnerabilities.

A penetration test combines automated scanning with manual investigation and controlled exploitation.

For example, a scanner might identify a vulnerable service. A penetration tester can investigate whether that vulnerability can actually be exploited within the organisation’s environment and what an attacker could accomplish.

Businesses can therefore benefit from using both approaches as part of a broader vulnerability-management and security-testing strategy.

Why Choose a CREST-Accredited Provider?

CREST accreditation can provide businesses with an additional level of assurance when selecting a security testing company.

Nevertheless, organisations should consider more than accreditation alone.

Important factors include:

  1. Relevant CREST accreditation
  2. Experience with your technology stack
  3. Qualified and experienced testers
  4. A clearly defined methodology
  5. Appropriate manual testing
  6. Comprehensive reporting
  7. Practical remediation advice
  8. Retesting capabilities

For example, Solusec provides CREST-accredited penetration testing across areas including web applications and APIs, infrastructure and networks, cloud environments, mobile applications and AI/LLM security. Its approach combines expert-led manual testing with automated techniques and includes remediation-focused retesting. 

Quick Decision Framework: Do You Need a CREST Penetration Test?

Consider arranging a professional penetration test if your organisation:

  • Operates internet-facing applications or infrastructure
  • Processes sensitive customer or business information
  • Has recently launched a new application
  • Has introduced significant software or infrastructure changes
  • Has migrated systems to the cloud
  • Uses APIs to expose important functionality
  • Has experienced a security incident
  • Needs independent security assurance
  • Has contractual or compliance-related testing requirements
  • Has never undergone a professional penetration test

If several of these apply, a penetration test can provide useful insight into your organisation’s real-world security exposure.

When Should a CREST Penetration Test Be Performed?

Testing is particularly useful after significant changes to an organisation’s technology environment.

Examples include:

  • New application launches
  • Major application updates
  • Cloud migrations
  • Significant API changes
  • Network architecture changes
  • Changes to authentication systems
  • Mergers and acquisitions
  • Major changes to business processes
  • Security incidents

The appropriate testing frequency ultimately depends on the organisation’s risk profile, technology environment and security requirements.

How to Prepare for a CREST Penetration Test

Good preparation can help ensure the assessment produces useful results.

Before testing begins, organisations should:

Define objectives: Decide what you want the assessment to demonstrate.

Confirm scope: Identify systems, applications and infrastructure that should be included.

Document authorised targets: Make sure the testing team has accurate information about the environment.

Identify critical systems: Highlight systems where disruption could have serious consequences.

Coordinate internally: Ensure relevant IT, security and operational teams understand the testing schedule.

Prepare for remediation: Make sure there is a process for reviewing and addressing findings after the assessment.

Frequently Asked Questions

1. What is included in a CREST penetration test?

A CREST penetration test can include scoping, reconnaissance, automated vulnerability identification, manual security testing, controlled exploitation, attack-path analysis, reporting, remediation recommendations and retesting. The exact activities depend on the agreed scope and type of assessment.

2. Does a CREST penetration test include vulnerability scanning?

Automated vulnerability scanning may form part of a penetration test, but a professional penetration test goes beyond automated scanning. Manual investigation and controlled exploitation are used to determine whether vulnerabilities can have a meaningful security impact.

3. Can a CREST penetration test test cloud environments?

Yes, where the provider has the appropriate capabilities and the cloud environment falls within the agreed scope. Cloud testing can assess areas such as identity, permissions, configurations and potential attack paths.

4. How long does a CREST penetration test take?

The duration depends on the scope and complexity of the environment. Testing a small application may require considerably less time than assessing a large network, multiple applications or a complex cloud environment.

5. What happens after a CREST penetration test?

The organisation receives a report detailing the findings and recommended remediation. Security teams can then address the vulnerabilities, after which retesting can be performed to verify that important weaknesses have been successfully fixed.

A CREST penetration test is much more than an automated vulnerability scan. It is a structured security assessment designed to help organisations understand how attackers could exploit weaknesses within a defined environment.

A comprehensive assessment can include reconnaissance, automated scanning, manual testing, controlled exploitation, attack-path analysis, risk assessment, reporting, remediation guidance and retesting.

For UK organisations operating modern digital environments, selecting an experienced and appropriately accredited provider is an important part of building effective cybersecurity assurance.

By combining professional penetration testing with continuous vulnerability management and timely remediation, businesses can move from simply identifying security weaknesses to understanding and actively reducing their real-world cyber risk.

Author Profile

Adam Regan
Adam Regan
Deputy Editor

Features and account management. 7 years media experience. Previously covered features for online and print editions.

Email Adam@MarkMeets.com

Leave a Reply