
Trust, credibility, and a track record of expertise and knowledge are key in the cybersecurity industry, and that’s why we are CREST certified at KIT365.
CREST (Council of Registered Ethical Security Testers) is an internationally recognised, non-profit accreditation body that sets rigorous standards for cybersecurity professionals and organisations.
The role of CREST is to ensure that when security tests are carried out, they are consistently of a high, ethical, and professional standard.
CREST supports accreditation across several significant areas of cybersecurity, including:
For organisations like KIT365, achieving CREST registration demonstrates our commitment to the highest standards for the customers we work with. It also means we’ve been independently assessed and verified to deliver cybersecurity services to that standard.
KIT365 began delivering PEN testing in 2020. We built up our people, processes and policies to ensure that our delivery was excellent and then we operated at this level for several years. Going for CREST registration felt like a natural next step for us, especially as we had been operating in the Cybersecurity industry for a while. We had already built up a range of accolades in other areas, but we wanted to formally prove the level we operated at for PEN testing and our ongoing commitment to excellence, and the CREST registration would give us that validation.
The assessment itself involved a significant amount of work behind the scenes at KIT365 and took around three months, which ran alongside our day-to-day work, as we were never willing to let standards slip elsewhere in the business while pursuing it. It included a methodology audit, where we had to submit our policies, procedures, and testing methods to CREST for review, ensuring everything adhered to industry standards. We also reviewed our data security controls, which tied in closely with our ISO 27001 certification.
While the process was thorough, it was a straightforward one for us, reflecting the standards we already had in place. A couple of things were sent back to us for clarification, but the assessors commented about how our process documentation was easy for people to understand and follow. We were happy to implement the changes suggested and our certification was achieved in 2025.
As CREST requires ongoing recertification, it also means an ongoing commitment to those standards through annual reassessment. Again, this is something KIT365 was happy to commit to going forward.
Whilst we’re proud of our CREST registration, its real value lies in what it delivers to our customers.
When customers work with us, knowing we’re CREST registered, they benefit from:
Ultimately, CREST registration proves that we’re a trusted and reliable partner for any business looking to protect its digital assets.
For us, it’s a reflection of our ongoing commitment to ourselves and our customers, to delivering high-quality, ethical, and rigorous technical solutions through our cybersecurity services.
For anyone working with us, it gives peace of mind knowing that their security is in skilled, efficient, accountable, and verified hands.






