Exploitr is now a CREST member company, accredited for delivering penetration testing services. It wasn't that long ago that we joined the CREST Pathway programme, which recognised our commitment to adhering to CREST's standards and Codes of Conduct and Ethics whilst we worked towards full membership.

What CREST membership means

CREST is a not-for-profit membership body that sets standards for the technical security industry. Membership is assessed at company level, where CREST examines an organisation's processes, methodologies, quality assurance procedures, and the qualifications of the staff delivering assessments. Member companies are required to re-audit periodically to maintain their status, so it isn't a one-off badge.

For a provider to hold the penetration testing specialism specifically, the assessment covers how engagements are scoped, tested, and reported, alongside the individual certifications and experience of the team carrying out the work.

Why we became a CREST member company

Before this, the claims we made about our methodology, reporting, and how we handle client data were claims you had to take on trust. We've worked hard to bring our processes, methodologies, and quality assurance up to the standard CREST requires, and membership means these are now audited through an independent assessment.

Achieving CREST membership hasn't changed how we work; it confirms that the way we already work meets a standard that CREST examines directly.

What CREST accreditation gives you as a buyer

CREST assesses member companies on their quality processes and procedures, information security practices, contract management, professional indemnity insurance, and how they handle complaints and conflicts of interest. A penetration test hands a provider a working list of your own exploitable weaknesses, and accreditation means an independent body has checked how that provider handles that responsibility rather than you having to take their word for it.

Member companies also operate under CREST's enforceable Codes of Conduct and Ethics, backed by a complaints and resolution process. If an engagement falls short of that standard, you have an independent body to raise it with, not just the provider directly.

Our methodology

Every Exploitr engagement is manually delivered and human-led, with no subcontracted testing, and fixed pricing that's agreed before any work starts. You can read the full breakdown on our penetration testing methodology page.

If you're planning a penetration test and want to talk through scope, get in touch, and we'll work with you to create an assessment scope that meets your requirements.