How to Verify a Cybersecurity Supplier's Credentials
ISO 27001, CREST and cybersecurity service licensing — which certificates matter, and how to check that one is real before you sign anything.
The Seek Tech editors28 July 2026
Security is the one category where you are least able to judge the work by looking at it. You cannot tell a thorough penetration test from a scan with a nicer cover page, and by the time the difference matters, the engagement is over.
Certificates are an imperfect proxy, but they are a checkable one. Here is what the common ones actually mean and how to confirm a supplier holds what they claim.
ISO/IEC 27001 — and why the scope line matters more than the logo
ISO 27001 certifies that an organisation runs an information security management system meeting the standard. It is about how the company manages security, not about how good any individual consultant is.
The part almost everyone skips is the scope statement printed on the certificate. A certificate can legitimately cover one office, one business unit, or one service line. A supplier can hold genuine ISO 27001 certification covering their data centre operations and have it tell you nothing about the consulting team you are hiring.
So ask for three things:
- The certificate itself, not a logo on a slide.
- The scope statement — read it and check the work you are buying falls inside it.
- The certification body that issued it, and their accreditation.
Then verify. A certification body will confirm a certificate on request, and many publish searchable client directories. Accredited certificates can also generally be checked through the accreditation body’s own register. Verifying with the issuer rather than the supplier is the entire point of the exercise — a PDF is trivially editable.
Also check the expiry. Certificates run in cycles with surveillance audits between recertifications, and a lapsed certificate is not a certificate.
CREST — for the people doing the testing
Where ISO 27001 speaks to the organisation, CREST accreditation speaks more directly to technical testing capability: penetration testing, incident response and related services. Individual testers also hold CREST qualifications distinct from company-level accreditation.
Two questions worth asking:
- Is the accreditation held by the company, or by one individual? If it is one person, ask whether that person is actually on your engagement.
- Which service is accredited? Accreditation is service-specific, and a firm accredited for one discipline is not automatically accredited for another.
CREST publishes a member directory, so this is checkable in a couple of minutes.
Licensing for cybersecurity service providers
Malaysia introduced a licensing regime for providers of certain cybersecurity services under the Cyber Security Act 2024, with penetration testing and managed security operations centre services among those covered. Providers of licensable services are expected to hold a licence issued under that framework.
If you are buying a penetration test or an outsourced SOC, ask whether the provider holds the relevant licence and for the licence details, then verify with the administering authority. This regime is comparatively new and its scope has been clarified over time, so treat the supplier’s summary of it as a starting point rather than a conclusion, and confirm the current requirements independently.
Questions that reveal more than any certificate
Certificates establish a floor. These get at the work:
- Who is on the engagement, by name, and what do they hold? Firms sell with senior people and deliver with juniors. Ask for named consultants in the statement of work.
- What is the methodology? A recognised framework named in the proposal beats an unnamed “proprietary approach”.
- What does the deliverable look like? Ask for a redacted sample report. A good one explains business impact and gives reproducible steps; a weak one is a tool export with severity colours.
- Is a retest included? Findings you cannot confirm you have fixed are findings you still have.
- What happens to the findings? Your vulnerabilities are among the most sensitive documents about your business. Ask how the report is transmitted, where it is stored, how long they keep it, and what is destroyed at the end.
The short version
Get the certificate number, the scope and the expiry, and verify all three with whoever issued them. Ask who is actually doing the work. Ask to see a sample report. And ask what happens to the findings when the job is done.
General guidance on evaluating suppliers, not legal or regulatory advice. Certification and licensing requirements change — confirm the current position with the relevant issuing or administering body before relying on any of it.
The certificate number, its scope statement and its expiry — verified with the issuing body, not the supplier.
Category-level guidance. It is not a statement about any company listed on this site, and it is not legal advice — confirm current requirements with the issuing body before you rely on them.