Skip to content
ResourcesCompliance

Do you need a CREST accredited tester for your tax software?

27 July 20267 min read
WHO ACTUALLY MANDATES CRESTFRAMEWORK OR BUYERCREST REQUIREDCBEST, Bank of EnglandYesSTAR-FS, FCA and PRA regulated firmsYesUK Government and MoD contractsYesDORA, EU financial entitiesYesSome cyber insurance policiesSometimesISO 27001NoSOC 2NoHMRC Terms of Use, MTD softwareNoSOURCES: FORTBRIDGE (CREST ACCREDITED), AND THE HMRC DEVELOPER HUB TERMS OF USE

If you make MTD software, almost nothing you are actually subject to requires a CREST accredited tester. The firms that hold CREST say so themselves.

What CREST actually is

CREST is a not for profit accreditation body for the cyber security industry. A CREST accredited company has had its processes, methodology and data handling assessed, and its testers hold CREST examinations. It is a real, meaningful quality signal, and it costs a supplier a significant amount of money and time to obtain and maintain.

What it is not is a legal requirement. It is a procurement filter, and whether that filter applies to you depends entirely on who your regulator is and who your customers are.

Who genuinely requires it

The clearest source on this is not us. It is Fortbridge, a CREST accredited firm, publishing the limits of its own credential on its own marketing site. Their list of where CREST is mandatory:

  • CBEST. Mandatory for systemically important banks and financial market infrastructure providers, under the Bank of England.
  • STAR-FS. Extends the same expectation to broader financial services firms regulated by the FCA and the PRA.
  • UK Government and MoD contracts. Government procurement frameworks frequently specify that penetration testing suppliers hold CREST accreditation.
  • DORA. Required for threat led penetration testing at financial entities operating in the EEA.
  • Some cyber insurance policies. A minority of insurers now specify in policy terms that tests must be performed by a CREST accredited company. Worth checking your own policy wording.

A company that builds MTD filing software, practice management, bookkeeping or payroll is, in the ordinary case, none of these.

What ISO 27001 and SOC 2 say

This is the one that matters most, because it is the framework your customers actually ask you about in a security questionnaire. Again, in Fortbridge's own words:

Both frameworks require competent, independent security testing. Neither names a scheme. CREST accreditation makes demonstrating that competence simpler for an auditor, which is a genuine convenience, but it is not the requirement itself.

What HMRC says

Nothing, on this point. HMRC's Developer Hub Terms of Use require the testing and name no scheme to do it:

HMRC then asks whether your application has passed penetration testing, and tells you to use either penetration test tools or an independent third party supplier. There is no accreditation attached to the third party route, and CREST, CHECK and every other named scheme are absent from the terms entirely. The longer version of what HMRC does and does not verify is in what HMRC actually checks.

The honest counter argument

Three points against everything above, because the argument is weaker if it is overstated.

  • Accreditation is a real signal. A CREST assessment covers methodology, quality assurance and how a firm handles your data. Where a supplier does not hold it, you are taking those on trust, and that is a legitimate thing to weigh.
  • One enterprise customer can override all of this.If a large customer's own procurement policy says CREST, then for that deal it says CREST, regardless of what the framework technically requires.
  • It saves you an argument. Handing an auditor a CREST report ends a conversation. Handing them a report from an unaccredited firm may start one, and you are the person who has to have it.

What to ask a supplier instead

If CREST is not the deciding filter for you, these four questions separate a real review from a scan with a logo on it. They work on us as well as on anyone else.

  • Which methodology do you follow, by name?The answer should be a published standard you can go and read, such as the OWASP Testing Guide, PTES or NIST SP 800-115. Not “our proprietary process”.
  • Is any of this automated, and which parts? Every honest supplier uses tools. The question is what a human does afterwards. A scanner cannot find a paid feature enforced only in the interface, because the endpoint responds normally.
  • What do I get, and can I show it to a customer? A report written only for engineers is no use in a security questionnaire.
  • Is a re-test included, and for how long? Findings you never confirm as fixed are findings you still have. Windows vary from thirty to ninety days.

The version of this we would give you on a call

If your buyers are accountancy practices and small businesses, and your obligations are HMRC's terms plus whatever your customers put in a questionnaire, CREST is a nice to have and the methodology question matters more. If you are selling into a bank, or bidding for a government framework, go and get an accredited firm and do not let anyone talk you out of it.

FAQ

Quick answers

Do I need a CREST accredited penetration tester for MTD software?
In the ordinary case, no. HMRC's Terms of Use require security testing including regular penetration testing, but name no accreditation scheme and explicitly permit either penetration test tools or an independent third party supplier. CREST is mandatory for CBEST, STAR-FS, UK Government and MoD contracts, and DORA, none of which apply to a typical tax software vendor.
Does ISO 27001 or SOC 2 require a CREST accredited tester?
No. Fortbridge, itself a CREST accredited firm, states publicly that ISO 27001, SOC 2 and similar frameworks do not mandate CREST specifically. Both require competent independent testing; neither names a scheme. CREST makes it simpler to demonstrate that competence to an auditor, but it is not the requirement.
When do I definitely need CREST?
If you are a systemically important bank or financial market infrastructure provider under CBEST, an FCA or PRA regulated firm under STAR-FS, a supplier bidding on UK Government or MoD frameworks, or an EU financial entity under DORA. Some cyber insurance policies also specify it, so check your policy wording.
What should I ask a penetration testing supplier instead?
Which named methodology they follow, such as the OWASP Testing Guide, PTES or NIST SP 800-115. Which parts are automated and what a human does afterwards. Whether the report is written so you can hand it to a customer. And whether a re-test is included, and for how long.

Who checks what your developers ship?

An independent security and build review of what your agency delivered. £2,500, about two weeks, with a re-test of their fixes included.