CREST-certified pentest
About CREST
CREST (Council for Registered Ethical Security Testers) is an international non-profit organization that certifies and accredits cybersecurity companies. Their accreditation process ensures that companies provide high-quality penetration testing by validating their skills, business processes, data security, and testing methods.
Vonahi Security is now a CREST member company in the following regions:
-
Europe, Middle East, and Africa (EMEA)
-
Australasia (Australia, Kiribati, New Zealand, Papua New Guinea)
-
In addition, the following islands are classified as Australasia: Antipodes Is., Auckland Is., Bounty Is., Campbell Is., Chatham Is., Cook Is., Fiji, Kermadec Is., Niue, Stewart Is, Christmas Is., Cocos Is., Lord Howe Is., Macquarie Is., Nauru, New Caledonia, Norfolk Is., Pitcairn Is.
-
Learn more about our CREST membership.
About the feature
Partners and customers now have an option to select a CREST-certified network penetration test when scheduling assessments within the vPenTest platform for any company in EMEA or Australasia region.
-
A CREST-certified pentest ensures that the entire pen testing process adheres to the highest legal, ethical, and technical standards under the terms of the CREST SOW.
-
The CREST pentesting process follows best practice in key areas such as scoping, reconnaissance, preparation, execution, technical delivery, reporting, and data protection.
How to schedule a CREST-certified pentest

This feature is available for any company with an EMEA or Australasia time zone. For example, if your organization is based in the US, but you’re running an assessment for a company located in EMEA, all you need to do is follow the steps below:
-
Go to the Company page.
-
Find the company you want to schedule a CREST-certified pentest for.
-
Click Edit Company from the Action dropdown button.
-
-
In the Edit Company form, make sure you select a time zone in the EMEA or Australasia region.
-
Europe time zones
-
GMT +00:00 (Western European Time)
-
GMT +01:00 (Central European Time)
-
GMT +02:00 (Eastern European Time)
-
-
Middle East time zones
-
GMT +02:00 (Israel Standard Time)
-
GMT +03:00 (Arabia Standard Time)
-
GMT +03:30 (Iran Standard Time)
-
GMT +04:00 (Gulf Standard Time)
-
GMT +04:30 (Iran Daylight Time)
-
-
Africa time zones
-
GMT -01:00 (Cape Verde Time)
-
GMT +00:00 (Greenwich Mean Time)
-
GMT +01:00 (West Africa Time)
-
GMT +02:00 (Central Africa Time)
-
GMT +03:00 (East Africa Time)
-
GMT +04:00 (Seychelles Time)
-
-
Australasia time zones
-
Australia
-
(GMT +08:00) Perth
-
(GMT +09:30) Darwin
-
(GMT +09:30) Adelaide
-
(GMT +10:00) Melbourne
-
(GMT +10:00) Sydney
-
(GMT +10:00) Brisbane
-
(GMT +10:00) Hobart
-
(GMT +10:00) Canberra
-
-
New Guinea
-
(GMT +10:00) Port Moresby
-
-
New Caledonia
-
(GMT +11:00) New Caledonia
-
-
Fiji
-
(GMT +12:00) Fiji
-
-
New Zealand
-
(GMT +12:00) Auckland
-
(GMT +12:00) Wellington
-
(GMT +12:00) Marshall Is
-
(GMT +12:45) Chatham Is.
-
(GMT +13:00) Tokelau Is
-
(GMT +13:00) Samoa
-
-
-
-
Click Save.
-
Now, when you go to schedule an assessment for that company, you’ll see an extra option for a CREST Certified Pentest in the first step of the scheduling wizard.

-
Schedule a new Assessment.
-
Select a Company. (It must have a time zone in the EMEA or Australasia region.)
-
In Step 1 of the Scheduling Wizard, scroll to the very bottom and select the checkbox for a CREST Certified Pentest.
NOTE As a CREST member company in EMEA and Australasia, Vonahi Security cannot allow partners to white-label CREST-certified pentests. Make sure you choose Vonahi Security branding for your report if you'd like a CREST-certified pentest.
-
Once it is selected, you'll see the following in the Summary step.