Audit methodology · Last verified

CBEST Threat Intelligence-Led Assessments

CBEST is the Bank of England, PRA and FCA's intelligence-led penetration testing regime for assessing cyber resilience of systemically important firms. Since 2014 it has assessed firms and financial market infrastructures the regulators judge systemically important, using red-team-style testing on live production systems rather than a written standard.

Class
Audit methodology
Owner
Bank of England, Prudential Regulation Authority (PRA) and Financial Conduct Authority (FCA)
Last verified

What it is

"CBEST promotes an intelligence-led penetration testing approach that mimics the actions of cyber attackers' intent on compromising an organisation's important business services (IBSs)."

"CBEST is a targeted assessment that allows regulators and firms to better understand weaknesses and vulnerabilities and take remedial actions, thereby improving the resilience of systemically important firms."

"Since 2014, CBEST has been an important part of the Bank of England (BoE), Prudential Regulation Authority (PRA), and Financial Conduct Authority (FCA) (together, the 'regulators') collective supervisory toolkit to assess the cyber resilience of firms and FMIs."

The assessment runs in four phases — Initiation, Threat Intelligence, Penetration Testing and Closure — against live production systems, using externally supplied, realistic threat scenarios rather than a checklist audit.

CBEST issues no certificate to the assessed firm. It is a recurring, regulator-supervised assessment regime, not a credential the firm can hold or display.

Who owns it

The Bank of England, the Prudential Regulation Authority and the Financial Conduct Authority run CBEST jointly, as part of their shared supervisory toolkit for the UK financial sector.

Who assesses it

Service providers must themselves be accredited: "The TISP must be CBEST accredited" (Threat Intelligence Service Provider) and "The PTSP must be CBEST accredited" (Penetration Testing Service Provider). That accreditation runs through CREST — "CREST performs a very important function. The regulator has reviewed the CREST company accreditation processes, Codes of Conduct and Ethics" — and requires named individual credentials: CCTIM ("CREST Certified Threat Intelligence Manager") for TISPs and CCSAM ("CREST Certified Simulated Attack Manager") for PTSPs.

Who asks for it

"The firm/FMI is requested by the regulator to undertake a CBEST assessment as part of the supervisory cycle."

A firm can also take part by agreement rather than instruction: participation may be "agreed in consultation with the regulator."

A third route is remedial: an assessment can be "triggered by the regulator...in support of post incident remediation activity."

Sources

Last verified:

This page is for information only; it does not accredit, certify or endorse any organisation. Requirements and programs change — always confirm against the primary source linked above.

Cite this page

Attributing this record helps other researchers verify it independently.

"CBEST Threat Intelligence-Led Assessments." Certifidex, FutureTechnologies. Last verified 31 August 2026. https://certifidex.com/frameworks/cbest

All frameworks & audits →