Home › Insights › Methodology & Assurance
Methodology & Assurance

How to Verify SQEP Credentials Before Commissioning a VAPT Engagement in Singapore

Before signing a VAPT statement of work in Singapore, buyers should verify three separate things: the provider's CSA/CSRO licence, the firm's CREST status, and the named testers' individual certifications — this article sets out exactly how to check each one.

By Infracom Team16 September 20266 min read
Watch the short explainer, then read on. More on our YouTube channel.

Before signing a VAPT statement of work in Singapore, verify three separate things, not one: the provider's CSA/CSRO licence on the official register, the firm's CREST status, and the individual certifications of the named testers who will actually perform the work. A logo on a proposal or a line in a capability deck confirms none of these — only the register does.

Procurement teams increasingly ask who is "CSRO licensed" and who is "CREST-related" in Singapore, but few consultancies set out a transparent method for checking. This gap matters because the three credentials answer different questions — legal permission, organisational maturity, and named-tester competence — and a buyer who checks only one is exposed on the other two.

What regulators and frameworks expect

Singapore treats penetration testing as a regulated activity, not a commercial preference. The Cyber Security Agency of Singapore (CSA) has announced the launch of its licensing framework for cybersecurity service providers under Part 5 of the Cybersecurity Act, taking effect from 11 April 2022. CSA licenses two types of cybersecurity service providers — penetration testing and managed security operations centre monitoring — because providers performing such services can have significant access into their clients' computer systems and sensitive information, and abuse of that access could disrupt a client's operations.

The framework is administered by the Cybersecurity Services Regulation Office (CSRO). Any person who engages in the business of providing a licensable cybersecurity service without a licence after 11 October 2022 is guilty of an offence and liable on conviction to a fine not exceeding $50,000 or to imprisonment for a term not exceeding two years, or both. The obligation sits with the entity contracting to deliver the work, so a Singapore engagement, subcontracted testing, or an overseas team serving a Singapore client all fall within scope.

CSRO does not expect buyers to take a provider's word for it. Consumers may refer to the lists of licensed cybersecurity service providers, and are encouraged to verify that a cybersecurity service provider holds a valid licence before engaging their services. Licensees are also restricted in how they may represent that status: licensees may use text to describe their licensure status, or direct clients to the list of Licensed Service Providers on the CSRO website, where the licensee's licence details are reflected, rather than displaying the CSRO or CSA logo itself.

Sitting alongside the licence is CREST, the international not-for-profit body that certifies individuals and accredits organisations delivering penetration testing. Singapore has actively built CREST into its professional ecosystem: the introduction of CREST penetration testing certifications and accreditations in Singapore was designed to ensure high standards for cybersecurity services, with government subsidies available to Singaporeans and small firms pursuing these credentials.

CREST's organisational model runs in stages, and the terminology matters when a buyer is comparing providers. CREST offers a three-step pathway to accreditation: Stage One, Pathway, is a baseline for organisations in early stages of cybersecurity maturity, providing initial entry into CREST's register of providers with Pathway status and representing an agreement to work toward meeting CREST accreditation standards; Pathway organisations must advance to Stage Two within two years. Stage Two, Pathway+, builds on the Pathway stage by undergoing a self-assessment against CREST standards and at least one other cybersecurity standard. A provider describing itself as "CREST Pathway+" is at Stage Two of that model — a distinct status from full company accreditation, and buyers should not conflate the two.

Individual certification runs on a separate, examined track. CREST Practitioner is an entry-level certification for candidates with at least 2,500 hours of experience, CREST Registered is a mid-tier certification for testers with at least 6,000 hours of experience, and CREST Certified is the highest level, intended as a benchmark for senior security professionals with at least 10,000 hours of experience. These map to the familiar CPSA, CRT and CCT exam names. Company status and individual certification are independent facts, and a credible provider can produce evidence of both.

Finally, ISO/IEC 27001 certification of the provider's own information security management system is worth checking as a fourth, complementary signal. It speaks to how the firm handles the client data, credentials and findings generated during a VAPT engagement — not to tester competence directly, but to the discipline surrounding it.

The three credentials compared

← Swipe to compare →

DimensionCSA/CSRO LicenceCREST Company StatusIndividual Certification (CPSA/CRT/CCT)
Legal status in SingaporeMandatory under the Cybersecurity Act; unlicensed provision is an offenceVoluntary quality signal, not a legal requirementVoluntary quality signal, not a legal requirement
What it verifiesThe entity is legally permitted to sell penetration testing servicesThe firm's methodology, processes and maturity have been assessed at Pathway or Pathway+ stage, or aboveThe named tester has passed a CREST examination at Practitioner, Registered or Certified level
Where to verifyCSRO public register of licensed service providersCREST's public accreditation registerCREST's individual certification register, cross-checked against the SOW-named testers
Typical renewal cycleFixed licence term, currently transitioning to a five-year cycle on renewalPathway organisations must progress to Pathway+ within two yearsCertifications expire and require re-examination or continuing professional development

How to prepare: a practical verification method

A security lead does not need specialist tools to run this check — only a short sequence, done before the statement of work is signed rather than after.

  1. Pull the CSRO register entry. Confirm the licensed entity's name matches exactly the entity signing the contract — not a related holding company, a reseller, or a subcontractor mentioned only in passing.
  2. Confirm the licence covers penetration testing specifically. The framework separately licenses managed SOC monitoring; check the service type listed, not just the presence of a licence.
  3. Check CREST status against the public register, not the provider's own marketing. Distinguish Pathway, Pathway+ and full accreditation, and note which one the provider actually holds.
  4. Ask for the individual certifications of the testers named in the proposal, not the company as a whole. Company-level status does not guarantee that certified individuals are the ones assigned to your engagement.
  5. Request evidence, not assertions. A licence number, a CREST membership reference and named tester certificate numbers should all be checkable independently against the respective registers.
  6. Repeat the check at contract time, not just at RFP stage. Licences and certifications can lapse or change between a proposal being issued and a statement of work being signed, particularly on longer procurement cycles.
  7. Confirm the provider's own information security posture. ISO 27001 certification of the consultancy itself indicates that client data generated during testing — scope documents, credentials, findings — is managed under a certified information security management system.

Document the outcome of each step. A short verification record — licence number, CREST reference, certification IDs, date checked — gives procurement and audit an artefact to point to later, rather than relying on memory of a sales conversation.

How Infracom helps

Infracom is a CSA CSRO-licensed provider and a CREST Pathway+ Organisation, with an all-Singaporean SQEP team and rates built for SME budgets rather than enterprise-only pricing. Because verification is central to how we position our own credentials, we structure engagement proposals so that the licence, our CREST Pathway+ status, and each named tester's individual certifications can be checked independently before a statement of work is signed. Read more about our team's qualifications on the SQEP page, or talk to us about building a GRC programme — including Cyber Trust Mark readiness — around your next VAPT engagement.

Sources (7)
  1. CSRO — Cybersecurity Services Regulation Office
  2. CREST
  3. ISO/IEC 27001 — Information security management
  4. CSA Kicks Off Licensing Framework for Cybersecurity Service Providers
  5. CSRO FAQ
  6. CREST Singapore Chapter press release
  7. What is CREST Certification? (Cobalt)

Get Infracom Insights by email

Practical cybersecurity governance and regulatory updates for Singapore and Australia. No more than a few emails a month; unsubscribe any time.

Infracom Consultancy Integration Pte Ltd

Your one-stop IT & cybersecurity partner — Singapore HQ since 2008, expanding to Australia in 2026.

506 Chai Chee Lane

Singapore 469026

Services
IT InfrastructureCloud SolutionsCybersecurityManaged ServicesData Center SolutionsIT Consulting
Consulting
SQEPGRCVAPT
Approach
MethodologyAbout UsInsightsNewsletterPrivacy Policy
Hours

Mon – Fri
9AM – 6PM SGT

Follow us
© Infracom Consultancy Integration Pte Ltd. All rights reserved.Privacy Policy