NCSC IT Health Check (ITHC) Penetration Testing
CCL are accredited by NCSC (under the CHECK scheme to deliver IT Health Checks (ITHC, penetration testing, pentesting). Our certified security consultants can assess all systems including web applications, mobile applications, wireless, infrastructure and cloud services. Our tailored services help identify your unique threats and vulnerabilities.
Features
- Web application testing
- Network infrastructure testing
- Wireless network testing
- Build reviews
- Network device reviews
- Database configuration reviews
- Mobile application testing
- AWS and Azure configuration reviews
- Secure code reviews
Benefits
- Testing methodologies approved by NCSC under CHECK scheme
- Comprehensive reports providing detailed information and remediation advice
- Understand the threats and risks to your systems
- Services are tailored to each client's needs and requirements
- All security consultants are certified under CREST or Tiger Scheme
- Adjusted risk ratings based on contextual information
- Expert testing and analysis supplemented with industry leading tools
- Minimise potential cost and reputational damage a breach would cause
- Security cleared consultants
Pricing
- Education pricing available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
5 2 7 7 4 9 8 8 2 4 9 5 1 8 1
Contact
CCL-FORENSICS LIMITED
Samantha Ollis
Telephone: 01789 261200
Email: tenders@cclsolutionsgroup.com
About your service
- Service categories
-
Cloud Support Services
Security Services
- Security quality assurance (QA) and testing
- Other
Service scope
- Service constraints
- Service constraints are defined during scoping and vary by engagement. The scope will set the systems, networks, applications, and time periods included. Delivery depends on timely customer authorisation, access to systems, and approval for testing.
User support
- Email or online ticketing support
- Yes
- Support response times
-
We respond to customer questions within four working hours during normal UK business hours (09:00–17:30, Monday to Friday, excluding UK public holidays). Initial responses acknowledge receipt and provide a resolution or an estimated timeframe.
During active penetration testing, we notify customers as soon as reasonably practicable if critical or high-risk vulnerabilities are identified. We also provide regular communication during delivery, including a daily end-of-day update summarising progress and significant findings.
At weekends and on public holidays, responses are limited. Queries received outside working hours are responded to on the next business day. - User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Support levels
-
We provide a single standard support level for all services. This support is included in the service price.
Support includes pre-engagement scoping and planning, delivered with a named account manager as the primary point of contact. Customers can contact the account manager during normal UK business hours for engagement management, scheduling, and coordination.
Technical support is provided by CHECK-approved Team Leaders and consultants involved in the engagement. Customers have access to the CHECK Team Leader for technical clarification during scoping, the testing window and after delivery of the final report.
We can provide a report walkthrough to explain findings, risk ratings, and recommended remediation actions. Reasonable follow-up support to clarify report content is included.
A separate cloud support engineer is not relevant to this service.
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Security Clearance (SC)
Pricing
- Discount for educational organisations
- Yes
Cyber security roles
| Role level | UK Rate | Offshore Rate |
|---|---|---|
| Lead cyber security audit and assurance | £1,100.00 | £1,100.00 |
| Principal cyber security audit and assurance | £1,250.00 | £1,250.00 |
| Role level | UK Rate | Offshore Rate |
|---|---|---|
| Associate cyber security governance and risk manager | £950.00 | £950.00 |
| Lead cyber security governance and risk manager | £1,175.00 | £1,175.00 |
| Principal cyber security governance and risk manager | £1,400.00 | £1,400.00 |
| Role level | UK Rate | Offshore Rate |
|---|---|---|
| Associate cyber security monitoring | £650.00 | £650.00 |
| Lead cyber security monitoring | £1,025.00 | £1,025.00 |
| Principal cyber security monitoring | £1,400.00 | £1,400.00 |
| Role level | UK Rate | Offshore Rate |
|---|---|---|
| Associate cyber incident response | £680.00 | £680.00 |
| Lead cyber security incident response | £2,100.00 | £2,100.00 |
| Principal cyber security incident response | £3,520.00 | £3,520.00 |
| Role level | UK Rate | Offshore Rate |
|---|---|---|
| Associate cyber security vulnerability management | £650.00 | £650.00 |
| Lead cyber security vulnerability management | £1,025.00 | £1,025.00 |
| Principal cyber security vulnerability management | £1,400.00 | £1,400.00 |
| Role level | UK Rate | Offshore Rate |
|---|---|---|
| Associate cyber security digital forensics | £680.00 | £680.00 |
| Lead cyber security digital forensics | £1,220.00 | £1,220.00 |
| Principal cyber security digital forensics | £1,760.00 | £1,760.00 |
| Role level | UK Rate | Offshore Rate |
|---|---|---|
| Associate cyber security testing | £950.00 | £950.00 |
| Lead cyber security penetration testing | £1,175.00 | £1,175.00 |
| Principal cyber security testing | £1,400.00 | £1,400.00 |
| Role level | UK Rate | Offshore Rate |
|---|---|---|
| Associate cyber security secure systems architecture and design | £950.00 | £950.00 |
| Lead cyber security secure systems architecture and design | £1,175.00 | £1,175.00 |
| Principal cyber security secure systems architecture and design | £1,400.00 | £1,400.00 |
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- SGS
- ISO/IEC 27001 accreditation date
- Tuesday 24 October 2023
- What the ISO/IEC 27001 doesn’t cover
- Nothing. All CCL services listed on Gcloud 15 are covered by our ISO27001 certification.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- SGS
- ISO 9001 accreditation date
- Saturday 25 October 2025
- What the ISO 9001 doesn’t cover
- None, All CCL services listed on Gcloud 15 are covered by our ISO9001 certification.
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 248ab3da-d757-4d02-b71d-69cd0eb0cf17
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 46702f5d-c8cd-4e7b-8f63-6f6e357b2a5b
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Ensuring new workers are informed of their right to join a trade union
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Volunteering opportunities for staff
-