Logo Menu

NCC Group penetration testing

NCC Group is a SOC 2 support firm in Manchester, UK providing penetration testing and compliance consulting, founded in 1999. Larger enterprises and regulated organizations that need a global provider for penetration testing, security consulting, and incident response under one roof.

Independent profile, researched from public sources. NCC Group has not reviewed this page.

Verified Penetration testingCompliance consulting Manchester, UK
Services
Penetration testing · Compliance consulting
Headquarters
Manchester, UK
Pricing
On request

Free and anonymous. We’ll follow up by email.

Who should hire NCC Group?

Larger enterprises and regulated organizations that need a global provider for penetration testing, security consulting, and incident response under one roof.

What makes NCC Group different?

A global, publicly listed cybersecurity firm founded in 1999, with CREST-member and CHECK-certified offensive security and technical assurance at scale.

Focus areas
Technical assurance and penetration testingSecurity consulting and implementationDigital forensics and incident responseManaged security servicesThreat intelligence
Accreditations
CRESTCHECKPCI QSAFedRAMP 3PAO
Frameworks supported
SOC 2ISO 27001PCI DSSFedRAMP
Regions served
United KingdomEuropeNorth AmericaAsia-Pacific

Pricing: NCC Group does not publish a standard price. Pricing depends on scope, environment, and engagement model — request a quote to get a current figure.

Links
Also listed on

Compare listed-scale CREST pentesting with Bishop Fox's US-led offensive security. Find a penetration testing firm for auditor-ready technical assurance. See NCC Group in the full support-firm directory.

Claim and upgrade this profile → Featured and Sponsor tiers add a badge and labeled placement on the hub pages.
Related profiles

Other service firms to compare.

  • NetSPI

    Compare services, specialties, and fit before you contact a provider.

  • Neutral Partners

    Compare services, specialties, and fit before you contact a provider.

Is NCC Group a SOC 2 auditor?

No. NCC Group is a cybersecurity and technical-assurance firm. It runs penetration tests, consulting, and some compliance assessments, including SOC 2 readiness support. A licensed CPA firm must still issue any SOC 2 report.

If you need the report issuer, start with the SOC 2 auditor directory.

What pentest work does NCC Group actually sell?

NCC Group sells point-in-time and continuous penetration testing, red, purple, and black-team attack simulation, and application, hardware, network, and cloud technical assurance. Its Technical Assurance page, reviewed 20 August 2026, also lists social-engineering tests and says the offensive-security bench is over 420 people.

That page names CHECK, CREST, and OSCP-certified consultants, plus testers cleared to SC and DV levels. Delivery is described as local in key regions or global, with fixed-cost, day-rate, and continuous models. Digital forensics, incident response, managed security, and threat intelligence sit alongside testing; they are separate buying motions, not extras assumed in a standard pentest quote.

Use the penetration testing firms hub when the job is a test, and the SOC 2 penetration testing hub when the report must map to an upcoming SOC 2 exam.

Which accreditations can a buyer verify independently?

Buyers can check CREST membership on NCC Group’s site, NCSC CHECK certification on NCSC’s organisation pages, and PCI QSA/ASV plus FedRAMP 3PAO claims on NCC Group’s governance page. NCSC listed the Manchester headquarters and certified CHECK status as of this review on 20 August 2026.

The NCSC organisation record also lists Cyber Incident Response, Cyber Incident Exercising, Cyber Resilience Testing Facility, and assured consultancy services. Those schemes matter for UK public-sector and CNI buyers. They do not, by themselves, prove fit for a narrow SaaS SOC 2 pentest.

Treat ISO 27001:2022 and ISO 9001:2015 on the governance page as certifications NCC Group holds for its own operations, not as proof that it will certify your ISMS. ISO certification still needs an accredited certification body.

Does NCC Group help with SOC 2, ISO 27001, PCI, or FedRAMP?

NCC Group supports SOC 2 as readiness and escrow consulting, not as the report issuer. The same standards and frameworks page offers ISO 27001 implementation support, and the governance page states PCI QSA/ASV and FedRAMP 3PAO roles.

That mix is useful when one provider should test systems, advise on gaps, and run a federal or payments assessment. It is the wrong mix if you need a CPA signature on a SOC 2 report from the same legal entity. Keep implementation and attestation separate: NCC Group (or another consultant) prepares; an independent auditor attests.

How much does a pentest from NCC Group cost?

NCC Group does not publish a standard pentest price. Its Technical Assurance page says engagements can be fixed-cost, day-rate, or continuous, and that delivery can be local or global. Confirm scope and a current quote before comparing firms.

Ask what the report will include (findings, CVSS or similar scoring, retest terms, and whether the write-up is meant for an auditor). Unpublished pricing is normal at this scale; it is not a substitute for a written statement of work.

When is a specialist a better fit than NCC Group?

NCC Group is a fit when you need listed-scale coverage, NCSC-assured CHECK testing, or several security workstreams under one contract. A specialist boutique such as Bishop Fox may fit better when you want a US-led, pentest-only offensive shop without the consulting and managed-service layers.

NCC Group’s About Us page, reviewed 20 August 2026, dates the firm to 1999 and says more than 1,800 experts work across the UK, Europe, North America, and Asia-Pacific. The homepage says “over 2,000 colleagues.” This directory records a conservative team-size floor of 1,800 from the expert figure, not a scraped third-party headcount.

How current is this NCC Group profile?

This page was checked against NCC Group’s public site and NCSC listings on 20 August 2026. Registry fields for name, services, support-firm status, and unpublished pricing were re-verified that day. Re-check headcount, scheme status, and 3PAO standing before you sign, because those facts move.

Buyer questions

NCC Group FAQ

Entity-specific answers from this firm's researched profile and verified directory record.

Is NCC Group a SOC 2 auditor?

No. NCC Group is a cybersecurity support firm. It can run penetration tests and SOC 2 readiness or escrow consulting, but a licensed CPA firm must perform the SOC 2 examination and issue the report.

Does NCC Group do penetration testing for SOC 2?

Yes, as a technical-assurance provider. NCC Group's Technical Assurance practice sells point-in-time and continuous penetration tests that many buyers use as input to a SOC 2 exam. That testing is evidence for the auditor. It is not the SOC 2 report.

Is NCC Group a CREST member and CHECK-certified?

NCC Group describes itself as a CREST member company. The UK National Cyber Security Centre lists NCC Group as a certified CHECK penetration-testing provider, with a Manchester headquarters at the XYZ Building, 2 Hardman Boulevard, Spinningfields, M3 3AQ. Confirm both listings before a public-sector or CNI engagement, because scheme status can change.

How much does NCC Group charge for a pentest?

NCC Group does not publish a standard pentest price. Its Technical Assurance page says buyers can choose fixed costs, day rates, or continuous models. Ask for a scoped quote and what the report will cover before comparing firms.

Does NCC Group perform FedRAMP assessments?

NCC Group's governance page states that it is a recognised FedRAMP Third Party Assessment Organization (3PAO) and can assess or advise cloud service organizations seeking FedRAMP authorization. That is a federal assessment role, not a SOC 2 attestation.

Request

Tell us what you need from NCC Group

Describe the workstreams you need and the outcome you are working toward. We’ll follow up by email with the next step, and your details stay private until you choose to be introduced.

Run a firm? Claim or upgrade this listing.

We send you 3–10 quotes from firms that actually fit, a shortlist, not a phone book.

What do you need? Select all that apply

We email you the quotes. Firms don't see your contact details until you choose one.

Optional. Up to 2,000 characters.

Add optional details timeline, platform, frameworks
Other frameworks your customers ask about

Compare options before taking a sales call.

Every request is read by a human before anything goes out.