Is NCC Group a SOC 2 auditor?
No. NCC Group is a cybersecurity and technical-assurance firm. It runs penetration tests, consulting, and some compliance assessments, including SOC 2 readiness support. A licensed CPA firm must still issue any SOC 2 report.
If you need the report issuer, start with the SOC 2 auditor directory.
What pentest work does NCC Group actually sell?
NCC Group sells point-in-time and continuous penetration testing, red, purple, and black-team attack simulation, and application, hardware, network, and cloud technical assurance. Its Technical Assurance page, reviewed 20 August 2026, also lists social-engineering tests and says the offensive-security bench is over 420 people.
That page names CHECK, CREST, and OSCP-certified consultants, plus testers cleared to SC and DV levels. Delivery is described as local in key regions or global, with fixed-cost, day-rate, and continuous models. Digital forensics, incident response, managed security, and threat intelligence sit alongside testing; they are separate buying motions, not extras assumed in a standard pentest quote.
Use the penetration testing firms hub when the job is a test, and the SOC 2 penetration testing hub when the report must map to an upcoming SOC 2 exam.
Which accreditations can a buyer verify independently?
Buyers can check CREST membership on NCC Group’s site, NCSC CHECK certification on NCSC’s organisation pages, and PCI QSA/ASV plus FedRAMP 3PAO claims on NCC Group’s governance page. NCSC listed the Manchester headquarters and certified CHECK status as of this review on 20 August 2026.
The NCSC organisation record also lists Cyber Incident Response, Cyber Incident Exercising, Cyber Resilience Testing Facility, and assured consultancy services. Those schemes matter for UK public-sector and CNI buyers. They do not, by themselves, prove fit for a narrow SaaS SOC 2 pentest.
Treat ISO 27001:2022 and ISO 9001:2015 on the governance page as certifications NCC Group holds for its own operations, not as proof that it will certify your ISMS. ISO certification still needs an accredited certification body.
Does NCC Group help with SOC 2, ISO 27001, PCI, or FedRAMP?
NCC Group supports SOC 2 as readiness and escrow consulting, not as the report issuer. The same standards and frameworks page offers ISO 27001 implementation support, and the governance page states PCI QSA/ASV and FedRAMP 3PAO roles.
That mix is useful when one provider should test systems, advise on gaps, and run a federal or payments assessment. It is the wrong mix if you need a CPA signature on a SOC 2 report from the same legal entity. Keep implementation and attestation separate: NCC Group (or another consultant) prepares; an independent auditor attests.
How much does a pentest from NCC Group cost?
NCC Group does not publish a standard pentest price. Its Technical Assurance page says engagements can be fixed-cost, day-rate, or continuous, and that delivery can be local or global. Confirm scope and a current quote before comparing firms.
Ask what the report will include (findings, CVSS or similar scoring, retest terms, and whether the write-up is meant for an auditor). Unpublished pricing is normal at this scale; it is not a substitute for a written statement of work.
When is a specialist a better fit than NCC Group?
NCC Group is a fit when you need listed-scale coverage, NCSC-assured CHECK testing, or several security workstreams under one contract. A specialist boutique such as Bishop Fox may fit better when you want a US-led, pentest-only offensive shop without the consulting and managed-service layers.
NCC Group’s About Us page, reviewed 20 August 2026, dates the firm to 1999 and says more than 1,800 experts work across the UK, Europe, North America, and Asia-Pacific. The homepage says “over 2,000 colleagues.” This directory records a conservative team-size floor of 1,800 from the expert figure, not a scraped third-party headcount.
How current is this NCC Group profile?
This page was checked against NCC Group’s public site and NCSC listings on 20 August 2026. Registry fields for name, services, support-firm status, and unpublished pricing were re-verified that day. Re-check headcount, scheme status, and 3PAO standing before you sign, because those facts move.