What is an IT Health Check?
An IT Health Check (ITHC) is a structured series of controlled security tests designed to identify vulnerabilities in an organisation’s IT infrastructure, systems and applications. It is the mandated form of penetration testing for public sector organisations in the UK, required before connecting to government networks and approved data-sharing environments.
ITHCs are delivered exclusively by suppliers accredited under the CHECK scheme, which is administered by the National Cyber Security Centre (NCSC). CHECK-accredited suppliers are security-cleared, making them the only approved providers for testing public sector systems. CyberLab is a CHECK-accredited provider, with a team of CHECK Team Leaders (CTLs) and CHECK Team Members (CTMs) experienced in delivering ITHCs across central government, local authorities, the NHS and regulated industries.
When is an IT Health Check Required?
An ITHC is mandatory in a number of specific situations. Organisations must complete an ITHC before connecting to the Public Services Network (PSN), before being listed on G-Cloud, before achieving NHS Digital Security Protection Toolkit (DSPT) compliance, and before connecting to the Pensions Dashboards Programme (PDP) ecosystem.
Some regulated industries and procurement frameworks also require evidence of a current ITHC as part of supplier due diligence. If your organisation is subject to any of these requirements, CyberLab can scope and deliver your ITHC to meet the specific code of connection requirements for each framework.
An IT Health Check goes beyond a standard vulnerability scan. It provides a structured, methodical assessment of your entire IT environment - from external infrastructure and internal systems to applications, APIs and remote access - giving your organisation a clear, evidenced picture of its security posture and a prioritised remediation plan. For public sector organisations, an ITHC is not optional. It is a prerequisite for connecting to government-approved networks and data-sharing frameworks, and the results feed directly into your compliance and audit reporting. Getting it right first time matters - and that starts with choosing a CHECK-accredited provider with genuine public sector experience.
Enhanced Security Posture
Proactively identifies and mitigates vulnerabilities to strengthen your defences against evolving cyber threats.
Regulatory Compliance
Ensures adherence to NCSC, CHECK, and other regulatory requirements, reducing the risk of non-compliance penalties.
Operational Resilience
Protects critical systems and minimises potential downtime by addressing risks before they can disrupt operations.
Trusted Assurance
Provides confidence to stakeholders by demonstrating a commitment to robust security practices and safeguarding sensitive data.
Thousands of organisations across the UK trust us, here’s why…
Accredited Expertise
Our consultants hold leading certifications and apply proven methodologies to deliver trusted, industry-standard guidance throughout your security journey.
Tailored Strategies
We design security approaches that align with your business goals, technology stack, and compliance requirements - ensuring you receive an optimised service throughout.
End-to-End Support
From initial assessment through to full implementation and ongoing optimisation, we provide complete guidance and hands-on support throughout.
Compliance Confidence
We help you meet GDPR, PCI DSS, and ISO 27001 requirements with solutions that simplify compliance.
Threat-Led Approach
Our experts think like attackers to identify vulnerabilities early, helping you stay ahead of evolving threats and minimise exposure.
Future-Proof Solutions
We deliver recommendations that adapt as the threat landscape changes, ensuring your organisation remains resilient over time.
Cost-Effective Protection
Our strategies maximise ROI by leveraging your existing technology investments and prioritising improvements that deliver measurable value.
Trusted Partnership
We act as an extension of your team, offering ongoing support and clear communication to give you confidence and peace of mind.
IT Health Check: The CyberLab Approach
Our IT Health Check process follows the NCSC scheme requirements and the specific codes of connection for PSN, G-Cloud, NHS DSPT and the Pensions Dashboards Programme. Every ITHC begins with careful scoping and ends with a clear, audit-ready report – so you have everything you need to demonstrate compliance and address findings with confidence.
One of our CHECK Team Leaders will work with you to define the scope of the engagement, establish rules of engagement, and confirm which environments, assets and systems are in scope. For organisations connecting to the Pensions Dashboards Programme, scope must include any environment where live pension data will be used – including external infrastructure, internal systems, applications, APIs and remote access services. We will help you define this clearly before testing begins to avoid gaps in your submission report.
Our team assesses all internet-facing systems and assets that store, process or transmit sensitive data. This includes reviewing data security configurations, TLS implementations, firewall rules and network segmentation, and testing against OWASP Top 10 vulnerabilities. Automated and manual vulnerability scanning is conducted to identify external attack vectors.
Internal testing covers all in-scope assets including servers, databases, file systems and internal network infrastructure. We assess database security configurations, server and network hardening, internal firewall and security gateway configurations, wireless setups where applicable, and access controls including VPN and third-party access. Least privilege access enforcement is reviewed across all relevant environments.
Automated and manual vulnerability scanning is conducted across both external and internal environments. Findings are classified by criticality and CVSS score (version 3.0 or above), in line with NCSC and PDP reporting requirements.
Why Choose CyberLab for an IT Health Check?
Unmatched Expertise
14-strong UK team, including 7 CHECK Team Leaders, 6 CTMs, and SC/NPPV3-cleared consultants.
ProvenTrack Record
Over a decade of high-stakes testing for public sector and regulated industries, building on our ex-Armadillo Sec heritage.
Trusted by 1,200+ Organisations
Including NHS, local authorities, housing,
manufacturing, education, and financial services.
RapidResponse
Next-day testing for compliance deadlines, audits, and urgent stakeholder needs.
No Jargon, NoOrphaned Reports
Just clear, evidence-based security improvement.
Success Stories
Penetration Testing

NHS
NHS Trust Strengthens Microsoft 365 Security with CyberLab
“Having used CyberLab before in a previous Head of IT role, I had no hesitation in engaging them again to assist us with our security needs. Simply, I wouldn’t use them if they didn’t consistently deliver value.”
Penetration Testing

Sealey Group
Sealey Group Secures E-Commerce with24/7 Cyber Defence
“Working with CyberLab has greatly enhanced our cyber security posture. Their proactive approach and tailored solutions have strengthened our defences, ensuring our customer data and operations remain secure.”
IT Health Check: FAQs
An IT Health Check is a structured series of controlled security tests used to identify vulnerabilities in an organisation’s IT infrastructure, systems and applications. In the UK public sector, an ITHC is the mandated form of penetration testing required before connecting to approved government networks and data-sharing frameworks. It must be conducted by a CHECK-accredited supplier whose testers are security-cleared.
A standard penetration test can be conducted by any CREST-accredited supplier. An IT Health Check specifically refers to the CHECK-scheme version of penetration testing, which is mandated for public sector use. CHECK-accredited suppliers are security-cleared, making them the only approved option for testing systems that connect to or process government data. CyberLab holds both CHECK and CREST accreditation.
A CyberLab ITHC covers external infrastructure testing, internal infrastructure testing, vulnerability scanning, application and API security assessment, remote access and VPN evaluation, and database security review. The exact scope is defined during the planning phase and agreed with your team to ensure it meets the specific code of connection requirements for your framework – whether that is PSN, G-Cloud, NHS DSPT or the Pensions Dashboards Programme.
Yes. Organisations connecting to the Pensions Dashboards Programme ecosystem – including pension providers, schemes and integrated service providers – must conduct an ITHC or penetration test and submit a report before connection is approved. The test must comply with the PDP code of connection and be conducted by a CREST or CHECK-accredited supplier. CyberLab is accredited under both schemes.
Timescales vary depending on the size and complexity of your environment. Straightforward ITHCs for smaller organisations can be scoped and delivered within a few weeks. For larger or more complex environments, or where multiple assets are in scope, the process takes longer. CyberLab offers next-day testing for urgent compliance deadlines – speak with our team to discuss your timeline.
You receive a comprehensive, audit-ready report that details all findings, including vulnerability descriptions, CVSS base scores (version 3.0 or above), severity classifications, potential impact assessments and specific remediation guidance for each finding. The report is formatted to meet the submission requirements for PSN, G-Cloud, NHS DSPT and PDP frameworks as applicable.
Most frameworks that require an ITHC specify that it should be repeated annually, or whenever significant changes are made to in-scope systems or infrastructure. Your CHECK-accredited supplier can advise on the appropriate frequency based on your specific framework requirements.
Yes. CyberLab has extensive experience working with NHS Trusts and healthcare organisations. Our consultants are SC-cleared and experienced in NHS DSPT requirements. We work with over 60 NHS organisations across the UK.
An ITHC must be conducted by a supplier accredited under the CHECK scheme, administered by the NCSC. CHECK Team Leaders (CTLs) lead the engagement, supported by CHECK Team Members (CTMs). All CHECK-accredited testers hold security clearance. CyberLab’s team includes 7 CHECK Team Leaders and 6 CTMs, all SC or NPPV3-cleared.


What is YourHackRisk Score?
Your Credit Score for Cyber Security
AI-powered cyber risk monitoring with secure dashboard and shareable reports, delivered by security experts.
Dark Web Scanning
Vulnerability Scanning
Recon Scanning
Supply Chain Security
This page was reviewed by Steve Clarke, Head of Penetration Testing at CyberLab, on 11.05.26.
Speak With an Expert
Enter your details and one of our experts will be in touch.
Whether you’re looking to implement basic cyber security best practice, improve your existing defences, or introduce a new system or solution, our team of expert consultants, engineers, and ethical hackers are here to help.
Our team specialise in creating bespoke security solutions and testing packages to improve and maintain your security posture.
We are 100% vendor agnostic and will only ever recommend the best products and solutions for your requirements.

















