Precursor Security
CHECK-Accredited Public Sector Assurance

NCSCITHealthCheck(ITHC)

Annual NCSC CHECK assessments for UK public sector organisations. Our Security Checked consultants deliver cyber security health checks covering PSN Code of Connection, GovAssure CAF, and HSCN compliance, with reports accepted by the PSN Authority on first submission.

CHECK Accredited
PSN · GovAssure · HSCN
From £8,000
Scroll
Compliance Coverage

One Assessment, Multiple Frameworks

Your ITHC satisfies the technical assurance requirements of every major UK public sector security framework. Identify your compliance obligation below.

Framework
Requirement Satisfied
Applies To
PSN Code of Connection
Annual ITHC technical assurance
All PSN-connected public sector bodies
GovAssure / NCSC CAF
Independent technical assessment for CAF self-assessment
Central government departments
HSCN
Network security assessment for connectivity compliance
NHS Trusts, health sector organisations
NCSC CHECK Scheme
Government-mandated penetration testing
OFFICIAL and above classifications
CHECK Scheme Scope

Conducted Under the
NCSC CHECK Scheme

Our IT Health Check covers every domain required for PSN Code of Connection compliance, GovAssure CAF assessment, and HSCN accreditation. CHECK-accredited team leaders oversee all testing phases.

Core Domain

Internal Infrastructure

A comprehensive audit of your internal network, including Active Directory, domain controllers, servers, and workstations. We identify lateral movement paths, privilege escalation routes, and misconfigurations across your connected estate.

Perimeter

External Perimeter

Scanning all internet-facing IP addresses and web applications to ensure no open doors exist for remote attackers targeting your public-facing infrastructure.

Wireless

Wireless Security

Auditing corporate and guest WiFi networks for encryption strength, segregation, and rogue access points across all physical sites included in the ITHC scope.

Remote Access

Remote Access (VPN)

Verifying that remote workers connect securely and that endpoint posture checks are rigorously enforced across all remote access pathways, including split-tunnel configurations.

Configuration

Build Reviews

Detailed configuration reviews of gold images (laptops, servers) against NCSC and CIS hardening guidelines, covering all sample device types required by the CHECK scheme.

GovAssure

GovAssure / CAF Alignment

For central government departments subject to GovAssure, we map ITHC findings to the NCSC Cyber Assessment Framework objectives. Our reporting provides the independent technical assessment evidence required for your annual GovAssure submission to Cabinet Office.

Engagement Pipeline

Engagement Workflow

Structured to minimise operational friction and maximise the value of the testing window.

Step 01

Scoping

We define the boundary of the ITHC, typically critical systems, core networking, and a sample of end-user devices. Scoping documentation is agreed within 5 working days, enabling immediate procurement sign-off. (Week 1-2)

Step 02

Testing Phases

Executing the CHECK-scheme test plan across all domains: internal infrastructure, external perimeter, wireless, and remote access. Typically 5-10 testing days conducted onsite and remotely. (Weeks 2-5)

Step 03

Remediation

Critical findings are escalated immediately. You have a defined remediation window (typically 2-4 weeks) to apply patches before the report is finalised. We support your team through prioritisation. (Weeks 5-7)

Step 04

Final Report

We issue the final ITHC report in the format required by your accreditor: PSN Authority, NCSC, HSCN, or Cabinet Office (GovAssure). Report delivery within 5 working days of testing completion. (Week 7-8)

Accreditation Verification

CREST-Accredited. Verifiable. UK-Based.

In a market where providers claim CHECK status without verification, provenance matters. Every Precursor ITHC is delivered by salaried, security-cleared engineers who hold CREST certification and operate under the NCSC CHECK scheme.

Verified
CREST

CREST Accredited

All testing delivered by CREST-certified consultants operating under the NCSC CHECK scheme, verifiable on both the CREST and NCSC CHECK directories.

Timeline
2weeks

Call to Report Delivery

From initial scoping call to accreditor-accepted final report in as little as two weeks. Timeline scales to meet PSN renewal and GovAssure submission cycles.

Accreditation
Verified
NCSC DirectoryCHECK Listed
CRESTAccredited
Data Residency100% UK
EngineersSalaried Staff
Indicative Pricing

ITHC Pricing by Organisation Type

Fixed-price quotes based on estate scope. Bring your IP range count and we will provide a precise quote within 48 hours.

Small Authority / ALB
District council, arm's-length body
From £8,000
Medium Council / NHS Trust
Unitary/county council, NHS Trust
£10,000 - £18,000
Central Government
Central gov department, MOD supply chain
£18,000 - £25,000+
CHECK-accredited testers
Fixed pricing
PSN Authority accepted
Post-test remediation support

All quotes are fixed-price with no hourly overruns. Request a Scoping Call

Deliverables

What You Receive

Every ITHC engagement includes the following deliverables, formatted for both technical teams and accreditor submission.

Final ITHC report in accreditor-accepted format (PSN Authority, NCSC, HSCN, Cabinet Office)
Executive summary suitable for Permanent Secretary or SIRO briefing
Detailed technical findings with CVSS scores and reproduction steps
Remediation guidance prioritised by risk and compliance impact
GovAssure CAF mapping where applicable (findings to CAF objectives)
Wireless assessment report covering all in-scope physical sites
Build review results against NCSC and CIS benchmarks
Re-testing of critical and high findings within the remediation window
Post-engagement debrief with your IT and security teams

Reports are delivered via our real-time penetration testing portal with role-based access. Also available in PDF and DOCX formats for accreditor submission.

Service Catalogue

Full Penetration Testing Catalogue

Comprehensive penetration testing services tailored to your environment.

Ready to Secure

The best time to test your defences is now.

Join the high-growth companies relying on Precursor for continuous offensive and defensive security.

CREST Triple Accredited|Fixed Price Quotes|Free Scoping Call|UK Based Team

Frequently Asked Questions

Common questions about this service, methodologies, and deliverables.

An IT Health Check (ITHC) is a structured security assessment of an organisation's IT estate, conducted under the NCSC CHECK scheme. It covers internal infrastructure, external perimeter systems, wireless networks, remote access controls, and configuration reviews of key systems. The ITHC is the primary compliance mechanism for organisations connecting to the Public Services Network (PSN) and Health and Social Care Network (HSCN), and provides technical assurance evidence for GovAssure submissions. It is distinct from a commercial penetration test in that it is mandatory for many public sector organisations, conducted by NCSC CHECK-accredited and security-cleared consultants, and reported in a format accepted by government accreditors. Historically referred to as the CESG IT Health Check before CESG's functions transferred to NCSC.

CREST is an industry certification body covering commercial penetration testing. CHECK (NCSC CHECK scheme) is a UK government scheme operated by the National Cyber Security Centre, mandatory for testing government systems and PSN-connected networks. Key differences: CHECK consultants are individually vetted and hold government security clearance (SC or DV); CHECK methodology is aligned to NCSC requirements; CHECK reports are accepted by the PSN Authority, Cabinet Office, and HSCN accreditors where CREST-only reports are not. If your organisation connects to PSN, GovAssure, or HSCN, or if your contract specifies CHECK-approved testing, you require a CHECK-accredited provider. You can verify Precursor Security's CHECK listing on the NCSC directory.

GovAssure requires central government departments to submit an annual self-assessment against the NCSC Cyber Assessment Framework (CAF). While the self-assessment is completed internally, it must be supported by independent technical evidence, including the results of a CHECK-accredited security assessment. Our GovAssure-aligned ITHC maps findings to specific CAF objectives (covering 'Managing Security Risk', 'Protecting Against Cyber Attack', 'Detecting Cyber Security Events', and 'Minimising the Impact of Incidents') and provides reporting in the format required to substantiate your CAF self-assessment ratings. We can advise on how to align the ITHC engagement timeline with your annual GovAssure submission cycle.

Yes. We have delivered ITHC assessments for NHS Trusts and health sector organisations with HSCN connectivity. Our assessments scope the HSCN connection boundary as well as relevant internal systems, with testing protocols designed to avoid disruption to live clinical services. Findings are mapped to NHS Data Security and Protection Toolkit (DSPT) requirements where applicable, supporting your annual DSPT submission. If you are uncertain whether a full CHECK ITHC or a targeted network assessment is required for your specific HSCN compliance obligations, we provide pre-scoping advisory at no charge.

The Public Services Network (PSN) is the UK government's secure network infrastructure. Organisations that connect to PSN (including local authorities, police forces, fire services, and NHS bodies) must maintain a Code of Connection (CoCo) that demonstrates their security posture meets PSN Authority requirements. A mandatory element of CoCo compliance is an annual IT Health Check conducted by a CHECK-accredited provider. The ITHC demonstrates that your organisation's connected systems do not introduce vulnerabilities to the wider PSN. Without a valid ITHC from a CHECK-accredited provider, your PSN Code of Connection cannot be renewed. Loss of PSN connectivity disrupts core public services including revenues and benefits systems, HR, and inter-agency data sharing. We provide end-to-end PSN ITHC services including scope documentation advice, testing, remediation guidance, and final report delivery in the format required by the PSN Authority.

NCSC IT Health Check pricing typically ranges from £8,000 to £25,000+ depending on scope, estate size, and security clearance requirements. Small district councils or arm's-length bodies (internal, external, wireless, two build reviews) start from £8,000. Medium unitary or county councils and NHS Trusts with additional cloud tenants and multiple sites typically fall in the £10,000-£18,000 range. Large central government departments requiring full estate coverage, multiple domains, and DV clearance typically range from £18,000-£25,000+. We provide fixed-price quotes after reviewing your scope documentation. All testing is delivered by CHECK-accredited, security-cleared consultants. See the pricing breakdown in our ITHC FAQ above, or contact us for a scoping call. Bring your IP range count and we will provide a quote within 48 hours.

For most UK public sector organisations connected to the PSN (Public Services Network), an annual ITHC is a mandatory requirement for Code of Connection (CoCo) compliance. ITHC is also required for HSCN connectivity (NHS), GovAssure (central government departments), and organisations handling OFFICIAL-SENSITIVE or higher classified data.

From scoping to accreditor-accepted report in 6-8 weeks. Step 1 (scoping and documentation review): Week 1-2. Step 2 (testing phases, onsite and remote): Weeks 2-5. Step 3 (remediation window and re-testing): Weeks 5-7. Step 4 (final report and accreditor submission): Week 7-8. Comprehensive testing typically requires 5-10 days onsite plus additional time for external testing and reporting. We can advise on timeline alignment with your PSN renewal or GovAssure submission cycle.

Internal vulnerability scanning cannot satisfy ITHC requirements for several reasons: (1) PSN Code of Connection explicitly requires testing by CREST-accredited external providers. Internal assessment does not satisfy this mandate. (2) GovAssure requires independent third-party assessment against the NCSC CAF, (3) Internal teams lack the adversarial mindset and exploitation skills to identify attack chains that scanners miss, (4) CHECK accreditation ensures your report is accepted by the PSN Authority, HSCN, and other accreditors, (5) External consultants with SC or DV clearance can test classified environments without creating insider risk, and (6) Fresh perspective identifies vulnerabilities that teams familiar with their own systems overlook. Most public sector organisations use internal IT for continuous monitoring while engaging CHECK teams for annual compliance testing.

No. Local authorities handling citizen data and connected to PSN or HSCN face the same compliance requirements as larger departments: (1) PSN Code of Connection applies regardless of authority size, (2) Ransomware groups specifically target smaller authorities knowing they have fewer resources. The 2024 Redcar and Cleveland attack cost £10.4M in recovery. (3) LGA Cyber 360 and the National Cyber Strategy require demonstrated security improvements, (4) Citizen data (council tax, benefits, housing, social services) is equally valuable to attackers regardless of population served, and (5) Shared services arrangements mean your vulnerabilities could cascade to partner authorities. We offer streamlined ITHC packages for smaller authorities starting from £8,000, a fraction of breach recovery costs and essential for maintaining PSN connectivity.

Yes. Modern ITHCs almost always include Azure and AWS tenants as major government workloads have moved to the cloud. We assess cloud configuration, identity management, and the security of hybrid connectivity between cloud and on-premise environments.

There is no pass or fail in the traditional sense, but critical vulnerabilities must be remediated. We work with you to prioritise fixes so you can maintain your accreditation. Most organisations receive some critical or high findings. The key is demonstrating a remediation plan and timeline to the accreditor. We provide structured remediation guidance and can support re-testing of resolved findings within the compliance window.