Public-sector connection assurance

IT Health Check (ITHC) for Public-Sector Assurance

An IT Health Check is the CHECK-scheme penetration test a public-sector body asks for before it will grant or renew a connection. The test itself has to come from accredited testers, so you commission that directly. What we do is get you through it: assess the environment first, close what a CHECK test would raise, prepare the scope and evidence, then help you act on the findings.

The test the connection owner wants

An ITHC is a CHECK-scheme test with a purpose

An IT Health Check is a penetration test of a defined environment, run to prove its security to whoever owns the connection you need. What sets it apart from a general penetration test is the requirement behind it: PSN, the pensions dashboards ecosystem and other public-sector connections expect the test to be delivered under the NCSC CHECK scheme, so the result carries weight with the body granting the connection.

That accreditation matters, which is why we are precise about where we sit. The formal test has to come from CHECK or CREST accredited testers, and you commission it directly. Our work is everything that decides the outcome: finding and fixing what the test would otherwise raise, defining a scope the connection owner will accept, assembling the evidence, and turning the report you get back into remediation your team can complete.

What we deliver, and what we do not

  • An internal assessment of the systems and IP ranges in scope before the formal test
  • The remediation to close what a CHECK test would raise, done with your team
  • Scoped to the specific PSN, pension-dashboard or public-sector connection requirement
  • The scope definition and evidence pack the connection owner expects
  • Support closing the tester's findings once the formal ITHC has run
  • Indicative fixed-scope pricing, from GBP 7,200, published rather than quote-only

Who needs one

When a connection requires an ITHC

An ITHC is almost always triggered by a connection requirement rather than chosen voluntarily. These are the situations that bring organisations to one.

PSN connections

Organisations connecting to the Public Services Network are required to demonstrate the security of their environment. An ITHC is the standard evidence, carried out to the scope the PSN connection compliance process expects.

Pension dashboards

Providers and integrators connecting to the pensions dashboards ecosystem must evidence the security of that connection. An ITHC delivered by CHECK-accredited testers is the recognised route to that assurance.

Public-sector connections

A wide range of central and local government services require an ITHC before granting or renewing a connection, from departmental systems to justice and health networks. Where the connection owner asks for a CHECK-scheme test, this is what they mean.

Quick answers

IT Health Check questions, answered

What is an IT Health Check (ITHC)?

An IT Health Check, or ITHC, is a penetration test of a defined environment carried out to demonstrate its security to a public-sector body before a connection is granted or renewed. It combines external and internal testing to find the weaknesses an attacker could exploit, and it is typically required where a system connects to a government network or service.

What does ITHC stand for?

ITHC stands for IT Health Check. The term is used across UK public-sector assurance, most notably for connections to the Public Services Network (PSN), the pensions dashboards ecosystem and other government services. It describes a scoped penetration test delivered under the CHECK scheme.

Does an ITHC have to be CHECK-accredited?

Yes, in almost every case. Public-sector connection processes require the test to be performed by testers working under the NCSC CHECK scheme, or by CREST-accredited testers, because the connection owner needs assurance it was carried out to a recognised standard. That formal test is therefore out of our scope and you commission it directly. Our work is everything around it, and it is the part that decides whether you pass: assessing the environment internally first, closing what a CHECK test would raise, preparing the scope and evidence, and helping your team act on the findings afterwards.

How the engagement runs

Who needs an IT Health Check?

Any organisation connecting to a public-sector network or service that requires proof of security: PSN-connected bodies, pension dashboard providers and integrators, and suppliers connecting to central or local government systems. If a connection owner has asked you for a CHECK-scheme test or an ITHC, this is the service that answers it.

What does an ITHC cost?

Indicative pricing starts from GBP 7,200, priced by the number of systems and IP ranges in scope, since the effort is driven by the size of the environment. Pricing is fixed-scope and published rather than quote-only. The fee covers our readiness and remediation work and excludes the formal CHECK-scheme test itself, which you commission from accredited testers. The pricing page shows ITHC alongside CAF, GovAssure and Secure by Design work.

See the published prices

Rocket above the CAF Assessment call to action

Meet the connection requirement

Scope your IT Health Check

A free 45 minute call establishes the systems and IP ranges in scope, the connection requirement you are meeting and the indicative fixed-scope cost of a managed, CHECK-accredited ITHC.