NCSCITHealthCheck(ITHC)
An NCSC IT Health Check (ITHC) is an annual security assessment of a public sector organisation's IT estate, delivered by a provider accredited under the CREST, CHECK, or Tiger scheme. It is required for organisations connecting to the Public Services Network (PSN) and Health and Social Care Network (HSCN), and for central government GovAssure submissions. Precursor Security delivers ITHC assessments as a CREST member firm, with reports accepted for PSN Code of Connection; where a formal NCSC CHECK deliverable is mandated (typically central government or OFFICIAL-SENSITIVE work) we partner with CHECK providers. DBS-checked consultants as standard. Engagements from £8,000.
Annual IT Health Check assessments for UK public sector organisations. Our DBS-checked consultants deliver cyber security health checks covering PSN Code of Connection, GovAssure CAF, and HSCN compliance, with reports accepted by the PSN Authority on first submission. SC-cleared engineers available for classified environments.
One Assessment, Multiple Frameworks
Your ITHC satisfies the technical assurance requirements of every major UK public sector security framework. Identify your compliance obligation below.
Aligned to the
NCSC ITHC Standard
Our IT Health Check covers every domain required for PSN Code of Connection compliance, GovAssure CAF assessment, and HSCN accreditation. CREST-accredited team leaders oversee all testing phases.
Internal Infrastructure
A comprehensive audit of your internal network, including Active Directory, domain controllers, servers, and workstations. We identify lateral movement paths, privilege escalation routes, and misconfigurations across your connected estate.
External Perimeter
Scanning all internet-facing IP addresses and web applications to ensure no open doors exist for remote attackers targeting your public-facing infrastructure.
Wireless Security
Auditing corporate and guest WiFi networks for encryption strength, segregation, and rogue access points across all physical sites included in the ITHC scope.
Remote Access (VPN)
Verifying that remote workers connect securely and that endpoint posture checks are rigorously enforced across all remote access pathways, including split-tunnel configurations.
Build Reviews
Detailed configuration reviews of gold images (laptops, servers) against NCSC and CIS hardening guidelines, covering all sample device types required by the CHECK scheme.
GovAssure / CAF Alignment
For central government departments subject to GovAssure, we map ITHC findings to the NCSC Cyber Assessment Framework objectives. Our reporting provides the independent technical assessment evidence required for your annual GovAssure submission to Cabinet Office.
Engagement Workflow
Structured to minimise operational friction and maximise the value of the testing window.
Scoping
We define the boundary of the ITHC, typically critical systems, core networking, and a sample of end-user devices. Scoping documentation is agreed within 5 working days, enabling immediate procurement sign-off. (Week 1-2)
Testing Phases
Executing the ITHC test plan across all domains: internal infrastructure, external perimeter, wireless, and remote access. Typically 5-10 testing days conducted onsite and remotely. (Weeks 2-5)
Remediation
Critical findings are escalated immediately. You have a defined remediation window (typically 2-4 weeks) to apply patches before the report is finalised. We support your team through prioritisation. (Weeks 5-7)
Final Report
We issue the final ITHC report in the format required by your accreditor: PSN Authority, NCSC, HSCN, or Cabinet Office (GovAssure). Report delivery within 5 working days of testing completion. (Week 7-8)
CREST-Accredited. Verifiable. UK-Based.
In a market where providers overstate their status, provenance matters. Every Precursor ITHC is delivered by salaried, security-cleared engineers who hold CREST certification.
CREST Accredited
All testing delivered by CREST-accredited, security-cleared consultants, verifiable on the CREST directory.
Call to Report Delivery
From initial scoping call to your initial report in as little as two weeks. Timeline scales to meet PSN renewal and GovAssure submission cycles.
Verified
ITHC Pricing by Organisation Type
Fixed-price quotes based on estate scope, benchmarked against the standard commercial rates in our penetration testing cost guide. Bring your IP range count and we will provide a precise quote within 48 hours.
All quotes are fixed-price with no hourly overruns. Request a Scoping Call
What You Receive
Every ITHC engagement includes the following deliverables, formatted for both technical teams and accreditor submission.
Reports are delivered via our real-time penetration testing portal with role-based access. Also available in PDF and DOCX formats for accreditor submission.
Between Annual ITHCs,
Stay Protected.
Your ITHC is a point-in-time assessment. Our defensive security services provide continuous monitoring, threat detection, and incident response to maintain your security posture between annual health checks.
Discuss Year-Round SecurityManaged SOC
24/7 threat detection and response from our UK-based Security Operations Centre, monitoring your estate between ITHCs.
Managed Detection and Response
Feed ITHC findings directly into our MDR to create custom detection rules for your specific vulnerabilities.
External Network Penetration Test
Targeted external infrastructure assessment between annual ITHCs for perimeter assurance.
Cloud Security Configuration
Dedicated Azure and AWS configuration review beyond the scope of the standard ITHC cloud assessment.
Full Penetration Testing Catalogue
Comprehensive penetration testing services tailored to your environment.
Internal Testing
Post-perimeter assessments targeting Active Directory, lateral movement, privilege escalation, and segmentation validation from inside your network.
The best time to test your defences is now.
Join the high-growth companies relying on Precursor for continuous offensive and defensive security.
Frequently Asked Questions
Common questions about this service, methodologies, and deliverables.
An IT Health Check (ITHC) is a structured security assessment of an organisation's IT estate, conducted under the NCSC CHECK scheme. It covers internal infrastructure, external perimeter systems, wireless networks, remote access controls, and configuration reviews of key systems. The ITHC is the primary compliance mechanism for organisations connecting to the Public Services Network (PSN) and Health and Social Care Network (HSCN), and provides technical assurance evidence for GovAssure submissions. It is distinct from a commercial penetration test in that it is mandatory for many public sector organisations, conducted by accredited, security-cleared consultants under the CREST, CHECK, or Tiger schemes, and reported in a format accepted by government accreditors. Historically referred to as the CESG IT Health Check before CESG's functions transferred to NCSC.
CREST is an industry certification body covering commercial penetration testing. CHECK (NCSC CHECK scheme) is a UK government scheme operated by the National Cyber Security Centre, mandatory for testing government systems and PSN-connected networks. Key differences: CHECK consultants are individually vetted and hold government security clearance (SC or DV); CHECK methodology is aligned to NCSC requirements; CHECK reports are accepted by the PSN Authority, Cabinet Office, and HSCN accreditors where CREST-only reports are not. If your organisation connects to PSN, GovAssure, or HSCN, or if your contract specifies CHECK-approved testing, you require a CHECK-accredited provider. Precursor delivers ITHC-style assessments as a CREST member firm and partners with CHECK providers where a formal CHECK deliverable is mandated.
GovAssure requires central government departments to submit an annual self-assessment against the NCSC Cyber Assessment Framework (CAF). While the self-assessment is completed internally, it must be supported by independent technical evidence, including the results of a CHECK-accredited security assessment. Our GovAssure-aligned ITHC maps findings to specific CAF objectives (covering 'Managing Security Risk', 'Protecting Against Cyber Attack', 'Detecting Cyber Security Events', and 'Minimising the Impact of Incidents') and provides reporting in the format required to substantiate your CAF self-assessment ratings. We can advise on how to align the ITHC engagement timeline with your annual GovAssure submission cycle.
Yes. We have delivered ITHC assessments for NHS Trusts and health sector organisations with HSCN connectivity. Our assessments scope the HSCN connection boundary as well as relevant internal systems, with testing protocols designed to avoid disruption to live clinical services. Findings are mapped to NHS Data Security and Protection Toolkit (DSPT) requirements where applicable, supporting your annual DSPT submission. If you are uncertain whether a full CHECK ITHC or a targeted network assessment is required for your specific HSCN compliance obligations, we provide pre-scoping advisory at no charge.
The Public Services Network (PSN) is the UK government's secure network infrastructure. Organisations that connect to PSN (including local authorities, police forces, fire services, and NHS bodies) must maintain a Code of Connection (CoCo) that demonstrates their security posture meets PSN Authority requirements. A mandatory element of CoCo compliance is an annual IT Health Check conducted by a provider accredited under the CREST, CHECK, or Tiger scheme. The ITHC demonstrates that your organisation's connected systems do not introduce vulnerabilities to the wider PSN. Without a valid ITHC from an appropriately accredited provider, your PSN Code of Connection cannot be renewed. Loss of PSN connectivity disrupts core public services including revenues and benefits systems, HR, and inter-agency data sharing. We provide end-to-end PSN ITHC services including scope documentation advice, testing, remediation guidance, and final report delivery in the format required by the PSN Authority.



