“helping security teams work more efficiently at scale, and identify vulnerabilities faster.” — William Wright
CREST's AI-Enabled Penetration Testing accreditation (July 2026)
In July 2026, CREST integrated a new optional module into its existing Penetration Testing Accreditation Standard to recognise responsible use of artificial intelligence within penetration testing services. The module enables providers that actively integrate AI into daily operations to undergo independent assessment and "formally demonstrate responsible, secure AI governance" to clients and regulators. CREST said the module will not affect standard memberships; rather, it offers an avenue for firms using AI to verify practices and earn "an extra layer of trusted assurance."
The first cohort: ten accredited providers
- Closed Door Security Ltd
- ImmuniWeb
- JUMPSEC Ltd
- Packetlabs
- Pentesys
- REDSECLABS Private Ltd
- Risk Associates
- SECNORA OÜ
- Solusec Ltd
- Thoropass Inc.
CREST granted the newly established AI-Enabled Penetration Testing accreditation to these ten companies as the organisation's "first cohort" of accredited providers spanning Europe, India and the United States.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleIndustry voices: Closed Door Security, Packetlabs, and CREST leadership
William Wright, CEO of Closed Door Security, emphasised the operational benefits and governance needs when he said AI is "helping security teams work more efficiently at scale, and identify vulnerabilities faster." Wright added that AI "needs to be governed appropriately" and that Closed Door Security is "proud to be part of the first CREST cohort to be accredited for AI-Enabled Penetration Testing."
Denis Kucinic, VP Operations at Packetlabs, said, "AI will be revolutionary for security providers like Packetlabs, but it's vital that we assure customers, and the wider industry, that it's being deployed and used responsibly." He called accreditation providers such as CREST a way for companies to turn voluntary promises into "concrete assurance" through "independent and assessable standards."
Nick Benson, CEO of CREST, framed the module as a shift in approach: the AI additions help the cybersecurity industry "move from discussion and principles around AI towards independently assured, responsible adoption."
CREST's March report, AI Principles, and June Charter
The AI-Enabled Penetration Testing module follows CREST's March 2026 report, "AI in Penetration Testing." That report found that over three-quarters (76%) of cybersecurity providers increased their AI usage over the prior year, and that 69% were already integrating AI into daily service delivery. CREST used the report's findings to publish a set of AI Principles in March and then an AI Charter in June; the Charter was "publicly signed by over 100 cybersecurity organizations."
What this means for technologists, procurement leaders, and regulators
- Technologists and security teams: CREST's accreditation offers a formal route to validate internal AI governance and to align operational AI use with an independent assessment. Providers that already use AI daily can now "undergo independent assessment" and signal that their practices meet an externally judged standard.
- Procurement and enterprise buyers: The optional module gives clients a concrete assurance mechanism — an "extra layer of trusted assurance" — to compare vendors that deploy AI in testing and to request demonstrable governance rather than rely solely on vendors' voluntary claims.
- Regulators and oversight bodies: By enabling providers to "formally demonstrate responsible, secure AI governance," the accreditation creates a documented, assessable trail that regulators can reference when considering how AI is being operationalised in penetration testing services.
CREST's action turns a conversation that began with a March report and a set of published principles into a practical accreditation pathway. The organisation and the first cohort frame the change as moving from theory to demonstrable practice: providers can show customers and regulators that AI is being used, and assessed, under defined rules. Whether the new module will scale beyond the initial ten accredited firms, how quickly other providers will seek accreditation, and how clients will incorporate accreditation status into procurement decisions are tangible, near-term questions left on the table as the industry tests this new assurance mechanism.




