Skip to main content
CybersecurityHacking

CREST Unveils AI Standards for Secure Pentesting Accreditation

Modern lab with computer equipment and large screen displaying code or network diagram, with a professional nearby.

"We recognize that buyers are increasingly demanding that AI-enabled services are independently assured. We believe these new additions to our standards will provide a practical, enforceable framework to regain the market’s trust," said Nick Benson, CEO of CREST.

What CREST has launched and how it fits into existing rules

On July 28, CREST unveiled an optional AI-Enabled Penetration Testing module that is integrated into its existing Penetration Testing Accreditation Standard. The new module is an add-on set of requirements intended for cybersecurity service providers that actively integrate AI into their operations and service delivery. CREST says the module provides independent assurance of responsible AI usage without altering standard CREST memberships; instead, it offers an extra layer of formal recognition for those that choose to pursue it.

Why CREST moved now: usage trends and prior publications

The module follows research and policy work CREST carried out earlier in the year. In March, CREST released an AI in Penetration Testing report that found 76% of cybersecurity providers had increased AI usage over the previous year and that 69% were already integrating AI into daily service delivery. That report prompted CREST to publish a set of AI Principles in March and, subsequently, an AI Charter in June that was publicly signed by over 100 cybersecurity organizations. CREST’s AI Working Group developed the additional standards and will continue to evolve them, the organization said.

How accreditation will be enforced

Benson underlined a governance distinction between voluntary statements and CREST’s formal accreditation. He said the accreditation is not merely a voluntary agreement: “Unlike voluntary agreements, this formal accreditation integrates directly into CREST’s existing complaints and discipline processes. This allows CREST to take action and enforce compliance across the ecosystem.” At the time of launch, no organization had yet been accredited under the new module; CREST expects the first accredited organization to appear within the next month.

Industry reactions: LRQA Cybersecurity and Closed Door Security

Responses from CREST members highlighted two themes: the need for consistent AI governance and the growing operational role of AI. Chris Oakley, SVP of assurance services for the Americas at LRQA Cybersecurity, a US-based CREST member, said the standards are based on collective industry experience and “provide a consistent answer to AI governance in cybersecurity.” William Wright, CEO of Closed Door Security, a Dubai-based CREST member, described the timing as critical: “Advanced AI systems are steadily moving towards becoming critical infrastructure, and it is essential that organizations are confident in the security surrounding them. With them now being adopted to support security operations and to identify and remediate vulnerabilities, they require a framework approach for responsible usage that this new standard brings.”

What this means for cybersecurity providers, buyers, and regulators

  • Cybersecurity providers: Existing CREST members and other service providers can now apply for the optional AI-Enabled Penetration Testing accreditation to demonstrate independent assessment of AI governance and practices within their accredited penetration testing services.
  • Buyers and clients: CREST frames the standard as a response to buyer demand for independent assurance of AI-enabled services — a demand CREST’s CEO explicitly cited when announcing the module.
  • Regulators and accountability mechanisms: Because the module integrates into CREST’s complaints and discipline framework, accredited firms will be subject to the same enforcement processes CREST applies elsewhere, potentially giving regulators and procurement officials a verifiable signal about an accredited provider’s AI governance.

CREST’s new optional module seeks to convert rapid AI adoption into demonstrable governance. Applications are open now, the AI Working Group will continue evolving the requirements, and the industry body expects its first accreditation under the module within the month following the July 28 launch — a near-term milestone that will test whether the framework delivers the enforceable assurance CREST says clients and regulators want.

Original story