CREST has launched the cybersecurity industry’s first AI accreditation additions for accredited cybersecurity service providers, introducing independently verified standards for the responsible use of artificial intelligence in cybersecurity services.
The initiative marks a significant shift from voluntary AI commitments to formal, independently assessed standards, helping organisations demonstrate responsible AI governance in AI-enabled penetration testing and other cybersecurity services.
According to CREST’s AI in Penetration Testing report, 76% of cybersecurity providers have increased their AI usage over the past year, while 69% are already integrating AI into daily service delivery. However, recognised standards for verifying responsible AI adoption have not kept pace with this rapid growth.
The optional AI-Enabled Penetration Testing requirements have been incorporated into the CREST Penetration Testing Accreditation Standard, providing organisations with an independently verifiable framework for responsible AI use. The accreditation also integrates with CREST’s existing complaints and disciplinary processes, enabling accountability and enforcement across the cybersecurity ecosystem.
CREST said the standards were developed in collaboration with industry stakeholders and build on the organisation’s AI Charter and AI Principles launched earlier this year. Applications are now open for both existing CREST members and cybersecurity service providers seeking accreditation for AI-enabled penetration testing services.
The organisation noted that the initiative comes as regulators, procurement teams and customers increasingly demand independent assurance that AI-powered cybersecurity services are secure, transparent and governed by recognised standards.
