Artificial intelligence is rapidly reshaping how cybersecurity services are designed and delivered. From penetration testing and vulnerability analysis to reporting and workflow automation, AI is already becoming part of everyday security practice. But how can providers demonstrate that they are using it responsibly?
Today, CREST is taking the next step in its AI programme with the launch of its first accreditation for AI-enabled cybersecurity services, giving service providers a practical framework for demonstrating responsible AI use within accredited cyber security services through independent assessment.
The new accreditation is underpinned by additions to our standards that have been developed with our AI Working Group. This builds on the foundations established by the CREST AI Charter and CREST’s industry-backed 9 Principles for AI in Cybersecurity, and moves the industry from voluntary commitments, towards independently verifiable assurance.
The pace of AI adoption across the cybersecurity profession has accelerated significantly over the past year.
CREST’s recent research found that 69% of penetration testing providers already use AI, while 76% have increased their use over the past 12 months. At the same time, 85% expect clients to demand greater transparency about how AI is being used within cybersecurity engagements.
These findings highlight a clear shift in market expectations.
Clients, regulators and procurement teams increasingly want independent evidence that AI-enabled cybersecurity services are secure, transparent and professionally governed. Service providers can no longer rely solely on claims about AI capability – they need recognised ways to demonstrate responsible practice.
Introducing CREST’s new AI accreditation
From today, 28 July 2026, cybersecurity service providers will be able to apply to have their use of AI within their service provision independently assured by CREST as part of our accreditation process using two new additions to CREST’s Accreditation Standards.
Company General Requirements (Domain 7 – Responsible AI Use)
This new domain within the requirements that CREST sets for all service providers covers the governance, oversight, transparency and responsible organisational use of AI by the service provider.
Penetration Testing Accreditation Standard (Annex B – AI-Enabled Penetration Testing)
This new annex to CREST’s Penetration Testing Standard introduces requirements for service providers using AI within penetration testing, helping ensure AI enhances professional judgement while maintaining the quality, integrity and trust expected of CREST-accredited services.
Together, these additions provide practical, independently assessable requirements that demonstrate responsible AI use within accredited cybersecurity services.
The launch of these standards represents the first phase of CREST’s AI accreditation programme. In the near future, CREST will open applications for a further accreditation:
Security Testing of AI
This new framework provides technology-agnostic requirements for organisations testing AI-enabled systems themselves.
While the additions to the Penetration Testing standard focus on how cybersecurity providers use AI responsibly to enable and enhance their services, this additional accreditation extends assurance to the security testing of AI technologies, recognising the growing need for trusted evaluation of AI-enabled systems across industry.
Thereafter, and as AI continues to transform cybersecurity, CREST will continue working with industry, governments, regulators and practitioners to ensure standards evolve alongside technology, helping service providers and developers innovate responsibly while maintaining trust, transparency and professional excellence.
The launch of these additions to CREST’s accreditation products reflects a broader shift taking place across the cybersecurity market.
As AI becomes embedded in professional practice, trust is increasingly becoming a competitive differentiator.
Independent accreditation enables organisations to:
Chris Oakley, SVP Assurance Services (Americas), LRQA Cybersecurity, a US-based CREST member, said: “In the US, we’ve seen regulators and auditors quickly move from asking, “is AI used?” to, “how is AI governed?”; there’s already an assumption that AI is playing a role. CREST’s new AI standards are based on the collective experience of cyber industry leaders and provide a consistent answer to AI governance in cybersecurity.”
Sanjay Verma, Managing Director, CyberZone Global, an Australia-based CREST member, said: “AI-enabled cybersecurity must be not only innovative, but also effective, fair and transparent. These principles are increasingly central to responsible AI governance globally and align with the intent of ISO/IEC 42001 (Artificial Intelligence Management System). These new CREST AI standards can translate them into practical, independently assessed expectations for providers.”
William Wright, CEO, Closed Door Security, a Dubai-based CREST member, said: “CREST’s new standard comes at a critical time as organisations are becoming increasingly dependent on AI. Advanced AI systems are steadily moving towards becoming critical infrastructure, and it is essential that organisations are confident in the security surrounding them. With them now being adopted to support security operations and to identify and remediate vulnerabilities, they require a framework approach for responsible usage that this new standard brings.”
Applications for the first AI standards are now open.
Service providers wishing to become part of the founding accreditation cohort will have the opportunity to help shape the future evolution of AI assurance while demonstrating leadership in trusted AI-enabled cybersecurity.
Further details are available via the CREST AI Hub.