Login to profile

Our Accreditation Standards

Our standards

We are committed to raising the standards of the cyber security industry and building trust between service providers and their clients. By publishing our accreditation standards, we aim to increase transparency for organisations seeking accreditation and provide clear insight into the assurance activities we conduct.

This transparency helps organisations better understand the requirements and processes involved in achieving accreditation, enabling them to prepare effectively. For buyers of cyber security services, it offers valuable information about how providers are assessed, increasing their confidence in selecting accredited organisations.

This initiative supports our mission to set global standards, promote consistent quality in cyber security services, and strengthen trust across the industry.

Benefits of the standards

Our accreditation standards directly address challenges in the cyber security industry by: 

  • Fostering international collaboration: bringing together global expertise to create excellence in cyber security practices and enhance alignment worldwide.
  • Increasing transparency and building capacity: offering publicly available best practices to support cyber security providers across all maturity levels.
  • Setting a benchmark of excellence: establishing our accreditations as a global reference point for high-quality cyber security services.

Available standards

CREST publishes accreditation standards covering the organisational and service-specific requirements applicable to accredited providers.

Organisational requirements:

CREST Accreditation Standard – Company General Requirements (including Responsible AI Use)

Service-specific standards:

  • Cyber Threat Intelligence
  • Incident Exercising
  • Incident Response
  • Penetration Testing
  • Security Architecture
  • Security Operations
  • Threat Intelligence for Simulated Attacks
  • Threat-led Penetration Testing
  • Vulnerability Assessment

Supplementary annexes:

  • AI-Enabled Penetration Testing Annex (contained within the CREST Penetration Testing Accreditation Standard)

We continually review and develop our published accreditation standards to reflect changes in professional practice, technology and market expectations.

There is no mandatory requirement for individuals to be CREST qualified for a company to achieve accreditation, instead individuals are assessed based on their skills and experience or any qualifications they may hold. CREST seeks to ensure the team is sufficiently staffed with people with suitable levels of knowledge and competence.

Download the standards

To download our standards you will need to complete a short form and once completed, the standards will be emailed to you. Click the button below to get started. Or contact us today.

Download our accreditation standards
Download our accreditation standards