We are committed to raising the standards of the cyber security industry and building trust between service providers and their clients. By publishing our accreditation standards, we aim to increase transparency for organisations seeking accreditation and provide clear insight into the assurance activities we conduct.
This transparency helps organisations better understand the requirements and processes involved in achieving accreditation, enabling them to prepare effectively. For buyers of cyber security services, it offers valuable information about how providers are assessed, increasing their confidence in selecting accredited organisations.
This initiative supports our mission to set global standards, promote consistent quality in cyber security services, and strengthen trust across the industry.
Our accreditation standards directly address challenges in the cyber security industry by:
CREST publishes accreditation standards covering the organisational and service-specific requirements applicable to accredited providers.
Organisational requirements:
CREST Accreditation Standard – Company General Requirements (including Responsible AI Use)
Service-specific standards:
Supplementary annexes:
We continually review and develop our published accreditation standards to reflect changes in professional practice, technology and market expectations.
There is no mandatory requirement for individuals to be CREST qualified for a company to achieve accreditation, instead individuals are assessed based on their skills and experience or any qualifications they may hold. CREST seeks to ensure the team is sufficiently staffed with people with suitable levels of knowledge and competence.
To download our standards you will need to complete a short form and once completed, the standards will be emailed to you. Click the button below to get started. Or contact us today.