CREST creates AI accreditation for penetration testing services
Global cybersecurity accreditation body CREST has introduced new artificial intelligence (AI) accreditation standards for cybersecurity service providers, becoming one of the first organizations to offer independently verified requirements for the responsible use of AI in penetration testing.
The new AI-enabled penetration testing standards are designed to assist accredited cybersecurity firms demonstrate that AI is being used securely, transparently and under appropriate governance. Applications for the optional accreditation are now open to existing CREST members and other cybersecurity providers seeking recognition for AI-enabled penetration testing services.
The move comes as AI adoption accelerates across the cybersecurity industry. According to CREST’s latest research, 76% of cybersecurity providers have increased their use of AI over the past year, while 69% now use the technology in their day-to-day service delivery. However, industry standards for verifying responsible AI use have not kept pace.
CREST Chief Executive Officer Nick Benson said the rapid adoption of AI has created an urgent need for stronger governance and independent assurance.
“AI adoption is outpacing governance. Organizations increasingly want proof that AI-enabled cybersecurity services are being used responsibly, and these standards provide a practical framework for independent verification,” Benson said.
Unlike voluntary AI commitments, the new accreditation is incorporated into CREST’s existing accreditation, complaints and disciplinary framework, allowing the organization to enforce compliance among accredited providers.
Industry leaders have commended the initiative, saying organizations are increasingly being asked not only whether AI is used, but also how it is governed.
Chris Oakley, Senior Vice President of Assurance Services (Americas) at LRQA Cybersecurity, said regulators and auditors are placing greater emphasis on AI governance, making consistent standards essential for cybersecurity providers.
William Wright, Chief Executive Officer of Closed Door Security, added that as AI becomes more deeply embedded in security operations and vulnerability management, organizations need a structured framework to ensure its responsible use.
CREST said the standards were developed in collaboration with cybersecurity experts through its AI Working Group and are expected to evolve alongside advances in AI technologies.
Download the free Kaspersky SMB Cybersecurity Guide here to learn how businesses can move beyond traditional antivirus and build a more resilient approach to cybersecurity.
Go to TECHTRENDSKE.co.ke for more tech and business news from the African continent and across the world.
Follow us on WhatsApp, Telegram, Twitter, and Facebook, or subscribe to our weekly newsletter to ensure you don’t miss out on any future updates. Send tips to editorial@techtrendsmedia.co.ke


