CREST has introduced an optional AI-Enabled Penetration Testing accreditation module designed to verify responsible AI usage among cybersecurity service providers. Launched on July 28, the new standard integrates into CREST's existing Penetration Testing Accreditation Standard and allows providers who actively use AI in their operations to undergo independent assessment. Applications are now open for existing CREST members seeking additional recognition for AI-enabled penetration testing services.
The initiative responds to rapid AI adoption across the cybersecurity industry. A CREST report from March found that 76% of cybersecurity providers increased their AI usage over the past year, with 69% already integrating AI into daily service delivery. This widespread adoption prompted CREST to develop AI Principles in March and an AI Charter in June, which over 100 cybersecurity organizations have signed.
The accreditation provides independent assurance of responsible AI governance and integrates directly into CREST's existing complaints and discipline processes. Unlike voluntary agreements, this formal accreditation allows CREST to enforce compliance across its membership. The standards were developed by CREST's AI Working Group and will continue to be refined as the technology and its applications develop.
CREST CEO Nick Benson stated the initiative addresses a market gap where AI adoption has outpaced governance frameworks. He noted that buyers increasingly demand independent assurance for AI-enabled services, and the new standard provides an enforceable framework to restore market confidence. While no organizations have received the accreditation at launch, CREST expects the first certified provider within a month.
Cybersecurity professionals should monitor which service providers obtain this accreditation when evaluating penetration testing vendors. Organizations using or planning to use AI-enabled security services should consider whether their providers meet these standards. CREST members interested in the accreditation can apply through the organization's existing certification processes, with the module serving as an optional add-on to standard penetration testing credentials.
Source: https://www.infosecurity-magazine.com/news/crest-ai-pentesting-accreditation/


