London: TECHz – News Desk
Global cybersecurity accreditation body CREST has introduced what it describes as the world’s first independently accredited AI standards for cybersecurity service providers, marking a significant step toward establishing verifiable governance for the use of artificial intelligence in professional security services.
The newly launched AI-Enabled Penetration Testing accreditation extends CREST’s existing Penetration Testing Accreditation Standard with AI-specific requirements. Rather than relying on voluntary AI pledges or self-assessments, the new framework enables cybersecurity providers to undergo an independent assessment demonstrating that AI is being deployed responsibly, securely, and under appropriate governance when delivering penetration testing services.
According to CREST, the accreditation is available both to existing CREST members and to cybersecurity service providers seeking independent recognition of their AI-enabled security capabilities. The standards are designed to provide assurance to enterprise customers, regulators, and procurement teams that AI-assisted cybersecurity services meet independently validated professional and technical requirements.
The launch follows CREST’s earlier research into AI adoption within penetration testing, which found that AI is increasingly being integrated into activities such as reconnaissance, reporting, and analysis, while experienced security professionals continue to oversee critical decision-making and higher-risk testing activities. The findings highlighted the growing need for consistent governance and industry-wide standards as AI becomes embedded in cybersecurity workflows.
CREST says its broader AI programme is built around four pillars: standards, assurance, research, and industry collaboration. Through its AI Hub and AI Charter initiatives, the organisation aims to help cybersecurity providers, buyers, and policymakers navigate AI adoption with greater transparency, accountability, and trust.
The organisation believes independently assessable AI standards will become increasingly important as organisations seek objective evidence that cybersecurity providers are using AI responsibly while maintaining the quality, integrity, and security of their services.


