CREST has announced the launch of its first AI additions to its standards for accredited cybersecurity service providers.
The company said that the first-of-its-kind initiative marks a critical transition for the industry, from voluntary commitments to independently verified standards for AI-enabled cybersecurity services.
Recognised standards
Over three-quarters (76%) of cybersecurity providers have increased their AI usage over the past year, and 69% are already integrating it into daily service delivery, according to CREST’s AI in Penetration Testing report.
However, recognised standards for demonstrating responsible AI use have not kept pace with this change.
As cybersecurity’s premier accrediting authority, CREST is stepping in to address this gap head-on.
The standards provide practical, independently assessable requirements.
These help service providers demonstrate and verify responsible AI usage, both within their businesses and when delivering services.
Applications are now open for both existing CREST members, as well as cybersecurity service providers who wish to obtain additional recognition for the use of AI within their accredited penetration testing services.
The optional AI-Enabled Penetration Testing requirements form part of the CREST Penetration Testing Accreditation Standard and provide independent assurance of responsible AI usage.
“There was no time to waste”
Nick Benson, CEO of CREST explained: “AI adoption is outpacing governance, and we are here to fix that.
“We recognise that buyers are increasingly demanding that AI-enabled services are independently assured.
“In such a fast-moving space, there was no time to waste.
“We believe these new additions to our standards will provide a practical, enforceable framework to regain the market’s trust,” he concluded.
AI assurance and trust
CREST highlighted that trust is becoming a competitive differentiator for providers.
Buyers, regulators and procurement teams are demanding greater accountability and independent evidence.
Given the high-stakes nature of the industry, unverified claims are no longer sufficient.
The industry now needs assurance that AI-enabled services are secure, transparent and professionally governed.
Unlike voluntary agreements, the company said that this formal accreditation integrates directly into CREST’s existing complaints and discipline processes.
This allows CREST to take action and enforce compliance across the ecosystem.
“A consistent answer to AI governance”
Chris Oakley, SVP Assurance Services (Americas), LRQA Cybersecurity, a US-based CREST member stated: “In the US, we’ve seen regulators and auditors quickly move from asking, “is AI used?” to, “how is AI governed?”; there’s already an assumption that AI is playing a role.
“CREST’s new AI standards are based on the collective experience of cyber-industry leaders and provide a consistent answer to AI governance in cybersecurity.”
“Effective, fair and transparent”
Sanjay Verma, Managing Director, CyberZone Global, an Australia-based CREST member, said: “AI-enabled cybersecurity must be not only innovative, but also effective, fair and transparent.
“These principles are increasingly central to responsible AI governance globally and align with the intent of ISO/IEC 42001 (Artificial Intelligence Management System).
Verma continued: “These new CREST AI standards can translate them into practical, independently assessed expectations for providers.”
“A critical time”
William Wright, CEO, Closed Door Security, a Dubai-based CREST member, said: “CREST’s new standard comes at a critical time as organisations are becoming increasingly dependent on AI.
“Advanced AI systems are steadily moving towards becoming critical infrastructure, and it is essential that organisations are confident in the security surrounding them.
“With them now being adopted to support security operations and to identify and remediate vulnerabilities, they require a framework approach for responsible usage that this new standard brings,” Wright concluded.

