CREST Launches World’s First Accredited AI Standards for Cybersecurity Service Providers
The first-of-its-kind initiative marks a critical transition for the industry, from voluntary commitments to independently verified standards for AI-enabled cybersecurity services.
CREST, the leading international non-profit representing the global cybersecurity industry, announces the launch of its first AI additions to its standards for accredited cybersecurity service providers. The first-of-its-kind initiative marks a critical transition for the industry, from voluntary commitments to independently verified standards for AI-enabled cybersecurity services.
Over three-quarters (76%) of cybersecurity providers have increased their AI usage over the past year, and 69% are already integrating it into daily service delivery, according to CREST’s AI in Penetration Testing report. However, recognised standards for demonstrating responsible AI use have not kept pace with this change.
As cybersecurity’s premier accrediting authority, CREST is stepping in to address this gap head-on. The standards provide practical, independently assessable requirements. These help service providers demonstrate and verify responsible AI usage, both within their businesses and when delivering services.
Applications are now open for both existing CREST members, as well as cybersecurity service providers who wish to obtain additional recognition for the use of AI within their accredited penetration testing services.
The optional AI-Enabled Penetration Testing requirements form part of the CREST Penetration Testing Accreditation Standard and provide independent assurance of responsible AI usage.
“AI adoption is outpacing governance, and we are here to fix that. We recognise that buyers are increasingly demanding that AI-enabled services are independently assured. In such a fast-moving space, there was no time to waste. We believe these new additions to our standards will provide a practical, enforceable framework to regain the market’s trust.”
– Nick Benson, CEO, CREST
Trust is becoming a competitive differentiator for providers. Buyers, regulators, and procurement teams are demanding greater accountability and independent evidence. Given the high-stakes nature of the industry, unverified claims are no longer sufficient. The industry now needs assurance that AI-enabled services are secure, transparent, and professionally governed.
Unlike voluntary agreements, this formal accreditation integrates directly into CREST’s existing complaints and discipline processes. This allows CREST to take action and enforce compliance across the ecosystem.
Chris Oakley, SVP Assurance Services (Americas), LRQA Cybersecurity, a US-based CREST member, said: “In the US, we’ve seen regulators and auditors quickly move from asking, “is AI used?” to, “how is AI governed?”; there’s already an assumption that AI is playing a role. CREST’s new AI standards are based on the collective experience of cyber industry leaders and provide a consistent answer to AI governance in cybersecurity.”
“CREST’s new standard comes at a critical time as organisations are becoming increasingly dependent on AI. Advanced AI systems are steadily moving towards becoming critical infrastructure, and it is essential that organisations are confident in the security surrounding them. With them now being adopted to support security operations and to identify and remediate vulnerabilities, they require a framework approach for responsible usage that this new standard brings.”
– William Wright, CEO, Closed Door Security, a Dubai-based CREST member
CREST developed these standards in collaboration with the industry and will continue to refine them through its AI Working Group.
The standards follow the launch of CREST’s industry-backed AI Charter and AI Principles in June. A global cohort of more than 100 founding signatory cybersecurity organisations – including more than 10% of CREST’s worldwide membership – publicly committed to supporting the responsible use of AI across industry services.
Existing CREST Members and cybersecurity service providers are now invited to apply for this new accreditation, or download the CREST Accreditation Standards to learn more.
It is worth mentioning that CREST has been appointed by NATO as an Implementing Agent to support cybersecurity capability building across partner nations. The collaboration will focus on strengthening cyber resilience, improving assurance, and developing sustainable workforce capability at a national level.

