cd /news/ai-policy/crest-opens-accreditation-for-ai-ena… · home topics ai-policy article
[ARTICLE · art-79097] src=letsdatascience.com ↗ pub= topic=ai-policy verified=true sentiment=· neutral

CREST Opens Accreditation for AI-Enabled Cybersecurity Services

CREST opened applications on July 28 for accreditation of AI-enabled cybersecurity services, backed by a new responsible-AI domain in its company requirements and an AI-enabled penetration-testing annex. The additions let providers seek independent assessment of governance, data protection and human oversight; a separate framework for testing the security of AI systems is planned but is not yet open.

read3 min views1 publishedJul 29, 2026
CREST Opens Accreditation for AI-Enabled Cybersecurity Services
Image: Letsdatascience (auto-discovered)

CREST opened applications on July 28 for accreditation of AI-enabled cybersecurity services, backed by a new responsible-AI domain in its company requirements and an AI-enabled penetration-testing annex. The additions let providers seek independent assessment of governance, data protection and human oversight; a separate framework for testing the security of AI systems is planned but is not yet open.

CREST opened applications on July 28 for its first accreditation covering AI-enabled cybersecurity services. The program is underpinned by two additions to its existing accreditation standards: Domain 7, Responsible AI Use, in the Company General Requirements and Annex B, AI-Enabled Penetration Testing, in the Penetration Testing Accreditation Standard.

The distinction matters. The current accreditation evaluates how service providers use AI in their own cybersecurity delivery. CREST says a separate, technology-agnostic framework for organizations that test the security of AI-enabled systems is planned for a later phase and is not yet open.

What applicants must demonstrate

Domain 7 covers organization-wide governance, oversight, transparency and responsible AI use. The penetration-testing annex adds service-specific requirements intended to keep AI use within the quality and professional-judgment expectations of CREST-accredited work.

IT Europa reports that applicants must show that material AI uses are approved and controlled, client and sensitive information is protected, and appropriate human oversight is retained. For penetration-testing engagements, assessment also covers how AI fits into the methodology, stays inside the agreed scope and rules of engagement, controls offensive content, and supports review of machine-assisted findings by competent personnel.

Jonathan Armstrong, CREST's head of product, told IT Europa that attestations are checked against supporting evidence. Examples can include policies, testing methodologies, technical controls, redacted engagement records, AI-assisted analysis, quality-assurance notes and final customer reports. CREST may request further evidence or corrective action when an applicant has not demonstrated compliance.

Infosecurity Magazine describes the requirements as optional additions for providers that want to demonstrate responsible AI use. CREST's public standards page lists the AI-enabled penetration-testing annex as supplementary to its existing penetration-testing standard rather than a replacement for the underlying accreditation.

Why CREST added the controls

CREST says its research found that 69% of surveyed penetration-testing providers already use AI, 76% had increased use during the preceding year, and 85% expected clients to demand more transparency about AI in cybersecurity engagements. Those are survey results from CREST's own research, not market-wide adoption measurements.

For buyers and risk teams, the practical change is an evidence-based assurance route. The requirements turn broad responsible-AI principles into assessable controls around approval, data handling, engagement boundaries, review and accountability. They do not establish that an accredited provider's AI tools are error-free, nor do they certify the security of a customer's AI system under the future framework.

Key Points #

  • 1CREST's July 28 launch adds organization-wide responsible-AI requirements and a supplementary annex for AI-enabled penetration-testing delivery.
  • 2Applicants must support governance, data protection, engagement boundaries and human review with evidence rather than relying on attestations alone.
  • 3The current accreditation covers providers' use of AI; CREST says a separate framework for testing AI-enabled systems will open later.

Scoring Rationale #

The accreditation translates responsible-AI principles into assessable controls for a sensitive cybersecurity service category. It is directly relevant to security providers, buyers and risk teams, while its optional scope and focus on assurance rather than a new technical capability keep the impact below the highest band.

Sources #

Primary source and supporting public references used for this report.

Practice interview problems based on real data

1,625 SQL & Python problems across 15 industry datasets — the exact type of data you work with.

Try 250 free problems

── more in #ai-policy 4 stories · sorted by recency
── more on @crest 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/crest-opens-accredit…] indexed:0 read:3min 2026-07-29 ·