{"slug": "crest-opens-accreditation-for-ai-enabled-cybersecurity-services", "title": "CREST Opens Accreditation for AI-Enabled Cybersecurity Services", "summary": "CREST opened applications on July 28 for accreditation of AI-enabled cybersecurity services, backed by a new responsible-AI domain in its company requirements and an AI-enabled penetration-testing annex. The additions let providers seek independent assessment of governance, data protection and human oversight; a separate framework for testing the security of AI systems is planned but is not yet open.", "body_md": "# CREST Opens Accreditation for AI-Enabled Cybersecurity Services\n\nCREST opened applications on July 28 for accreditation of AI-enabled cybersecurity services, backed by a new responsible-AI domain in its company requirements and an AI-enabled penetration-testing annex. The additions let providers seek independent assessment of governance, data protection and human oversight; a separate framework for testing the security of AI systems is planned but is not yet open.\n\nCREST opened applications on July 28 for its first accreditation covering AI-enabled cybersecurity services. The program is underpinned by two additions to its existing accreditation standards: **Domain 7, Responsible AI Use**, in the Company General Requirements and **Annex B, AI-Enabled Penetration Testing**, in the Penetration Testing Accreditation Standard.\n\nThe distinction matters. The current accreditation evaluates how service providers use AI in their own cybersecurity delivery. CREST says a separate, technology-agnostic framework for organizations that test the security of AI-enabled systems is planned for a later phase and is not yet open.\n\n### What applicants must demonstrate\n\nDomain 7 covers organization-wide governance, oversight, transparency and responsible AI use. The penetration-testing annex adds service-specific requirements intended to keep AI use within the quality and professional-judgment expectations of CREST-accredited work.\n\nIT Europa reports that applicants must show that material AI uses are approved and controlled, client and sensitive information is protected, and appropriate human oversight is retained. For penetration-testing engagements, assessment also covers how AI fits into the methodology, stays inside the agreed scope and rules of engagement, controls offensive content, and supports review of machine-assisted findings by competent personnel.\n\nJonathan Armstrong, CREST's head of product, told IT Europa that attestations are checked against supporting evidence. Examples can include policies, testing methodologies, technical controls, redacted engagement records, AI-assisted analysis, quality-assurance notes and final customer reports. CREST may request further evidence or corrective action when an applicant has not demonstrated compliance.\n\nInfosecurity Magazine describes the requirements as optional additions for providers that want to demonstrate responsible AI use. CREST's public standards page lists the AI-enabled penetration-testing annex as supplementary to its existing penetration-testing standard rather than a replacement for the underlying accreditation.\n\n### Why CREST added the controls\n\nCREST says its research found that 69% of surveyed penetration-testing providers already use AI, 76% had increased use during the preceding year, and 85% expected clients to demand more transparency about AI in cybersecurity engagements. Those are survey results from CREST's own research, not market-wide adoption measurements.\n\nFor buyers and risk teams, the practical change is an evidence-based assurance route. The requirements turn broad responsible-AI principles into assessable controls around approval, data handling, engagement boundaries, review and accountability. They do not establish that an accredited provider's AI tools are error-free, nor do they certify the security of a customer's AI system under the future framework.\n\n## Key Points\n\n- 1CREST's July 28 launch adds organization-wide responsible-AI requirements and a supplementary annex for AI-enabled penetration-testing delivery.\n- 2Applicants must support governance, data protection, engagement boundaries and human review with evidence rather than relying on attestations alone.\n- 3The current accreditation covers providers' use of AI; CREST says a separate framework for testing AI-enabled systems will open later.\n\n## Scoring Rationale\n\nThe accreditation translates responsible-AI principles into assessable controls for a sensitive cybersecurity service category. It is directly relevant to security providers, buyers and risk teams, while its optional scope and focus on assurance rather than a new technical capability keep the impact below the highest band.\n\n## Sources\n\nPrimary source and supporting public references used for this report.\n\nPractice interview problems based on real data\n\n1,625 SQL & Python problems across 15 industry datasets — the exact type of data you work with.\n\n[Try 250 free problems](/problems)", "url": "https://wpnews.pro/news/crest-opens-accreditation-for-ai-enabled-cybersecurity-services", "canonical_source": "https://letsdatascience.com/news/crest-adds-ai-penetration-testing-accreditation-a8c72931", "published_at": "2026-07-29 14:02:23+00:00", "updated_at": "2026-07-29 18:33:45.143234+00:00", "lang": "en", "topics": ["ai-policy", "ai-ethics", "ai-safety"], "entities": ["CREST", "Jonathan Armstrong", "IT Europa", "Infosecurity Magazine"], "alternates": {"html": "https://wpnews.pro/news/crest-opens-accreditation-for-ai-enabled-cybersecurity-services", "markdown": "https://wpnews.pro/news/crest-opens-accreditation-for-ai-enabled-cybersecurity-services.md", "text": "https://wpnews.pro/news/crest-opens-accreditation-for-ai-enabled-cybersecurity-services.txt", "jsonld": "https://wpnews.pro/news/crest-opens-accreditation-for-ai-enabled-cybersecurity-services.jsonld"}}