The cybersecurity industry is undergoing significant changes as the newly established accreditation for AI-Enabled Penetration Testing is now available, granted by CREST, the prominent industry body. This groundbreaking step has already seen ten companies achieve this accreditation, a move that recognizes and endorses the responsible usage of artificial intelligence within penetration testing services.
This AI-Enabled Penetration Testing accreditation module, set to be integrated into CREST’s existing Penetration Testing Accreditation Standard by July 2026, marks a pivotal shift in how penetration testing services leverage AI technologies. Encompassing a diverse range of firms worldwide, the first cohort of accredited providers includes companies from Europe, India, and the United States. Among them are notable names such as Closed Door Security Ltd, ImmuniWeb, JUMPSEC Ltd, Packetlabs, Pentesys, REDSECLABS Private Ltd, Risk Associates, SECNORA OÜ, Solusec Ltd, and Thoropass Inc.
With the introduction of this new module, accredited providers that actively incorporate AI into their operations can now undergo an independent assessment to affirm their commitment to responsible and secure AI governance. This accreditation serves as a formal recognition of their skills and adherence to the highest standards, offering clients and regulators an assurance of the integrity of their practices while using AI technology. While this new accreditation will not impact standard memberships, it provides an avenue for those using AI to externally verify their methodologies, thus gaining an additional layer of trusted assurance in an increasingly complex digital landscape.
One prominent voice in this transition is William Wright, the CEO of Closed Door Security, a member of CREST based in the UK and UAE. Wright highlights the profound influence that AI can have on penetration testing, expressing that it allows security teams to operate more efficiently, scale their capabilities, and identify vulnerabilities with greater speed. However, he emphasizes the necessity for appropriate governance surrounding AI technologies. Closed Door Security is proud to be among the first CREST members to gain this prestigious accreditation, underscoring their commitment to ensuring that AI is adopted in a manner that genuinely enhances organizational security.
Echoing these sentiments, Denis Kucinic, VP of Operations at Packetlabs, a Canada-based CREST member, acknowledges the transformational potential of AI for security firms. He stresses the importance of assuring clients and the broader industry that AI is being utilized responsibly. Kucinic points out that accreditation bodies like CREST play a crucial role in this regard. By establishing independent and assessable standards, organizations can substantiate their voluntary commitments to responsible AI deployment.
CREST’s CEO, Nick Benson, views the introduction of AI standards within the accreditation framework as a vital progression. He notes that it allows the cybersecurity sector to transition from merely discussing AI and its principles to establishing an environment of independently assured and responsible adoption of AI technologies.
Moreover, the launch of the AI-Enabled Penetration Testing accreditation follows the earlier release of CREST’s comprehensive report on AI in Penetration Testing in March 2026. This report revealed compelling statistics: more than three-quarters, or 76%, of cybersecurity providers indicated a significant increase in their usage of AI within the past year. Additionally, 69% reported that they are already integrating AI into their daily service offerings.
The insights from this report prompted CREST to publish a detailed set of AI Principles in March and an accompanying AI Charter in June. The Charter has gained widespread endorsement, with over 100 cybersecurity organizations lending their signatures to this cause, highlighting the sector’s unified approach toward responsible AI usage.
In the landscape of cybersecurity, where risks are ever-evolving, the push for transparent and accountable AI adoption is paramount. The new accreditation not only sets a standard for excellence but also fosters a culture of trust and assurance in the use of AI technologies. As organizations continue to embrace these advancements, the importance of responsible governance becomes increasingly critical in safeguarding the data and systems that underpin modern society.
The accreditation is a significant step toward ensuring that AI’s integration into cybersecurity remains beneficial, effective, and aligned with the core values of security and integrity. Thus, CREST and its accredited members pave the way for a future where AI serves not only as a tool for advancement but as a responsible partner in the ever-vigilant fight against cyber threats.

