HomeRisk ManagementsNew CREST AI Standards for AI-Enabled Pentesting Accreditation

New CREST AI Standards for AI-Enabled Pentesting Accreditation

Published on

spot_img

The cybersecurity industry body CREST has announced the introduction of new standards aimed at accrediting AI penetration testing services, marking a significant development within the domain of cybersecurity. This initiative, revealed on July 28, 2023, is designed to cater to the increasing demand for responsible AI use in the sector. The new accreditation requirements serve as optional add-ons for cybersecurity service providers keen to demonstrate their commitment to ethical AI usage, both internally and while delivering client services.

The AI-Enabled Penetration Testing requirements represent a novel module that integrates seamlessly with CREST’s existing Penetration Testing Accreditation Standard. This move allows accredited providers who leverage AI technologies within their operational frameworks to undergo an independent assessment. By doing so, they can formally showcase their adherence to responsible and secure AI governance—an aspect that is increasingly becoming a priority for clients and regulatory bodies alike.

Importantly, this new module does not alter standard membership terms; instead, it offers a pathway for providers utilizing AI to validate their practices and acquire an additional layer of trusted assurance. Applications are now open for both existing CREST members and other cybersecurity service providers eager to gain recognition for their use of AI in accredited penetration testing services.

Industry Context and Growing Demand for AI Standards

The launch of the AI penetration testing module aligns with a broader trend of rising AI adoption across the industry. According to a report published by CREST in March, over three-quarters (76%) of cybersecurity providers reported an uptick in AI utilization over the past year. Additionally, by the time of the report, 69% of those surveyed had already started integrating AI into their daily service delivery. This trend underscores the urgent need for established governance frameworks, especially as automated systems become more embedded in critical cybersecurity functions.

In response to this demand, CREST published a set of guiding principles for AI-enabled activities in March, followed by an AI Charter in June that garnered signatures from over 100 cybersecurity organizations. The recent introduction of the AI standards module was developed by a dedicated AI Working Group within CREST, which is committed to continually refining these standards in line with industry advancements.

Anticipation for First Accreditations

The expectation for the initial accreditations is high, with Nick Benson, CEO of CREST, indicating that the first accredited organization is anticipated within a month of the module’s launch. He emphasized the importance of timely rollout, stating that delaying the accreditation process would diminish its significance. According to Benson, as buyers increasingly demand independent assurances for AI-enabled services, these new standards provide a tangible and enforceable framework necessary to restore trust in the market.

In remarks to Infosecurity, Benson highlighted that this formal accreditation aligns closely with CREST’s existing complaints and discipline procedures. This integration empowers CREST to enforce compliance throughout the ecosystem effectively, filling a critical gap between the rapid adoption of AI technologies and the frameworks overseeing them.

Responses from Industry Leaders

Industry leaders have voiced their support for the new AI standards, emphasizing the collective wisdom that underpins them. Chris Oakley, Senior Vice President of Assurance Services for the Americas at LRQA Cybersecurity—also a CREST member—stated that the new standards are a well-considered answer to the evolving challenges of AI governance in cybersecurity.

William Wright, CEO of Closed Door Security, based in Dubai, articulated the timely relevance of the standards, noting the growing reliance of organizations on AI systems. He remarked on how advanced AI technologies are increasingly recognized as critical infrastructure. Therefore, it is essential for organizations to be assured of the security measures surrounding these technologies, especially as they start to support security operations and address vulnerabilities.

Overall, CREST’s new AI-Enabled Penetration Testing standards aim not only to regulate AI use within penetration testing but also to instill a sense of assurance in a landscape where cybersecurity threats are continually evolving. By establishing these standards, CREST seeks to fortify the responsible use of AI and ensure that organizations adopting these technologies can do so with confidence, safeguarding their operations against potential vulnerabilities and threats.

Source link

Latest articles

CISA Enhances SBOM Standards – Cyber Defense Magazine

A Modern Blueprint for Software Transparency On July 29, 2026, the Cybersecurity and Infrastructure Security...

Why Open-Weight AI Outperforms Closed Systems

Nvidia's Open Secure AI Alliance Sparks Debate Over Control of AI Technologies In recent discussions...

Autonomous AI Agent Exploits Zero-Day Vulnerability to Breach Hugging Face Infrastructure

In July 2026, a security breach involving an autonomous AI agent that utilized OpenAI...

Copilot Worm Can Spread via Microsoft Word Documents

The Rise of the AI Worm: Unveiling Vulnerabilities in Microsoft Word Documents In a groundbreaking...

More like this

CISA Enhances SBOM Standards – Cyber Defense Magazine

A Modern Blueprint for Software Transparency On July 29, 2026, the Cybersecurity and Infrastructure Security...

Why Open-Weight AI Outperforms Closed Systems

Nvidia's Open Secure AI Alliance Sparks Debate Over Control of AI Technologies In recent discussions...

Autonomous AI Agent Exploits Zero-Day Vulnerability to Breach Hugging Face Infrastructure

In July 2026, a security breach involving an autonomous AI agent that utilized OpenAI...