CREST announced on 28 July 2026 that it has added AI-specific requirements to its Penetration Testing Accreditation Standard, opening applications for both existing members and any cybersecurity service provider seeking independent recognition for responsible AI use within their accredited services. The additions mark a shift from the industry's previous reliance on voluntary commitments and public pledges toward independently enforceable standards with formal compliance and discipline processes attached.
The numbers motivating the move are stark. Seventy-six percent of cybersecurity providers have increased their AI usage in the past year, according to CREST's own AI in Penetration Testing report, and 69% are already integrating AI into daily service delivery. Recognition that responsible use needs to be demonstrable, not just asserted, is growing among buyers, regulators, and procurement teams — particularly as AI moves further into high-stakes security operations.
The new requirements are practical rather than aspirational. CREST describes them as independently assessable, covering how providers deploy AI within their businesses and during service delivery. Non-compliance can trigger CREST's existing complaints and discipline processes, giving the standard teeth that voluntary frameworks lack.
"AI adoption is outpacing governance, and we are here to fix that," said Nick Benson, CEO of CREST. "We recognise that buyers are increasingly demanding that AI-enabled services are independently assured. In such a fast-moving space, there was no time to waste. We believe these new additions to our standards will provide a practical, enforceable framework to regain the market's trust."
CREST developed the requirements through its AI Working Group, drawing on member experience from multiple geographies. Chris Oakley, SVP Assurance Services (Americas) at LRQA Cybersecurity, noted that US regulators and auditors have already moved past asking whether AI is used to asking how it is governed. Sanjay Verma, Managing Director at CyberZone Global in Australia, observed that the requirements align with ISO/IEC 42001, the Artificial Intelligence Management System standard, translating those principles into assessable expectations for security service providers.
The announcement follows the June 2026 launch of CREST's AI Charter and AI Principles, which attracted more than 100 founding signatory organisations — representing over 10% of CREST's global membership — committing publicly to responsible AI use. Moving from a charter to an accreditation standard completes that arc: principles become requirements, and requirements become independently verifiable.
Existing CREST members and other providers can apply for the new accreditation or download the updated standards from crest-approved.org.
To stay across the latest in cloud, AI and enterprise tech analysis from Compare the Cloud, subscribe to our weekly newsletter at https://www.comparethecloud.net/newsletter