Ten firms earn first CREST accreditation for AI-enabled penetration testing

Ten cybersecurity providers have become the first in the world to achieve CREST's AI-Enabled Penetration Testing accreditation, introduced in July 2026 to set an independent standard for how AI tools can be used in pen testing without sidelining human oversight.

The cohort spans seven countries: Closed Door Security and JUMPSEC from the UK, Packetlabs from Canada, ImmuniWeb and Solusec from Europe, and firms from India, UAE, and the US including Thoropass and Pentesys. All were assessed against CREST's published requirements for responsible and secure AI integration within penetration testing services.

The accreditation was built in response to a shift the industry body says it is watching closely. CREST's own research found that 76% of cybersecurity providers have increased AI usage over the past year and 69% are already integrating it into daily operations. The gap is between adoption and accountability: clients are asking for evidence, not promises, on how AI is being used and what oversight remains.

Nick Benson, CEO of CREST, said: "As AI becomes increasingly ingrained in cybersecurity services, it's crucial that the industry moves from discussion and principles towards independently assured, responsible adoption. It is clear that this is what clients are increasingly demanding of them. This latest accreditation provides a practical framework for doing exactly that, emphasising the combination of responsible practice with professional judgement, quality and human accountability."

The practical significance of the accreditation is the audit trail it creates. Pen testing firms that sign voluntary AI principles can now convert those pledges into verifiable proof of compliance, something buyers can reference in procurement rather than take on trust.

William Wright, CEO of Closed Door Security, said: "AI offers significant support to penetration testing, helping security teams work more efficiently at scale, and identify vulnerabilities faster. However, it needs to be governed appropriately. Closed Door Security is proud to be part of the first CREST cohort to be accredited for AI-Enabled Penetration Testing, ensuring the technology is adopted safely to genuinely benefit and improve the security of organisations."

Denis Kucinic, VP Operations at Packetlabs, added: "AI will be revolutionary for security providers like Packetlabs, but it's vital that we assure customers, and the wider industry, that it's being deployed and used responsibly. Accreditation providers like CREST help companies do exactly that. With independent and assessable standards, providers can back up voluntary promises with concrete assurance."

CREST launched a companion standard, the Security Testing of AI Accreditation, in August 2026, covering the reverse direction: how to test AI systems for vulnerabilities, rather than how to use AI in tests. Existing CREST members can apply for the new AI-Enabled Penetration Testing accreditation through the CREST membership portal.

To stay across the latest in cloud, AI and enterprise tech analysis from Compare the Cloud, subscribe to our weekly newsletter at https://www.comparethecloud.net/newsletter

More News