Testing the testers: CREST opens accreditation for providers assessing GenAI and LLM systems

For enterprise buyers commissioning security assessments of AI systems, there has been no independent way to verify whether the provider handling the work actually understands the technology they are testing. Generative AI introduces attack surfaces — prompt injection, retrieval manipulation, orchestration layer vulnerabilities — that conventional penetration testing practitioners may never have encountered. CREST's new Security Testing of AI accreditation is designed to close that gap.

The standard, announced today by the international cybersecurity non-profit, establishes independently assessable requirements for providers carrying out security testing of GenAI and LLM-enabled systems. Accreditation assesses whether a provider has appropriate technical expertise, testing methodologies, governance and quality controls, tooling, AI-specific risk evaluation processes, and the evidence standards to support its conclusions.

Nick Benson, CEO of CREST, said the standard was designed to respond to a clear market gap: "This latest addition to our new AI range of standards and accreditations was specifically curated to respond to an emerging market need. Our membership told us very clearly that as their clients deployed AI-enabled tech, they required more information on their AI testing credentials."

The standard applies the whole-system view. Rather than treating the AI model as the sole attack surface, it extends to applications, prompt engineering, retrieval mechanisms, data sources, memory, tools, plugins, APIs, orchestration layers, and downstream systems influenced by AI outputs — the full stack through which a real attack would move.

CREST research puts the context in relief: 69% of penetration testing providers already use AI, and 76% have increased usage over the past year. The new standard sits alongside the AI-Enabled Penetration Testing accreditation CREST launched in July, which covered how providers use AI within their own testing work. This latest one addresses a different question: whether they can test AI in client environments.

Early members indicate there is appetite. Tim Reed, Technical Director at UK-based Sentrium Security Limited, said the standard "turns responsible AI from a promise into something that can be evidenced and assessed. We believe this will strengthen buyer confidence, reward credible providers and set a higher bar for the profession, which is why we intend to pursue accreditation." Yann Chalençon, Head of Cyber Security Services at wizlynx group in Switzerland, described it as "a clear, independently verified framework that will help create consistency, strengthen assurance and build trust in both the testing process and the wider use of AI-enabled cybersecurity services."

Existing CREST members and non-member cybersecurity providers can apply for accreditation now. Applicants must either hold CREST Penetration Testing Accreditation or apply for it concurrently.

To stay across the latest in cloud, AI and enterprise tech analysis from Compare the Cloud, subscribe to our weekly newsletter at https://www.comparethecloud.net/newsletter

More News