Security News

CREST Launches AI-Enabled Pentesting Accreditation, Certifies First 10 Providers

Infosecurity Magazine · 3 Sept 2026
Key Takeaway When selecting a penetration testing provider that uses AI tools, ask whether they hold CREST's AI-Enabled Penetration Testing accreditation as evidence of responsible AI governance.

Cybersecurity industry body CREST has awarded its newly created AI-Enabled Penetration Testing accreditation to 10 companies spanning Europe, India and the US. Introduced in July 2026 as an optional module within CREST's existing Penetration Testing Accreditation Standard, the accreditation allows providers that use AI in their testing services to be independently assessed and demonstrate responsible, secure AI governance to clients and regulators.

The module doesn't change standard CREST memberships, but gives AI-using providers a way to formally verify their practices. Industry leaders from accredited firms, including Closed Door Security and Packetlabs, said the accreditation helps ensure AI is deployed responsibly while still enabling security teams to work more efficiently and identify vulnerabilities faster. CREST CEO Nick Benson said the move helps the industry shift from talking about AI principles to demonstrating independently assured, responsible adoption in practice.

The accreditation follows CREST's March 2026 report on AI in penetration testing, which found 76% of cybersecurity providers had increased AI usage over the past year and 69% were already using it in daily service delivery. That report also led to CREST publishing AI Principles and an AI Charter, the latter signed by more than 100 cybersecurity organizations.

AI security penetration testing CREST accreditation SMB security
Building or buying AI systems? Governing them under ISO 42001 ->

Summarised by CISO AI from Infosecurity Magazine. We link back to every original so you can read it yourself.