CREST Launches AI Accreditation for Cybersecurity Services
Artificial intelligence is moving into penetration-testing workflows, from reconnaissance and vulnerability scanning to analysis, reporting and automation. That adoption can increase speed and coverage, but it also raises questions about accountability, data handling and whether machine-generated findings receive adequate human review. CREST, an international accreditation body for technical cybersecurity services, is seeking to turn voluntary principles into independently assessable controls, preserving professional judgment and trust as providers embed AI in client engagements.
CREST opened applications on July 28, 2026, for its first accreditation covering AI-enabled cybersecurity services. The framework adds Domain 7, Responsible AI Use, to its Company General Requirements, addressing governance, accountability, oversight and transparency, and adds Annex B, AI-Enabled Penetration Testing, to its penetration-testing standard. More than 50 CREST members have begun the accreditation process. CREST research found 69% of penetration-testing providers already use AI, 76% increased usage over the past year and 85% expect clients to demand greater transparency.
All Coverage
1 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.