Summary
- CREST has awarded its first AI-enabled penetration-testing accreditations to ten cybersecurity providers.
- The scheme assesses responsible, secure, and appropriate AI use alongside professional oversight and accountability.
- Accreditation introduces a procurement benchmark but does not establish that AI-assisted testing is inherently more effective than conventional testing.
CREST has accredited the first ten companies under its AI-enabled penetration-testing programme, moving the use of artificial intelligence in professional security testing from voluntary principles towards a formal assurance framework.
The London-based cybersecurity accreditation body launched the scheme in July and announced its first cohort on 3 September. The providers include companies operating across several markets, reflecting the increasingly international use of AI-assisted tooling inside penetration-testing services.
CREST says the accreditation assesses organisations against requirements for the responsible, secure, and appropriate use of AI within penetration testing. The programme builds on an earlier set of responsible-AI principles that the organisation says more than 100 companies have signed.
The significance of the accreditation lies less in whether AI can automate individual testing tasks — a capability already widely available — than in whether buyers can establish how those tools are governed when they are incorporated into a professional service.
Penetration testing frequently involves privileged access, sensitive architecture, exploitable vulnerabilities, credentials, proprietary applications, and information that an organisation would not ordinarily expose to external AI services. Introducing models or agentic tools into that environment raises questions about data handling, model access, human oversight, auditability, and the authority given to automated systems.
Those issues become harder to resolve through ordinary supplier marketing because the term AI-enabled can describe very different operating models. One provider might use a model to summarise evidence or assist with report preparation, while another could permit automated systems to interact directly with targets during discovery and exploitation.
An accreditation framework can create a common set of questions around those differences. It can also make procurement teams less dependent on claims that a provider is using AI responsibly without defining what that means in practice.
CREST’s own research illustrates how quickly the market is changing. The organisation says 76% of cybersecurity providers surveyed have increased their use of AI over the past year, while 69% are already incorporating it into day-to-day service delivery. Those figures come from CREST’s research population rather than the entire penetration-testing market, but they indicate that AI use is no longer experimental for a substantial portion of service providers.
Formal assurance does not, however, settle the separate question of testing quality. An AI accreditation should not be interpreted as evidence that an AI-assisted test will necessarily identify more vulnerabilities, exercise better judgement, or provide more useful risk analysis than a conventionally delivered engagement.
The distinction matters for procurement. Assurance can establish requirements around process, accountability, and responsible use without turning a technology choice into a proxy for technical competence. Existing testing methodology, tester skills, scope, independence, and reporting quality remain relevant regardless of whether AI contributes to the engagement.
As security-service suppliers increase their use of agentic systems, customers are also likely to seek clearer contractual boundaries. Those may include which models can process engagement data, where information is stored, whether prompts or results are retained by third parties, what actions require human authorisation, and how the provider records automated activity.
CREST’s first cohort therefore marks an early attempt to make those governance questions independently assessable. The value of the programme will depend on whether the standard remains sufficiently specific as AI use progresses from supporting human testers towards systems capable of carrying out increasingly autonomous security-testing tasks.




