21 Aug 2026

CREST, the international non-profit representing the global cybersecurity industry, announces the launch of its Security Testing of AI standard and accreditation. The new standard for cybersecurity service providers establishes independently assessable requirements for testing Generative AI and Large Language Model (LLM)-enabled systems.

AI systems are moving rapidly from experimentation into real-world deployment, with AI becoming embedded within organizations’ applications, workflows, products and business processes. But up until now, buyers have had no way to know whether the cybersecurity providers testing their AI systems actually have the capability to do so.

Providing independent assurance

The CREST Security Testing of AI accreditation has been introduced to address that. It is designed to provide independent assurance that cybersecurity service providers have the demonstrable specialist capability to securely and effectively test AI systems.

It assesses whether providers have appropriate:

  • Technical expertise and practitioner competence.
  • Testing methodologies.
  • Governance and quality controls.
  • Technical approaches and tooling.
  • Processes for identifying and evaluating AI-specific security risks.
  • Evidence to support the conclusions reached during testing.

AI security expertise

Once accredited, providers offer buyers independent assurance of their AI testing capabilities. This helps guide procurement, streamline supplier due diligence, and eliminate reliance on unsupported claims about AI security expertise.

Nick Benson, CEO of CREST, said: “This latest addition to our new AI range of standards and accreditations was specifically curated to respond to an emerging market need. Our membership told us very clearly that as their clients deployed AI-enabled tech, they required more information on their AI testing credentials. Offering " Security testing of AI systems" and demonstrating the ability to deliver it effectively are two different things. Buyers need to know that the providers assessing their AI have the right expertise and methodologies. Providers now have a way to develop their policies in line with our standard, demonstrate their technical capabilities through independent assessment, giving buyers that all-important confidence to proceed.”

Entire attack surface

The Security Testing of AI standard has been created under the principle that AI security testing needs to consider the whole system.

To recognize the broader system-level security challenge, the new standard does not just treat the underlying model itself as the entire attack surface. It recognises that testing needs to also consider applications, prompts and system instructions, retrieval mechanisms, data sources, memory, tools, plugins, APIs, orchestration layers and downstream systems influenced by AI outputs.

AI assurance program

The Security Testing of AI standard and accreditation marks the latest stage of CREST's growing AI assurance program. Recent CREST research highlights the magnitude of this evolution across cybersecurity: 69% of penetration testing providers already use AI, and 76% have increased their usage over the past year. Responding to this rapid rate of adoption, CREST announced its AI-Enabled Penetration Testing standard in July. This focused on how a penetration testing provider uses AI within the delivery of its services, while this latest standard assures their capability to test AI systems.

Tim Reed, Technical Director, Sentrium Security Limited, a UK-based CREST member, said: "CREST’s standards turn responsible AI from a promise into something that can be evidenced and assessed. We believe this will strengthen buyer confidence, reward credible providers and set a higher bar for the profession, which is why we intend to pursue accreditation.”

AI-enabled cybersecurity services

Yann Chalençon, Head of Cyber Security Services, wizlynx group, a Switzerland-based CREST member, said: "CREST’s new standard provides a clear, independently verified framework that will help create consistency, strengthen assurance and build trust in both the testing process and the wider use of AI-enabled cybersecurity services.” CREST developed these standards in collaboration with the industry and will continue to refine them through its AI Working Group.

The standards follow the launch of CREST’s industry-backed AI Charter and AI Principles in June. A global cohort of more than 100 founding signatory cybersecurity organizations - including more than 10% of CREST’s worldwide membership - publicly committed to supporting the responsible use of AI across industry services.

Existing CREST Members and cybersecurity service providers are now invited to apply for this new accreditation. The Security Testing of AI accreditation builds on CREST’s Penetration Testing Accreditation, which organizations must hold or apply for alongside this one.