CREST Opens Accreditation for AI-Enabled Cybersecurity Services

Let's Data Science – AI Governance(Global) 29 Jul 2026 48

Agencies procuring penetration-testing services now have an emerging assurance marker for suppliers' responsible AI use - worth factoring into vendor assessment criteria.

  • CREST launched accreditation on 28 July for AI-enabled cybersecurity service providers, covering governance, data protection, and human oversight.
  • The accreditation is optional and covers how providers use AI in delivery; a separate framework for testing AI-enabled systems is planned but not yet open.
  • Relevant to APS agencies procuring penetration-testing services, as an evidence-based assurance signal for vendor due diligence.
  • Monitor Agencies and their security teams may want to monitor CREST's planned second framework for testing the security of AI-enabled systems, as it will be more directly relevant to agencies deploying AI.
  • Consider Procurement and cyber risk teams could consider whether CREST AI-enabled accreditation status becomes a relevant criterion when engaging penetration-testing providers.

Implications are AI-generated. Starting points, not advice — see methodology for how they're framed.

View original source