CREST Opens Accreditation for AI-Enabled Cybersecurity Services
Agencies procuring penetration-testing services now have an emerging assurance marker for suppliers' responsible AI use - worth factoring into vendor assessment criteria.
Key points
- CREST launched accreditation on 28 July for AI-enabled cybersecurity service providers, covering governance, data protection, and human oversight.
- The accreditation is optional and covers how providers use AI in delivery; a separate framework for testing AI-enabled systems is planned but not yet open.
- Relevant to APS agencies procuring penetration-testing services, as an evidence-based assurance signal for vendor due diligence.
Implications for Australian agencies
- Monitor Agencies and their security teams may want to monitor CREST's planned second framework for testing the security of AI-enabled systems, as it will be more directly relevant to agencies deploying AI.
- Consider Procurement and cyber risk teams could consider whether CREST AI-enabled accreditation status becomes a relevant criterion when engaging penetration-testing providers.
Implications are AI-generated. Starting points, not advice — see methodology for how they're framed.
View original source
Copied.
Appeared in:
Weekly digest, 27 July 2026
"CREST Opens Accreditation for AI-Enabled Cybersecurity Services"
Source: Let's Data Science – AI Governance
Published: 29 July 2026
URL: https://letsdatascience.com/news/crest-adds-ai-penetration-testing-accreditation-a8c72931
CREST opened applications on 28 July 2026 for accreditation of AI-enabled cybersecurity services, adding a Responsible AI Use domain to its Company General Requirements and a supplementary AI-Enabled Penetration Testing annex to its existing standard. Applicants must demonstrate evidence-backed governance, data protection, engagement boundary controls, and human oversight of machine-assisted findings. The current accreditation evaluates how service providers use AI in their own delivery, not the security of customers' AI systems; a separate framework for the latter is planned. CREST's own survey found 69% of penetration-testing providers already use AI, with 85% expecting clients to demand greater transparency.
Implications for Australian agencies:
- [Monitor] Agencies and their security teams may want to monitor CREST's planned second framework for testing the security of AI-enabled systems, as it will be more directly relevant to agencies deploying AI.
- [Consider] Procurement and cyber risk teams could consider whether CREST AI-enabled accreditation status becomes a relevant criterion when engaging penetration-testing providers.
Retrieved from SIMS, 16 September 2026.