CREST has introduced a new optional AI-Enabled Penetration Testing accreditation module as an add-on to its existing penetration testing standard, giving cybersecurity service providers a way to independently demonstrate responsible and secure AI governance in both internal operations and client-facing testing engagements. The body said the move responds to rapid AI adoption across the sector and growing customer demand for independently assured AI-enabled services, and it expects the first organization to achieve the accreditation shortly after launch.
The accreditation follows CREST’s broader push to formalize AI safeguards for cyber services through its AI Principles and an AI Charter backed by more than 70 firms at launch and later cited alongside support from over 100 organizations. The charter sets nine principles spanning governance, transparency, auditability, human oversight, data sovereignty, secure development, supply-chain assurance, and resilience, while requiring firms to disclose AI use to clients, maintain reviewable records, and protect client data, prompts, outputs, and AI-generated assets. CREST said the framework is intended to move the industry from voluntary commitments toward independently assessable standards for AI-enabled security services.

See the reporting duties and controls this puts on the clock.
3 events from the most recent confirmed update back to the earliest known activity.
On July 28, CREST introduced optional AI-Enabled Penetration Testing requirements as an add-on to its existing Penetration Testing Accreditation Standard. The module allows cybersecurity service providers to undergo independent assessment of responsible and secure AI governance in internal operations and client-facing pentesting services.
On July 9, CREST launched its AI Charter for responsible AI use in cybersecurity services. The charter debuted with 73 founding signatories and set out nine principles covering governance, transparency, auditability, human oversight, data handling, secure development, supply-chain assurance, and resilience.
CREST published its AI Principles for AI-enabled cybersecurity activities. Later reporting says these nine principles were initially revealed in March and informed subsequent CREST AI governance initiatives.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
3 references tracked. Mallory keeps watching after this page renders.
infosecurity-magazine.com
Open sourceinfosecurity-magazine.com
Open sourcecrest-approved.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.