CREST Introduces AI‑Powered Penetration‑Testing Certification, Welcomes First Ten Providers
CREST, the independent body that sets standards for cyber‑security testing, announced today that it has enrolled its inaugural cohort of ten service providers into a newly created accreditation for AI‑enabled penetration testing. The move represents the first formal recognition of security firms that combine traditional manual testing methods with artificial‑intelligence tools to uncover vulnerabilities.
Founded more than two decades ago, CREST has built a reputation for rigorous, peer‑reviewed certification programs that cover everything from individual ethical hackers to whole testing organisations. Its existing penetration‑testing accreditation has long been a benchmark for quality and reliability. The latest scheme expands that framework to address the growing use of machine‑learning models, automated scanners and other AI‑driven techniques that are reshaping how security assessments are performed.
AI‑enabled penetration testing leverages algorithms that can rapidly analyse code, scan networks and even generate exploit payloads with minimal human input. Proponents argue that such automation increases coverage, reduces time‑to‑detect, and allows testers to focus on higher‑level analysis. At the same time, the technology raises questions about false‑positive rates, model bias and the need for continuous human oversight. CREST’s accreditation seeks to codify best practices that balance speed with accuracy and ethical responsibility.
The ten firms selected for the first cohort underwent a multi‑stage evaluation that examined the robustness of their AI tools, the transparency of their model training data, and the extent of human review embedded in their workflows. Participants must also adhere to CREST’s code of conduct, demonstrate documented validation processes for AI outputs, and commit to ongoing monitoring of tool performance. By meeting these criteria, the providers earn a label that signals to clients that their AI‑augmented testing meets an industry‑wide standard.
Industry observers see the certification as a timely response to market pressure. As AI capabilities become more accessible, organisations increasingly demand assurance that security assessments are both cutting‑edge and trustworthy. A formal accreditation gives buyers a concrete way to differentiate vendors that have proven their AI practices against a neutral benchmark, potentially influencing procurement decisions and shaping future regulatory expectations.
Looking ahead, CREST plans to broaden the program beyond the initial ten members, refining the criteria as the technology evolves. The body has indicated an intention to collaborate with regulators, academic researchers and AI ethicists to keep the standards aligned with emerging threats and best‑practice guidance. If successful, the AI‑enabled penetration‑testing accreditation could become a template for similar certifications across other cyber‑security domains, establishing a baseline for responsible AI use in the field.
Comments (0)
Be the first to comment.
Join the discussion