CREST has introduced new standards tied to AI-enabled penetration testing, adding an accreditation option for cybersecurity service providers. The industry body said the new requirements are designed as an optional add-on rather than a replacement for existing penetration testing standards.

The AI-Enabled Penetration Testing requirements were unveiled on July 28. Based on the announcement, the aim is to give providers a way to demonstrate that they are using artificial intelligence responsibly when delivering security testing services.

The move reflects growing interest in how AI tools are being applied in offensive security work, including penetration testing. By creating a formal accreditation layer, CREST appears to be giving clients and the wider market a clearer benchmark for assessing providers that want to highlight responsible AI practices.

Because the new framework is positioned as an add-on, companies can choose whether to pursue it alongside their current CREST credentials. The update signals that AI use in cybersecurity services is becoming important enough for industry bodies to define dedicated standards around trust, oversight and service quality.