AI cybersecurity standards have been officially launched by CREST to provide the first global accreditation for artificial intelligence-enabled security services. This initiative represents a shift from voluntary compliance toward independent, verified standards for the global security sector.
According to the organization’s recent report on artificial intelligence in penetration testing, 76% of cybersecurity providers used artificial intelligence during the past year. Furthermore, 69% of these firms already integrate the technology into their daily service delivery operations to clients.
The Need for AI Cybersecurity Standards
The rapid adoption of these technologies created a significant gap in verified governance across the industry. Consequently, the new framework introduces independent, assessable requirements to verify that providers use artificial intelligence responsibly in their internal operations and client-facing services.
“The pace of AI adoption has outpaced governance, and we are looking to address this. We know that buyers are increasingly demanding independent assurance for AI-enabled services. In this fast-moving environment, there was no time to lose. We believe these new additions to our standards will provide a practical, actionable framework to restore market confidence.”
Nick Benson, CEO of CREST
Accreditation and Industry Integration
The new requirements for AI cybersecurity standards are now open for applications from existing members and new providers. Specifically, these optional criteria integrate directly into the established penetration testing accreditation framework of the organization, providing an independent guarantee of responsible technology use.
“In the US, we have seen a rapid shift from regulators and auditors asking ‘is AI being used?’ to ‘how is AI being managed?’; it is already assumed by everyone that AI is playing a part. The new CREST AI standards build on the collective expertise of industry leaders, providing a unified answer to AI governance in this space.”
Chris Oakley, Senior Vice President of Quality Assurance at LRQA
Global Collaboration and Standards Development
The organization developed these criteria in close collaboration with the wider security industry. Notably, this launch follows the introduction of the AI Charter in June, which secured signatures from more than 100 global organizations, representing over 10% of the group’s global membership.
“The new CREST standard comes at a critical time, as organizations increasingly rely on AI. Advanced AI systems are steadily moving towards becoming critical infrastructure, and it is vital that organizations have trust in the security around them. With these advanced systems now being trusted to support security operations, identify vulnerabilities, and remediate them, it demands a framework for responsible use, which this new standard provides.”
William Wright, CEO of Closed Door Security
Future Outlook and NATO Partnership
In addition to these new AI cybersecurity standards, the organization continues to expand its global influence. Specifically, NATO recently appointed the group as an implementing agent to support cybersecurity capacity building in partner nations, focusing on resilience and workforce development.





