Qualysec
Blog

Understanding the New CREST AI Security Testing Accreditation

Explore the new CREST AI Security Testing Accreditation, its core requirements, standards, and why human-led penetration testing matters for AI security.

Published on September 15, 2026
Read Time: 13 min
CONNECT WITH US

The integration of AI into cybersecurity activities and enterprises is growing quickly. This is why CREST has officially launched AI Security Testing Accreditation. Through this accreditation, CREST evaluates a provider’s technical expertise, testing methodologies, governance, and controls for conducting AI security assessments. 

Currently, 69% of penetration testing providers use automated machine learning applications, and 76% have increased their use. This shows the importance of taking a clear stance on AI use and security testing.

In this guide, we will discuss CREST AI Security Testing Accreditation and the requirements for cybersecurity organizations to obtain it. We will also discuss the standards, requirements, testing scope, and AI security threats.

Key Takeaways

  • CREST currently offers three AI security testing standards.
  • AI security testing evaluates the technical abilities and processes of the provider.
  • Tests will include models, applications, RAG, APIs, tools, and other parts of AI.
  • It is important to conduct human-led AI penetration testing.
  • Providers require repeatable and defensible AI security testing techniques.
  • Some of the key risks include prompt injection, data poisoning, leakage, and output manipulation.
  • Organizations must ensure their credentials, governance, testing, and evidence are appropriate before submission.

Why Did CREST Introduce New AI Security Accreditations?

CREST launched the new accreditation for AI-enabled cybersecurity on 20th August 2026. Artificial intelligence is becoming increasingly used in security services, including CREST penetration testing. Buyers had limited ways to verify whether providers had the expertise, governance, and methodologies to use AI responsibly or test AI systems securely. The CREST Security Testing of AI accreditation provides a structured way to assess whether providers have the skills and processes needed to test AI systems securely. 

Rapid Adoption of AI Across Cybersecurity Services

Adoption of AI technology has been growing very fast among penetration testing providers. This is why there is an increased need for independent verification.

  • 69% of penetration testing providers currently use AI in their service offerings.
  • 76% increased their use of AI in the last 12 months.
  • 85% anticipate client requests for transparency regarding the use of AI.

These data prove that AI technology is being rapidly adopted in cybersecurity services, but independent benchmarks are lagging.

Turning AI Principles Into Assessable Requirements

The new AI standards created by CREST turn the voluntary AI principles of CREST into mandatory standards that can be independently assessed. Before creating the accreditations, CREST AI guidance was mainly based on its AI Charter and 9 Principles. They played an important role in guiding the responsible use of AI.

The new standards take those concepts further by transforming them into tangible requirements. This allows organizations to measure the use and management of AI by cybersecurity companies.

  • Independent evidence can be obtained by clients, regulators, and procurement professionals regarding the security, transparency, and professionalism of AI-based cybersecurity services.
  • Providers can demonstrate responsible AI use through documented controls and oversight rather than relying solely on marketing claims.
  • Buyers commissioning AI security assessments can verify whether providers have the specialist capabilities and methodologies needed to test AI systems effectively.

Establishing a Benchmark for AI Security Testing Capabilities

The Security Testing of AI accreditation provides a benchmark for evaluating whether providers can securely test AI and LLM-enabled systems. 

Until now, buyers had limited access to identifying the technical capabilities of any security testing vendor that assesses their AI systems. The newly developed security testing of AI accreditation is aimed at addressing this issue through assessment of various areas. These include:

  • Technical and practitioner proficiency
  • Approved methods of testing involving all layers of AI systems
  • Appropriate governance, quality control measures, and tools
  • Process to assess the risks associated with AI
  • Proof of testing results

This helps buyers to recognize providers who have AI security capabilities versus providers who just have experience within the field.

Supporting Regulator and Auditor Expectations

AI accreditations by CREST create a framework for evidencing good AI governance, professional judgment, and human accountability. Regulators and auditors are no longer looking at whether an organization employs AI or not. They also want to understand how AI is governed, controlled, and assured.

The newly introduced CREST AI Security Testing Accreditation provides a recognized accreditation standard for cybersecurity organizations. Through this, they can prove their AI security testing capability. This proves that qualified testers, proper methodology, the right tools, and human supervision enable their AI security testing capability.

What Are The Different AI Rules That CREST Announced?

CREST’s new AI rules involve three categories. These include your organization’s responsibility for internal AI use, AI-enabled penetration testing, and testing the AI systems of your clients. Each area has specific requirements for how your organization uses, governs, and assesses AI.

I) Rules For Responsible Internal AI Use

These principles describe how you can leverage AI within your organization without revealing any client data.

  • Domain 7 General Requirements: You require proper governance and oversight of the AI systems that your team uses within the organization.
  • Data Isolation: Make sure that no client source code, reconnaissance logs, vulnerability data, and any other type of sensitive data is shared with non-approved public AI models.
  • Operational Transparency: Track all the AI systems approved by your organization and how client or business data is processed through those AI systems.
  • Access Controls: Requires role-based access controls to restrict which employees can access sensitive information processed by internal AI tools.

II) Standards For AI-enabled Penetration Testing

This will help in understanding how AI can be applied to penetration testing under the supervision of security experts.

  • Annex B Integration Rules: Sets requirements for integrating AI assistants and automated tools into penetration testing workflows.
  • Human-in-the-Loop Controls: You have to make sure that qualified security personnel supervise the AI-assisted tests. Fully autonomous assessments should not be allowed.
  • False Positive Validation: The testers have to manually validate all outputs provided by AI before adding them to the client reports.
  • Workflow Optimization Limitations: You may use AI to optimize reconnaissance and enumeration activities. But you cannot use it as a substitute for a professional security assessment.

III) Standards For Testing Clients’ AI Systems

These requirements explain how you can test clients’ AI and LLM-based systems and identify security risks across the wider AI environment.

  • External Testing Scope: You must be able to conduct secure testing of third-party generative AI systems and language models.
  • AI-Specific Vulnerability Testing: Requires you to demonstrate capabilities for identifying risks such as prompt injection, data poisoning, model extraction, and insecure output handling. 
  • AI Ecosystem Testing: Testers should be able to check for interactivity between AI models and vector databases and other components.

Need help with the new CREST AI rules?

Talk to our team to check your AI setup and ensure your security controls are fully aligned.

Talk to a Security Expert

CREST

Key Differences Between the AI Standards

AI Standard / Rule Category Primary Focus Area Target Entity Evaluated Core Operational Objective
Responsible Internal AI Use (Domain 7) Internal tool deployment and administrative data hygiene. The cybersecurity vendor’s internal corporate environment. Prevent client data leaks and ensure responsible internal AI adoption.
AI-Enabled Penetration Testing (Annex B) Service delivery integration and workflow acceleration. The vendor’s live penetration testing processes and toolchains. Enforce human-in-the-loop oversight and rigorous output verification.
Testing Clients’ AI Systems External diagnostic testing and adversarial evaluation. The client’s generative AI models and LLM ecosystems. Certify specialist capability to uncover prompt injection, data leakage, and model vulnerabilities.

What Is The New AI Security Testing Standard And Why Does It Matter?

The CREST AI Security Testing Accreditation standard provides an approach to test AI systems through their models, applications, data, and associated components. It is more than just testing the base model; it includes testing the entire AI environment.

  • Whole-System Architecture Scope: Test coverage consists of the core architecture and the applications, infrastructure, and other components that exist around it.
  • Retrieval-Augmented Generation (RAG): The testing scope includes vector databases, embedding models, and knowledge retrieval pipelines because of risks like data poisoning and unauthorized data access.
  • Prompt and System Instructions: The assessment looks into the system instructions, constraints, and input handling for prompt injection risks.
  • External Tooling and Plugins: The testing scope includes external APIs, execution platforms, plugins, and function calling for the AI-based workflow.
  • Orchestration and Memory: Testing involves the orchestration layer, session memory, state management, and downstream systems affected by AI-generated outputs.

Why Does It Matter?

With this accreditation, your organization will have a recognized methodology to show capabilities in testing AI & LLM based systems. It assists you in organizing testing approaches, technical capabilities, governance, and evidence to meet the security needs of AI.

As a cybersecurity provider, you can use this standard to:

  • Enhance skills for testing AI: Enhance skills in testing the model, data, applications, APIs, retrieval engines, and interconnected components.
  • Demonstrate technological proficiency: Ensure that your experts can share their understanding of the possible hazards of AI and the testing procedure.
  • Use a standard approach to testing: Use a common approach to testing AI security risks.
  • Facilitate quality assurance: Make sure that there is evidence for decisions in regard to testing, results, and risk assessment.
  • Demonstrate professional knowledge: Provide evidence that your organization can carry out structured testing in AI security.

What Are The Main Security Risks That An Accredited Provider Looks for?

A CREST-accredited provider should assess the security of AI systems, models, use cases, data, tooling, and components as a group. The primary threats are:

  • Prompt Injection: Attackers try to manipulate the input to circumvent the system instructions, perform unauthorized operations, or access sensitive information.
  • Data Poisoning and Leakage: Attackers try to alter training and retrieval data or use the AI models for retrieval of sensitive information.
  • Insecure Output Handling: The applications may blindly trust the AI output and be susceptible to threats like XSS, code execution, or SQL injection.
  • Supply Chain Issues: The risks of relying on third-party models, open-source model weights, plugins, or AI components.

Could prompt injection break your AI?

Let Qualysec take a close look at your AI setup. Our highly experienced team checks every corner of your system to catch hidden security risks before real hackers do.

Request Free Security Audit

Security Audit

What Strict Requirements Does A Cybersecurity Company Need to Meet To Pass the AI Security Testing?

The CREST AI Security Testing Accreditation requires evidence of technical skills, qualifications, methodology for testing, good governance, and credible evidence. The CREST accreditation is dependent on the ability to test generative AI and LLM-based systems. It accredits your security testing service, not the AI product itself.

1. Meeting The Baseline CREST Requirements

Your organization needs to obtain the proper credentials from CREST to demonstrate that it has a well-assessed security testing process.

  • Baseline CREST accreditation: It is expected that you should have a baseline CREST service accreditation, most likely the standard penetration testing accreditation.
  • Pathway through CREST: This indicates that your organisation is working along the CREST pathway.
  • Increasingly higher accreditation standard: CREST granted its first AI-related accreditations to 10 organisations globally in September 2026, indicating that the accreditation is still being awarded to a restricted number of organizations.

2. Having The Expertise To Assess AI Security

Your security team needs the expertise to test the architecture, applications, data feeds, tools, and processes that are part of the AI application.

They should demonstrate:

  • Understanding of AI and LLM architectures
  • Awareness of AI-oriented security testing techniques
  • Knowledge of AI security testing techniques.
  • Experience with conducting AI application and integration risk assessments
  • Knowledge about testing AI applications and interdependent services.
  • AI interpretation skills

3. Repeatable and Defensible Testing Methodologies

You require testing methodologies that reliably uncover unique AI vulnerabilities and document the process of testing each element in the AI ecosystem.

Some elements for which your testing method must account include:

  • AI models and applications
  • RAG and retrieval pipelines
  • Prompts and system instructions
  • Plugins and other external tools
  • Orchestration and memory systems

The testing method should be mapped against known threat modeling frameworks such as MITRE ATLAS to show the breadth and rigor of testing. But the focus should remain on producing a defensible methodology rather than following one framework alone.

4. Governance, Quality Controls, and Tooling

Your organization should have governance and quality controls in place for your tools, processes, and data used during effective CREST AI Security Testing Accreditation.  

Controls should include:

  • Keeping an authorized inventory of AI and security testing tools
  • Using version-controlled scripts for testing purposes
  • Handling data in accordance with proper measures
  • Maintaining oversight over the use of AI tools during service delivery
  • Following up on proper quality control during testing

This will help you maintain consistency and accountability during the testing process.

5. Evidence Quality and Substantiated Conclusions

It is necessary to back up your findings with reliable evidence rather than simply providing the raw outputs from automated tools.

For each of the findings, you will have to provide:

  • The testing steps used to identify the issue
  • Reproducible evidence supporting the finding
  • Relevant testing artefacts
  • The reasoning behind the risk rating
  • Clear analysis supporting the conclusion

This way, you can easily validate your findings and prove that your AI security assessments are based on professional analysis.

Conclusion

The CREST AI Security Testing Accreditation is a structured approach cybersecurity organizations can use to prove their skills in testing AI and LLM-powered systems. It is not simply the use of AI-powered tools that matters in the accreditation process. You must demonstrate the necessary qualifications, skills, testing, as well as other elements.

As AI becomes more prevalent in the security industry and enterprise solutions, this will assist organizations in establishing standardized security testing methods for AI. Training for those criteria can also enable your team to hone its overall testing methods. 

To help enterprises navigate this evolving landscape, partnering with providers offering CREST-accredited penetration testing services ensures your security assessments meet the highest global standards of rigor, governance, and human-led oversight.

Secure Your AI and LLM Applications from Cyberattacks.

Qualysec’s expert team tests your AI, RAG pipelines, and infrastructure to keep your business safe and help you easily meet security standards.

Schedule AI Penetration Test

AI Penetration Testing

FAQs

What is the main purpose of CREST’s AI Security Testing Accreditation?

The accreditation explicitly confirms that cybersecurity vendors can be trusted to test AI and LLM-based systems in a safe manner. It evaluates technical knowledge, testing process, human involvement, and professional responsibility.

How does CREST differentiate between internal use of AI and client system testing?

Internal AI rules are focused on governance and the protection of sensitive client data when delivering the service. Client system testing concentrates on finding vulnerabilities in the external AI and LLM environments.

Do organizations need pre-existing credentials to apply for CREST AI accreditation?

Yes, organisations are required to have or obtain a baseline CREST service accreditation. This generally includes CREST’s Penetration Testing Accreditation.

What is the actual scope of the analysis of an AI security assessment?

Testing extends beyond the base model to the wider environment of AI. It includes RAG pipelines, system instructions, APIs, orchestration layers, memory, and external tools.

What is the need for human supervision in CREST-accredited AI penetration testing?

Human oversight ensures qualified security professionals review and validate AI-assisted testing results. It also maintains professional judgement and accountability throughout the assessment. 

Pabitra Kumar Sahoo

About Pabitra Kumar Sahoo

Pabitra Kumar Sahoo is the Co-Founder and Chief Operating Officer (COO) at Qualysec. With a deep commitment to elevating global cybersecurity standards, he directs corporate operations and service strategy, helping enterprises mitigate compliance debt and defend their digital infrastructure through elite, human-led penetration testing.

Leave a Comment.

Your email address will not be published. Required fields are marked *

Related Blogs

Subscribe to Newsletter

Get the latest cybersecurity insights, compliance tips, and vulnerability reports delivered directly to your inbox.