Get a free audit

Field Notes / Accreditation

CREST Now Accredits How AI Is Used in Penetration Testing. Three Standards Are Live. Ten Firms Hold the First One.

On 28 July 2026 CREST opened two new accreditations covering how a provider governs and uses AI inside your test. By 21 August 2026 a third was open too, covering whether a provider is fit to test an AI system at all. CREST’s own research says 69% of providers already use AI in penetration testing, and its published breakdown puts 9% on autonomous, agent-based testing. Here are the three questions to put in your next RFP, and what a straight answer to each one looks like.

Author
Red Team Partners
Read
10 MIN READ
Filed
21 Sep 2026
A London skyline behind a lit machine-room corridor, the two halves of a question every UK buyer of penetration testing now has to ask.

01 Three standards, three questions

CREST published the two new additions to its Accreditation Standards on 28 July 2026. From that date a cybersecurity service provider can apply to have its use of AI within service provision independently assured as part of accreditation CREST launch .

The first addition is Domain 7, Responsible AI Use. CREST places it in the Company General Requirements, the part of the standard that applies to every accredited provider whatever service it sells. CREST describes it as covering "the governance, oversight, transparency and responsible organisational use of AI by the service provider" CREST launch . That is a question about the firm, not about your engagement.

The second is Annex B, AI-Enabled Penetration Testing, a new annex to the Penetration Testing Standard. CREST says it "introduces requirements for service providers using AI within penetration testing, helping ensure AI enhances professional judgement while maintaining the quality, integrity and trust expected of CREST-accredited services" CREST launch . That is a question about your test.

CREST flagged the third on the same day, as the one coming next. Security Testing of AI covers providers assessing AI systems on behalf of clients, and CREST says it "extends assurance to the security testing of AI technologies" CREST launch . All three are listed on CREST’s AI Hub CREST AI Hub . By 21 August 2026 providers could apply for it Compare the Cloud .

Put plainly, that gives a UK buyer three lines for an RFP:

  1. Are you accredited against CREST Domain 7? If not, what governs your organisation’s use of AI, and who signed it off?
  2. Are you accredited against Annex B, and where does AI touch my engagement? Name the phases. Name the person who reviews AI output before it reaches my report.
  3. If you are testing my AI system, are you accredited for Security Testing of AI? And what is in scope when you do it?

On 3 September 2026 those questions stopped being rhetorical. Infosecurity Magazine reported that ten providers became the first in the world to achieve AI-Enabled Penetration Testing accreditation: Closed Door Security, ImmuniWeb, JUMPSEC, Packetlabs, Pentesys, REDSECLABS, Risk Associates, SECNORA, Solusec and Thoropass Infosecurity Magazine . Compare the Cloud put the cohort at ten firms across seven countries, two of them UK firms, Closed Door Security and JUMPSEC Compare the Cloud . CREST’s CEO Nick Benson said the accreditation helps the industry "move from discussion and principles around AI towards independently assured, responsible adoption" Infosecurity Magazine .

Ten is a small number, and it is the point. CREST said at launch that "over 50 of our members have already started the process" CREST launch . So the honest read today is that a handful of firms hold it, several dozen are working through it, and the rest have not started. Asking the question separates those three groups in one email.

02 What AI actually does in a test

If you picture a robot running the test and a human rubber-stamping the output, the published numbers point somewhere else. CREST’s research report puts 47% of organisations using AI for reporting and 44% for vulnerability scanning and enumeration. Only 9% report using autonomous, agent-based testing CREST usage figures .

The surrounding research, based on 62 cybersecurity providers across 19 countries, found 69% using AI in penetration testing workflows, 76% increasing that use over the past year, and 85% expecting clients to ask about AI use in testing CREST research 2026 . Read the last figure carefully. Providers already expect the question. The ones worth hiring have an answer ready.

CREST names where the work lands: early-stage reconnaissance and enumeration, configuration review, reporting and quality assurance CREST research 2026 CREST global research . It also records that providers hold greater caution for AI in core testing activity, production environments and high-assurance reporting CREST research 2026 . That maps to what the tooling is good at. A model reads a long proxy log faster than a person and does not get bored halfway down it. It summarises a config dump. It drafts the first version of a finding.

Then it hits the wall. Whether an IDOR is exploitable depends on your business logic, your data, and what a real attacker gains by reaching it. A model can flag the pattern. Deciding the severity means knowing that the record it exposes is a payroll file and that the account holding it belongs to a contractor who left in March. That judgement is the job.

A practitioner at CREST’s Abu Dhabi roundtable in February 2026 put it in five words: "The AI guard rail is me." CREST research 2026

CREST’s own conclusion gives you the shape of a good answer. AI delivers its strongest results "when it sits inside controlled processes, with clear data handling, defined review steps and accountable sign-off" CREST research 2026 . Three testable nouns sit in that sentence, and they are the three things to ask a supplier to describe: data handling, review steps, sign-off. If a provider cannot tell you where your data goes, who checks the machine’s output, and whose name is on the report, the accreditation question is already answered.

03 Reading the DSIT market map as a buyer

Count the British suppliers and the question answers itself. DSIT commissioned Pye Tait Consulting to map the AI and software security services market and published the result on 10 July 2026 DSIT market map . The 2025 analysis identified 66 AI and 960 software security providers. The 2026 sectoral study showed the market had grown to 111 AI and 1,141 software security providers DSIT market map .

The AI count rose 68% in twelve months. Two in five of the firms on the 2026 list were not on the 2025 one. A buyer reading that list has almost nothing to sort it by.

The same publication shows the gaps. Of the AI security providers DSIT surveyed, 27% say services covering proper data and model disposal are not offered at all. On maintaining regular security updates, patches and mitigations, 16% reported not offering it DSIT market map . For the mature software security market the picture is different: fewer than 10% say they do not offer services aligned to most principles, with one outlier at 17% for providing a year’s notice of end-of-support DSIT market map .

Those are shares of the providers who responded to the survey. Researchers contacted 1,906 software and 127 AI security providers to achieve a minimum of 200 software and 50 AI responses, by telephone and online, with the survey running from November 2025 to January 2026 DSIT market map . So the figures describe the respondents and not all 111 firms. They are still the best public read on the market you are buying from.

For scale, DSIT’s 2026 sectoral analysis estimates 2,603 firms active in UK cyber security, up 438 firms or 20% on the previous report, with £14.7 billion in revenue, £9.1 billion GVA and roughly 69,600 full-time equivalents DSIT sectoral analysis 2026 . In a market that size, with no shared standard, the buyer carries the sorting work. Three CREST standards now do some of it for you.

04 The second buying decision

Domain 7 and Annex B answer one question: how does this provider use AI on me. Security Testing of AI answers a different one: can this provider test an AI system at all. Treat them as two decisions with two sets of evidence, and ask for the evidence separately.

Existing CREST members and non-member providers can apply for Security Testing of AI accreditation now, and applicants must either hold CREST Penetration Testing Accreditation or apply for it concurrently Compare the Cloud . The assessment looks at whether a provider has appropriate technical expertise, testing methodologies, governance and quality controls, tooling, AI-specific risk evaluation processes, and the evidence standards to support its conclusions Compare the Cloud .

The scope of the standard is the useful part for a buyer, because it doubles as a scoping checklist. It covers GenAI and LLM-enabled systems across applications, prompts and system instructions, retrieval mechanisms and data sources, memory, tools, plugins and APIs, orchestration layers, and the downstream systems influenced by AI outputs International Security Journal .

Take that list into your next AI testing conversation and read it out. If a proposal covers the prompt and stops there, it covers one line of eight. The orchestration layer and the downstream systems are where an injected instruction turns into a transaction. Check the proposal names both.

Nick Benson, CEO of CREST, framed the buyer’s side of it directly: "Buyers need to know that the providers assessing their AI have the right expertise and methodologies" International Security Journal .

This is the work we do on AI penetration testing and AI red teaming engagements, and the scope list above is close to the scope our service pages already set out: the prompts, the retrieval pipeline, the tools and APIs the model can call, the permissions it holds, and the business logic around it. If you want the governance side of the same question, our Field Note on what AI governance frameworks actually ask you to test tracks the requirement through three UK documents.

05 If you resell testing

If you are an MSP, an agency or a consultancy selling penetration testing under your own brand, the Domain 7 question travels down your supply chain before it travels up. Your client’s auditor asks you how AI is governed in the service you sold them. You ask your supplier. The gap between those two moments is where a reseller gets caught.

No published source says UK auditors are asking that question yet. Treat it as a forecast you can test cheaply. CREST’s research found 85% of providers expecting clients to ask about AI use in testing CREST research 2026 . Send your testing supplier three lines this week and keep the reply:

  • Are you accredited against CREST Domain 7 and Annex B, or have you applied? Give me the date.
  • Which phases of a delivered engagement use AI, and what client data leaves our environment for that to happen?
  • Which named role reviews AI-assisted output before it reaches a report that carries my brand?

A supplier that answers in two working days is a supplier you can put in front of an auditor. One that sends a paragraph about responsible innovation is a liability with your logo on it. Our white-label penetration testing page sets out how we work behind a partner brand, and the partner programme covers the commercial side.

06 Where we stand, and what to ask us

An article telling you to check accreditation has to say where its author stands. Red Team Partners is not in the cohort of ten that Infosecurity Magazine named on 3 September 2026 Infosecurity Magazine . Our operators hold CREST certification as individual practitioners. That is practitioner certification, and it is a different thing from the company-level accreditations CREST opened this summer. We will not blur the two in an article about not blurring them.

What we do promise on every engagement is on the service pages already: every finding is verified by a CREST-certified operator before it reaches you. Domain 7 and Annex B exist to make a claim like that assessable by somebody other than the firm making it. That is a good development for a buyer, and we would rather be held to the standard than argue with it.

So put the three questions to us the way you would put them to anyone else. Ask what governs our use of AI. Ask which phases of your engagement it touches and what leaves your environment. Ask who signs off before a finding reaches your report. Ask the same three of every firm on your shortlist, in writing, and compare the answers side by side. The firm that answers fastest and most specifically is usually the firm doing the work properly.

If you are buying a test of an AI system rather than a network, start with the scope list from the Security Testing of AI standard and work down it line by line. We will do that with you on a call and tell you which lines apply to what you have built. See how we test AI systems, then book a call and bring the three questions with you.

References

Sources

  1. CREST. "CREST launches additional accreditation to help build trust in AI-enabled cybersecurity services." Published 28 July 2026. crest-approved.org
  2. CREST. "CREST research: how AI is changing penetration testing." Findings from original research with 62 cybersecurity providers across 19 countries. Published 15 May 2026. crest-approved.org
  3. CREST. "AI in Penetration Testing: Research Report" landing page (usage figures: 47% reporting, 44% vulnerability scanning and enumeration, 9% autonomous agent-based testing). crest-approved.org
  4. CREST. "CREST publishes global research on the use of AI in penetration testing." Published 31 March 2026. crest-approved.org
  5. CREST. AI Hub, listing the three live AI standards: Responsible AI Use, AI-Enabled Penetration Testing, Security Testing of AI. crest-approved.org
  6. Compare the Cloud. "Testing the testers: CREST opens accreditation for providers assessing GenAI and LLM systems." Published 21 August 2026. comparethecloud.net
  7. International Security Journal. CREST AI testing standard: scope and quote from Nick Benson, CEO of CREST. Published 25 August 2026. internationalsecurityjournal.com
  8. Infosecurity Magazine. "CREST names first cohort to achieve AI-enabled penetration testing accreditation." Published 3 September 2026. infosecurity-magazine.com
  9. Compare the Cloud. "Ten firms earn first CREST accreditation for AI-enabled penetration testing." Published 4 September 2026. comparethecloud.net
  10. DSIT / Pye Tait Consulting. "Mapping of the AI and software security services market." Published 10 July 2026. gov.uk
  11. DSIT. "Cyber security sectoral analysis 2026." 2,603 active UK cyber security firms, £14.7 billion revenue, £9.1 billion GVA, approximately 69,600 FTEs. gov.uk