These tools and metrics are designed to help AI actors develop and use trustworthy AI systems and applications that respect human rights and are fair, transparent, explainable, robust, secure and safe.
CREST AI Accreditation Standards for Cybersecurity Services
The CREST AI Accreditation Standards for Cybersecurity Services enable cybersecurity service providers to apply to have their use of AI within their service provision independently assured by CREST as part of its accreditation process. The first AI accreditation was launched in July 2026 and gives service providers a practical framework for demonstrating responsible AI use within accredited cyber security services through independent assessment.
- Domain 7: Responsible AI Use, part of the Company General Requirements, covers the governance, oversight, transparency and responsible organisational use of AI by the service provider. CREST’s AI Hub describes these requirements as covering AI governance, accountability and oversight.
- Annex B: AI-Enabled Penetration Testing, part of the Penetration Testing Accreditation Standard, introduces requirements for service providers using AI within penetration testing, helping ensure AI enhances professional judgement while maintaining the quality, integrity and trust expected of CREST-accredited services. CREST also describes this as providing assurance that AI is used in penetration testing in a controlled, authorised and professionally supervised way.
- Security Testing of AI establishes independently assessable requirements for organisations testing AI-enabled systems. It covers security testing of relevant components of AI systems, including models, application layers and orchestration components.
Together, these standards provide practical, independently assessable requirements supporting responsible AI use within accredited cybersecurity services and the security testing of AI systems. They build on CREST’s voluntary AI principles by providing independently verifiable assurance.
About the tool
You can click on the links to see the associated tools
Developing organisation(s):
Tool type(s):
Objective(s):
Impacted stakeholders:
Purpose(s):
Target sector(s):
Country/Territory of origin:
Lifecycle stage(s):
Type of approach:
Maturity:
Usage rights:
Target groups:
Target users:
Stakeholder group:
Validity:
Enforcement:
Geographical scope:
People involved:
Required skills:
Technology platforms:
Use Cases
Would you like to submit a use case for this tool?
If you have used this tool, we would love to know more about your experience.
Add use case




























