Volver a Noticias
SeguridadAI Understanding sesión informativa

CREST launches accreditation standard for firms testing AI systems

SecurityBrief Asia reports that CREST has launched an AI security-testing standard and accreditation for cybersecurity providers, covering models and the surrounding applications, data, tools and workflows.

Por 7 min read
AI-generated editorial illustration accompanying CREST launches accreditation standard for firms testing AI systems
La versión corta

SecurityBrief Asia reports that CREST has launched an AI security-testing standard and accreditation for cybersecurity providers, covering models and the surrounding applications, data, tools and workflows.

que paso

SecurityBrief Asia reports that CREST launched a Security Testing of AI standard and accreditation for cybersecurity service providers. The framework assesses whether providers have the expertise, methods, governance, controls and evidence needed to test AI-enabled systems.

SecurityBrief Asia reports that CREST, a global not-for-profit cybersecurity standards and accreditation body, has launched a Security Testing of AI standard and accreditation for cybersecurity service providers. The stated purpose is to give organisations an independent assurance signal when choosing firms to test systems that use generative AI or large language models. The article presents the launch as a response to a market gap: organisations are adopting AI-enabled applications and workflows, but buyers may have difficulty determining whether a testing provider has the relevant technical expertise.

According to SecurityBrief Asia, the accreditation sets assessable requirements across technical expertise, practitioner competence, testing methodologies, governance, quality controls, tooling, processes for identifying AI-specific security risks, and the evidence used to support testing conclusions. The scheme therefore evaluates both a provider’s testing capability and the controls surrounding its work. The report says providers must already hold CREST’s Penetration Testing Accreditation, or apply for it alongside the new AI testing approval. That links the new scheme to an existing CREST baseline for penetration-testing services.

The report says the standard treats an AI system as a whole system rather than only an underlying model. Its described scope includes applications, prompts and system instructions, retrieval mechanisms, data sources, memory, tools, plugins, APIs, orchestration layers and downstream systems affected by AI outputs. This matters because vulnerabilities can arise at integration points or in the surrounding infrastructure, including the way a model receives information, invokes tools or passes results into other systems. SecurityBrief Asia reports that the standard was developed with the sector through CREST’s AI Working Group.

CREST chief executive Nick Benson told SecurityBrief Asia that members and clients wanted more information about providers’ AI-testing credentials as clients deployed AI-enabled technology. Benson distinguished between using the phrase “security testing of AI systems” and demonstrating the expertise and methodologies needed to perform that work. The article also quotes Sentrium Security technical director Tim Reed and wizlynx group head of cyber security services Yann Chalençon, both of whom support the framework. Their comments are industry endorsements, not independent evaluations of the standard.

SecurityBrief Asia places the launch within CREST’s broader AI-assurance programme. The article says CREST introduced an AI-Enabled Penetration Testing standard in July, focused on how providers use AI while delivering testing services. The newly reported accreditation addresses the different question of whether providers can test AI systems themselves. The report also says that more than 100 founding cybersecurity organisations have signed CREST’s AI Charter and AI Principles, representing more than 10% of its worldwide membership. These figures and descriptions were not independently confirmed for this assessment.

Lea la fuente principal: securitybrief.asia

Por qué es importante

AI security assessments increasingly involve more than testing a model in isolation. A formal accreditation could give organisations a clearer procurement and supplier-due-diligence signal, although the report does not independently establish how widely the scheme will be adopted or whether it will improve testing outcomes.

The practical significance is that AI testing is becoming a procurement and governance problem, not only a technical one. A company commissioning an assessment may need confidence that a vendor understands prompt manipulation, retrieval risks, tool access, data handling, memory, orchestration and downstream effects. SecurityBrief Asia reports that CREST’s framework is designed to make those capabilities assessable. If buyers use the accreditation as one part of supplier due diligence, it could make provider claims easier to compare.

The whole-system emphasis is also consequential. Testing only a model’s responses may miss weaknesses in the application around it: an instruction hierarchy may be exposed, a retrieval source may be poisoned, a connected tool may have excessive permissions, or an output may trigger an unsafe downstream action. The source does not report any specific vulnerability or test result from the new scheme, so it does not demonstrate that the framework has found or prevented such failures. It reports the scope and intended assurance function of the accreditation.

The framework could also influence what providers document. SecurityBrief Asia says CREST will assess governance, quality controls, processes and evidence as well as technical skill. That emphasis may encourage firms to explain how test cases are selected, how findings are validated, how limitations are recorded and how conclusions are supported. For customers, this could be more useful than a bare claim that a provider has experience with AI. The report does not state the scoring method, pass threshold, reassessment cycle or public availability of assessment reports.

The distinction between the July AI-Enabled Penetration Testing standard and this new accreditation is important. One concerns the use of AI by a testing provider; the other concerns the provider’s ability to test AI systems. Those activities can involve different risks and competencies. A firm might use AI to accelerate conventional security work without being qualified to assess model behavior, retrieval pipelines or agent-like tool integrations. Conversely, an AI-testing accreditation would not by itself prove that every engagement is well scoped or that a particular deployment is secure.

The public impact remains uncertain because the source contains no independent buyer, regulator or academic assessment. The reported support from CREST members shows that participating providers see value in the scheme, but it does not establish market acceptance. Nor does the article show that accreditation reduces incidents, improves vulnerability discovery or produces consistent results across providers. Those unknowns should temper any claim that the launch establishes a new industry-wide quality bar.

Qué ver a continuación

The key questions are whether buyers require the accreditation, how CREST evaluates providers in practice, and whether the standard produces comparable testing quality across vendors. The report does not provide the full standard, assessment results, implementation timetable or independent responses from buyers and regulators.

The first issue to watch is adoption by buyers. SecurityBrief Asia identifies procurement and supplier due diligence as central goals, but it does not report whether major organisations require the accreditation in tenders or contracts. Evidence that buyers use it to distinguish providers would show that the scheme has become more than a voluntary professional credential. Without buyer uptake, the accreditation may primarily serve as a signal within the cybersecurity-services market.

The second issue is transparency about assessment. The report names broad areas of evaluation but does not provide the standard’s detailed controls, test procedures, evidence requirements or pass criteria. Observers should look for information about how CREST examines provider competence, how often accreditation is renewed, how conflicts of interest are managed and whether failed or restricted assessments are disclosed. These details would help determine how much confidence the accreditation can reasonably support.

The third issue is technical coverage. AI deployments vary widely, from simple language-model features to systems with retrieval, memory, external tools, APIs and automated downstream actions. CREST’s reported whole-system scope is broad, but the article does not explain how assessments will handle differences in architecture, model access, data sensitivity or operational impact. Future guidance or published case studies could show whether the standard is practical across these settings rather than merely comprehensive in description.

The fourth issue is outcome evidence. CREST members quoted in the report say the framework could create consistency and strengthen trust, but those are expectations rather than measured findings. Useful follow-up evidence would include anonymised assessment results, examples of AI-specific weaknesses discovered through accredited testing, or comparisons showing that accredited providers produce more reliable findings. None of that evidence is present in the source, and the launch should not be treated as proof of improved security.

Finally, the relationship with other AI-security frameworks will matter. The article describes CREST’s own AI assurance programme but does not discuss how its accreditation aligns with government guidance, sector-specific rules or other testing standards. Buyers may need to combine it with risk assessments, secure development practices, access controls, monitoring and human review. SecurityBrief Asia reports the launch and its intended role; it does not independently confirm the programme’s eventual reach, effectiveness, regulatory recognition or timetable for provider assessments.

Guías y cuestionarios relacionados

Ética de la IAAgentes de IAModelos de IA explicadosChatGPT y LLMPon a prueba lo que sabes: prueba un cuestionario gratuito sobre IABusque un término de IA en nuestro glosario
¿Encontró esto útil?