IT Brief New Zealand - Technology news for CIOs & IT decision-makers
New Zealand
CREST launches AI testing standard for cyber firms

CREST launches AI testing standard for cyber firms

Tue, 25th Aug 2026 (Today)
Mark Tarre
MARK TARRE News Chief

CREST has launched a Security Testing of AI standard and accreditation for cybersecurity service providers, aimed at giving buyers independent assurance over providers testing Generative AI- and large language model-enabled systems.

The accreditation sets assessable requirements for providers that test AI systems used in applications, workflows, products, and business processes. It is intended to address a market gap, as organisations adopting AI have lacked a recognised way to judge whether a testing provider has the necessary expertise.

Under the framework, providers are assessed on technical expertise, practitioner competence, testing methodologies, governance, quality controls, tooling, processes for identifying AI-specific security risks, and the evidence used to support testing conclusions. For customers, this is intended to provide a clearer basis for procurement and supplier due diligence.

Nick Benson, Chief Executive Officer at CREST International, said the scheme was shaped by feedback from members and their clients as AI systems moved into wider use.

"This latest addition to our new AI range of standards and accreditations was specifically curated to respond to an emerging market need. Our membership told us very clearly that as their clients deployed AI-enabled tech, they required more information on their AI testing credentials. Offering 'security testing of AI systems' and demonstrating the ability to deliver it effectively are two different things. Buyers need to know that the providers assessing their AI have the right expertise and methodologies. Providers now have a way to develop their policies in line with our standard and demonstrate their technical capabilities through independent assessment, giving buyers that all-important confidence to proceed," Benson said.

Whole system

The standard is built on the view that AI security testing should cover the entire system, not just the underlying model. That means the scope extends to applications, prompts and system instructions, retrieval mechanisms, data sources, memory, tools, plugins, APIs, orchestration layers, and downstream systems affected by AI outputs.

The approach reflects a broader shift in cyber risk as AI becomes embedded in operational systems. By focusing on the wider environment around a model, the standard aims to address attack surfaces that can emerge from integration points and supporting infrastructure, as well as from the model itself.

The accreditation also builds on CREST's existing Penetration Testing Accreditation. Providers must already hold that accreditation, or apply for it alongside the new AI testing approval, linking the standard to an established baseline for testing services.

Growing adoption

Recent research cited by CREST points to rapid AI uptake across cybersecurity providers. According to the research, 69% of penetration testing providers already use AI, and 76% have increased their use over the past year.

That growth has led CREST to expand its AI assurance work. In July, it introduced an AI-Enabled Penetration Testing standard covering how a provider uses AI in delivering testing services. The new accreditation differs by assessing whether a provider can test AI systems themselves.

Industry members said the framework could bring more consistency to a fast-moving area where methods and claims often vary.

"CREST's standards turn responsible AI from a promise into something that can be evidenced and assessed. We believe this will strengthen buyer confidence, reward credible providers, and set a higher bar for the profession, which is why we intend to pursue accreditation," Reed said.

Tim Reed is Technical Director at Sentrium Security, a CREST member.

Another member company also backed the move.

"CREST's new standard provides a clear, independently verified framework that will help create consistency, strengthen assurance, and build trust in both the testing process and the wider use of AI-enabled cybersecurity services," Chalençon said.

Yann Chalençon is Head of Cyber Security Services at wizlynx group, which is also a CREST member.

Broader programme

The launch forms part of CREST's wider AI assurance programme, which also includes an AI Charter and AI Principles. More than 100 founding signatory cybersecurity organisations have publicly committed to supporting the responsible use of AI across industry services, representing more than 10% of its worldwide membership.

Established in 2006, CREST is a global not-for-profit body focused on standards and accreditation in cybersecurity. It works with member companies, practitioners, governments, regulators, and industry groups. The new AI testing standard was developed in collaboration with the sector through its AI Working Group.

For buyers of cybersecurity services, the key question is whether the market will accept independent accreditation as a useful filter in a field where demand is rising quickly but technical claims can be hard to verify. For providers, the standard creates a route to formal assessment at a time when clients are asking more detailed questions about how AI systems are tested and secured.

The scheme requires providers to show evidence not only of technical skill but also of the processes and controls behind their work, placing as much scrutiny on how findings are reached as on the findings themselves.