CREST launches standard to accredit providers testing AI and LLM-enabled systems

0

CREST has launched a new standard and accreditation aimed at assessing whether cybersecurity service providers can securely test generative AI and large language model (LLM)-enabled systems.

The Security Testing of AI standard is intended to give buyers “independently assessable requirements” for evaluating providers’ AI testing capability, addressing what CREST described as a gap in the market where organisations could not easily verify whether suppliers had the skills and methods they claimed.

Under the accreditation, providers are assessed across six areas: practitioner competence, testing methodologies, governance and quality controls, tooling and technical approaches, processes for identifying and evaluating AI-specific security risks, and the quality of evidence supporting testing conclusions.

Nick Benson, CEO of CREST, said the accreditation was created in response to customer demand for clearer credentials as clients deploy AI-enabled technology. “Offering ‘Security testing of AI systems’ and demonstrating the ability to deliver it effectively are two different things,” he said.

CREST said the standard is based on the principle that security testing should consider the broader AI system rather than treating the underlying model as the entire attack surface. It said testing should also account for surrounding components such as applications, prompts and system instructions, retrieval mechanisms, data sources, memory, tools and plugins, APIs, orchestration layers, and downstream systems influenced by AI outputs.

The new accreditation follows CREST’s AI-Enabled Penetration Testing standard announced in July, which focuses on how testing providers use AI in service delivery. By contrast, the Security Testing of AI accreditation is intended to validate providers’ capability to test AI systems themselves.

CREST cited recent research indicating 69% of penetration testing providers already use AI, and 76% have increased their AI usage over the past year.

Tim Reed, technical director at UK-based CREST member Sentrium Security Limited, said CREST’s standards “turn responsible AI from a promise into something that can be evidenced and assessed,” and said the company intends to pursue accreditation.

Yann Chalençon, head of cyber security services at Switzerland-based CREST member wizlynx group, said the standard provides an independently verified framework aimed at improving consistency and assurance in AI-related testing.

Applications are open to existing CREST members and external cybersecurity providers. CREST said the Security Testing of AI accreditation builds on its Penetration Testing Accreditation, which organisations must hold or apply for alongside the new accreditation.

Share.