Cybersecurity organisation CREST has launched a new accreditation aimed at helping organisations assess whether providers have the expertise to test AI-enabled systems securely, as generative AI and large language models become embedded in business applications.
The Security Testing of AI standard sets independently assessable requirements for cybersecurity service providers, giving buyers a way to assess suppliers’ technical expertise, testing methodologies and governance.
CREST said the accreditation addresses a growing gap as AI moves from experimentation into applications, products and business processes. Buyers have had limited ways to distinguish providers with specialist AI security testing capabilities from those simply claiming expertise.
The standard assesses practitioner competence, testing methodologies, governance and quality controls, technical approaches and tooling, and processes for identifying and evaluating AI-specific security risks. Providers must also produce evidence supporting their testing conclusions.
The approach takes a system-level view of AI security rather than treating the underlying model as the only attack surface. Testing can encompass applications, prompts and system instructions, retrieval mechanisms, data sources, memory, tools, plugins, APIs, orchestration layers and downstream systems affected by AI-generated outputs.
That broader approach is increasingly relevant to connected products and services, where an AI model may sit alongside multiple applications, APIs, data sources and Cloud or Edge components.
CREST chief executive Nick Benson said the organisation’s members had identified a need for greater visibility into the AI testing credentials of cybersecurity providers.
“Offering security testing of AI systems and demonstrating the ability to deliver it effectively are two different things,” he said.
The accreditation is the latest element of CREST’s expanding AI assurance programme. In July, the organisation introduced an AI-Enabled Penetration Testing standard covering how providers use AI to deliver cybersecurity services. The latest standard instead focuses on their ability to test AI-enabled systems themselves.
CREST research cited in the announcement found that 69% of penetration testing providers already use AI, while 76% have increased their use of the technology over the past year.
CREST said the standards were developed with its AI Working Group and will continue to evolve as AI technologies and security risks change.
Existing CREST members and cybersecurity service providers can now apply for the Security Testing of AI accreditation. Providers must hold, or apply alongside it for, CREST’s Penetration Testing Accreditation.
There’s plenty of other editorial on our sister site, Electronic Specifier! Or you can always join in the conversation by commenting below or visiting our LinkedIn page.
