Techno Time

CREST brings a new AI assurance agenda to FDC Summit 2026

Thursday 20 August 2026 11:58
CREST brings a new AI assurance agenda to FDC Summit 2026

Artificial intelligence is changing cybersecurity services faster than many assurance frameworks were designed to handle.

Penetration testers are using AI to accelerate reconnaissance, reporting and vulnerability analysis, security operations teams are automating investigations, and service providers are increasingly embedding generative and agentic AI into workflows that were once entirely human-led.

The technology may be moving quickly, but trust is becoming harder to measure.

That is the gap CREST is preparing to address at FDC Summit 2026, where the international cybersecurity accreditation body will participate as a Strategic Partner from September 22 to 24.

Unlike most participants in the summit, CREST is not arriving with a security platform or a portfolio of cybersecurity products.

Its role is built around something different: defining whether the companies delivering cybersecurity services can demonstrate the technical capability, governance and professional standards required to be trusted.

And in 2026, artificial intelligence has moved directly into that discussion.

A new accreditation for AI-enabled cybersecurity

CREST made one of its most significant moves of the year on July 28, launching its first accreditation framework specifically designed for cybersecurity providers using AI in the delivery of their services.

The new framework adds a Responsible AI Use domain to CREST’s general accreditation requirements, covering governance, oversight, transparency and organizational accountability.

It also introduces a dedicated AI-Enabled Penetration Testing annex aimed at providers using artificial intelligence during penetration testing engagements.

More than 50 CREST members had already begun the process of demonstrating compliance with the new requirements when the accreditation was launched.

The timing makes the initiative particularly relevant to FDC Summit.

AI is increasingly being used by cybersecurity companies to make services faster and more scalable, but customers may have little visibility into how those systems operate or how much human oversight remains involved.

CREST is attempting to create an independent benchmark for that question.

AI is already inside penetration testing

CREST’s own research shows that artificial intelligence is no longer experimental inside professional cybersecurity services.

Its 2026 global study into AI use in penetration testing found that 47% of organizations were using AI for reporting, while 44% were applying it to vulnerability scanning and enumeration.

However, only 9% reported using autonomous, agent-based penetration testing, suggesting that the industry remains cautious about allowing AI to take over higher-risk parts of the testing process.

That distinction is important.

AI can help a penetration tester process information faster, draft reports or identify potential vulnerabilities, but fully autonomous testing introduces additional questions around authorization, accuracy and accountability.

A false positive in an AI-generated report may create confusion.

An autonomous system incorrectly interacting with a production environment could create a much more serious problem.

CREST’s position is therefore not that AI should replace cybersecurity professionals, but that its use needs to remain governed and independently verifiable.

Human judgment is still part of the equation

The organization’s research found that providers are adopting AI most heavily for supporting tasks such as reconnaissance, analysis and reporting, while retaining stronger human involvement in areas where professional judgment and risk are higher.

That makes the emerging model very different from the idea of completely autonomous cybersecurity.

Instead, AI is becoming another capability inside a professional service.

The challenge for customers is determining whether a provider is using that capability responsibly.

Who validates AI-generated findings?

How is sensitive client information handled?

Which models are being used?

What happens when the AI produces an incorrect recommendation?

And who remains accountable for the final decision?

These are increasingly procurement questions rather than purely technical ones.

CREST is expanding beyond penetration testing

AI assurance is only one part of a wider expansion taking place inside CREST’s accreditation framework.

During 2026, the organization introduced or updated standards covering Cyber Threat Intelligence, Threat Intelligence for Simulated Attack, Threat-Led Penetration Testing, Incident Response, Security Operations, Vulnerability Assessment and Security Architecture.

In April, CREST launched a new accreditation specifically for Security Architecture, responding to growing demand for independent validation that organizations can design security into complex environments rather than add controls only after systems are deployed.

The broader direction is clear.

As cybersecurity becomes more specialized, companies buying services need a way to distinguish between marketing claims and independently assessed capability.

That issue becomes even more important as AI makes it easier for providers to automate parts of their services and potentially present similar capabilities without the same level of expertise behind them.

Governments and internal security teams are now part of the model

Another notable development arrived in August.

CREST issued new guidance allowing cybersecurity teams operating inside enterprises and government organizations to pursue accreditation against the same underlying standards applied to external service providers.

The guidance covers internal capabilities including penetration testing, SOC operations, threat intelligence, incident response, vulnerability assessment and security architecture.

This could make CREST’s presence at FDC particularly relevant to government and critical infrastructure organizations.

Many large institutions now operate their own security operations centers and internal testing teams rather than outsourcing every cybersecurity function.

Independent assurance can therefore apply not only to the supplier an organization hires, but to the security capability it has built internally.

That aligns closely with FDC Summit’s broader focus on strengthening digital infrastructure and national cyber resilience.

Cybersecurity procurement is becoming a security issue itself

CREST has also been targeting another persistent problem: choosing the right cybersecurity provider.

In March, it launched the CREST Marketplace, a platform designed to give organizations a clearer way to identify and compare accredited cybersecurity service providers.

The logic behind the platform reflects a problem familiar to many cybersecurity buyers.

The market contains thousands of vendors and service providers, all using similar language around expertise, advanced threats and cutting-edge capabilities.

For a company or government organization without deep internal expertise, separating real capability from marketing can be difficult.

CREST attempts to insert independent assurance into that procurement process.

This becomes even more relevant as AI lowers the barrier to producing sophisticated-looking cybersecurity services while simultaneously increasing the complexity of assessing how those services are delivered.

What CREST could bring to FDC Summit 2026

CREST’s participation gives FDC Summit a dimension that differs from the technology demonstrations offered by vendors.

Its central question is not which AI-powered cybersecurity tool is more advanced.

It is how organizations can know whether the companies using those tools are competent, accountable and operating them responsibly.

The answer is becoming particularly important as AI enters penetration testing, Security Operations Centers, incident response and threat intelligence.

CREST says further AI assurance requirements are already planned for areas including security testing of AI, Security Operations, Incident Response, Threat Intelligence and Threat-Led Penetration Testing.

That means the accreditation model itself is beginning to evolve alongside the technology.

At FDC Summit 2026, CREST may therefore bring one of the event’s less visible but increasingly important cybersecurity conversations to the table.

As AI makes security services faster and more automated, organizations will need something technology alone cannot provide.

Proof that they can still be trusted.