REDSECLABS Joins First Cohort of CREST AI-Enabled Penetration Testing Providers
REDSECLABS is one of 10 cybersecurity companies in the first group to achieve CREST accreditation for the responsible use of AI in penetration testing.
LONDON, United Kingdom, 3 September 2026 — REDSECLABS has become one of the first organisations accredited by CREST for AI-Enabled Penetration Testing.
The company is part of the first cohort to achieve the new accreditation, which assesses how AI is used within the delivery of professional penetration testing services.
CREST introduced the AI-Enabled Penetration Testing accreditation in July 2026 as AI became increasingly common in security testing workflows. The requirements cover areas including AI governance, oversight, transparency and the controls organisations have in place when using AI as part of penetration testing.
For REDSECLABS, the accreditation formalises an approach the company has already been developing within its offensive security work: using AI to support testers while keeping experienced security professionals responsible for validation, decisions and final findings.
AI is already changing how penetration testing is done. At REDSECLABS, we use it where it genuinely helps our testers cover more ground and look at systems from more angles. The findings still have to stand up to human review and judgment.
"What I like about the CREST accreditation is that clients don’t simply have to take our word for it. There is now an independent standard behind how we use AI in real engagements", said Rafay Baloch, Founder & CEO, REDSECLABS
AI in practical penetration testing
REDSECLABS uses AI selectively within its testing workflow, including areas such as reconnaissance, analysis, vulnerability enumeration and supporting the review of larger volumes of technical information.
The aim is not to automate away the penetration tester. It is to give experienced testers better tools for examining increasingly complex environments.
Human testers remain responsible for determining whether a potential issue is genuine, understanding its security impact and deciding how it should be reported to the client.
This is particularly important where automated tools can produce false positives, miss business-logic weaknesses or fail to understand the wider context in which a vulnerability could be exploited.
Independent assurance for clients
The CREST accreditation gives organisations an independent way to assess whether a penetration testing provider has appropriate controls around its use of AI.
For clients, particularly those operating in regulated or security-sensitive environments, that provides greater visibility into how AI is being incorporated into an assessment and how its output is governed and reviewed.
It also provides a clearer distinction between simply using AI tools and operating them as part of a defined, professionally supervised security testing process.
REDSECLABS will continue developing its AI-assisted testing capabilities as the technology evolves, while maintaining human oversight and the technical standards required for professional penetration testing.
About REDSECLABS
REDSECLABS is a London-headquartered cybersecurity consulting and offensive security company providing penetration testing, red teaming, application and API security testing, cloud security assessments and security compliance services.
The company works with organisations to identify and address security weaknesses across applications, infrastructure and cloud environments.
For more information, visit www.redseclabs.com.
About CREST
CREST is a global not-for-profit organisation that develops accreditation standards and professional qualifications for the cybersecurity industry. Its accreditation frameworks are designed to help organisations identify providers that meet recognised standards for technical capability, professional practice and governance.
For more information, visit www.crest-approved.org.