News

ImmuniWeb Earns CREST AI-Enabled Penetration Testing Accreditation 2026

News | 11.09.2026

Organizations increasingly ask a difficult question: can AI-driven penetration testing be trusted to meet regulatory, contractual and data protection requirements? Without an independent standard, buyers had no reliable way to separate marketing claims from verified, safe and compliant use of AI in offensive security. The new CREST accreditation for AI-Enabled Penetration Testing directly addresses that gap, and ImmuniWeb is among the first providers to pass it.

What was announced

On September 9, 2026, ImmuniWeb announced that it has been accredited by CREST for AI-Enabled Penetration Testing. The company is among the first 10 organizations worldwide to receive this brand-new accreditation, launched by CREST in July 2026 after a thorough verification of AI technology, people and processes.

ImmuniWeb has been developing its award-winning AI-enabled penetration testing technology since 2019 and holds nearly 100 international awards. The company already operates as a CREST-accredited provider of traditional penetration testing services and now extends this status to AI-enabled delivery on the international market.

While we have been successfully using our proprietary AI models to intelligently automate and accelerate penetration testing for over eight years, we are delighted to be among the first companies accredited to provide AI-enabled penetration testing in a regulated, compliant and safe manner

Dr. Ilia Kolochenko, Chief Architect and CEO at ImmuniWeb

Why this matters

For CIOs, CISOs, IT directors and procurement leaders, the accreditation provides an independent benchmark. It confirms that a vendor uses AI responsibly, securely and appropriately within penetration testing engagements, aligning with data protection laws and industry regulations that increasingly scrutinize algorithmic tooling.

The accreditation also formalizes a balanced delivery model. Instead of positioning AI as a replacement for human testers, ImmuniWeb combines proprietary AI models with skilled cybersecurity professionals who supervise automated tasks. This approach preserves the predictability, reliability and quality that regulators and enterprise buyers expect while lowering the total cost of security testing.

Technical details

  • Accreditation body: CREST, an international not-for-profit representing the global cyber security industry with over 500 accredited member companies.
  • Scheme launch: AI-Enabled Penetration Testing accreditation introduced by CREST in July 2026.
  • Assessment scope: independent requirements for responsible, secure and appropriate use of AI within penetration testing services, covering technology, people and processes.
  • ImmuniWeb standing: among the first 10 accredited providers worldwide and an existing CREST-accredited penetration testing provider.
  • Delivery model: proprietary AI models combined with human expert supervision for advanced security testing.
  • Track record: AI-enabled penetration testing in production since 2019, with customers and partners across more than 70 countries.

Softprom and ImmuniWeb

Softprom is the official distributor of ImmuniWeb. Organizations that need CREST-accredited AI-enabled penetration testing, application security assessments or continuous attack surface management can request scoping, pricing and technical guidance through Softprom.

This content was prepared as part of the Softprom DistriFlow project — an automated system for monitoring and adapting vendor news. Original source: original article.