APTS is a governance framework for the behavior of autonomous pentest platforms and a compliance baseline for vendors, MSSPs and enterprises — not a how-to for pentesting, not a replacement for PTES, WSTG or OSSTMM, and not a tool or vendor ranking. While PTES describes the seven phases of a pentest and WSTG catalogs web testing techniques, APTS addresses the platform's properties: scope enforcement, safe autonomy, accountability, decision trails and audit isolation for AI-driven systems. The standard is published as an OWASP project in Version 0.1.0 (licensed under CC BY-SA 4.0) and is freely available via the OWASP project page and GitHub.
OWASP APTS: Autonomous Penetration Testing Standard
AI-driven pentest platforms increasingly execute attack chains on their own — the OWASP Autonomous Penetration Testing Standard (APTS) is the first governance framework built for exactly that: 173 requirements, 8 domains, 3 compliance tiers, 4 autonomy levels.
173tier-required requirements in three cumulative compliance tiers
8domains — from Scope Enforcement (26) to Reporting (15)
72requirements form the Tier 1 Foundation baseline
4autonomy levels: L1 Assisted to L4 Autonomous
The OWASP Autonomous Penetration Testing Standard (APTS, Version 0.1.0, OWASP Foundation, licensed under CC BY-SA 4.0) is a governance standard for autonomous and AI-assisted penetration testing platforms. It defines what such systems must deliver to operate safely, transparently and within defined boundaries — regardless of whether the platform is run as a vendor product, as-a-service or in-house. APTS is explicitly not a testing methodology: it replaces neither PTES nor OWASP WSTG or OSSTMM, but complements them with what those standards do not cover — the platform's behavior during execution, from scope enforcement through kill switch and audit trails to manipulation resistance. The 173 tier-required requirements are spread across 8 domains and staged in three cumulative compliance tiers; a four-level autonomy model (L1–L4) couples the degree of autonomy to the required assurance level. The standard is relevant for vendors, MSSPs, enterprise security teams, procurement and auditors — and from a regulatory perspective, because its controls map to the EU AI Act, ISO/IEC 42001, NIS2 and DORA.
The Essentials at a Glance
Six topic blocks — tap to expand.
Four autonomy levels: L1 to L4
As autonomy increases, so do the assurance requirements — no jump from manual to fully autonomous. Tap a level.
- The human plans and executes, the platform makes suggestions — for example a vulnerability scan with recommendations.
Vulnerability scanRecommendations
- The platform plans, the human approves every step — guided exploitation with approval gates.
- In practice, L2 is sufficient for many organizations: what matters is not how autonomous a platform can be, but how autonomous it needs to be for the specific use case.
Guided exploitationApproval gates
- The platform plans and executes, the human monitors — autonomous recon with supervised exploitation.
Autonomous reconSupervised exploitation
- End-to-end autonomous operation, for example as a continuous autonomous red team.
- The standard's core principle: as autonomy increases, so do the assurance requirements — L4 is only defensible with Tier 3 evidence.
Continuous autonomous red teamTier 3 evidence
Standards & Sources
The content on this page is based on the following publicly available guides and studies.
OWASP Autonomous Penetration Testing Standard (APTS)
Version 0.1.0, licensed under CC BY-SA 4.0 (as of July 2026): 173 tier-required requirements across 8 domains, 3 compliance tiers and 4 autonomy levels; available via the OWASP project page and github.com/OWASP/APTS.
EU AI Act — Verordnung (EU) 2024/1689
Regulatory anchor for APTS: risk management (Art. 9), logging (Art. 12), Human Oversight (Art. 14) as well as accuracy and robustness (Art. 15) map to the APTS domains.
ISO/IEC 42001:2023 — AI Management System
Management system standard for AI; APTS controls serve as a control baseline for operational controls, performance monitoring and supply chain.
NIS2 — Richtlinie (EU) 2022/2555
Risk management under Art. 21 and supply chain security under Art. 21(2)(d) draw on the APTS domains SE, SC, MR and TP for autonomous testing components.
DORA — Verordnung (EU) 2022/2554
Threat-led penetration tests (TLPT), ICT third-party risk management and the testing program under Art. 24–27 can be verifiably underpinned with APTS-compliant platforms.
Related Services
Deploy autonomous pentesting with governance
VamiSec supports you along the entire APTS lifecycle: gap assessment against all 8 domains, vendor due diligence, integration into ISO 27001 and ISO 42001, regulatory mapping, as well as classic and AI-assisted penetration tests with a verifiable audit trail.