Book an Appointment

OWASP APTS: Autonomous Penetration Testing Standard

AI-driven pentest platforms increasingly execute attack chains on their own — the OWASP Autonomous Penetration Testing Standard (APTS) is the first governance framework built for exactly that: 173 requirements, 8 domains, 3 compliance tiers, 4 autonomy levels.

Last updated: July 2026 · Valeri Milke, ISO 27001 & ISO 42001 Lead Auditor

173tier-required requirements in three cumulative compliance tiers
8domains — from Scope Enforcement (26) to Reporting (15)
72requirements form the Tier 1 Foundation baseline
4autonomy levels: L1 Assisted to L4 Autonomous

The OWASP Autonomous Penetration Testing Standard (APTS, Version 0.1.0, OWASP Foundation, licensed under CC BY-SA 4.0) is a governance standard for autonomous and AI-assisted penetration testing platforms. It defines what such systems must deliver to operate safely, transparently and within defined boundaries — regardless of whether the platform is run as a vendor product, as-a-service or in-house. APTS is explicitly not a testing methodology: it replaces neither PTES nor OWASP WSTG or OSSTMM, but complements them with what those standards do not cover — the platform's behavior during execution, from scope enforcement through kill switch and audit trails to manipulation resistance. The 173 tier-required requirements are spread across 8 domains and staged in three cumulative compliance tiers; a four-level autonomy model (L1–L4) couples the degree of autonomy to the required assurance level. The standard is relevant for vendors, MSSPs, enterprise security teams, procurement and auditors — and from a regulatory perspective, because its controls map to the EU AI Act, ISO/IEC 42001, NIS2 and DORA.

The Essentials at a Glance

Six topic blocks — tap to expand.

Four autonomy levels: L1 to L4

As autonomy increases, so do the assurance requirements — no jump from manual to fully autonomous. Tap a level.

Assisted
  • The human plans and executes, the platform makes suggestions — for example a vulnerability scan with recommendations.
Vulnerability scanRecommendations

Standards & Sources

The content on this page is based on the following publicly available guides and studies.

OWASP Foundation · 2026

OWASP Autonomous Penetration Testing Standard (APTS)

Version 0.1.0, licensed under CC BY-SA 4.0 (as of July 2026): 173 tier-required requirements across 8 domains, 3 compliance tiers and 4 autonomy levels; available via the OWASP project page and github.com/OWASP/APTS.

Europäische Union · 2024

EU AI Act — Verordnung (EU) 2024/1689

Regulatory anchor for APTS: risk management (Art. 9), logging (Art. 12), Human Oversight (Art. 14) as well as accuracy and robustness (Art. 15) map to the APTS domains.

ISO/IEC · 2023

ISO/IEC 42001:2023 — AI Management System

Management system standard for AI; APTS controls serve as a control baseline for operational controls, performance monitoring and supply chain.

Europäische Union · 2022

NIS2 — Richtlinie (EU) 2022/2555

Risk management under Art. 21 and supply chain security under Art. 21(2)(d) draw on the APTS domains SE, SC, MR and TP for autonomous testing components.

Europäische Union · 2022

DORA — Verordnung (EU) 2022/2554

Threat-led penetration tests (TLPT), ICT third-party risk management and the testing program under Art. 24–27 can be verifiably underpinned with APTS-compliant platforms.

Deploy autonomous pentesting with governance

VamiSec supports you along the entire APTS lifecycle: gap assessment against all 8 domains, vendor due diligence, integration into ISO 27001 and ISO 42001, regulatory mapping, as well as classic and AI-assisted penetration tests with a verifiable audit trail.