OWASP APTS Compliance Checklists

Informative Appendix (non-normative)

This appendix is part of the OWASP Autonomous Penetration Testing Standard (APTS). It organizes all 173 tier-required requirements by domain and compliance tier so that platform operators (vendors, service providers, and enterprise security teams) and customers can quickly identify what must be satisfied for each tier within each domain. All requirements referenced here are defined in the domain READMEs, which are the authoritative source. Advisory practices (identifiers of the form APTS-<DOMAIN>-A0x) live in the Advisory Requirements appendix and are not included in tier conformance.

How to use: For your target compliance tier, satisfy all requirements at that tier and all lower tiers within each domain. Tier 2 includes all Tier 1 requirements; Tier 3 includes all Tier 1 and Tier 2 requirements.

Notation: Each requirement is marked MUST (mandatory) or SHOULD (recommended). Both MUST and SHOULD requirements must be satisfied for tier conformance. No partial credit.


1. Scope Enforcement (SE) --- 26 Requirements

Tier 1 (9 Requirements)

Tier 2 (16 Requirements)

Tier 3 (1 Requirement)


2. Safety Controls & Impact Management (SC) --- 20 Requirements

Tier 1 (6 Requirements)

Tier 2 (12 Requirements)

Tier 3 (2 Requirements)


3. Human Oversight & Intervention (HO) --- 19 Requirements

Tier 1 (13 Requirements)

Tier 2 (6 Requirements)


4. Graduated Autonomy Levels (AL) --- 28 Requirements

Tier 1 (11 Requirements)

Tier 2 (9 Requirements)

Tier 3 (8 Requirements)


5. Auditability & Reproducibility (AR) --- 20 Requirements

Tier 1 (7 Requirements)

Tier 2 (12 Requirements)

Tier 3 (1 Requirement)


6. Manipulation Resistance (MR) --- 23 Requirements

Tier 1 (13 Requirements)

Tier 2 (9 Requirements)

Tier 3 (1 Requirement)


7. Third-Party & Supply Chain Trust (TP) --- 22 Requirements

Tier 1 (10 Requirements)

Tier 2 (11 Requirements)

Tier 3 (1 Requirement)


8. Reporting (RP) --- 15 Requirements

Tier 1 (3 Requirements)

Tier 2 (10 Requirements)

Tier 3 (2 Requirements)


Summary

Domain Tier 1 Tier 2 Tier 3 Total
Scope Enforcement (SE) 9 16 1 26
Safety Controls (SC) 6 12 2 20
Human Oversight (HO) 13 6 0 19
Graduated Autonomy (AL) 11 9 8 28
Auditability (AR) 7 12 1 20
Manipulation Resistance (MR) 13 9 1 23
Supply Chain Trust (TP) 10 11 1 22
Reporting (RP) 3 10 2 15
Total 72 85 16 173

Tier 1 + Tier 2 + Tier 3 = 173 tier-required requirements. Advisory practices are documented separately in the Advisory Requirements appendix and do not count toward any tier.