Certification · Hands-on exam

ACIP

Attify Certified IoT Pentester

Validate your ability to assess a connected IoT ecosystem, demonstrate impact, and produce a professional report under exam conditions.

2 hrsTechnical window · live lab
48 hrsWriteup submission window
3 tiersPractitioner · Specialist · Expert
70 / 30Technical / writeup weighting

01 — What ACIP certifies

A performance signal, not a tool certification.

ACIP certifies that you can find, validate and communicate vulnerabilities across the full IoT attack surface: hardware artifacts, firmware, wireless protocols, web interfaces and networked infrastructure.

This is not a multiple-choice test. It is a performance signal for people who need to prove they can assess connected-device environments and communicate results to decision makers. One exam, one price. Your performance determines your tier.

02 — How the exam works

Two phases. One private assessment environment.

You receive an engagement brief, a prepared browser-based workstation with no internet egress, and representative evidence artifacts. Targets, topology and objective paths are revealed only in the brief.

Phase 1 · 2-hour technical window

Browser-based workstation, no internet egress.

A private assessment environment with connected systems, realistic dependencies and exam-specific evidence artifacts. Pre-configured with the required tools: firmware utilities, network tooling, protocol analysis, scripting environments.

Phase 2 · 48-hour writeup window

Finalize and submit the professional writeup.

Findings, methodology, evidence, impact analysis and remediation guidance. AI tools may be used for cross-checking and polishing; you remain responsible for originality and technical correctness. About 30% of your score.

03 — Domains assessed

Six domains that mirror a real IoT engagement.

D1

Reconnaissance & hardware artifacts

Interpret logs, dumps, images and captures from a connected-device engagement. Turn early evidence into an assessment plan.

D2

Firmware analysis

Extract, inspect and reason about embedded firmware to recover evidence and connect device behavior to system risk.

D3

Radio & protocol analysis

Understand what the traffic means, where trust breaks down, and how protocol findings affect impact.

D4

Live exploitation

Move from discovery to demonstrated access. Validate findings in a live environment, not just describe them.

D5

Post-exploitation & impact

Reason across connected systems and show why a finding matters. Attack-chain thinking over isolated wins.

D6

Professional reporting

The report a client or hiring manager can trust: clear findings, reproducible evidence, realistic impact, actionable remediation.

04 — Evaluation

Scored on what you demonstrated, not what you intended.

~70% TECHNICAL OBJECTIVES
~30% WRITEUP

Technical objectives are verified from your submitted evidence and methodology. Not all objectives carry the same weight. Every candidate gets a unique assessment instance.

Writeup quality is graded on clarity, technical correctness, impact articulation and remediation. You must meet the minimum on both dimensions or you do not certify.

Tier 1

ACIP Practitioner

Solid fundamentals across the IoT attack surface. Clear methodology and adequate evidence discipline.

Tier 2

ACIP Specialist

Demonstrated depth, effective attack chaining across connected systems, client-ready reporting.

Tier 3

ACIP Expert

Comprehensive mastery, full attack chain completion, professional-grade deliverables and exceptional methodology.

05 — What ACIP signals

Readable by employers, security leaders and clients, not just candidates.

ReaderWhat ACIP helps them evaluate
CandidatesWhether they can demonstrate practical IoT assessment capability under exam conditions.
EmployersWhether a practitioner can work across hardware artifacts, firmware, wireless protocols, exploitation, impact and reporting.
Security leadersWhether a team member can produce evidence-backed findings and communicate risk clearly.
ClientsWhether the credential holder has been assessed on realistic connected-device work, not only theory or tool familiarity.

06 — AI tools and FAQ

Tool output is not a substitute for demonstrated understanding.

The exam workstation has no internet access. Your evidence must come from your own investigation. In the writeup window, AI tools may be used to cross-check and polish.

  • Do I need special hardware or software?

    A modern browser and a stable connection. The workstation is accessed via noVNC with all assessment tooling pre-installed.

  • What if I don't pass?

    You receive specific feedback on the objectives and report areas that need work. Retakes are $129 after a 6-month waiting period.

  • How should I prepare?

    Complete Offensive IoT Exploitation or build equivalent hands-on skills. The exam does not teach; it certifies.

  • How long is it valid?

    Two years from issue. Passing candidates receive a verifiable digital badge for LinkedIn and professional profiles.

07 — Pricing

One exam. One price. Or bundle it with training, or go All-Access.

Every option includes one exam attempt, results and feedback within 72 hours, a session recording, and a verifiable digital badge valid for 2 years. Retakes are $129 after a 6-month waiting period.

Exam $449

One attempt in a live environment. For people who already have the skills.

Exam + course videos $1,349

Offensive IoT Exploitation program plus the exam. The recommended path.

All-Access pass · per year $2,000

Every live Attify track, anything that ships during your paid year, and one certification attempt. Founders' price, locked while you renew.

Get All-Access