No. Microsoft does not publish a dedicated penetration testing report or third-party penetration test certificate specifically for Dynamics CRM/Dynamics 365 Customer Engagement 9.1 On-Premises that customers can use as evidence for go-live.
This is because Dynamics 365 CRM 9.1 On-Premises is customer-hosted. Microsoft secures the application itself, but the overall security depends on how the customer deploys and configures the infrastructure (Windows Server, SQL Server, IIS, Active Directory, ADFS/IFD, firewalls, reverse proxies, TLS configuration, etc.). Therefore, Microsoft does not certify the security of an individual on-premises deployment.