Offensive security certifications
Which cert, and how to actually pass it. Exam format, what it really costs, how hard it actually is, and what the report has to look like — for all 19 of them. Written by people who sat them.

Choosing a certification
Which one first?
OSCP is not automatically the answer, and for a lot of people it is the wrong first exam. See the sequencing →
The method, not the box
Enumeration and Active Directory references that hold across every one of these exams. Open the references →
The report decides it
Most of these exams are graded on a professional report, and most failures are report failures. How grading works →
Certification vendors
Eight vendors, and they do not test the same way. Picking a vendor is most of the decision — their exam style follows you through every certification in the ladder.
Exam formats and how long each one takes
These exams are not two-hour multiple-choice papers. The shortest is under four hours; the longest keeps you working for ten days and then grades the document you write about it.

Every certification we cover
Network penetration testing
| Cert | Vendor | Level | Exam |
|---|---|---|---|
| EJPT eLearnSecurity Junior Penetration Tester | INE | entry | 48-hour exam |
| CPTS HTB Certified Penetration Testing Specialist | Hack The Box | intermediate | 10-day window |
| PNPT Practical Network Penetration Tester | TCM Security | intermediate | 5-day exam + 2-day report + live debrief |
| OSCP OffSec Certified Professional | OffSec | advanced | 23h 45m + 24h report |
| CPENT Certified Penetration Testing Professional | EC-Council | advanced | 24h exam (2x12h or 1x24h) + 7-day report |
| OSEP OffSec Experienced Penetration Tester | OffSec | expert | 47h 45m + 24h report |
Web application security
Red teaming & Active Directory
| Cert | Vendor | Level | Exam |
|---|---|---|---|
| CRTP Certified Red Team Professional | Altered Security | intermediate | 24-hour exam + report |
| CRTO Certified Red Team Operator | Zero-Point Security | advanced | 48h runtime across a 4-day window |
| CRTE Certified Red Team Expert | Altered Security | advanced | 48-hour exam + report |
| CARTP Certified Azure Red Team Professional | Altered Security | advanced | 24-hour exam + report |
Defensive & SOC analysis
Exploit development
| Cert | Vendor | Level | Exam |
|---|---|---|---|
| OSED OffSec Exploit Developer | OffSec | expert | 47h 45m + 24h report |
Wireless
| Cert | Vendor | Level | Exam |
|---|---|---|---|
| OSWP OffSec Wireless Professional | OffSec | entry | 3h 45m + 24h report |