19 certifications · 8 vendors

Offensive security certifications

Which cert, and how to actually pass it. Exam format, what it really costs, how hard it actually is, and what the report has to look like — for all 19 of them. Written by people who sat them.

A chart of 19 offensive-security certifications arranged in six rows by discipline — network penetration testing, web application security, red teaming and Active Directory, defensive and SOC analysis, exploit development, and wireless — and four columns by level from entry to expert.
Pick the lane first, then the level. Levels are relative to each other, not to job titles.

Choosing a certification

Choosing

Which one first?

OSCP is not automatically the answer, and for a lot of people it is the wrong first exam. See the sequencing →

Preparing

The method, not the box

Enumeration and Active Directory references that hold across every one of these exams. Open the references →

Passing

The report decides it

Most of these exams are graded on a professional report, and most failures are report failures. How grading works →

Certification vendors

Eight vendors, and they do not test the same way. Picking a vendor is most of the decision — their exam style follows you through every certification in the ladder.

EC-Council1 certification
INE1 certification
PortSwigger1 certification
TCM Security1 certification
Zero-Point Security1 certification

Exam formats and how long each one takes

These exams are not two-hour multiple-choice papers. The shortest is under four hours; the longest keeps you working for ten days and then grades the document you write about it.

A bar chart comparing hands-on time against report-writing time for 17 certifications. CPTS is ten days split evenly between hands-on and reporting; OSCP is 23 hours 45 minutes hands-on followed by a 24-hour report window; BSCP and OSWP are under four hours.
Hands-on time against reporting time. The report window is not a formality — it is graded, and it is where most people lose the exam.

Every certification we cover

Network penetration testing

CertVendorLevelExam
EJPT
eLearnSecurity Junior Penetration Tester
INEentry48-hour exam
CPTS
HTB Certified Penetration Testing Specialist
Hack The Boxintermediate10-day window
PNPT
Practical Network Penetration Tester
TCM Securityintermediate5-day exam + 2-day report + live debrief
OSCP
OffSec Certified Professional
OffSecadvanced23h 45m + 24h report
CPENT
Certified Penetration Testing Professional
EC-Counciladvanced24h exam (2x12h or 1x24h) + 7-day report
OSEP
OffSec Experienced Penetration Tester
OffSecexpert47h 45m + 24h report

Web application security

CertVendorLevelExam
BSCP
Burp Suite Certified Practitioner
PortSwiggerintermediate4-hour exam
CBBH
HTB Certified Bug Bounty Hunter
Hack The Boxintermediate7-day exam
OSWE
OffSec Web Expert
OffSecexpert48 hours
CWEE
HTB Certified Web Exploitation Expert
Hack The Boxexpert10-day window

Red teaming & Active Directory

CertVendorLevelExam
CRTP
Certified Red Team Professional
Altered Securityintermediate24-hour exam + report
CRTO
Certified Red Team Operator
Zero-Point Securityadvanced48h runtime across a 4-day window
CRTE
Certified Red Team Expert
Altered Securityadvanced48-hour exam + report
CARTP
Certified Azure Red Team Professional
Altered Securityadvanced24-hour exam + report

Defensive & SOC analysis

CertVendorLevelExam
CJCA
HTB Certified Junior Cybersecurity Associate
Hack The Boxentry5-day exam
OSDA
OffSec Defense Analyst
OffSecintermediate23h 45m + 24h report
CDSA
HTB Certified Defensive Security Analyst
Hack The Boxintermediate7-day exam

Exploit development

CertVendorLevelExam
OSED
OffSec Exploit Developer
OffSecexpert47h 45m + 24h report

Wireless

CertVendorLevelExam
OSWP
OffSec Wireless Professional
OffSecentry3h 45m + 24h report