All 19

Offensive security certifications

There are 19 offensive-security certifications worth knowing, from 8vendors, ranging from a $99 four-hour web exam to $1,749 OffSec courses. They split by discipline — network, web, red team, defense, exploit development and wireless — and by level from entry to expert. OSCP is the most recognised; CPTS, PNPT and the $99 BSCP are the strongest value; eJPT is the usual entry point.

Certifications
19
Vendors
8
From
$99

Compare all 19 certifications

Click any column heading to sort — by cost, level, vendor or exam length.

CertificationVendorLevelFocusExam timeFrom
OSCP
OffSec Certified Professional
OffSecadvancedNetwork penetration testing23h 45m + 24h report$1,749
CPTS
HTB Certified Penetration Testing Specialist
Hack The BoxintermediateNetwork penetration testing10-day window$210
OSEP
OffSec Experienced Penetration Tester
OffSecexpertNetwork penetration testing47h 45m + 24h report$1,749
EJPT
eLearnSecurity Junior Penetration Tester
INEentryNetwork penetration testing48-hour exam$249
PNPT
Practical Network Penetration Tester
TCM SecurityintermediateNetwork penetration testing5-day exam + 2-day report + live debrief$499
OSDA
OffSec Defense Analyst
OffSecintermediateDefensive & SOC analysis23h 45m + 24h report$1,749
OSWE
OffSec Web Expert
OffSecexpertWeb application security48 hours$1,749
CRTP
Certified Red Team Professional
Altered SecurityintermediateRed teaming & Active Directory24-hour exam + report$249
OSED
OffSec Exploit Developer
OffSecexpertExploit development47h 45m + 24h report$1,749
CDSA
HTB Certified Defensive Security Analyst
Hack The BoxintermediateDefensive & SOC analysis7-day exam$490
CRTO
Certified Red Team Operator
Zero-Point SecurityadvancedRed teaming & Active Directory48h runtime across a 4-day window£399
OSWP
OffSec Wireless Professional
OffSecentryWireless3h 45m + 24h report$799
CPENT
Certified Penetration Testing Professional
EC-CounciladvancedNetwork penetration testing24h exam (2x12h or 1x24h) + 7-day report$999
BSCP
Burp Suite Certified Practitioner
PortSwiggerintermediateWeb application security4-hour exam$99
CRTE
Certified Red Team Expert
Altered SecurityadvancedRed teaming & Active Directory48-hour exam + report$299
CBBH
HTB Certified Bug Bounty Hunter
Hack The BoxintermediateWeb application security7-day exam$490
CWEE
HTB Certified Web Exploitation Expert
Hack The BoxexpertWeb application security10-day window$350
CJCA
HTB Certified Junior Cybersecurity Associate
Hack The BoxentryDefensive & SOC analysis5-day exam$105
CARTP
Certified Azure Red Team Professional
Altered SecurityadvancedRed teaming & Active Directory24-hour exam + report$449

"From" shows the entry price; several bundle training, labs or a subscription — see each certification for the full breakdown. Figures verified against vendor pages, September 2026.

Network penetration testing

The broadest offensive-security path and what most "penetration tester" job listings mean. These certifications prove you can enumerate a network, exploit what you find, move laterally through Active Directory, and write it up as a client would expect. This is where most people start and where OSCP still sets the bar for recognition.

EJPT — eLearnSecurity Junior Penetration Tester

INEentry48-hour exam$249

The eJPT (eLearnSecurity Junior Penetration Tester) is INE Security's entry-level, fully hands-on pentest certification. You get a 48-hour practical exam in a live lab, auto-graded with dynamic flags — no written report. Passing needs 70% overall plus per-section minimums. It's cheap, beginner-friendly, and proves you can enumerate and exploit, not just memorize theory.

Full EJPT guide →

CPTS — HTB Certified Penetration Testing Specialist

Hack The Boxintermediate10-day window$210

The CPTS (HTB Certified Penetration Testing Specialist) is a hands-on penetration testing cert from Hack The Box, earned through HTB Academy's Penetration Tester path. A standalone exam voucher is about $210, or it comes bundled in Silver Annual ($490/year). The exam is one 10-day window covering both the practical and a commercial-grade report. It is widely considered very hard.

Full CPTS guide →

PNPT — Practical Network Penetration Tester

TCM Securityintermediate5-day exam + 2-day report + live debrief$499

The PNPT (TCM Security) is a hands-on penetration-testing cert: run a full external-to-internal engagement, compromise Active Directory, write a report, then present a live 15-minute debrief to an assessor. It costs $499 (USD), bundled with 45+ hours of training and one free retake. You get five days to test plus two to report. Difficulty is beginner-to-intermediate — fair and realistic.

Full PNPT guide →

OSCP — OffSec Certified Professional

OffSecadvanced23h 45m + 24h report$1,749

The OSCP (OffSec Certified Professional, course code PEN-200) is a hands-on penetration-testing certification from OffSec. The current course-and-exam bundle costs $1,749; the Learn One subscription is $2,749 a year. The exam is a proctored 23-hour-45-minute practical, followed by 24 hours to write the report, and you need 70 of 100 points to pass. It is genuinely demanding, but sits at the entry level of OffSec's ladder.

Full OSCP guide →

CPENT — Certified Penetration Testing Professional

EC-Counciladvanced24h exam (2x12h or 1x24h) + 7-day report$999

CPENT (Certified Penetration Testing Professional) is EC-Council's advanced, hands-on pentest certification. The exam is a live enterprise cyber range you tackle as one 24-hour session or two 12-hour sessions, with a report due within seven days. Cut scores vary by form (roughly 60–85%); score above 90% and you also earn the LPT (Master) title. It's broad, tough, and pricey.

Full CPENT guide →

OSEP — OffSec Experienced Penetration Tester

OffSecexpert47h 45m + 24h report$1,749

The OSEP (OffSec Experienced Penetration Tester, course code PEN-300) is OffSec's advanced evasion and breaching certification. The course-and-exam bundle costs $1,749, or $2,749 a year on Learn One. The exam is a proctored 47-hour-45-minute practical against a full corporate network, plus 24 hours to report. You pass by reaching the final objective or scoring 100 points. It is significantly harder than OSCP.

Full OSEP guide →

Web application security

Focused on finding and exploiting flaws in web applications — injection, access control, SSRF, deserialization and the exploit-development skills behind them. These suit bug-bounty hunters and application-security engineers, and range from a four-hour practical (BSCP) to expert white-box source-code review (OSWE, CWEE).

BSCP — Burp Suite Certified Practitioner

PortSwiggerintermediate4-hour exam$99

BSCP (Burp Suite Certified Practitioner) is PortSwigger's hands-on web-security certification, tied to the free Web Security Academy. The exam costs $99 and runs four hours: you exploit two deliberately vulnerable web apps, each in three stages, ending by reading a protected file. It is fully auto-graded — no written report. You also need an active Burp Suite Professional subscription. Certification lasts five years.

Full BSCP guide →

CBBH — HTB Certified Bug Bounty Hunter

Hack The Boxintermediate7-day exam$490

HTB CBBH — the Certified Bug Bounty Hunter — is Hack The Box's beginner-to-intermediate web-application certification. Since October 2025 it's been renamed HTB CWES (Certified Web Exploitation Specialist); the exam is unchanged and existing holders converted automatically. You earn it through HTB Academy, where a Silver Annual subscription ($490/year) includes the voucher. The exam runs seven days and ends in a commercial-grade report. Fair, not trivial.

Full CBBH guide →

OSWE — OffSec Web Expert

OffSecexpert48 hours$1,749

The OSWE (OffSec Web Expert) is OffSec's advanced web-application security certification, earned through the WEB-300 course. It centers on white-box source-code review and exploit development. The course-plus-exam bundle starts at $1,749; the exam is a 48-hour (47h 45m) hands-on assessment plus 24 hours to write the report, and you need 85 of 100 points to pass. Hard, but not heavily time-pressured.

Full OSWE guide →

CWEE — HTB Certified Web Exploitation Expert

Hack The Boxexpert10-day window$350

CWEE is HTB's expert-level web exploitation certification, earned through HTB Academy. It's a white-box (and black-box) exam where you review source code, build exploits from scratch, and write patches. You get a 10-day exam window plus a commercial report. Prerequisites: complete the Senior Web Penetration Tester path and hold a voucher. Standalone exam: $350; the Gold Annual plan ($1,260) bundles it.

Full CWEE guide →

Red teaming & Active Directory

These assume you can already pentest and take you into adversary simulation: Active Directory attack chains, command-and-control tradecraft, evasion, and cloud identity abuse. They are the layer above general penetration testing, and cover both on-premises AD (CRTP, CRTE, CRTO) and Azure (CARTP).

CRTP — Certified Red Team Professional

Altered Securityintermediate24-hour exam + report$249

CRTP (Altered Security) is a beginner-friendly Active Directory red-team certification built on the "Attacking and Defending Active Directory" course. It costs $249–$499 (USD) depending on 30–90 days of lab access, includes one exam attempt, and runs a 24-hour hands-on exam across five target servers plus a report. Difficulty is entry-level but genuinely hands-on; a $99 retake keeps it low-stress.

Full CRTP guide →

CRTO — Certified Red Team Operator

Zero-Point Securityadvanced48h runtime across a 4-day window£399

CRTO (Zero-Point Security) certifies red-team operators via the "Red Team Ops" course, which teaches Cobalt Strike and C2 tradecraft. It costs £399 (GBP), including a licensed Cobalt Strike lab and unlimited free exam attempts. The exam is an assumed-breach CTF: 48 hours of runtime across a four-day window, needing 6 of 8 flags to pass. Difficulty is fair and unusually well-taught.

Full CRTO guide →

CRTE — Certified Red Team Expert

Altered Securityadvanced48-hour exam + report$299

CRTE (Certified Red Team Expert) is Altered Security's advanced on-prem Active Directory red-team certification, a step beyond CRTP. Lab bundles start at $299 for 30 days and include one exam attempt. The exam is a 48-hour hands-on assault on a multi-domain AD environment, followed by a written report of your solutions and mitigations. Certification lasts three years.

Full CRTE guide →

CARTP — Certified Azure Red Team Professional

Altered Securityadvanced24-hour exam + report$449

CARTP (Certified Azure Red Team Professional) is Altered Security's Azure and Entra ID red-team certification, taught by Nikhil Mittal. Lab bundles start at $449 for 30 days and include one exam attempt. The exam is a 24-hour hands-on assessment across multiple Azure tenants, where you compromise every resource and submit a report. It's cloud-focused, the counterpart to the on-prem CRTP/CRTE track. Valid three years.

Full CARTP guide →

Defensive & SOC analysis

The blue-team path — detecting and analysing attacks rather than launching them. Hands-on SOC and detection certifications like CDSA and OSDA put you in a live SIEM to reconstruct an intrusion, and they pair well with offensive experience because knowing the attack makes the detection obvious.

CJCA — HTB Certified Junior Cybersecurity Associate

Hack The Boxentry5-day exam$105

CJCA is HTB's entry-level certification, the Certified Junior Cybersecurity Associate, run by Hack The Box through HTB Academy. It covers both offensive and defensive foundations in one hands-on, hybrid exam plus a written report. You get a 5-day exam window. Prerequisites: finish the Junior Cybersecurity Analyst path and hold a voucher. Standalone exam: $105; also bundled in the $490 Silver Annual plan.

Full CJCA guide →

OSDA — OffSec Defense Analyst

OffSecintermediate23h 45m + 24h report$1,749

OSDA (OffSec Defense Analyst, exam code SOC-200) is a hands-on blue-team certification focused on detecting and documenting attacker activity through an ELK SIEM. It starts at $1,749 with the course-plus-exam bundle. The proctored exam runs 23 hours 45 minutes across ten phases, plus 24 hours to report; you need 75 of 100 points. It is challenging but fair for its foundational level.

Full OSDA guide →

CDSA — HTB Certified Defensive Security Analyst

Hack The Boxintermediate7-day exam$490

HTB CDSA — the Certified Defensive Security Analyst — is Hack The Box's blue-team credential for SOC work: detection, log and traffic analysis, investigation, and incident handling. You earn it through HTB Academy, where a Silver Annual subscription ($490/year) bundles the exam voucher. The exam is hands-on and runs seven days, ending in a written investigation report. Difficulty is intermediate — demanding but fair, not memorization.

Full CDSA guide →

Exploit development

Deep, narrow, and aimed at vulnerability research and malware analysis. Exploit-development certifications teach reverse engineering, memory-corruption bugs, custom shellcode and modern-protection bypasses — a different discipline from general pentesting, and one of the few structured hands-on routes into the field.

OSED — OffSec Exploit Developer

OffSecexpert47h 45m + 24h report$1,749

OSED (OffSec Exploit Developer, exam code EXP-301) is a hands-on Windows user-mode exploit-development certification: reverse engineering, stack and SEH overflows, custom shellcode, and DEP/ASLR bypasses. It starts at $1,749 with the course-plus-exam bundle. The proctored exam runs 47 hours 45 minutes across three tasks, plus 24 hours to report; you need 60 of 100 points. It is genuinely hard.

Full OSED guide →

Wireless

A focused niche: attacking Wi-Fi networks — recovering keys, breaking encryption, and gaining access to a target access point. Wireless is a small category with one main credential (OSWP), usually taken as an add-on rather than a primary certification.

OSWP — OffSec Wireless Professional

OffSecentry3h 45m + 24h report$799

The OSWP (OffSec Wireless Professional) is OffSec's wireless-attack certification, earned through the PEN-210 course. The proctored exam runs about 3 hours 45 minutes against live wireless scenarios, followed by 24 hours to submit a PDF report proving you recovered the keys. It's one of OffSec's easier, cheaper certs, doesn't expire, and is narrow but genuinely hands-on for Wi-Fi security work.

Full OSWP guide →