PortSwigger · intermediate

BSCP: Burp Suite Certified Practitioner

The short answer

BSCP (Burp Suite Certified Practitioner) is PortSwigger's hands-on web-security certification, tied to the free Web Security Academy. The exam costs $99 and runs four hours: you exploit two deliberately vulnerable web apps, each in three stages, ending by reading a protected file. It is fully auto-graded — no written report. You also need an active Burp Suite Professional subscription. Certification lasts five years.

Price from
$99
Exam
4-hour exam
Level
Intermediate
Report
No

What BSCP is and who runs it

Burp Suite Certified Practitioner (BSCP) is the certification from PortSwigger, the company behind Burp Suite and the free Web Security Academy. It certifies practical web-application hacking: not multiple-choice theory, but your ability to find and exploit real vulnerabilities using Burp. The exam maps directly to the Web Security Academy syllabus — the same free labs (SQL injection, XSS, access control, SSRF, deserialization, JWT attacks, and more) that anyone can practise online. That tight link between free training and a paid, hands-on exam is what makes BSCP distinctive and widely respected among web testers.

Cost and what’s included

The exam fee is $99, priced in US dollars, pounds, and euros. That is cheap for a hands-on cert — but there is a catch on top: you must have access to an active Burp Suite Professional subscription to sit the exam, and PortSwigger does not hand you a free licence for it. So the real cost is $99 plus a Burp Pro subscription (a separate annual licence, priced on the vendor site) if you or your employer do not already have one. The training itself — the entire Web Security Academy — is free, including a free practice exam that mirrors the real thing.

Time: the exam and the report

There is no report — this is the key difference from OSCP-style or Altered Security exams. BSCP is fully auto-graded. You get four hours and two deliberately vulnerable web applications. Each application is solved in three stages: gain access to any user account, escalate to the admin interface, then use that access to read the contents of a protected file on the server and submit that string. Submitting the secret is what proves the stage — no write-up, no screenshots, no waiting for a grader. The clock is tight: roughly two hours per app if you split evenly, so speed and a repeatable methodology matter as much as knowledge.

How hard it is, honestly

BSCP is genuinely challenging, mostly because of time pressure and breadth. The vulnerabilities themselves are things you will have practised in the Academy, but the exam expects you to recognise and chain them fast, across an unfamiliar app, under a four-hour clock. Many capable testers fail the first attempt on timing alone, then pass comfortably once they have built speed and lean on Burp Scanner to triage. It is not a beginner’s first cert — you should be able to clear all Practitioner-level Academy labs unaided before booking. Knowledge plus pace is the whole game.

Is it worth it — and for whom

For web-application pentesters, bug-bounty hunters, and developers who want to prove practical AppSec skill, BSCP is excellent value and increasingly recognised by employers. It is proof you can actually exploit, not just describe, common web bugs — and the underlying free training is worth doing regardless of whether you sit the exam. It is less relevant if your work is network, cloud, or Active Directory focused. The five-year validity is generous, and because the syllabus is free, the barrier is your time and a Burp Pro licence, not a big course fee.

How to prepare

Work through the Web Security Academy topic by topic and complete every Practitioner-level lab without looking at solutions — that is the syllabus. Then grind the “mystery” labs, which randomise the vulnerability so you practise identification, and take the free practice exam under real conditions. Learn to drive Burp efficiently: run the scanner in the background to flag issues while you test manually, and build a checklist so you never stall. Rehearse the three-stage pattern until it is muscle memory, then book once your timing is reliable.

SourcesPortSwigger — BSCP CertificationPortSwigger — How the exam works

Common questions

How much does the BSCP exam cost?

$99 exam fee, plus an active Burp Suite Pro licence (separate annual cost). Set by PortSwigger and subject to change — confirm the current price on their page.

How long is the BSCP exam?

The BSCP exam runs 4-hour exam.

Does BSCP require a written report?

No. BSCP is auto-graded from what you submit in the exam, with no separate written report.

Who runs the BSCP certification?

BSCP (Burp Suite Certified Practitioner) is run by PortSwigger. It is an intermediate exam in the web application security track.

Can you retake the BSCP exam?

No pause once started; a retake is another $99. Certification lasts 5 years.

What people who sat BSCP say

Four hours doesn't feel very long for a practical exam, especially one that covers such an expansive range of techniques.
Offsec Danoffensivelysecured.com
It was a fun exam and undoubtedly challenging in places.
Harry Northovernorthover.co