CPTS: HTB Certified Penetration Testing Specialist
The CPTS (HTB Certified Penetration Testing Specialist) is a hands-on penetration testing cert from Hack The Box, earned through HTB Academy's Penetration Tester path. A standalone exam voucher is about $210, or it comes bundled in Silver Annual ($490/year). The exam is one 10-day window covering both the practical and a commercial-grade report. It is widely considered very hard.
- Price from
- $210
- Exam
- 10-day window
- Level
- Intermediate
- Report
- Yes
What CPTS is and who runs it
The HTB Certified Penetration Testing Specialist (CPTS) is run by Hack The Box, the company behind the HTB hacking labs, and it is earned entirely inside their training platform, HTB Academy. Unlike a sit-down multiple-choice exam, CPTS is proof-of-work: you complete the Penetration Tester job-role path, then attack a simulated corporate network and write it up. It targets people who want to demonstrate real, end-to-end internal penetration testing skills — enumeration, exploitation, Active Directory, pivoting, and reporting — rather than trivia.
Cost and what’s included
Pricing runs through HTB Academy rather than a single exam fee. A standalone CPTS exam voucher is listed at $210 ($249.90 incl. VAT). Most candidates instead subscribe: Silver Annual is $490/year and includes Tier II module access plus one exam voucher per year usable for CPTS (or CWES/COAE/CDSA); Gold Annual is $1,260/year for Tier III access and a wider voucher. The modules that prepare you are part of the subscription, so the real cost is course plus voucher bundled together. Promotions and tier contents change, so confirm on the vendor page before buying.
Time: the exam and the report
This is where CPTS differs from most certs. Per HTB, “the exam lab will be accessible for ten (10) days” and you have those same ten days to upload your report from the time you enter the exam. So it is a single 10-day window covering both the hands-on hacking and the written report — not a 5-and-5 split, and not ten practical days plus another ten for reporting. You collect flags across the environment to reach a minimum point requirement, then submit a commercial-grade penetration testing report in English. Results arrive within 20 business days.
How hard it is, honestly
CPTS has a reputation for being genuinely tough, and reviewers who have done both often rate it harder than OSCP in scope. It is less about a ticking clock — you have ten days — and more about breadth: the environment is large, chained, and full of plausible rabbit holes, and the report is graded seriously, so many find the write-up the most painful part. HTB does not publish the exact passing point threshold; you must reach the minimum points and then pass an instructor’s review of your report. (The “12 of 14 flags” figure that circulates is community lore, not an official number.)
Is it worth it — and for whom
For aspiring or junior penetration testers, CPTS is strong value: the price is low relative to OSCP, the labs are extensive, and the exam mirrors real internal engagement work, deliverable included. It is less recognized by non-technical HR filters than OSCP, so if you need a name a recruiter reflexively checkboxes, weigh that. But for building and proving hands-on competence — especially Active Directory and pivoting — it is well regarded and increasingly respected.
How to prepare
Complete 100% of the Penetration Tester job-role path — it is the official prerequisite (28 modules) and maps closely to the exam. Do the modules hands-on, take thorough notes as you go, and build a reporting template before exam day so writing is not a scramble. Practice pivoting and Active Directory attacks until they are routine, and treat note-taking discipline as an exam skill, not an afterthought. Each voucher includes two attempts, and you get feedback after a failed first try.
SourcesHTB Academy subscriptions & pricingHTB CPTS details (10-day window, retakes, prereqs)HTB Academy Certifications

Common questions
How much does the CPTS exam cost?
$210 exam voucher, or Silver Annual $490/yr (includes a voucher). Set by Hack The Box and subject to change — confirm the current price on their page.
How long is the CPTS exam?
The CPTS exam runs 10-day window.
Does CPTS require a written report?
Yes. Hack The Box grades a written report alongside the practical, and it counts toward whether you pass — see how the report is graded on the reports page.
Who runs the CPTS certification?
CPTS (HTB Certified Penetration Testing Specialist) is run by Hack The Box. It is an intermediate exam in the network penetration testing track.
Can you retake the CPTS exam?
Two attempts per voucher; voucher valid 365 days.
What people who sat CPTS say
The CPTS exam is absolutely brutal and unforgiving. 10 days might seem like a reasonable amount of time, but there are so many rabbit holes.
The relief never came because I still had that report to do.
Before taking the course, Active Directory was one of the topics I struggled with and felt a bit intimidated by.