OSEP: OffSec Experienced Penetration Tester
The OSEP (OffSec Experienced Penetration Tester, course code PEN-300) is OffSec's advanced evasion and breaching certification. The course-and-exam bundle costs $1,749, or $2,749 a year on Learn One. The exam is a proctored 47-hour-45-minute practical against a full corporate network, plus 24 hours to report. You pass by reaching the final objective or scoring 100 points. It is significantly harder than OSCP.
- Price from
- $1,749
- Exam
- 47h 45m + 24h report
- Level
- Expert
- Report
- Yes
What OSEP is and who runs it
OSEP stands for OffSec Experienced Penetration Tester, and like OSCP it is run by OffSec. It is the certification attached to the PEN-300 course, “Advanced Evasion Techniques and Breaching Defenses.” Where OSCP proves you can break into machines, OSEP is about doing it against a defended, realistic corporate network: getting an initial foothold through client-side attacks, writing loaders that slip past antivirus, bypassing controls like AMSI, AppLocker, and UAC, and then moving laterally through an Active Directory environment to compromise a critical asset. It sits at the 300 level in OffSec’s ladder and, unlike OSCP+, the certification does not expire.
Cost and what’s included
The pricing model mirrors OffSec’s other courses. The Course + Cert Bundle is $1,749 and gives 90 days of access to the PEN-300 materials, the labs, and a single exam attempt. The Learn One subscription is $2,749 per year, covering one 200- or 300-level course, its associated labs, and two exam attempts. The course itself is large — over 600 hours of material across 18-plus modules, plus multiple multi-machine challenge labs that closely mirror the exam. Additional retake vouchers are purchased separately if you exhaust your attempts.
Time: the exam and the report
The OSEP exam is a marathon: 47 hours and 45 minutes of hands-on time, essentially two full days, all of it proctored. You then have a further 24 hours to submit your documentation. The generous clock exists because the exam is one large interconnected network rather than isolated boxes; you are expected to sleep, eat, and take breaks across the two days. As with all OffSec exams, the report is mandatory and strictly judged. Proof files must be shown in an interactive shell, not a web shell or RDP session, or the target scores nothing.
How hard it is, honestly
OSEP is a real step up from OSCP and is regularly described as one of the more technically demanding OffSec certs. You pass one of two ways: retrieve the secret.txt flag on the final target (proving full compromise of the objective), or accumulate at least 100 points from flags worth 10 each. The hard parts are antivirus and defense evasion, custom loader development leaning on C#/PowerShell, and chaining attacks across Linux and Windows in AD. It rewards people who already understand Active Directory; if you do not, expect the challenge labs to take weeks. The course material is comprehensive but somewhat dated, so supplementary AD study helps.
Is it worth it — and for whom
OSEP is aimed at working penetration testers and aspiring red-teamers, not beginners, and it is worth it if you want to move from basic exploitation into evasion and internal-network tradecraft. The skills — malware-style loaders, AV bypass, lateral movement — map reasonably well to real red-team engagements. It is not a first cert, and it is overkill if you do not work in or near offensive security. Reviewers who value it still concede the price is steep; its return comes from the skills and the niche recognition, less from broad HR name-recognition than OSCP.
How to prepare
Come in comfortable with OSCP-level skills and Active Directory. Many people warm up with CRTP or CRTE from Altered Security, or HTB’s red-team content, before starting PEN-300. Work slowly through the modules — do not rush, techniques build on each other — and then spend dedicated weeks on the six challenge labs, which are the best predictor of exam readiness. Learn a scripting/tooling stack (C#, PowerShell, BloodHound, Impacket, Chisel/Ligolo, Rubeus) and practice building your own AV-evasion loaders rather than relying on commercial C2, which is banned in the exam.
SourcesOffSec PEN-300 course & pricingOSEP Exam GuideOffSec Exam Retake Policy

Common questions
How much does the OSEP exam cost?
$1,749 course + exam bundle (or $2,749/yr Learn One). Set by OffSec and subject to change — confirm the current price on their page.
How long is the OSEP exam?
The OSEP exam runs 47h 45m + 24h report.
Does OSEP require a written report?
Yes. OffSec grades a written report alongside the practical, and it counts toward whether you pass — see how the report is graded on the reports page.
Who runs the OSEP certification?
OSEP (OffSec Experienced Penetration Tester) is run by OffSec. It is an expert-level exam that assumes you can already do the core work in the network penetration testing track.
Can you retake the OSEP exam?
1 attempt in the bundle, 2 on Learn One; cooling-off 4/8/12 weeks.
What people who sat OSEP say
So far, this is the most intensive exam I've ever taken compared to any other course or certification I've obtained.
The OSEP is a good challenge and is a worthwhile certification to get for penetration testers.