CDSA vs OSDA
Two defensive exams that come up together — how they actually differ, and who each one is for.
Both are hands-on blue-team certs, but they sit at very different price points. CDSA costs $490 as an annual subscription and gives you a 7-day exam plus report focused on SOC detection and investigation. OSDA is a $1,749 bundle with a roughly 24-hour exam and 24-hour report centred on detection through an ELK SIEM. Pick CDSA for value; OSDA for the OffSec name and time pressure.
- CDSA
- intermediate, $490/yr Silver Annual (bundles the exam voucher)
- OSDA
- intermediate, $1,749 course + exam bundle (or $2,749/yr Learn One)
- Harder
- about equal
| CDSA | OSDA | |
|---|---|---|
| Vendor | Hack The Box | OffSec |
| Level | intermediate | intermediate |
| Duration | 7-day exam | 23h 45m + 24h report |
| Format | hands-on SOC investigation ending in a written report, no MCQ | practical blue-team detection + report |
| Cost | $490/yr Silver Annual (bundles the exam voucher) | $1,749 course + exam bundle (or $2,749/yr Learn One) |
What each one is
CDSA (Certified Defensive Security Analyst) is Hack The Box’s blue-team credential. It maps to the SOC Analyst job-role path and tests whether you can monitor, investigate, and respond to intrusions using enterprise tooling — log analysis, SIEM queries, network and endpoint forensics, and a written incident report. It targets working or aspiring SOC analysts, incident responders, and threat hunters at an intermediate level.
OSDA (Offensive Security Defense Analyst) is OffSec’s defensive cert, earned through the SOC-200 course. It leans hard on detection: understanding attacker TTPs across Windows, Linux, Active Directory, and web, then finding and documenting them through an ELK SIEM. Despite the “Offensive Security” branding, this is a blue-team exam.
The real difference
The two overlap heavily — both are practical, both hand you logs and ask you to reconstruct an attack. The gap is emphasis and rigour. CDSA runs broad across the SOC workflow, from triage through response and reporting, and its exam gives you a full week. OSDA narrows onto detection and the SIEM, and compresses the practical into a single sitting of just under 24 hours followed by a 24-hour reporting window, with a 75/100 pass mark.
Culturally they differ too. CDSA lives on HTB’s subscription platform, where the same membership unlocks other paths. OSDA carries the OffSec exam style — timed, high-pressure — which some employers still weight more heavily by brand recognition.
Cost and time
This is where the decision often lands. CDSA is a $490 annual Silver subscription that includes the training path plus one exam voucher, and the subscription also opens other certifications. OSDA is a $1,749 Learn One bundle covering the SOC-200 course, lab time, and exam attempts — more than three times the cost.
On time, CDSA’s 7-day exam window is forgiving: you can investigate, rest, and write without racing the clock. OSDA’s roughly 24-hour proctored exam plus 24-hour report is far more intense and closer to how OffSec runs its offensive exams.
Which one to choose
If you want a defensible, well-rounded SOC-analyst credential and cost matters, CDSA is the stronger buy: cheaper, broader, and generous on exam time. It suits people breaking into or levelling up within a SOC.
Choose OSDA if you specifically want OffSec on your CV, prefer a sharper focus on detection and SIEM work, and can absorb both the price and the exam intensity. It is also a natural pick for red teamers who want to see how their activity looks from the defender’s side.
Neither is wrong. CDSA wins on value and breadth; OSDA wins on brand and detection depth. Match the choice to your budget and to what your target employers actually recognise.
What people who sat these say
HTB CDSA is one of the most comprehensive certifications targeted towards beginner and even intermediate SOC analysts.
I think this is a fantastic foundational blue team certification.
Full detail on each: CDSA · OSDA. For where both sit in a longer plan, see the roadmap.