Head to head

CJCA vs EJPT

Two exams that come up together — how they actually differ, and who each one is for.

Both are entry-level, but they test different things. CJCA is Hack The Box's foundational cert covering both offence and defence, with a 5-day exam that ends in a written report. eJPT is INE's junior pentest cert: 48 hours, auto-graded, no report, purely offensive. Choose CJCA to sample red and blue and practise reporting; choose eJPT to prove hands-on pentest enumeration.

CJCA
entry, $105 exam voucher, or bundled in $490/yr Silver Annual
EJPT
entry, Bundled with INE training (commonly ~$249); no sticker price on the INE page
Harder
about equal
CJCAEJPT
VendorHack The BoxINE
Levelentryentry
Duration5-day exam48-hour exam
Formatentry-level hands-on offensive + defensive, ending in a written report48-hour auto-graded practical with dynamic flags; no written report
Cost$105 exam voucher, or bundled in $490/yr Silver AnnualBundled with INE training (commonly ~$249); no sticker price on the INE page

What each one is

CJCA (Certified Junior Cybersecurity Associate) is Hack The Box’s entry credential for complete beginners. It spans both sides of security — basic offensive techniques and defensive fundamentals — plus core IT and networking skills. The exam is a multi-day, hands-on scenario that finishes with a written report, so beginners get a taste of red team, blue team, and documentation in one sitting.

eJPT (Junior Penetration Tester) is INE’s entry pentest cert, formerly under the eLearnSecurity name. It is purely offensive: reconnaissance, enumeration, host and network exploitation, and basic web attacks. The exam is a hands-on lab where you answer questions tied to what you actually compromise, and it is graded automatically.

The real difference

The headline split is scope and grading. CJCA is a generalist first step that deliberately touches both offence and defence, then asks you to write up what you found — a genuine report, marked by a human. eJPT is single-lane: it only cares whether you can enumerate and exploit a network, and a machine scores your answers with no report to write.

That makes CJCA broader but shallower per topic, and eJPT narrower but a truer preview of a pentester’s day. If you already know you want offensive security, eJPT points straight there. If you are still deciding between red and blue, CJCA lets you feel both before committing.

Cost and time

CJCA is bought either as a $105 exam voucher on its own or bundled into HTB’s $490 annual subscription, which also unlocks the training path and other certs. Its exam runs across five days, giving you room to investigate and then write the report without time pressure.

eJPT comes with an INE bundle at roughly $249, which includes the Penetration Testing Student training and the exam voucher, plus a free retake. The exam gives you 48 hours of lab access. Watch for INE discount campaigns, which frequently cut the price sharply.

Pure voucher cost favours CJCA, but eJPT’s bundle includes more offensive training hours — so compare what you actually need, not just the sticker.

Which one to choose

Pick CJCA if you are starting from zero and want a structured tour of both attacking and defending, and if practising report-writing early appeals to you. It is the gentler, more exploratory on-ramp.

Pick eJPT if you already know pentesting is the goal and you want a recognised, hands-on offensive cert that proves you can enumerate and exploit. It is the more focused, career-directed entry cert for aspiring pentesters.

Many people do both, or use one to confirm the direction before spending on the next. Neither is a shortcut — both reward the hours you put into the labs.

What people who sat these say

CJCA is worth considering. Not because it is easy, and not because any certification is a magic ticket.
Bob Theisenholds HTB CJCA
I recommend eJPT to anyone starting out in pentesting.
Void4m0nholds eJPT

Full detail on each: CJCA · EJPT. For where both sit in a longer plan, see the roadmap.