Head to head

CPTS vs PNPT

Two pentest exams that come up together — how they actually differ, and who each one is for.

Start with PNPT if you're newer or want the gentler on-ramp: $499 buys around 45 hours of training, a five-day exam, a free retake, and a live debrief that rehearses client reporting. Move to CPTS when you want serious technical depth — it's harder, cheaper per exam ($210–490), and its 10-day engagement demands deep chaining and a strict report. Newcomer: PNPT. Depth: CPTS.

CPTS
intermediate, $210 exam voucher, or Silver Annual $490/yr (includes a voucher)
PNPT
intermediate, $499 (exam + 45h training, 12-month access; one free retake)
Harder
about equal
CPTSPNPT
VendorHack The BoxTCM Security
Levelintermediateintermediate
Duration10-day window5-day exam + 2-day report + live debrief
Formatone 10-day window covering both the hack and a commercial report, fully practical, no MCQfull external-to-internal engagement, report, and a live 15-minute debrief
Cost$210 exam voucher, or Silver Annual $490/yr (includes a voucher)$499 (exam + 45h training, 12-month access; one free retake)

What each one is

CPTS (Certified Penetration Testing Specialist) is Hack The Box’s intermediate certification, focused on technical depth: enumeration, complex vulnerability chaining, Active Directory and consultancy-grade reporting, delivered through the HTB Academy path and a 10-day exam. PNPT (Practical Network Penetration Tester) is TCM Security’s beginner-to-intermediate certification, built around a realistic end-to-end network engagement — OSINT and external access through to internal Active Directory and the domain controller — capped by a live debrief. Both are practical, report-driven exams; they aim at different stages of a career.

The real difference

Difficulty and emphasis. PNPT is the more accessible and methodology-first exam: a realistic small-business AD environment, five unproctored days, and a mandatory 15-minute debrief that checks whether you can actually explain your findings to a client. CPTS is markedly harder — its initial access alone plays like a hard box, and it expects deep chaining plus a report that markers dissect line by line. People who have sat both consistently rate CPTS the tougher assessment. PNPT rewards process, communication and staying in scope; CPTS rewards raw technical range and stamina.

Cost and time

PNPT is $499 and includes the full training (around 45 hours) plus one free retake; the exam gives you five days for the practical, two more for the report, then the debrief. CPTS is $210 for the exam voucher, or roughly $490 with a subscription that bundles the training, followed by a single 10-day exam window and reporting. Both sit far below OSCP’s price, so cost is rarely the deciding factor between these two — difficulty and goals are.

Which one to choose

If you are new to penetration testing, or you specifically value reporting, scoping and client communication, PNPT is the better starting point and the debrief is genuinely useful practice. If you already have fundamentals and want the hardest technical test at this level, or you want to prove deep AD and chaining skill, choose CPTS. A common, sensible path is PNPT first to learn the shape of the job, then CPTS to push technical depth. Neither yet matches OSCP for name recognition.

What people who sat these say

CPTS was the hardest.
Fabriceholds CPTS, OSCP and PNPT
supposedly much harder (by multiple accounts) than the PNPT I failed earlier that year
grepStrengthpassed CPTS after sitting PNPT the same year

Full detail on each: CPTS · PNPT. For where both sit in a longer plan, see the roadmap.