CPTS vs PNPT
Two pentest exams that come up together — how they actually differ, and who each one is for.
Start with PNPT if you're newer or want the gentler on-ramp: $499 buys around 45 hours of training, a five-day exam, a free retake, and a live debrief that rehearses client reporting. Move to CPTS when you want serious technical depth — it's harder, cheaper per exam ($210–490), and its 10-day engagement demands deep chaining and a strict report. Newcomer: PNPT. Depth: CPTS.
- CPTS
- intermediate, $210 exam voucher, or Silver Annual $490/yr (includes a voucher)
- PNPT
- intermediate, $499 (exam + 45h training, 12-month access; one free retake)
- Harder
- about equal
| CPTS | PNPT | |
|---|---|---|
| Vendor | Hack The Box | TCM Security |
| Level | intermediate | intermediate |
| Duration | 10-day window | 5-day exam + 2-day report + live debrief |
| Format | one 10-day window covering both the hack and a commercial report, fully practical, no MCQ | full external-to-internal engagement, report, and a live 15-minute debrief |
| Cost | $210 exam voucher, or Silver Annual $490/yr (includes a voucher) | $499 (exam + 45h training, 12-month access; one free retake) |
What each one is
CPTS (Certified Penetration Testing Specialist) is Hack The Box’s intermediate certification, focused on technical depth: enumeration, complex vulnerability chaining, Active Directory and consultancy-grade reporting, delivered through the HTB Academy path and a 10-day exam. PNPT (Practical Network Penetration Tester) is TCM Security’s beginner-to-intermediate certification, built around a realistic end-to-end network engagement — OSINT and external access through to internal Active Directory and the domain controller — capped by a live debrief. Both are practical, report-driven exams; they aim at different stages of a career.
The real difference
Difficulty and emphasis. PNPT is the more accessible and methodology-first exam: a realistic small-business AD environment, five unproctored days, and a mandatory 15-minute debrief that checks whether you can actually explain your findings to a client. CPTS is markedly harder — its initial access alone plays like a hard box, and it expects deep chaining plus a report that markers dissect line by line. People who have sat both consistently rate CPTS the tougher assessment. PNPT rewards process, communication and staying in scope; CPTS rewards raw technical range and stamina.
Cost and time
PNPT is $499 and includes the full training (around 45 hours) plus one free retake; the exam gives you five days for the practical, two more for the report, then the debrief. CPTS is $210 for the exam voucher, or roughly $490 with a subscription that bundles the training, followed by a single 10-day exam window and reporting. Both sit far below OSCP’s price, so cost is rarely the deciding factor between these two — difficulty and goals are.
Which one to choose
If you are new to penetration testing, or you specifically value reporting, scoping and client communication, PNPT is the better starting point and the debrief is genuinely useful practice. If you already have fundamentals and want the hardest technical test at this level, or you want to prove deep AD and chaining skill, choose CPTS. A common, sensible path is PNPT first to learn the shape of the job, then CPTS to push technical depth. Neither yet matches OSCP for name recognition.
What people who sat these say
CPTS was the hardest.
supposedly much harder (by multiple accounts) than the PNPT I failed earlier that year
Full detail on each: CPTS · PNPT. For where both sit in a longer plan, see the roadmap.