Head to head

CRTO vs OSEP

Two exams that come up together — how they actually differ, and who each one is for.

These solve different problems. CRTO teaches red-team operations through a real command-and-control framework for £399 and a flag-based exam. OSEP costs $1,749 and drills custom evasion, breaching and Active Directory with a two-day objective exam plus a written report. Choose CRTO for affordable operator tradecraft; choose OSEP for hand-rolled evasion depth and the OffSec name.

CRTO
advanced, £399 (GBP), incl. licensed Cobalt Strike lab
OSEP
expert, $1,749 course + exam bundle (or $2,749/yr Learn One)
Harder
OSEP
CRTOOSEP
VendorZero-Point SecurityOffSec
Leveladvancedexpert
Duration48h runtime across a 4-day window47h 45m + 24h report
Formatassumed-breach CTF; capture 6 of 8 flags (75%); no written reportpractical evasion + report; reach the objective or 100 pts
Cost£399 (GBP), incl. licensed Cobalt Strike lab$1,749 course + exam bundle (or $2,749/yr Learn One)

What each one is

CRTO — Certified Red Team Operator, from Zero-Point Security — is a red-team operations course. You learn to run an engagement through a commercial command-and-control framework: building and tuning payloads, moving laterally, abusing Active Directory, and simulating an adversary inside an assumed-breach network. It is written and taught by an active red teamer, and it is unapologetically operator-focused.

OSEP — OffSec Experienced Penetration Tester, the PEN-300 course — is OffSec’s advanced evasion and breaching certification. It concentrates on getting past defenses that are switched on: writing your own payloads, thinking through antivirus and application-control bypasses, phishing for a foothold, and pushing through Active Directory once you are inside.

The real difference

Both are advanced and both touch evasion and AD, but they come at it from opposite ends. CRTO teaches you to operate like a red teamer using a mature C2 — the skill is tradecraft and orchestration. OSEP teaches you to build the evasion yourself, largely without a C2 to lean on — the skill is hand-rolling loaders and bypasses.

They are also from different vendors, and that matters. One reviewer who holds both found Active Directory not as well covered in OSEP as it is in CRTO — OSEP’s strength is custom evasion, not AD depth. On the other side, the OffSec name still travels further on a résumé, so CRTO can look less shiny despite excellent material.

Cost and time

This is the starkest gap. CRTO is £399 (roughly $500). OSEP is $1,749 — more than three times the price.

The exams differ too. CRTO gives you 48 hours of lab time spread across a four-day window, and you pass by capturing six of eight flags; there is no report to write. OSEP runs a 47-hour-45-minute hands-on exam followed by 24 hours to submit a written report, and you pass by reaching the objective or scoring 100 points. OSEP asks for more money, more exam endurance, and formal reporting.

Which one to choose

Choose CRTO if budget is real, you want practical experience operating a C2 and running adversary simulations, and you are aiming at red-team work. Its strong AD coverage and low price make it the easier first step.

Choose OSEP if you specifically want to prove you can write your own evasion and breach hardened defenses, or if you are on the OffSec track and want the brand recognition that comes with it.

They are not mutually exclusive. A common path is CRTO first — cheaper, strong on AD — then OSEP to add custom-evasion depth and the OffSec credential. Neither replaces the other; they document different halves of modern offensive work.

What people who sat these say

This certification probably won't look as shiny as something from OffSec on your resume, despite the great material and value provided.
Stefano Lanaroholds CRTO plus multiple red-team certs
Active Directory vulnerabilities are not as well covered as they are in the CRTO.
Marmeusholds OSCP, CRTO, OSEP

Full detail on each: CRTO · OSEP. For where both sit in a longer plan, see the roadmap.