CRTO vs OSEP
Two exams that come up together — how they actually differ, and who each one is for.
These solve different problems. CRTO teaches red-team operations through a real command-and-control framework for £399 and a flag-based exam. OSEP costs $1,749 and drills custom evasion, breaching and Active Directory with a two-day objective exam plus a written report. Choose CRTO for affordable operator tradecraft; choose OSEP for hand-rolled evasion depth and the OffSec name.
- CRTO
- advanced, £399 (GBP), incl. licensed Cobalt Strike lab
- OSEP
- expert, $1,749 course + exam bundle (or $2,749/yr Learn One)
- Harder
- OSEP
| CRTO | OSEP | |
|---|---|---|
| Vendor | Zero-Point Security | OffSec |
| Level | advanced | expert |
| Duration | 48h runtime across a 4-day window | 47h 45m + 24h report |
| Format | assumed-breach CTF; capture 6 of 8 flags (75%); no written report | practical evasion + report; reach the objective or 100 pts |
| Cost | £399 (GBP), incl. licensed Cobalt Strike lab | $1,749 course + exam bundle (or $2,749/yr Learn One) |
What each one is
CRTO — Certified Red Team Operator, from Zero-Point Security — is a red-team operations course. You learn to run an engagement through a commercial command-and-control framework: building and tuning payloads, moving laterally, abusing Active Directory, and simulating an adversary inside an assumed-breach network. It is written and taught by an active red teamer, and it is unapologetically operator-focused.
OSEP — OffSec Experienced Penetration Tester, the PEN-300 course — is OffSec’s advanced evasion and breaching certification. It concentrates on getting past defenses that are switched on: writing your own payloads, thinking through antivirus and application-control bypasses, phishing for a foothold, and pushing through Active Directory once you are inside.
The real difference
Both are advanced and both touch evasion and AD, but they come at it from opposite ends. CRTO teaches you to operate like a red teamer using a mature C2 — the skill is tradecraft and orchestration. OSEP teaches you to build the evasion yourself, largely without a C2 to lean on — the skill is hand-rolling loaders and bypasses.
They are also from different vendors, and that matters. One reviewer who holds both found Active Directory not as well covered in OSEP as it is in CRTO — OSEP’s strength is custom evasion, not AD depth. On the other side, the OffSec name still travels further on a résumé, so CRTO can look less shiny despite excellent material.
Cost and time
This is the starkest gap. CRTO is £399 (roughly $500). OSEP is $1,749 — more than three times the price.
The exams differ too. CRTO gives you 48 hours of lab time spread across a four-day window, and you pass by capturing six of eight flags; there is no report to write. OSEP runs a 47-hour-45-minute hands-on exam followed by 24 hours to submit a written report, and you pass by reaching the objective or scoring 100 points. OSEP asks for more money, more exam endurance, and formal reporting.
Which one to choose
Choose CRTO if budget is real, you want practical experience operating a C2 and running adversary simulations, and you are aiming at red-team work. Its strong AD coverage and low price make it the easier first step.
Choose OSEP if you specifically want to prove you can write your own evasion and breach hardened defenses, or if you are on the OffSec track and want the brand recognition that comes with it.
They are not mutually exclusive. A common path is CRTO first — cheaper, strong on AD — then OSEP to add custom-evasion depth and the OffSec credential. Neither replaces the other; they document different halves of modern offensive work.
What people who sat these say
This certification probably won't look as shiny as something from OffSec on your resume, despite the great material and value provided.
Active Directory vulnerabilities are not as well covered as they are in the CRTO.
Full detail on each: CRTO · OSEP. For where both sit in a longer plan, see the roadmap.