CWEE vs OSWE
Two web exams that come up together — how they actually differ, and who each one is for.
These are the two hardest web-exploitation certs, and they are close. Both are expert white-box exams demanding source-code review and working exploits. OSWE ($1,749) is a 47h45m exam plus a 24-hour report, with wider recognition through the OSCE3 track. HTB's CWEE is cheaper — a $350 voucher, or ~$1,260 Gold — with a relaxed 10-day window. Budget picks CWEE; prestige picks OSWE.
- CWEE
- expert, $350 exam voucher, or $1,260/yr Gold Annual (bundles it)
- OSWE
- expert, From roughly $1,749 with course (WEB-300)
- Harder
- about equal
| CWEE | OSWE | |
|---|---|---|
| Vendor | Hack The Box | OffSec |
| Level | expert | expert |
| Duration | 10-day window | 48 hours |
| Format | white-box web exploit development + commercial report, expert level | practical white-box web + report |
| Cost | $350 exam voucher, or $1,260/yr Gold Annual (bundles it) | From roughly $1,749 with course (WEB-300) |
What each one is
OSWE (OffSec’s WEB-300) is the long-standing benchmark for expert web exploitation: white-box source-code review turned into custom exploits, wrapped in one of OffSec’s OSCP-style endurance exams. CWEE (HTB Certified Web Exploitation Expert) is Hack The Box’s answer to it — the same expert white-box tier, source review plus working exploits, delivered on HTB’s newer platform. People who have passed both describe them as the two most technically advanced web certs currently available, and treat CWEE as the direct HTB equivalent of OSWE.
The real difference
The skills overlap heavily — both demand that you read code and produce exploits — but the emphasis differs. OSWE goes deeper on exploit engineering: you write custom scripts, handle reverse shells in code, and race a clock. CWEE leans broader and more modern, covering edge-case vulnerability classes and expecting you to patch what you find, not just exploit it. One holder of both rated OSWE 7.5 out of 10 for difficulty and CWEE a 10, partly because CWEE’s targets combine web with other services. Recognition still favours OSWE, largely because it feeds OffSec’s prestigious OSCE3 track.
Cost and time
Cost is where CWEE pulls ahead. OSWE is a $1,749 bundle for the course and one attempt; the exam is 47 hours 45 minutes to hit 85/100, then a 24-hour reporting window. CWEE is far cheaper — a $350 exam voucher, or roughly $1,260 for the Gold annual tier that bundles the training — and it gives you a non-proctored 10-day window to finish and report. For many candidates the lower price and looser clock, with no invigilator watching, are the deciding factors.
Which one to choose
If recognition and the OSCE3 path matter to you, OSWE is still the safer résumé line. If budget, modern content, or exam comfort matter more, CWEE delivers comparable rigour for less money and far less time pressure. Several people who have done both recommend OSWE first, for its exploit-development foundations, then CWEE to broaden into newer vulnerability classes — but in either order you finish with elite white-box skills. There is no wrong choice here; there is only which trade-off you prefer.
What people who sat these say
If you can do both, which is my recommendation, I would suggest the order OSWE first and then CWEE.
Found both CWEE and OSWE equally challenging as both require understanding source code to exploit vulnerabilities.
Full detail on each: CWEE · OSWE. For where both sit in a longer plan, see the roadmap.