EJPT vs PNPT
Two pentest exams that come up together — how they actually differ, and who each one is for.
This is the classic progression. eJPT is INE's entry cert — a 48-hour, auto-graded lab that proves you can enumerate and exploit, with no report. PNPT is TCM Security's beginner-to-intermediate exam: five days on a simulated network, two days to write a professional report, then a live debrief. Start with eJPT to build fundamentals; move to PNPT to prove you can run a real engagement.
- EJPT
- entry, Bundled with INE training (commonly ~$249); no sticker price on the INE page
- PNPT
- intermediate, $499 (exam + 45h training, 12-month access; one free retake)
- Harder
- PNPT
| EJPT | PNPT | |
|---|---|---|
| Vendor | INE | TCM Security |
| Level | entry | intermediate |
| Duration | 48-hour exam | 5-day exam + 2-day report + live debrief |
| Format | 48-hour auto-graded practical with dynamic flags; no written report | full external-to-internal engagement, report, and a live 15-minute debrief |
| Cost | Bundled with INE training (commonly ~$249); no sticker price on the INE page | $499 (exam + 45h training, 12-month access; one free retake) |
What each one is
eJPT (Junior Penetration Tester) from INE is where most people start. It covers the fundamentals — reconnaissance, enumeration, host and network exploitation, and basic web attacks — in a hands-on lab exam that runs for 48 hours and is graded automatically from questions tied to what you compromise. There is no report to write.
PNPT (Practical Network Penetration Tester) from TCM Security is the next rung. It simulates a full engagement against a corporate network, including an Active Directory attack chain. You get five days to compromise the environment, two more to write a professional penetration-test report, and then a live debrief where you present your findings to TCM’s assessors.
The real difference
eJPT answers “can you find and exploit a vulnerability?” PNPT answers “can you run a client engagement end to end?” That includes pivoting through Active Directory, chaining weaknesses, writing a report a client would actually accept, and defending your work out loud in the debrief.
The debrief is the standout. Very few certifications at this level make you explain your methodology to real assessors, and it mirrors what happens after a real test. eJPT never asks you to communicate results; PNPT makes communication half the exam.
Cost and time
eJPT is bundled with INE’s Penetration Testing Student training at roughly $249, includes a free retake, and gives you 48 hours of exam lab time. Discounts appear regularly, so the effective price is often lower.
PNPT is $499 and includes the full training courses, the exam, and a free retake. The exam itself spans seven days total — five to attack, two to report — plus the scheduled debrief. For the money you get considerably more training content and a far more realistic assessment, though it is a bigger time commitment.
Which one to choose
If you are starting from zero, take eJPT first. It removes the paralysis of not knowing where to begin, builds core enumeration and exploitation habits, and confirms that offensive security is the path you want.
Move to PNPT once you are comfortable in the labs. It validates the things eJPT does not test — Active Directory, real reporting, and client communication — and sits closer to what a junior pentesting job actually demands. Many people use PNPT as their bridge toward tougher exams later.
You do not strictly need eJPT before PNPT. If you already have solid hands-on experience from platforms and CTFs, PNPT can be your entry point directly. But for most beginners, the eJPT-then-PNPT path is the smoothest way up.
What people who sat these say
It not only gave me hands-on skills in penetration testing but also boosted my confidence to pursue more advanced certifications.
the PNPT has been the best certification exam I have taken so far
Full detail on each: EJPT · PNPT. For where both sit in a longer plan, see the roadmap.