Exam report guides, by vendor
Most of these exams are scored on a written report, not just on getting root — and a large share of failures are report failures, not hacking failures. Every vendor's standard reduces to one test: could a competent stranger reproduce your work from the page alone? Start with the general standard, then your vendor's specifics.
- Report-graded vendors
- 5
- The one test
- Reproducible?
- Top avoidable fail
- No IP in the proof shot

Structure, evidence standards and grading criteria that sit behind every vendor's rules — and the failure modes that cost people an exam they had already passed on the machines.
Read the guide →What the OSCP, OSEP, OSWE, OSED, OSWP and OSDA report has to contain, how it is marked, and the mistakes that fail an otherwise passing exam.
Full guide →Hack The BoxWhat the CPTS, CBBH, CDSA and CWEE report has to contain — a client-ready commercial deliverable, not an exam answer sheet.
Full guide →Altered SecurityWhat the CRTP, CRTE and CARTP report has to contain — the Active Directory attack path, documented so it can be walked again.
Full guide →TCM SecurityWhat the PNPT report has to be, how the 15-minute live debrief works, and why TCM grades communication as heavily as the compromise.
Full guide →EC-CouncilWhat the CPENT report must contain, why it is the evidence that makes your range flags count, and how the CPENT and LPT Master score bands work.
Full guide →Not listed: CRTO (Zero-Point), BSCP (PortSwigger) and eJPT (INE) are flag-based or auto-graded and have no written report to prepare.