How TCM Security grades the PNPT report and debrief
Applies to PNPT.
What the PNPT report has to be, how the 15-minute live debrief works, and why TCM grades communication as heavily as the compromise.
- PNPT
- 5-day exam + 2-day report + live debrief
TCM Security asks for something no other exam on this site does: after the report, you get on a live call and present your findings. The PNPT is graded on whether you can communicate an engagement to the people paying for it, not only on whether you reached the domain controller. Two of its five required components — the report and the debrief — are about exactly that.
What the report has to be
TCM’s requirement is deliberately short: a “detailed, professionally written report.” There is no official section list, no mandated length, and no required file format — the standard is that the document reads like a real client deliverable, not exam notes. As TCM puts it, if your report does a poor job of conveying what you found, it is as if those parts of the exam never happened.
In practice the shape follows TCM’s own public sample report and course material: an executive summary written for a non-technical reader, a scope and severity-rated findings summary, then technical findings with impact, affected systems and remediation for each, informational findings, and the supporting output. The distinguishing requirement is the executive summary — OffSec does not ask for one, TCM does, and it is where people who only know how to write technical steps come unstuck.
The live debrief
After you submit the report, you schedule a 15-minute video call with TCM’s assessors — all senior penetration testers. You show photo ID, give an overview of the vulnerabilities you found, and walk through how you ultimately compromised the domain controller. The intent is a client-style briefing: high-level, focused on how you got in, the impact, and what to fix — not a command-by-command technical dump.
It is a required component. All five pieces — OSINT, the external-to-internal compromise, reaching the DC, the report and the debrief — have to be completed to pass, so a strong hacking run that falls apart on the call is a real way to fail. Rehearse it: candidates consistently find they need several run-throughs to explain the whole engagement clearly inside fifteen minutes.
How the time works
You get five days on the machines and two further days for the report — seven days total, with the report window built in rather than squeezed into the exam. You submit, then book the debrief. Every voucher includes one free retake; further attempts are cheaper, and TCM rebuilds the environment between attempts, so a retake is not the same run again.
Where people lose it
- Ran out of days with a thin report. The hacking eats the week and the document gets rushed. It is graded like a deliverable — budget the two days.
- Missing evidence. Screenshots not captured before moving on, then impossible to reconstruct. Document as you go.
- A weak OSINT section. People over-write the exploitation and under-write the reconnaissance, leaving the report lopsided.
- Treating it like a CTF. Chasing shells with no structured methodology reads straight through into a disorganised report.
- Under-rehearsing the debrief. Freezing, or overrunning the fifteen minutes, on findings you clearly understood.
PNPT vs OSCP, in one line
OSCP asks whether a stranger could reproduce your steps. PNPT asks whether you could explain the engagement to the client who is paying for it.
The exams this covers
- what the PNPT exam involvesUnderstand