TCM Security

How TCM Security grades the PNPT report and debrief

Applies to PNPT.

What the PNPT report has to be, how the 15-minute live debrief works, and why TCM grades communication as heavily as the compromise.

PNPT
5-day exam + 2-day report + live debrief

TCM Security asks for something no other exam on this site does: after the report, you get on a live call and present your findings. The PNPT is graded on whether you can communicate an engagement to the people paying for it, not only on whether you reached the domain controller. Two of its five required components — the report and the debrief — are about exactly that.

What the report has to be

TCM’s requirement is deliberately short: a “detailed, professionally written report.” There is no official section list, no mandated length, and no required file format — the standard is that the document reads like a real client deliverable, not exam notes. As TCM puts it, if your report does a poor job of conveying what you found, it is as if those parts of the exam never happened.

In practice the shape follows TCM’s own public sample report and course material: an executive summary written for a non-technical reader, a scope and severity-rated findings summary, then technical findings with impact, affected systems and remediation for each, informational findings, and the supporting output. The distinguishing requirement is the executive summary — OffSec does not ask for one, TCM does, and it is where people who only know how to write technical steps come unstuck.

The live debrief

After you submit the report, you schedule a 15-minute video call with TCM’s assessors — all senior penetration testers. You show photo ID, give an overview of the vulnerabilities you found, and walk through how you ultimately compromised the domain controller. The intent is a client-style briefing: high-level, focused on how you got in, the impact, and what to fix — not a command-by-command technical dump.

It is a required component. All five pieces — OSINT, the external-to-internal compromise, reaching the DC, the report and the debrief — have to be completed to pass, so a strong hacking run that falls apart on the call is a real way to fail. Rehearse it: candidates consistently find they need several run-throughs to explain the whole engagement clearly inside fifteen minutes.

How the time works

You get five days on the machines and two further days for the report — seven days total, with the report window built in rather than squeezed into the exam. You submit, then book the debrief. Every voucher includes one free retake; further attempts are cheaper, and TCM rebuilds the environment between attempts, so a retake is not the same run again.

Where people lose it

PNPT vs OSCP, in one line

OSCP asks whether a stranger could reproduce your steps. PNPT asks whether you could explain the engagement to the client who is paying for it.

The exams this covers