Which certification should you take first?
The honest answer is that it depends on where you are starting and what you want to do — and that OSCP, the default recommendation, is the wrong first exam for a lot of people.
Don't start with OSCP if you're new — start with eJPT to build the baseline, then CPTS or PNPT for a full methodology. Pick a direction first (network, web, red team, or defense); the direction matters more than the badge. OSCP is worth holding but is a checkpoint you prepare for, not a starting line.
- New to the field
- eJPT → CPTS or PNPT
- Aiming at OSCP
- CPTS first, then OSCP
- Web focus
- BSCP → OSWE
- Defensive
- CDSA or OSDA

Start by picking a direction, not a certification
The vendors cluster by discipline. Committing to a direction first narrows nineteen options to a handful, and the direction matters more than the badge: an employer hiring a web pentester does not care that you hold a network cert.
- Network penetration testing — the broadest path, and the one most job listings mean by "pentester".
- Web application security — deep specialisation, strong demand, different skill set.
- Red teaming and Active Directory — assumes you can already pentest; this is the layer above.
- Defensive and SOC analysis — the blue-team path, often overlooked and less crowded.
If you are new to the field
Do not start with OSCP. It is a hard exam that assumes a working baseline, and starting there is how people burn a voucher and their confidence in one week.
Start with something that builds and confirms the baseline: EJPT is designed for exactly this, entry-level and practical. CJCA covers similar ground on the defensive side. From there, CPTS or PNPT are strong intermediate steps that teach a full methodology and, unlike OSCP, include Active Directory as a core part of the exam rather than an add-on.

If OSCP is the goal
It is still worth holding — it is the most widely recognised name in the space, which is exactly why its search results are dominated by the vendor and the big education brands. But treat it as a checkpoint you prepare for, not a starting line. CPTS in particular covers overlapping ground with a gentler on-ramp and a longer report window, and people who do it first tend to find OSCP less of a wall.
After a first pentest cert
This is where the paths fork by direction:
- Deeper into offense: OSEP for evasion and advanced techniques, or the red-team path — CRTO and CRTP — for Active Directory operations.
- Into web: BSCP then OSWE, which is one of the most respected and most specialised exams in the field.
- Into defense: CDSA or OSDA, which pair well with offensive experience because knowing the attack makes the detection obvious.
A note on cost and time
These are expensive in money and in months. Stacking three certifications in a year is possible and rarely wise — the market values demonstrated skill over a row of acronyms, and a portfolio of work often outweighs the next badge. Pick the one that opens the door you are actually trying to walk through, and go deep.
Every certification, mapped
The full landscape by discipline and level is on the certifications page.