Sequencing

Which certification should you take first?

The honest answer is that it depends on where you are starting and what you want to do — and that OSCP, the default recommendation, is the wrong first exam for a lot of people.

Don't start with OSCP if you're new — start with eJPT to build the baseline, then CPTS or PNPT for a full methodology. Pick a direction first (network, web, red team, or defense); the direction matters more than the badge. OSCP is worth holding but is a checkpoint you prepare for, not a starting line.

New to the field
eJPT → CPTS or PNPT
Aiming at OSCP
CPTS first, then OSCP
Web focus
BSCP → OSWE
Defensive
CDSA or OSDA
A decision tree for choosing a first offensive-security certification by starting point: new to the field starts eJPT then CPTS; aiming at OSCP goes CPTS then OSCP then OSEP; web application security is BSCP then OSWE; red team and Active Directory is CRTP, CRTO then CRTE; defensive is CDSA or OSDA.
Find the branch that matches you. Direction first, then the sequence within it.

Start by picking a direction, not a certification

The vendors cluster by discipline. Committing to a direction first narrows nineteen options to a handful, and the direction matters more than the badge: an employer hiring a web pentester does not care that you hold a network cert.

If you are new to the field

Do not start with OSCP. It is a hard exam that assumes a working baseline, and starting there is how people burn a voucher and their confidence in one week.

Start with something that builds and confirms the baseline: EJPT is designed for exactly this, entry-level and practical. CJCA covers similar ground on the defensive side. From there, CPTS or PNPT are strong intermediate steps that teach a full methodology and, unlike OSCP, include Active Directory as a core part of the exam rather than an add-on.

A typical network-penetration-testing progression: eJPT (entry) to CPTS (intermediate) to OSCP (advanced) to OSEP (expert).
One common route through the network-pentest track — build the baseline before OSCP, not on it.

If OSCP is the goal

It is still worth holding — it is the most widely recognised name in the space, which is exactly why its search results are dominated by the vendor and the big education brands. But treat it as a checkpoint you prepare for, not a starting line. CPTS in particular covers overlapping ground with a gentler on-ramp and a longer report window, and people who do it first tend to find OSCP less of a wall.

After a first pentest cert

This is where the paths fork by direction:

A note on cost and time

These are expensive in money and in months. Stacking three certifications in a year is possible and rarely wise — the market values demonstrated skill over a row of acronyms, and a portfolio of work often outweighs the next badge. Pick the one that opens the door you are actually trying to walk through, and go deep.

Every certification, mapped

The full landscape by discipline and level is on the certifications page.