Skip to main content
Offensive Security (Pentest / Red Team)Listed as a primary cert for that lane. Back to pathway
Cybersecurity

CPTS

HTB's modern offensive benchmark, respected by practitioners, still building HR recognition.

DifficultyIntermediate
Study3–5 months
Exam (indicative)£165
Validlifetime

Vendor record

This entry has not yet been read against the vendor's own documentation. Exam names, codes and prices shown on this page are indicative; check the vendor before booking anything.

Compare
POST verdict

Strong

Market-level call. Not personal advice.

The most technically rigorous commercially available pentest cert right now, held back only by recruiter name-recognition lag.

Confidence
Medium
Signal
Medium
Why this confidence
Lab depth and exam difficulty are well documented across practitioner communities and independent attempts. The recognition gap is real but closing, so a High confidence call on long-term value is premature while the market is still calibrating.
Why this signal strength
Practitioners at MDSec, SensePost-lineage shops and red team forums rate it highly. Keyword penetration on UK job board specs still trails OSCP by a significant margin, which matters for candidates relying on inbound recruiter contact.
Who this pays off for
  • Mid-level practitioners who want a technically credible cert and can tolerate the recruiter recognition lag while CPTS builds market share
  • Consultants at shops where hiring panels review CVs without HR keyword pre-filtering
  • Pentesters supplementing OSCP who need to evidence breadth across the HTB Pro Labs attack surface
Who walks away with nothing
  • An immediate OSCP replacement on UK consultancy job specs that list OffSec certs explicitly
  • A cert that accelerates CREST CRT preparation on its own without separate CHECK methodology study
  • Equivalent recognition to OSCP for SC-cleared or government framework supplier audits
The named failure mode

Lab completion theatre. Candidates clock Pro Lab percentage without finishing the accompanying module paths, producing shallow attack-chain knowledge that collapses under methodology questioning in technical interviews.

Recruiter signal, not marketing

Buys genuine technical credibility with practitioners reviewing CVs directly and provides deep lab reps across AD, web and network attack surfaces. Does not buy CREST registration, does not satisfy CHECK team member requirements, and does not yet move the needle on automated recruiter screening at volume-hiring consultancies.

Falsifiability
  • HTB formalises a CREST or NCSC-recognised accreditation partnership
  • Major UK consultancies add CPTS to published accepted-qualifications lists alongside OSCP
  • OffSec pricing or accessibility changes push candidates toward CPTS at scale, triggering recruiter familiarity

This tells you whether the cert is worth pursuing. It does not tell you whether it is worth pursuing for you.

See if it's right for you

This cert in isolation tells you very little. Here is where it actually sits. The pathways that use it, and the roles it realistically supports.

  • Pentest interviews at modern shops
  • Strong portfolio signal
  • Community credibility
Practitioner take

CPTS is HackTheBox's answer to OSCP, and on technical depth it's the better exam. Modern web exploitation, AD attack chains, real lateral movement, a seven-day window with a written report. It sits in Tier 2 because of recognition, not quality. UK pentest consultancies still ask for OSCP by name in job specs, and CPTS lands somewhere between novelty and respected depending on the hiring manager. Take it if you're already deep in HTB Academy modules, want the strongest technical pentest exam available, and the rest of your CV can carry the conversation about why you skipped OSCP.

Authored opinion. Updated against current hiring conditions, not vendor marketing.

Recommended prior knowledge

  • HTB Academy Penetration Tester path

Common misconceptions

  • CPTS alone clears HR filters; it doesn't replace shipped, documented work.

What this cert does NOT guarantee

  • Government roles that still list OSCP by name

Practitioner judgement. External evidence review pending.

Last reviewed: not yet reviewed · UK market

The next step

A cert is a signal. A Career Verdict tells you whether the signal is worth sending.

A Career Verdict tells you whether this cert earns its place on your specific route, what it won't fix, and what to sit before or after it.

A route shows what is possible. A Career Verdict makes the call.

POST ATLASVerdict no. PA-2026-0512
Career analysis report

Career Verdict

Helpdesk → Security Architect

“Realistic, but not by adding another certification.”
  1. 01
    The callA clear judgement on whether your route is realistic, and under what conditions.
  2. 02
    Where the route breaksThe most likely point to stall, and why it happens in practice.
  3. 03
    What to do nextSpecific priorities for the next 6–24 months, and what to drop.
Generated within POST’s practitioner-authored assessment frameworkPOST ATLAS

Career Verdict

£39One-off payment. No subscription.
  • The callA single written judgement on whether the route is realistic for you.
  • Plateaus and failure modesThe flat years and the specific ways this route tends to stall.
  • Where you standThe strongest and weakest parts of your current position, named.
  • Salary realityWhat this route actually pays, set against what you've been told it pays.
See the Career Verdict

Usually within minutes of payment. Kept 24 months, then deleted. Deletion on request at any time.

Built on POST's practitioner-authored assessment framework, informed by two decades across helpdesk, infrastructure and security. The verdict applies that framework to your inputs.