Skip to main content
Cybersecurity

GIAC GWAPT

SANS web app pentest cert. Credible in SANS-funded shops; OSWE is the deeper alternative.

DifficultyIntermediate+
Study3–6 months
Exam£770 (with course) / £1,575 standalone
Valid4 years
Compare
POST verdict
WorkableMarket-level call. Not personal advice.

The GIAC web-app track. Useful where SANS branding is the institutional preference; outside that, OSWE and bug-bounty output dominate.

Confidence: Medium Signal strength: Low
Recognition is concentrated in SANS-aligned consultancies and US-federal-adjacent work. UK commercial web pentest hiring weights OSWE, Burp Suite Certified Practitioner and documented research more heavily.
Strong inside MOD-cleared, intelligence and SANS-funded enterprise hiring. Weaker in commercial UK web pentest hiring, where the screened combination is OSWE plus Burp Suite Certified Practitioner plus bug-bounty output. The GIAC-AppSec-narrow-track pattern keeps the addressable market thin at UK commercial web-pentest consultancies.
Who this pays off for
  • Web-app pentesters at MOD-cleared or US-federal-adjacent consultancies where SANS branding is the institutional default
  • Enterprise AppSec professionals at SANS-funded large UK organisations using employer-paid training rather than self-funded OSWE
  • Pentesters targeting defence or intelligence community web-app engagements where GIAC is the named acceptable credential
Who walks away with nothing
  • An OSWE substitute. UK commercial web-pentest consultancies screen for OSWE plus PortSwigger output rather than GWAPT
  • A general pentest credential. GWAPT is web-app-scoped; broad pentest hiring screens for OSCP plus reps instead
  • An AppSec engineering credential. The exam is exploitation-shaped, not secure-development-lifecycle focused
The named failure mode

The GWAPT-vs-OSWE comparison trap. Candidates self-fund GWAPT expecting parity with OSWE in commercial UK web-pentest hiring, then discover that hiring panels at named consultancies treat OSWE plus Burp Suite Certified Practitioner as the screened combination instead.

Recruiter signal, not marketing

Credibility in SANS-aligned web-pentest hiring at MOD-cleared and US-federal-adjacent firms. Sits alongside GPEN for GIAC-shaped offensive careers. Does not substitute for OSWE plus PortSwigger output in commercial UK web-pentest hiring, and does not displace bug-bounty track record at mature programmes.

Falsifiability
  • SANS materially reduces GIAC pricing or restructures the web-app track in a way that drives commercial UK consultancy adoption beyond MOD-cleared hiring
  • PortSwigger's Burp Suite Certified Practitioner programme becomes the only screened credential at mid-market UK web-pentest consultancies, displacing both GWAPT and OSWE
  • UK regulated finance explicitly names GIAC AppSec credentials as required competencies for CBEST or TBEST-aligned web-app testing

This tells you whether the cert is worth pursuing. It does not tell you whether it is worth pursuing for you.

See if it's right for you

This cert in isolation tells you very little. Here is where it actually sits. The pathways that use it, and the roles it realistically supports.

  • Web pentest shortlists in SANS-aligned environments
Practitioner take

GWAPT is the web application pentest cert and it sits in an awkward spot. The syllabus is competent, the SANS course teaches modern web exploitation properly, and the cert holds up technically. The market problem is that web pentest hiring weights OSWE, Burp Suite Certified Practitioner, and demonstrable PortSwigger Academy lab evidence above GWAPT, mostly because those credentials prove the same skills at a fraction of the price. Take GWAPT only when an employer funds the SANS course and you're already inside a web-focused security seat. Skip it self-funded. BSCP plus a public writeup portfolio outperforms it on every UK web pentest CV.

Authored opinion. Updated against current hiring conditions, not vendor marketing.

Recommended prior knowledge

  • Web app testing experience

Common misconceptions

  • GIAC GWAPT alone clears HR filters; it doesn't replace shipped, documented work.

What this cert does NOT guarantee

  • Senior AppSec roles by itself

The next step

A cert is a signal. A Career Verdict tells you whether the signal is worth sending.

A Career Verdict tells you whether this cert earns its place on your specific route, what it won't fix, and what to sit before or after it.

A route shows what people usually do. A Career Verdict judges whether it's realistic for you.

Get a judgement on your situation£39, one-off. Built for your inputs, yours to keep.

Built on POST's practitioner-authored assessment framework, calibrated by James from twenty years across helpdesk, infrastructure and security. Framework is human-authored; the verdict applies it to your inputs.