Skip to main content
Cybersecurity

GIAC GWAPT

SANS web app pentest cert. Credible in SANS-funded shops; OSWE is the deeper alternative.

DifficultyIntermediate+
Study3–6 months
Exam (indicative)£770 (with course) / £1,575 standalone
Valid4 years

Vendor record

This entry has not yet been read against the vendor's own documentation. Exam names, codes and prices shown on this page are indicative; check the vendor before booking anything.

Compare
POST verdict

Workable

Market-level call. Not personal advice.

The GIAC web-app track. Useful where SANS branding is the institutional preference; outside that, OSWE and bug-bounty output dominate.

Confidence
Medium
Signal
Low
Why this confidence
Recognition is concentrated in SANS-aligned consultancies and US-federal-adjacent work. UK commercial web pentest hiring weights OSWE, Burp Suite Certified Practitioner and documented research more heavily.
Why this signal strength
Strong inside MOD-cleared, intelligence and SANS-funded enterprise hiring. Weaker in commercial UK web pentest hiring, where the screened combination is OSWE plus Burp Suite Certified Practitioner plus bug-bounty output. The GIAC-AppSec-narrow-track pattern keeps the addressable market thin at UK commercial web-pentest consultancies.
Who this pays off for
  • Web-app pentesters at MOD-cleared or US-federal-adjacent consultancies where SANS branding is the institutional default
  • Enterprise AppSec professionals at SANS-funded large UK organisations using employer-paid training rather than self-funded OSWE
  • Pentesters targeting defence or intelligence community web-app engagements where GIAC is the named acceptable credential
Who walks away with nothing
  • An OSWE substitute. UK commercial web-pentest consultancies screen for OSWE plus PortSwigger output rather than GWAPT
  • A general pentest credential. GWAPT is web-app-scoped; broad pentest hiring screens for OSCP plus reps instead
  • An AppSec engineering credential. The exam is exploitation-shaped, not secure-development-lifecycle focused
The named failure mode

The GWAPT-vs-OSWE comparison trap. Candidates self-fund GWAPT expecting parity with OSWE in commercial UK web-pentest hiring, then discover that hiring panels at named consultancies treat OSWE plus Burp Suite Certified Practitioner as the screened combination instead.

Recruiter signal, not marketing

Credibility in SANS-aligned web-pentest hiring at MOD-cleared and US-federal-adjacent firms. Sits alongside GPEN for GIAC-shaped offensive careers. Does not substitute for OSWE plus PortSwigger output in commercial UK web-pentest hiring, and does not displace bug-bounty track record at mature programmes.

Falsifiability
  • SANS materially reduces GIAC pricing or restructures the web-app track in a way that drives commercial UK consultancy adoption beyond MOD-cleared hiring
  • PortSwigger's Burp Suite Certified Practitioner programme becomes the only screened credential at mid-market UK web-pentest consultancies, displacing both GWAPT and OSWE
  • UK regulated finance explicitly names GIAC AppSec credentials as required competencies for CBEST or TBEST-aligned web-app testing

This tells you whether the cert is worth pursuing. It does not tell you whether it is worth pursuing for you.

See if it's right for you

This cert in isolation tells you very little. Here is where it actually sits. The pathways that use it, and the roles it realistically supports.

  • Web pentest shortlists in SANS-aligned environments
Practitioner take

GWAPT is the web application pentest cert and it sits in an awkward spot. The syllabus is competent, the SANS course teaches modern web exploitation properly, and the cert holds up technically. The market problem is that web pentest hiring weights OSWE, Burp Suite Certified Practitioner, and demonstrable PortSwigger Academy lab evidence above GWAPT, mostly because those credentials prove the same skills at a fraction of the price. Take GWAPT only when an employer funds the SANS course and you're already inside a web-focused security seat. Skip it self-funded. BSCP plus a public writeup portfolio outperforms it on every UK web pentest CV.

Authored opinion. Updated against current hiring conditions, not vendor marketing.

Recommended prior knowledge

  • Web app testing experience

Common misconceptions

  • GIAC GWAPT alone clears HR filters; it doesn't replace shipped, documented work.

What this cert does NOT guarantee

  • Senior AppSec roles by itself

Practitioner judgement. External evidence review pending.

Last reviewed: not yet reviewed · UK market

The next step

A cert is a signal. A Career Verdict tells you whether the signal is worth sending.

A Career Verdict tells you whether this cert earns its place on your specific route, what it won't fix, and what to sit before or after it.

A route shows what is possible. A Career Verdict makes the call.

POST ATLASVerdict no. PA-2026-0512
Career analysis report

Career Verdict

Helpdesk → Security Architect

“Realistic, but not by adding another certification.”
  1. 01
    The callA clear judgement on whether your route is realistic, and under what conditions.
  2. 02
    Where the route breaksThe most likely point to stall, and why it happens in practice.
  3. 03
    What to do nextSpecific priorities for the next 6–24 months, and what to drop.
Generated within POST’s practitioner-authored assessment frameworkPOST ATLAS

Career Verdict

£39One-off payment. No subscription.
  • The callA single written judgement on whether the route is realistic for you.
  • Plateaus and failure modesThe flat years and the specific ways this route tends to stall.
  • Where you standThe strongest and weakest parts of your current position, named.
  • Salary realityWhat this route actually pays, set against what you've been told it pays.
See the Career Verdict

Usually within minutes of payment. Kept 24 months, then deleted. Deletion on request at any time.

Built on POST's practitioner-authored assessment framework, informed by two decades across helpdesk, infrastructure and security. The verdict applies that framework to your inputs.