Still the practitioner benchmark for offensive security in UK consultancy and red-team hiring. Earned the hard way, respected for that reason.
- UK pentest consultancies and red-team functions continue to treat OSCP as the working-class senior signal. CREST CRT carries regulatory weight, but OSCP carries practitioner weight, and the two reinforce rather than replace each other.
- Pentest consultancy and red-team JDs name OSCP as required or strongly preferred. CHECK and CREST CRT sit alongside it for regulated UK work, but recruiter shortlist behaviour treats OSCP as the default filter.
Best for
- Sysadmins and SOC analysts with active homelab time targeting a first pentest consultancy seat
- Internal movers in security teams formalising existing offensive reps for a consultancy hire
- AppSec and red-team candidates pairing OSCP with OSEP, OSWE or CRTO to widen senior shortlist coverage
Usually a mistake for
- Career changers with no Linux, networking or scripting fundamentals. The exam will end at hour eight rather than hour twenty-four.
- Compliance-track or GRC-leaning candidates. CISSP, CISM or CRISC carry more weight on those shortlists.
- Defenders looking to broaden into offensive thinking. BTL1, GCIH or PEH do more for the actual day job.
Common mistake
Booking the exam attempt before the lab work is real. Candidates rely on writeups and methodology mnemonics, run out of attack surface on the second box, and never recover the time. The walkthrough-prepared-OSCP-attempt pattern is the most common reason capable candidates fail two attempts in a row before passing on the third.
What it actually does
Shortlist position on UK pentest consultancy, red-team and offensive security engineer roles. It does not unlock CREST-regulated test lead positions without CRT, and it does not substitute for shipped engagement reports at senior consultant level.
What would change this call
- OffSec restructures the OSCP exam toward a multi-day engagement-report format and the practitioner signal sharpens further
- CREST CRT becomes the dominant UK pentest hiring filter for non-regulated commercial work as well as regulated
- Hands-on platforms like Hack The Box Pro Labs or TCM PNPT reach recruiter recognition parity with OSCP in mainstream UK consultancy hiring
This tells you whether the cert is worth pursuing. It does not tell you whether it is worth pursuing for you.
See if it's right for you