Skip to main content
Offensive Security (Pentest / Red Team)Listed as a long-term cert for that lane. Back to pathway
Cybersecurity

OSEP

OffSec's evasion / advanced AD cert, only meaningful after OSCP and red-team exposure.

DifficultyAdvanced
Study6–9 months
Exam (indicative)~£1,400
Valid3 years

Vendor record

This entry has not yet been read against the vendor's own documentation. Exam names, codes and prices shown on this page are indicative; check the vendor before booking anything.

Compare
POST verdict

Workable

Market-level call. Not personal advice.

OSCP's harder, narrower successor. A real signal for red team and adversary-simulation roles, near-invisible to general pentest hiring.

Confidence
High
Signal
Medium
Why this confidence
UK red team and adversary-simulation practices recognise the AV-evasion and lateral-movement scope directly. CREST CCT INF and OSEP appear together in senior red-team JDs at named consultancies.
Why this signal strength
Heavily weighted at red-team consultancies and at CBEST-aligned firms running adversary-simulation engagements. Largely irrelevant to web app or general internal pentest hiring, where OSCP plus reps is the screened combination. The AV-evasion-as-portfolio trap traps candidates without documented engagement output above the cert weight.
Who this pays off for
  • Red team operators at named UK consultancies running CBEST, STAR-FS or TBEST-aligned adversary-simulation engagements
  • Pentesters with OSCP plus two to four years of internal infrastructure reps wanting to move into evasion-shaped engagement work
  • Specialists targeting financial services purple-team roles where AV and EDR evasion is part of the scoped objective rather than out of scope
Who walks away with nothing
  • A general pentest credential. OSEP is evasion and process-injection focused; broad pentest hiring screens for OSCP plus engagement reps instead
  • A web app credential. OSWE is OffSec's web track; OSEP scope is internal infrastructure and evasion, not source-code review or chained web exploitation
  • An OSCP substitute. Hiring managers expect OSCP first; OSEP without it reads as an unusual entry path rather than a senior signal
The named failure mode

The OSEP-after-OSCP escalation pattern stalling without engagement output. Candidates pass both exams without three to six months of documented evasion-shaped engagement reps, and red-team consultancies screen for that operational record before the cert weight begins to count.

Recruiter signal, not marketing

Direct credibility in UK red team and adversary-simulation hiring at named consultancies, particularly where CBEST or TBEST scope demands documented evasion competency. Does not substitute for OSCP in general pentest hiring, does not displace OSWE for web-app roles, and adds limited weight outside adversary-simulation specialist tracks.

Falsifiability
  • OffSec restructures the OSCP-OSEP-OSWE certification path in a way that elevates OSEP to a more visible mid-tier credential outside red-team specialist hiring
  • Bank of England CBEST or PRA TBEST framework guidance explicitly references OSEP-style evasion competencies as a named requirement for accredited providers
  • EDR market consolidation reduces the diversity of evasion targets to a point where the cert's scope narrows in operational relevance

This tells you whether the cert is worth pursuing. It does not tell you whether it is worth pursuing for you.

See if it's right for you

This cert in isolation tells you very little. Here is where it actually sits. The pathways that use it, and the roles it realistically supports.

  • Senior pentest / red-team interviews
  • EDR evasion / C2 tradecraft credibility
Practitioner take

OSEP is OffSec's evasion and lateral movement cert and it's the credential that genuinely matters when red team hiring stops asking about OSCP and starts asking what you can do once EDR is in the way. The PEN-300 syllabus is AV bypass, custom tooling, AppLocker and constrained language mode, kerberos abuse, and persistence in mature AD estates. The exam is 48 hours and assumes you can write your own loaders. Take it when you've spent at least a year in a red team or senior pentest seat and the next move is internal red team lead or specialist consultancy work. Skip it straight off OSCP. The gap between the two exams is the gap between knowing exploitation and operating against a defender, and skipping it shows on day one of the engagement.

Authored opinion. Updated against current hiring conditions, not vendor marketing.

Recommended prior knowledge

  • OSCP or equivalent

Common misconceptions

  • OSEP alone clears HR filters; it doesn't replace shipped, documented work.

What this cert does NOT guarantee

  • Red-team lead roles on its own

Practitioner judgement. External evidence review pending.

Last reviewed: not yet reviewed · UK market

The next step

A cert is a signal. A Career Verdict tells you whether the signal is worth sending.

A Career Verdict tells you whether this cert earns its place on your specific route, what it won't fix, and what to sit before or after it.

A route shows what is possible. A Career Verdict makes the call.

POST ATLASVerdict no. PA-2026-0512
Career analysis report

Career Verdict

Helpdesk → Security Architect

“Realistic, but not by adding another certification.”
  1. 01
    The callA clear judgement on whether your route is realistic, and under what conditions.
  2. 02
    Where the route breaksThe most likely point to stall, and why it happens in practice.
  3. 03
    What to do nextSpecific priorities for the next 6–24 months, and what to drop.
Generated within POST’s practitioner-authored assessment frameworkPOST ATLAS

Career Verdict

£39One-off payment. No subscription.
  • The callA single written judgement on whether the route is realistic for you.
  • Plateaus and failure modesThe flat years and the specific ways this route tends to stall.
  • Where you standThe strongest and weakest parts of your current position, named.
  • Salary realityWhat this route actually pays, set against what you've been told it pays.
See the Career Verdict

Usually within minutes of payment. Kept 24 months, then deleted. Deletion on request at any time.

Built on POST's practitioner-authored assessment framework, informed by two decades across helpdesk, infrastructure and security. The verdict applies that framework to your inputs.