Skip to main content
Offensive Security (Pentest / Red Team)Listed as a long-term cert for that lane. Back to pathway
Cybersecurity

OSWE

OffSec's web-exploitation cert. The deepest hands-on AppSec credential for source-aware testers.

DifficultyAdvanced
Study6–9 months
Exam (indicative)~£1,400
Valid3 years

Vendor record

This entry has not yet been read against the vendor's own documentation. Exam names, codes and prices shown on this page are indicative; check the vendor before booking anything.

Compare
POST verdict

Workable

Market-level call. Not personal advice.

A real web-app exploitation signal where source-code review and chained-bug work is the scope. Outside that scope, the recognition runs thin.

Confidence
Medium
Signal
Medium
Why this confidence
Recognised at UK web-focused consultancies and AppSec practices, but the addressable market is narrower than general pentest. Bug bounty output now competes with OSWE as a screening signal in the same hiring panels.
Why this signal strength
Strong within dedicated web-app pentest and AppSec consultancies running source-code-led engagements. Weaker in general pentest hiring, where OSCP plus engagement reps remains the screened combination and OSWE adds breadth rather than gating credibility. The source-code-only trap narrows the credential's signal at AppSec hiring panels valuing breadth across runtime and design review.
Who this pays off for
  • Web-app pentesters at UK consultancies running source-code-led testing against fintech, SaaS and bespoke enterprise web platforms
  • AppSec engineers wanting an exploitation-shaped credential to complement secure-code review and SAST tooling experience
  • Bug bounty hunters formalising chained-bug and authentication-bypass research into a recognised offensive credential
Who walks away with nothing
  • A general pentest credential. OSWE is web-app and source-code focused; broad pentest hiring screens for OSCP plus reps instead
  • An AppSec engineering credential. The exam is exploitation-led, not secure-development-lifecycle or threat-modelling focused, and CSSLP or domain reps cover that ground
  • A bug bounty substitute. Mature programmes recognise documented critical-severity output more directly than the cert line item
The named failure mode

The OSWE-without-bug-bounty-context trap. Candidates pass the exam without a public research footprint or HackerOne or Bugcrowd track record, and UK web-pentest consultancies screen those signals together rather than weighting the cert alone.

Recruiter signal, not marketing

Credibility in dedicated web-app pentest hiring at named UK consultancies and in AppSec engineering roles where exploitation depth is valued. Sits naturally alongside Burp Suite Certified Practitioner and bug-bounty output. Does not substitute for OSCP in general pentest hiring, and does not displace CSSLP-style credentials in secure-development-lifecycle roles.

Falsifiability
  • OffSec updates the OSWE syllabus to cover modern API, GraphQL and identity-provider exploitation in a way that broadens its relevance beyond classical web stacks
  • PortSwigger's Burp Suite Certified Practitioner programme becomes the dominant screened credential for UK web-app pentest hiring, narrowing OSWE's market
  • Major UK web-pentest consultancies publicly shift their hiring criteria to weight documented bug-bounty output above structured exploitation certs

This tells you whether the cert is worth pursuing. It does not tell you whether it is worth pursuing for you.

See if it's right for you

This cert in isolation tells you very little. Here is where it actually sits. The pathways that use it, and the roles it realistically supports.

  • Senior AppSec / code-review interviews
  • Bug-bounty credibility
Practitioner take

OSWE is OffSec's white-box web exploitation cert and it sits in a very specific lane: source code review, authentication bypass, and chained vulnerabilities in real applications. The WEB-300 course teaches you to read a codebase and turn a logic flaw into RCE, which is genuinely different work from running Burp against a black-box target. Take it when you're already in an application security or web pentest seat and the work involves source access. Skip it as a generalist web cert. BSCP plus a public lab portfolio carries further on a black-box pentest CV, and OSWE only pays back when the role specifically demands source-led review. The exam is brutal and the price is high; both only make sense with the seat already in front of you.

Authored opinion. Updated against current hiring conditions, not vendor marketing.

Recommended prior knowledge

  • Strong web app testing experience

Common misconceptions

  • OSWE alone clears HR filters; it doesn't replace shipped, documented work.

What this cert does NOT guarantee

  • Pentest or red-team roles by itself

Practitioner judgement. External evidence review pending.

Last reviewed: not yet reviewed · UK market

The next step

A cert is a signal. A Career Verdict tells you whether the signal is worth sending.

A Career Verdict tells you whether this cert earns its place on your specific route, what it won't fix, and what to sit before or after it.

A route shows what is possible. A Career Verdict makes the call.

POST ATLASVerdict no. PA-2026-0512
Career analysis report

Career Verdict

Helpdesk → Security Architect

“Realistic, but not by adding another certification.”
  1. 01
    The callA clear judgement on whether your route is realistic, and under what conditions.
  2. 02
    Where the route breaksThe most likely point to stall, and why it happens in practice.
  3. 03
    What to do nextSpecific priorities for the next 6–24 months, and what to drop.
Generated within POST’s practitioner-authored assessment frameworkPOST ATLAS

Career Verdict

£39One-off payment. No subscription.
  • The callA single written judgement on whether the route is realistic for you.
  • Plateaus and failure modesThe flat years and the specific ways this route tends to stall.
  • Where you standThe strongest and weakest parts of your current position, named.
  • Salary realityWhat this route actually pays, set against what you've been told it pays.
See the Career Verdict

Usually within minutes of payment. Kept 24 months, then deleted. Deletion on request at any time.

Built on POST's practitioner-authored assessment framework, informed by two decades across helpdesk, infrastructure and security. The verdict applies that framework to your inputs.