Skip to main content
Cybersecurity

CompTIA PenTest+

Recognised in compliance-driven shops; carries far less weight than OSCP/PNPT in technical interviews.

DifficultyIntermediate+
Study3–5 months
Exam£240
Valid3 years
Compare
POST verdict
OverratedMarket-level call. Not personal advice.

Clears HR keyword filters at compliance-driven buyers, but practitioners treat it as weak technical evidence and that gap doesn't close.

Confidence: High Signal strength: Low
Market position is stable and well observed over several years. The HR-versus-practitioner split is not a transitional phase, it reflects a structural difference in what the cert was designed to prove.
The signal it sends depends entirely on who is reading the CV. CompTIA brand recognition gets it through some HR filters. Any practitioner-led screen immediately deprioritises it against OSCP, CPTS or CREST CRT.
Who this pays off for
  • Candidates targeting in-house security roles at large enterprises or public sector bodies where HR qualification frameworks list CompTIA by name
  • Testers in US-aligned organisations where DoD 8570 or 8140 compliance drives hiring criteria and UK equivalents follow suit
  • Professionals needing a vendor-neutral pentest line item for audit or procurement documentation rather than practitioner credibility
Who walks away with nothing
  • A stepping stone that builds the practical skills needed for OSCP or CREST CRT without substantial additional lab work
  • A cert that carries weight at UK consultancies like NCC, PTP or Context where hiring panels are active pentesters
  • An alternative to CREST CRT for CHECK team member status, which has no CompTIA pathway
The named failure mode

Compliance-credibility conflation. Candidates assume HR filter success translates to technical interview credibility, arriving at consultancy-side interviews unable to walk through an engagement methodology under questioning.

Recruiter signal, not marketing

Buys passage through automated screening at compliance-led buyers and ticks vendor-neutral boxes in procurement frameworks. Does not buy respect in practitioner interviews, does not satisfy CREST registration requirements, and does not evidence hands-on attack capability to any hiring manager who has sat the OSCP exam themselves.

Falsifiability
  • CompTIA adds a genuinely hands-on practical exam component with report deliverable, shifting it toward PNPT territory
  • UK public sector procurement frameworks explicitly replace CREST CRT references with CompTIA PenTest+ as an accepted equivalent
  • NCSC or DSIT update the CCP scheme to reference PenTest+ as an approved qualification, pulling it into government hiring pipelines

This tells you whether the cert is worth pursuing. It does not tell you whether it is worth pursuing for you.

See if it's right for you

This cert in isolation tells you very little. Here is where it actually sits. The pathways that use it, and the roles it realistically supports.

  • DoD 8570 pentest baseline
  • Government / contractor filtering
Practitioner take

PenTest+ is the cert that compliance frameworks like and practising pentesters don't. The exam covers scoping, methodology, and reporting at a competent vendor-neutral level, which is genuinely useful knowledge for an internal pentester or a junior consultant. The market reality, though: hiring managers at offensive security shops will weight PNPT, eJPT, OSCP, and HTB CPTS above PenTest+ every time, because those certs require you to compromise a real lab and write the report. Take PenTest+ if you're in an internal team that maps roles to DoD 8570 or CompTIA-friendly compliance lists. Skip it if you're trying to break into consultancy work.

Authored opinion. Updated against current hiring conditions, not vendor marketing.

Recommended prior knowledge

  • Security+ knowledge
  • Basic Linux & networking

Common misconceptions

  • CompTIA PenTest+ alone clears HR filters; it doesn't replace shipped, documented work.

What this cert does NOT guarantee

  • Consulting pentest roles
  • Red team work

The next step

A cert is a signal. A Career Verdict tells you whether the signal is worth sending.

A Career Verdict tells you whether this cert earns its place on your specific route, what it won't fix, and what to sit before or after it.

A route shows what people usually do. A Career Verdict judges whether it's realistic for you.

Get a judgement on your situation£39, one-off. Built for your inputs, yours to keep.

Built on POST's practitioner-authored assessment framework, calibrated by James from twenty years across helpdesk, infrastructure and security. Framework is human-authored; the verdict applies it to your inputs.