Skip to main content
Offensive Security (Pentest / Red Team)Listed as a primary cert for that lane. Back to pathway
Cybersecurity

PNPT

Practical, AD-heavy offensive cert. Cheaper and arguably more realistic than OSCP for internal pentest work.

DifficultyIntermediate
Study2–3 months
Exam (indicative)£314 (incl. retake)
Validlifetime

Vendor record

This entry has not yet been read against the vendor's own documentation. Exam names, codes and prices shown on this page are indicative; check the vendor before booking anything.

Compare
POST verdict

Workable

Market-level call. Not personal advice.

Solid practical signal for junior roles, but UK consultancy shortlisting still defaults to OSCP or CRT as the bar.

Confidence
Medium
Signal
Medium
Why this confidence
Consistent practitioner feedback on lab quality and exam rigour, but recruiter recognition data in UK consultancy hiring remains thin relative to OffSec and CREST-aligned certs.
Why this signal strength
TCM's reputation has grown fast in practitioner circles. The five-day exam plus written report maps directly to real engagement workflow. Recognition outside that circle is still patchy on UK job specs.
Who this pays off for
  • Career changers needing affordable, verifiable hands-on evidence before their first pentest interview
  • Candidates building toward OSCP who want a report-writing rep before the big outlay
  • Roles at smaller UK boutiques where hiring managers screen CVs themselves rather than through keyword-filtered HR
Who walks away with nothing
  • A direct OSCP substitute for CREST-registered consultancy shortlists
  • Sufficient standalone evidence for SC-cleared or CHECK-adjacent roles where CREST CRT or CCT is the explicit requirement
  • A cert that buys the same recruiter filter pass-rate as OffSec certs at volume-hiring shops
The named failure mode

Report-writing credit gap. Candidates skip the narrative quality of the exam report and submit a bare findings list, burning the one differentiator PNPT has over multiple-choice alternatives.

Recruiter signal, not marketing

Buys credibility in practitioner-led interviews and demonstrates methodology discipline through the report artefact. Does not buy CREST registration for the holder's employer, does not clear HR keyword filters that list OSCP or CHECK, and does not carry weight in DoD-equivalent UK government procurement frameworks.

Falsifiability
  • CREST introduces an associate-level pathway that explicitly cross-credits PNPT exam evidence
  • Large UK consultancies (NCC, PTP, Pen Test Partners) publicly list PNPT as an accepted entry qualifier on job specs
  • TCM Security gains GCHQ CCP or equivalent scheme recognition

This tells you whether the cert is worth pursuing. It does not tell you whether it is worth pursuing for you.

See if it's right for you

This cert in isolation tells you very little. Here is where it actually sits. The pathways that use it, and the roles it realistically supports.

  • Junior pentest interviews
  • AD attack credibility
  • Consulting shortlists
Practitioner take

PNPT is the cheap, honest pentest cert that's become a credible alternative to OSCP for people who can't justify the cost. Five days of exam time, a full client report deliverable, and a syllabus that drills Active Directory and internal pivoting where OSCP only brushes them. The catch is recognition. UK consultancies still default to OSCP on shortlists, so PNPT is the right call only if you're targeting internal red team roles, US-leaning shops, or you genuinely cannot lay out the OSCP fee. Pair it with public writeups of the lab boxes and a clean GitHub of your tooling. Skip it if you've already started on OSCP.

Authored opinion. Updated against current hiring conditions, not vendor marketing.

Recommended prior knowledge

  • TryHackMe / HTB consistency
  • AD basics

Common misconceptions

  • PNPT alone clears HR filters; it doesn't replace shipped, documented work.

What this cert does NOT guarantee

  • Senior red-team roles alone
  • AppSec engineering

Practitioner judgement. External evidence review pending.

Last reviewed: not yet reviewed · UK market

The next step

A cert is a signal. A Career Verdict tells you whether the signal is worth sending.

A Career Verdict tells you whether this cert earns its place on your specific route, what it won't fix, and what to sit before or after it.

A route shows what is possible. A Career Verdict makes the call.

POST ATLASVerdict no. PA-2026-0512
Career analysis report

Career Verdict

Helpdesk → Security Architect

“Realistic, but not by adding another certification.”
  1. 01
    The callA clear judgement on whether your route is realistic, and under what conditions.
  2. 02
    Where the route breaksThe most likely point to stall, and why it happens in practice.
  3. 03
    What to do nextSpecific priorities for the next 6–24 months, and what to drop.
Generated within POST’s practitioner-authored assessment frameworkPOST ATLAS

Career Verdict

£39One-off payment. No subscription.
  • The callA single written judgement on whether the route is realistic for you.
  • Plateaus and failure modesThe flat years and the specific ways this route tends to stall.
  • Where you standThe strongest and weakest parts of your current position, named.
  • Salary realityWhat this route actually pays, set against what you've been told it pays.
See the Career Verdict

Usually within minutes of payment. Kept 24 months, then deleted. Deletion on request at any time.

Built on POST's practitioner-authored assessment framework, informed by two decades across helpdesk, infrastructure and security. The verdict applies that framework to your inputs.