HackTheBox’s CPTS has been quietly building a reputation as the most technically demanding — and best-priced — penetration testing certification in the market. In 2026, it’s no longer a quiet alternative to OSCP. It’s a direct competitor.

Here’s the real breakdown.

What Is HTB CPTS?

The HTB Certified Penetration Testing Specialist (CPTS) is HackTheBox Academy’s flagship professional certification. It’s built on the Penetration Tester learning path — 28 modules covering everything from network enumeration to Active Directory attacks to enterprise-level reporting.

Unlike certifications that pair a video course with a bolt-on exam, CPTS integrates training and assessment tightly. You complete the path, you earn exam access. The exam directly tests what the course teaches — no surprise pivots, no obscure techniques pulled from outside the syllabus.

That alignment between training and exam is one of the reasons it’s developed a strong reputation fast.

What You’ll Learn

The 28-module path is the most comprehensive single-vendor training path in the CPTS/OSCP tier. Topics include:

  • Penetration testing methodologies — scoping, engagement structure, process
  • Information gathering & OSINT — passive and active recon techniques
  • Web application pentesting — injection, authentication bypasses, API attacks
  • Active Directory enumeration and attacks — Kerberoasting, AS-REP Roasting, DCSync, Pass-the-Hash, BloodHound
  • Windows & Linux privilege escalation — the full range of local exploits, misconfigs, and abusable permissions
  • Pivoting and lateral movement — double pivots, SOCKS proxies, tunneling inside segmented networks
  • Post-exploitation — credential harvesting, persistence, data collection
  • Vulnerability assessment — from discovery to risk scoring
  • Documentation and reporting — professional pentest reports that meet real-world standards

That last one is worth highlighting. Most certifications treat reporting as an afterthought. CPTS has a dedicated module — and the exam enforces it. More on that in a moment.

The Exam

The CPTS exam is where this certification earns its difficulty rating.

You get a 10-day window to compromise a black-box enterprise environment — approximately 8 machines, both Windows and Linux, across a realistic multi-segment network. The environment is professionally built: stable, well-connected, and unforgiving if your methodology is loose.

There are 14 flags distributed across the environment. To pass, you need at minimum 12 flags, for a score of at least 85 out of 100 points.

Getting 12 flags sounds like a comfortable margin. It isn’t. The environment requires solid technique across every domain the course covers — you can’t skip the AD attacks or ignore the web app portion and still hit that threshold.

The Report Is Where People Fail

This is the part most reviews undersell.

Many candidates compromise the entire environment, grab all 14 flags, and still fail CPTS. Not because of their technical work — because of the report.

HackTheBox holds the pentest report to a strict professional standard. The Documentation & Reporting module outlines exactly what’s required. If your report is missing structure, lacks executive-ready findings, or doesn’t follow the prescribed format — you don’t pass, even with a perfect lab score.

Three exam attempts are included. But don’t assume you’ll lean on them. Treat every attempt like it’s your last, and treat the report like it’s going to a real client. Because in terms of quality expectations, it is.

Exam specs at a glance:

  • Window: 10 days for the lab
  • Format: Black-box enterprise environment (~8 machines, Windows + Linux)
  • Flags: 14 total, 12 required to pass
  • Passing score: 85/100
  • Report: Required, strict standard — professional quality expected
  • Attempts: 3 included with exam voucher

Pricing: Where CPTS Completely Dominates

This is the headline comparison against OSCP.

OptionCost
Student subscription (3–4 months) + exam voucher~$242 USD
Silver Annual subscription + exam voucher~$700 USD
Gold Annual subscription + exam voucher~$1,470 USD
OSCP (PEN-200, 90 days + 1 exam attempt)$1,499 USD

If you have a .edu email address, the student subscription runs $8/month. Complete the path in 3–4 months, pay the $210 exam voucher, and you’re certified for under $250.

Even the Silver Annual option — which gives full access to all Tier 0–II modules and works if you don’t have a student email — comes in at roughly half the cost of OSCP.

For self-funded practitioners, this is a meaningful difference. OSCP’s retake fee alone ($249) costs more than the CPTS student path.

CPTS vs OSCP: The Direct Comparison

HTB CPTSOSCP (PEN-200)
Price$242–$700 (student/Silver path)$1,499
Exam window10 days24 hours + 24-hour report
Exam formatEnterprise network, black-boxStandalone machines + AD set
Flags/machines14 flags (12 to pass)Points-based (70/100 to pass)
Report required✅ Yes — strict standard✅ Yes — required
AD coverage✅ Very deep✅ Moderate
Web app coverage✅ Comprehensive✅ Present
Industry recognitionGrowing — strong in EU & HTB circlesGold standard across all markets
Retake cost3 attempts included$249/attempt
DifficultyHigh — 10 days, enterprise scopeHigh — 24-hour sprint
Best forTechnical depth, budget-consciousIndustry baseline, hiring optionality

The core difference: OSCP is a 24-hour sprint across a diverse set of targets. CPTS is a 10-day marathon inside a realistic enterprise environment. Neither is easier — they’re hard in different ways.

OSCP tests your ability to execute quickly under time pressure across machine variety. CPTS tests your ability to methodically work through a complex environment over time, including the reporting standard that professional engagements require.

Who Is CPTS Right For?

CPTS is a strong choice if:

  • You’re budget-constrained and OSCP’s price tag is a real obstacle
  • You want deeper web application and Active Directory coverage than OSCP provides
  • You learn well from structured, module-based content (HackTheBox Academy is genuinely good)
  • You’re targeting technical pentesting roles, especially in Europe or at companies that know the HTB ecosystem
  • You already have some foundational skills — a few HTB machines, basic Linux fluency, network concepts

CPTS may not be the first choice if:

  • You’re targeting US-based consulting firms where OSCP is a listed requirement
  • You need the credential that hiring managers recognize by name alone
  • You prefer time-boxed exams over multi-day formats

The industry recognition gap is closing — but it’s real. OSCP has 15+ years of brand equity. CPTS has maybe 3–4. If a job posting says “OSCP required,” CPTS won’t substitute it yet, even though the technical bar is comparable.

Difficulty: Honest Assessment

CPTS is hard. Not “it sounds hard” hard — actually hard.

The 28-module path takes most people 3–6 months if they’re working through it seriously alongside other commitments. Rushing it produces the kind of shallow technique knowledge that the exam will immediately expose.

The exam environment is enterprise-scale. You’re not exploiting a single isolated box — you’re working through a real network with trust relationships, segmented subnets, and the kind of lateral movement chains that require connecting what you learned across multiple modules simultaneously.

And then there’s the report. Most people underestimate how much time the report takes and how strictly it’s evaluated.

Before attempting CPTS, you should be comfortable with:

  • Basic networking (subnets, routing, common ports)
  • Linux and Windows command line fundamentals
  • How Active Directory authentication works
  • At least some hands-on hacking experience (HTB, THM, or similar)

Complete beginners can start CPTS. But you’ll move significantly faster and retain more if you have some baseline before you begin the path.

The Training Path: What Makes It Worth the Price

One thing CPTS has over OSCP that often gets overlooked: the quality of the included training.

PEN-200 (OSCP) is good. It’s been around for years and covers a lot of ground. But HackTheBox Academy’s instructional design is consistently more up-to-date, the labs are more interactive, and the 28-module path goes deeper in several categories — especially web applications and Active Directory.

The Attacking Enterprise Networks module is worth calling out specifically. It’s essentially a mini-exam environment, purpose-built to simulate the CPTS exam structure. Candidates who complete it thoroughly and understand what they did are significantly better prepared for the real thing.

Modules that matter most for the exam:

  1. Active Directory Enumeration & Attacks — central to the exam environment
  2. Attacking Common Applications — the web attack surface
  3. Attacking Enterprise Networks — the closest thing to an exam rehearsal
  4. Documentation & Reporting — the module most candidates skim and then regret

Do all of them. Do the skill assessments. Don’t skip.

Verdict

HTB CPTS is the best-value professional penetration testing certification available in 2026. At $242 (student path) to $700 (Silver Annual), it delivers technical depth, a realistic enterprise exam environment, and professional-grade reporting standards at a fraction of OSCP’s price.

The trade-off is recognition. OSCP still wins on name recognition in hiring — particularly in North America. If you’re targeting roles where OSCP is explicitly required, that gap matters.

But if you’re building your skills, proving your capabilities, and want a certification that will genuinely make you better at penetration testing — not just certification-ready — CPTS is hard to beat.

And if budget is a constraint at all, it’s not even a close decision.


Quick ratings:

Technical depth⭐⭐⭐⭐⭐
Price-to-value⭐⭐⭐⭐⭐
Industry recognition⭐⭐⭐ (growing)
Training quality⭐⭐⭐⭐⭐
Exam difficulty⭐⭐⭐⭐
Overall⭐⭐⭐⭐½


Need professional-grade security content for your organization? CipherWrite delivers technical blog posts, whitepapers, and LinkedIn content written by working security professionals.