Almost every pentest vendor says its team is "certified". But certifications vary enormously — from multiple-choice knowledge tests to gruelling multi-day practical exams. As a buyer, you don't need to know how to pass them; you need to know which ones indicate a tester can actually find what matters in your environment. This guide is written for buyers, not candidates.
Why certifications matter (and their limits)
Practical certifications prove that a person, at some point, performed real attacks under time pressure in a lab. That's valuable evidence. But they don't prove current skill, domain expertise or report-writing ability. Use certifications as a minimum filter, then look at experience, sample reports and the specific testers assigned to you.
Individual tester certifications
| Certification | Issuer | Format | Signals |
|---|---|---|---|
| OSCP | OffSec | Hands-on practical exam | Solid network and system exploitation foundation; a common baseline for professional testers |
| OSWE | OffSec | Practical, white-box web exploitation | Can read source code and chain web vulnerabilities — strong for web/API tests |
| OSEP | OffSec | Practical, evasion and advanced AD | Advanced internal and red team capability |
| OSCE3 | OffSec | Awarded for OSWE + OSEP + OSED | Broad advanced offensive skills |
| CRTO / CRTL | Zero-Point Security | Practical red team operations | Command-and-control and adversary simulation skills |
| CREST CRT / CCT | CREST | Practical + written exams | Recognised for regulated testing (UK, APAC, Middle East); CCT is senior level |
| GPEN / GWAPT / GCPN / GXPN | GIAC (SANS) | Proctored exams with practical elements | Strong knowledge in pentest, web, cloud and advanced exploitation |
| BSCP | PortSwigger | Practical web exam | Hands-on web application testing skill |
| eWPTX / eCPPT | INE | Practical exams | Web and network practical ability |
| CEH | EC-Council | Knowledge exam (practical option available) | Foundational awareness; weaker signal on its own |
Which certifications matter for which test?
- Web and API testing: OSWE, BSCP, GWAPT, eWPTX — plus evidence of web-specific research or bug bounty results.
- Network and Active Directory: OSCP, OSEP, CRTO, GPEN, CREST CRT.
- Red teaming: CRTO/CRTL, OSEP, OSCE3, GXPN — plus a track record of evading modern EDR.
- Cloud: GCPN and cloud-provider security certifications, plus demonstrable cloud attack research.
- Mobile: experience with OWASP MASVS/MASTG and published mobile research matter more than any single cert.
Company-level accreditations
- CREST membership — audited processes and qualified staff; often required by UK and some APAC/Middle East regulators.
- CERT-In empanelment — required for some Indian government and regulated engagements.
- ISO/IEC 27001 — shows the provider manages its own information security, which matters because they'll hold sensitive data about your vulnerabilities.
- PCI QSA / ASV status — relevant if you need PCI assessment or approved scanning, which are different services from penetration testing.
- FedRAMP 3PAO — required for testing within FedRAMP authorisations in the US.
Better signals than certificates
- CVEs discovered and responsibly disclosed by the team
- Open-source offensive tools they maintain
- Conference talks and technical blog posts
- Years of full-time pentesting experience of the assigned testers
- A sample report showing manual, chained findings
How to ask a vendor about certifications
Ask: "Please share anonymised CVs, including certifications and years of experience, for the testers who will be assigned to our project." Company-wide claims like "50+ OSCPs" tell you little if your test is staffed by a junior tester. See our full vendor selection checklist.
Frequently asked questions
Is OSCP enough for a web application test?
OSCP is a strong general baseline, but web testing benefits from web-specific credentials such as OSWE or BSCP and proven web testing experience.
Is CEH a good indicator of pentest skill?
On its own it mainly shows foundational knowledge. Look for practical, hands-on certifications and real experience as stronger signals.