What you’ll learn in this article…
- CPTS requires a 10-day hands-on pentest plus a professional report.
- Total cost runs roughly $490 to $700 including training and voucher.
- The credential never expires, so no renewal fees or continuing education apply.
How do you actually earn the Hack The Box Certified Penetration Testing Specialist (CPTS) credential, and is a 10-day practical exam worth the roughly $210 voucher plus training costs? The CPTS exam asks candidates to compromise a segmented Active Directory network and write a consulting-grade report, not bubble in answers about theoretical CVEs.
That format creates real tension for career changers: the credential carries genuine technical weight among hiring managers in offensive security, but it demands 200-plus lab hours and comfort with ambiguity that no multiple-choice exam tests.
As practical penetration-testing credentials keep displacing memorization-based ones, CPTS has become one of the clearest signals a candidate can actually hack, not just recite.
CPTS Credential Snapshot
Before you commit training hours and voucher fees, the question worth answering upfront is whether the CPTS delivers enough practical depth to justify its middle-tier price and 10-day exam commitment. The snapshot below gives you the hard specifics, and you can use our Compare Cybersecurity Certifications Side by Side tool to weigh it against alternatives like the OSCP or PNPT without hunting through marketing pages.
Core Certification Details
- Full name: HTB Certified Penetration Testing Specialist
- Issuing body: Hack The Box Academy
- Level: Intermediate
- Exam format: Hands-on practical assessment with a written professional report
- Exam duration: 10 days of lab access, followed by a report submission window
- Flags: 14 flags in the exam environment, with a minimum of 12 required
- Passing score: 85 points, factoring in flags and report quality
- Report requirement: Yes, a professional penetration testing report must be submitted and graded1
Cost and Access
- Exam voucher: $210
- Total program cost range: roughly $242 to $700, depending on which HTB Academy subscription tier you use to unlock the required training modules1
- Prerequisite training: Completion of the Penetration Tester job-role path (28 modules) on HTB Academy
- External prerequisites: None. There are no mandatory prior certifications or verified work experience requirements.
Validity
- Validity period: Lifetime. The credential does not expire.
- Renewal: Not required. There are no continuing education units or annual maintenance fees.2
All specifications above reflect the current CPTS program as documented on the Hack The Box Academy certification page, last verified July 2026. Because Hack The Box has adjusted exam mechanics (flag counts, passing thresholds) in past releases, confirm details on the official page before purchasing a voucher.2
What the CPTS Validates and Who It's For
The HTB Certified Penetration Testing Specialist is built around a single premise: proving you can compromise a multi-host network from scratch and document the entire engagement, not just answer multiple-choice questions about how attacks work in theory. Every phase of a real penetration test, from the first scan to the final deliverable, is assessed inside a live lab environment.
Core Skill Domains
The CPTS certification covers a broad set of offensive-security competencies that map directly to the workflow of a professional penetration tester:
- Information gathering and enumeration: Identifying services, subdomains, and misconfigurations across network and web attack surfaces.
- Web application attacks: Exploiting common and intermediate-level web vulnerabilities, including injection flaws, authentication bypasses, and server-side request manipulation.
- Active Directory exploitation: Attacking Windows domain environments through techniques like Kerberoasting, delegation abuse, ACL misconfigurations, and credential harvesting.
- Privilege escalation on Linux and Windows: Elevating access through kernel exploits, misconfigured services, scheduled tasks, and abusable permissions.
- Pivoting and tunneling: Moving laterally across segmented networks by chaining compromises and forwarding traffic through tunnels.
- Penetration test reporting: Producing a professional-grade report that communicates findings, risk ratings, and remediation steps to both technical and non-technical stakeholders.
This combination means the exam does not test any single skill in isolation. Candidates must chain techniques together across multiple hosts, which mirrors the complexity of a real-world engagement.
Three Ideal Candidate Profiles
Not everyone is equally well-positioned to pursue CPTS. These three profiles tend to get the most value:
- Career changers with foundational IT skills who have spent time learning networking, Linux administration, and basic scripting and are ready to transition into offensive security through hands-on cybersecurity labs.
- Early-career security professionals in SOC, IT support, or vulnerability management roles who want a practical credential that demonstrates exploitation ability rather than just monitoring or compliance knowledge.
- Working penetration testers and red teamers who want to validate their skills through a rigorous, lab-based assessment, either as a complement to or substitute for other certifications like the OSCP.
Where CPTS Sits on the Difficulty Spectrum
It helps to be clear about what CPTS is not. It is not an entry-level certification. Candidates without meaningful exposure to networking, command-line tools, and at least some vulnerability exploitation will struggle significantly. If you are brand new to cybersecurity, a foundational credential like the eJPT provides a gentler starting point with guided learning paths.
At the other end, CPTS does not target security managers or governance professionals. It carries no policy, compliance, or leadership content. Its entire value proposition is rooted in the ability to hack a realistic environment and write up what you found. That focus places it within the intermediate-to-advanced practical tier, as outlined in our Cybersecurity Certification Roadmaps, roughly comparable in difficulty to the OSCP while emphasizing end-to-end engagement methodology and reporting quality over timed speed.
Eligibility, Prerequisites, and Recommended Experience
One of the most refreshing things about the CPTS is how Hack The Box handles eligibility: there is no degree requirement (as covered in Cybersecurity Certification Prerequisites Explained), no mandatory years of work experience, no background check, and no employer sponsorship needed. The only formal prerequisite is completing the HTB Academy Penetration Tester job-role path, which is where the real gatekeeping happens. That path is what determines whether you are actually ready, not a résumé.
The Formal Prerequisite: The Penetration Tester Path
The Penetration Tester path contains 28 modules1 and clocks in at roughly 342 hours of content according to Hack The Box's own time estimate.2 If you followed HTB's suggested pace of 8 hours per day, you could theoretically finish in 1.5 to 2 months. In practice, community study logs tell a different story: the average learner studies about 2.47 hours per day3 and takes closer to 156 calendar days (roughly 105 active study days) to work through the material.3 Community consensus puts total prep at somewhere between 250 and 350 hours before feeling ready to book the exam.3
To unlock the full path, you need at least the Silver Annual plan ($490/year),4 which grants Tier II module access and includes a CPTS exam voucher. The Gold Annual plan ($1,260/year) adds broader access if you want to explore additional job-role paths.4 If you buy the exam voucher separately, it runs $210.4
Recommended Background Before You Start
The path assumes intermediate technical competence. Anyone starting from zero IT background can absolutely become a penetration tester,become a penetration tester but expect a significant ramp-up period on top of the 250 to 350 hour prep window. Comfortable footing in these areas will save you weeks:
- Networking fundamentals: subnetting, common ports, TCP/UDP, DNS, and how traffic actually flows.
- Linux command line: file permissions, process management, and comfort living in a terminal.
- Basic scripting: enough Python or Bash to modify a proof-of-concept exploit or automate enumeration.
- Web technologies: HTTP requests, cookies, sessions, and how modern web apps are structured.
Skills That Pay Off on Exam Day
Beyond the path itself, four supplementary skills consistently separate people who pass from those who retake: professional report writing, deep Burp Suite proficiency, Active Directory enumeration and exploitation, and comfort with multi-host pivoting through segmented networks.
Self-Assessment Before You Commit
Before paying for a subscription, honestly answer these three questions:
- Can you enumerate and exploit a Windows Active Directory environment without following a step-by-step walkthrough?
- Have you written a professional penetration test report, with an executive summary, technical findings, and remediation guidance?
- Are you mentally prepared for a multi-day practical exam with no multiple-choice safety net, where partial credit depends on the quality of your writeup?
If two or more of those answers are "not yet," that is fine, it just tells you where to spend your first month of study.
Exam Format, Domains, Scoring, and Reporting Requirements
The CPTS exam is a 10-day, hands-on penetration test that mirrors real-world black-box enterprise networks. Unlike multiple-choice certifications, this assessment evaluates your ability to compromise an Active Directory environment and document every step. Here is how it works, start to finish.
Inside the 10-Day Exam Window
You receive a full 240 hours (10 calendar days) to complete the exam, but Hack The Box recommends splitting that time into roughly 7 or 8 days of active hacking followed by 2 or 3 days for report writing.4 The clock starts the moment you activate the lab, so plan your schedule carefully. Most candidates treat this like an intensive work sprint, clearing their calendar to avoid interruptions.
The Lab Environment and Flag Distribution
The exam environment simulates a mid-size enterprise network containing approximately eight interconnected machines.2 Across those hosts, you must locate and capture 14 unique flags.2 Each flag represents a distinct objective, such as obtaining sensitive files, credentials, or domain-level access. The network is black-box, meaning no initial credentials or topology diagrams are provided; you begin with the same information an external attacker would have.
Scoring and the Passing Threshold
Flags are not all worth the same value. The total possible score is 100 points, and you must accumulate at least 85 points (85%) to pass.3 To put that in perspective, capturing 12 of the 14 flags is typically enough to clear the bar,2 as some flags are weighted more heavily. There is no partial credit for incomplete attempts; you either own the flag or you do not. This high threshold underscores the practical rigor Hack The Box demands; a candidate can technically capture the majority of evidence and still fail if the written report does not meet standards.
The Written Report: Your Ticket to Passing
Even with enough flags, many candidates stumble at the reporting phase. The exam requires a professional penetration test report, which carries significant weight in the final grade.5 Failing here is the most common reason for a retake. Your document must include at minimum:
- Executive Summary: a high-level overview framing the engagement in business terms.
- Technical Findings: detailed attack chains with screenshots, command outputs, and reproducible steps.
- Risk-Prioritized Remedies: actionable recommendations ranked by severity.
Reports that omit screenshot evidence, lack clear reproduction steps, or read like a log of commands rather than a consultant's deliverable are routinely rejected. Hack The Box expects you to communicate as a practicing specialist, not a student.
Proctoring and Submission Logistics
The CPTS exam is entirely non-proctored; unlike other online cybersecurity exams, there is no live proctor watching your screen, nor identity-verification software running. Instead of real-time oversight, Hack The Box relies on the depth and detail of your final report to validate your work. You access the lab environment through a VPN connection, with credentials provided after you schedule and start your exam attempt. Once you finish, you submit the report directly through the Hack The Box Academy portal. After submission, grading may take several weeks; if you pass, the certification is issued digitally. Be mindful that multiple failed attempts may lead to a temporary block on scheduling new exams, as the platform enforces a cooldown policy.6
CPTS Exam Pathway: From Enrollment to Certification
The path from first enrollment to earning your HTB Certified Penetration Testing Specialist credential follows a structured sequence. Each stage builds on the last, so plan your timeline accordingly.

Full Cost Breakdown: Training, Exam Voucher, Retakes, and Renewal
Understanding the total investment for the CPTS certification is essential for budgeting your cybersecurity education. The costs break down into three main components: the Hack The Box (HTB) Academy subscription that provides training content, the exam voucher, and any potential retake fees. Below we break down each component so you can estimate your out-of-pocket expense with confidence.
HTB Academy Subscription Tiers
HTB Academy uses a tiered subscription model. The Student Plan is the most budget-friendly, at $96 per year1, giving access to Tier I and Tier II modules. It requires student verification2 and does not include an exam voucher. The Silver Annual plan, priced at $490 per year1, also provides Tier I, II access but includes one exam voucher per year, making it a convenient bundle for CPTS candidates. For broader access, the Gold Annual plan costs $1,260 per year1 and unlocks Tier I, III content plus multiple exam vouchers for several HTB certifications3. Monthly plans are also available: Silver Monthly at $181, Gold Monthly at $381, and Platinum Monthly at $681, but these operate on a cubes-based system and do not come with exam vouchers, so they may not be the most cost-effective for completing the structured CPTS learning path unless you only need a short burst of access. Corporate pricing starts at approximately $250 per seat per month or $2,500 per seat annually, with custom quotes for larger teams.
Exam Voucher and Retake Costs
The CPTS exam voucher is priced at $210, though European candidates may see a slightly higher amount around $249.90 due to VAT.4 This fee covers one complete examination attempt, including all necessary lab access and the report submission process. If you need to retake the exam, you must purchase a new voucher at the same $210 rate.4 Hack The Box does not currently publish an official waiting period between attempts, but common practice suggests allowing several weeks for additional study before reattempting. Importantly, there is no discounted retake fee, so each attempt costs the full price.4
Total All-In Cost Comparison: Student vs. Standard Path
For an individual preparing for the CPTS, the most direct paths are the Student Annual plan or the Silver Annual bundle. A student who pays $96 for the subscription1 and then purchases the $210 exam voucher separately4 spends a total of $306. A professional using the Silver Annual plan pays $490 total, with the exam voucher already included.1 That is an all-in cost difference of $184 in favor of the student route. If you choose a monthly subscription, the cost becomes variable and depends on how many months you need to complete the training. For example, six months of Silver Monthly ($18/month) plus the exam voucher totals $318, but this assumes you can finish all required modules within the monthly cube allocation1, which may not be realistic. Most learners will need additional cube purchases or a longer subscription, making the annual paths more predictable.
Renewal Fees and Lifetime Cost
As of 2026, Hack The Box certifications, including the CPTS, do not carry a renewal fee. The credential does not expire, which means once you earn it, your lifetime cost is exactly what you paid for training and the exam. This is a notable advantage over certifications that require annual maintenance fees or continuing education credits with associated costs. It keeps the total investment low over the long term.
CPTS vs. OSCP: A Price Comparison
One of the most frequent questions from penetration testing newcomers is how CPTS stacks up against the more established OSCP in terms of cost. The OSCP typically requires an upfront investment of $1,500 to $2,500 when purchased through OffSec’s bundled course and exam plans, such as the Learn One subscription. In contrast, even the most expensive common path for CPTS, the Silver Annual plan at $490, is a fraction of that price. For students, the gap widens further, with CPTS costing under $350. This substantial price difference makes the CPTS an appealing option for self-directed learners who want a rigorous, practical certification without the financial strain of the OSCP.
How Difficult the CPTS Exam Is and How to Prepare
The Penetration Tester path alone demands 200 to 300 hours of lab time, and most candidates will spend an additional 50 to 100 hours in Pro Labs and self-directed practice before attempting the exam. That baseline alone puts the CPTS well beyond entry-level practical assessments and squarely in the intermediate-to-advanced tier.
Where the CPTS Sits in the Offensive Security Landscape
Community survey data consistently rank the CPTS as more demanding than eLearnSecurity’s eJPT, a foundational cybersecurity certification, and comparable to or harder than the PNPT from TCM Security, particularly in Active Directory exploitation depth and report writing rigor. The consensus among reviews aggregated on cybersecurity forums places the CPTS slightly above the OSCP in terms of breadth of attack chains and reporting requirements, though the OSCP’s time-boxed, proctored format creates its own pressure. A widely referenced 2025 community poll on a popular ethical hacking subreddit found that 68% of respondents who held both credentials rated the CPTS as the more technically thorough exam, while acknowledging the OSCP’s stronger brand recognition in HR workflows.
A Stepwise Preparation Plan
Start with the official Hack The Box Academy Penetration Tester job role path. It covers every domain that appears on the exam: network pivoting, Linux and Windows privilege escalation, Active Directory attacks, web application exploitation, and professional report writing. After completing the path, move into one or two Pro Labs. Dante builds chained attack surfaces in a mid-size corporate network, while Offshore pushes deeper into Active Directory trusts and lateral movement across segmented environments. Practice report writing on standalone machines by producing full penetration test reports, not just notes, to internalize the structure Hack The Box expects. Spend focused time on your weakest domains. Most learners log extra hours in the AD Enumeration & Attacks and SQLMap Essentials modules before they feel ready for the certification exam.
Realistic Time Expectations
With a cybersecurity certification study plan, plan on five to six months of consistent study if you have no prior pentesting experience but a solid grasp of networking and basic Linux and Windows administration, averaging ten to fifteen hours per week. Learners who have already passed a practical exam like the eJPT or hold a role in a SOC or junior security engineering position often trim that window to three to four months, because they can skip foundational material and move directly to hands-on exploitation. If Active Directory attacks are new to you, expect the preparation timeline to stretch toward the longer end regardless of other experience. The path volume is not the bottleneck; it is the depth of the lab scenarios that demands iteration.
Where Candidates Stumble and How to Avoid It
- Insufficient report quality: The exam requires a well-structured penetration test report that mirrors a real client deliverable. Mitigation: During practice, write reports using the Hack The Box reporting template and have a peer review them before you schedule the exam.
- Inability to pivot through multi-host chains: The lab environment contains multiple machines that must be compromised in sequence, and failing to establish a reliable pivot method stops progress completely. Mitigation: Replay the pivoting and tunneling modules from the Penetration Tester path and practice with Chisel, Ligolo, and native SSH forwarding on Pro Lab networks until it becomes second nature.
- Running out of time due to poor methodology: The exam gives a generous window compared to some alternatives, but disorganized enumeration wastes hours. Mitigation: Develop a repeatable checklist: scan all hosts, catalog services, prioritize low-hanging vulnerabilities, document findings immediately, and resist the urge to chase a single difficult vector before exhausting simpler avenues.
CPTS Vs. OSCP Vs. PNPT Vs. Ejpt: How It Compares
The practical penetration testing credential market has fully shifted away from multiple-choice exams, and CPTS sits at the center of that shift alongside OSCP certification and PNPT certification, while eJPT certification remains the lone hybrid holdout aimed at newcomers.
Format and Duration
CPTS gives candidates 10 days to compromise a simulated corporate network and capture 12 of 14 available flags across 8 exam machines, unproctored. OSCP compresses the pressure into roughly 23 hours and 45 minutes of hands-on hacking against 6 machines, followed by a 24-hour report window, and it is proctored.2 PNPT spreads the work across 5 days of testing plus 2 days of reporting, and uniquely requires a live debrief call where candidates defend their findings verbally.3 eJPT is the outlier: a 48-hour hybrid exam blending practical tasks with 35 multiple-choice questions, and it skips the report entirely.4
Cost and Reporting
CPTS runs about 490 dollars for the full training-to-exam pathway, closely matching PNPT's roughly 499 dollars.3 OSCP costs considerably more, typically 1,499 to 1,749 dollars depending on the bundle chosen.2 eJPT is the budget option at 200 to 300 dollars.4 Every credential except eJPT requires a written professional report as part of passing, meaning CPTS, OSCP, and PNPT all test communication skills alongside exploitation, while eJPT tests neither writing nor client-facing polish.
Recognition and Compliance
None of these four credentials currently carry DoD 8570/8140 approval, so candidates targeting federal or DoD-contractor roles will need to look elsewhere regardless of which they choose. Employer recognition, however, varies sharply. OSCP still commands the strongest brand recognition among hiring managers and remains the default benchmark many job postings reference by name.2 PNPT has built a strong reputation for its practical, small-business-style engagement scenario and its live debrief.3 CPTS earns moderate to high recognition, particularly among employers already familiar with Hack The Box's training ecosystem, though it has not yet reached OSCP's household-name status. eJPT is understood industry-wide as an entry-level credential, useful for demonstrating foundational skill but rarely a hiring differentiator on its own.4
Validity
All four certifications are non-expiring once earned, so the comparison really comes down to upfront cost, exam pressure format, and how much weight a target employer places on the issuing body's name.
For career changers deciding where to start, eJPT can validate fundamentals cheaply, CPTS or PNPT offer strong mid-tier value, and OSCP remains the stretch goal once budget and experience allow.
Related Articles
Jobs, Salary Expectations, and Employer Recognition
The CPTS certification maps directly to roles where hands-on exploitation skills matter more than theoretical knowledge, as detailed in our cybersecurity career guide. If you can demonstrate that you breached a realistic enterprise network, wrote a professional report, and documented your methodology, hiring managers in offensive security take notice. The credential's practical nature makes it particularly relevant for positions where day-one technical competence is expected.
Target Job Titles Where CPTS Adds Value
The certification aligns most closely with these roles:
- Junior Penetration Tester: Entry-level positions at security consultancies or internal red teams where CPTS demonstrates you can execute a full engagement independently.
- Penetration Testing Consultant: Client-facing roles at boutique security firms or Big Four advisory practices where professional reporting is as important as technical skills.
- Red Team Operator: Positions focused on adversary emulation, where CPTS validates your ability to chain vulnerabilities across complex environments.
- Application Security Engineer: Roles blending offensive testing with secure development guidance, where exploitation fluency helps you communicate risks to developers.
- Vulnerability Analyst: Positions requiring deep technical analysis of security flaws, where CPTS proves you understand exploitation beyond scanner output.
Salary Context: Information Security Analysts
The Bureau of Labor Statistics tracks Information Security Analysts (SOC 15-1212) as the closest occupational proxy for penetration testing roles. According to 2024 BLS data, the national landscape looks like this:
- Median annual wage: approximately $124,910
- 25th to 75th percentile range: roughly $92,160 to $159,600
- Total national employment: about 179,430 positions
Specialized penetration testers, particularly those with consulting experience or niche expertise, often earn above the 75th percentile. The BLS projects employment growth for Information Security Analysts at roughly 30 to 35 percent through the early 2030s1, placing the occupation among the fastest-growing in the economy. This growth reflects expanding attack surfaces, regulatory pressure, and the ongoing shortage of qualified offensive security practitioners.
Employer Recognition: Current Status
CPTS is gaining traction in the private sector, though it remains newer than established alternatives like OSCP. Job postings explicitly mentioning CPTS are still relatively limited. Tracking data from early 2026 shows approximately eight active postings citing CPTS specifically over a twelve-week period1, placing it in a stable but emerging market presence category. Growth indicators suggest upward momentum as awareness spreads.
Employers familiar with Hack The Box often view CPTS favorably because they understand the platform's reputation for realistic, challenging lab environments. However, CPTS does not yet appear on the DoD 8570/8140 approved baseline certification list2, which limits its utility for federal contractor positions requiring specific credential mandates. Hack The Box has not publicly announced formal NICE framework work role mapping for CPTS1, so government-sector applicants should verify whether their target agency or contract accepts the credential.
There is one notable exception in the federal space: CPTS holders have received recognition for FedRAMP penetration testing work2. The credential appears on lists of accepted qualifications for third-party assessment organizations, and practitioners have noted A2LA R311 recognition in consulting contexts3. This suggests that while DoD compliance roles remain off the table, certain federal security assessment work does acknowledge CPTS competence.
How Employers Compare CPTS to OSCP
In hiring conversations, CPTS and OSCP often occupy similar mental space for recruiters. Both are hands-on, practical exams that prove you can compromise systems under pressure. Some employers with internal red teams specifically seek candidates who hold both, viewing them as complementary rather than redundant, and our guide to choosing a cybersecurity certification can clarify the distinctions. OSCP's longer track record means it remains the safer choice for applicants uncertain about their target employer's familiarity with HTB. That said, security-focused hiring managers increasingly recognize CPTS as a rigorous credential that validates real-world penetration testing methodology.
Information Security Analyst Salary by State
Penetration testing roles often fall under the broader Information Security Analysts category tracked by the U.S. Bureau of Labor Statistics. The table below shows median and mean annual wages across all 50 states, the District of Columbia, and Puerto Rico, based on 2024 OEWS data. High-cost tech corridors such as Washington, California, and Maryland lead the pack, while states with smaller cybersecurity workforces still report six-figure medians in many cases.
| State | Total Employment | Median Annual Wage | Mean Annual Wage | 25th Percentile | 75th Percentile |
|---|---|---|---|---|---|
| Washington | 6,830 | $142,920 | $144,140 | $117,040 | $169,350 |
| California | 15,800 | $140,660 | $152,640 | $105,150 | $178,090 |
| Maryland | 8,770 | $140,480 | $145,450 | $105,230 | $175,390 |
| New Jersey | 4,730 | $135,390 | $141,130 | $108,320 | $168,240 |
| Delaware | 630 | $134,050 | $130,860 | $105,310 | $154,060 |
| New Mexico | 1,760 | $133,780 | $131,220 | $101,940 | $166,300 |
| Virginia | 18,670 | $132,460 | $136,680 | $101,610 | $166,510 |
| New York | 8,860 | $131,100 | $139,540 | $98,320 | $170,220 |
| Colorado | 5,840 | $130,570 | $135,980 | $102,350 | $164,010 |
| Connecticut | 1,160 | $130,500 | $127,740 | $95,260 | $152,410 |
| New Hampshire | 730 | $129,690 | $128,040 | $98,540 | $158,360 |
| Minnesota | 2,550 | $128,830 | $126,150 | $99,300 | $145,860 |
| District of Columbia | 2,010 | $127,760 | $132,790 | $109,680 | $150,920 |
| Massachusetts | 5,780 | $127,610 | $129,350 | $101,730 | $161,940 |
| Hawaii | 580 | $125,790 | $128,310 | $99,730 | $154,340 |
| Arizona | 4,170 | $125,320 | $123,780 | $88,520 | $161,250 |
| Texas | 14,730 | $124,970 | $126,800 | $96,020 | $149,780 |
| Georgia | 6,480 | $124,270 | $126,380 | $92,620 | $156,390 |
| Idaho | 870 | $121,970 | $145,880 | $87,980 | $157,060 |
| Wyoming | N/A | $121,290 | $122,570 | $82,350 | $161,650 |
| North Carolina | 6,850 | $121,070 | $122,310 | $88,560 | $147,030 |
| Oregon | 1,370 | $119,000 | $132,430 | $93,650 | $152,880 |
| Illinois | 4,560 | $114,300 | $119,540 | $83,960 | $138,130 |
| Iowa | 1,180 | $112,950 | $116,710 | $82,990 | $133,830 |
| North Dakota | 340 | $112,330 | $101,200 | $89,520 | $112,330 |
| Alabama | 3,290 | $111,110 | $112,800 | $79,870 | $138,270 |
| Pennsylvania | 4,420 | $110,230 | $114,870 | $79,670 | $137,900 |
| Rhode Island | 880 | $109,410 | $117,010 | $85,790 | $141,690 |
| West Virginia | 270 | $107,820 | $103,770 | $79,870 | $123,770 |
| Ohio | 5,070 | $107,570 | $115,600 | $83,480 | $137,430 |
| Nevada | 1,570 | $106,530 | $111,340 | $80,380 | $136,710 |
| Florida | 13,770 | $105,990 | $117,500 | $86,250 | $139,150 |
| Michigan | 3,120 | $104,540 | $107,630 | $79,920 | $129,150 |
| South Dakota | 430 | $103,310 | $104,120 | $86,360 | $115,300 |
| Missouri | 2,560 | $102,440 | $107,250 | $78,210 | $130,810 |
| Alaska | 210 | $102,170 | $111,900 | $96,320 | $121,060 |
| Kansas | 1,380 | $99,420 | $100,850 | $71,960 | $129,080 |
| Wisconsin | 1,760 | $99,210 | $106,260 | $79,640 | $128,770 |
| Kentucky | 1,790 | $98,210 | $102,820 | $67,650 | $128,910 |
| Utah | 1,720 | $97,180 | $101,430 | $72,800 | $127,980 |
| Nebraska | 1,120 | $95,470 | $103,310 | $85,120 | $122,360 |
| Maine | 270 | $93,710 | $99,420 | $73,890 | $129,560 |
| Arkansas | 1,010 | $93,560 | $96,080 | $66,800 | $125,550 |
| Louisiana | 580 | $88,200 | $101,280 | $73,830 | $107,250 |
| Montana | N/A | $87,100 | $99,560 | $87,100 | $102,650 |
| Vermont | 80 | $86,810 | $95,800 | $67,080 | $108,940 |
| Oklahoma | 1,270 | $86,500 | $92,390 | $57,490 | $117,500 |
| Mississippi | 560 | $84,640 | $89,910 | $60,240 | $105,830 |
| Indiana | 2,540 | $78,290 | $91,740 | $64,500 | $115,650 |
| Puerto Rico | 470 | $59,520 | $62,190 | $44,780 | $81,330 |
Renewal, Continuing Education, and Expiration Policy
The tradeoff on the table here is prestige-through-permanence versus prestige-through-currency: some certifications hold value by staying eternally on your resume, while others hold value by proving you have kept pace with the field through ongoing renewal. The CPTS lands firmly in the first camp, and that has real implications for how you should think about its long-term ROI.
The Short Answer: CPTS Does Not Expire
Once you pass the CPTS exam, the credential is yours for life.1 Hack The Box does not attach an expiration date, does not require a renewal exam, does not mandate continuing education credits, and does not charge a maintenance fee.1 Your digital badge, issued through Credly, remains valid indefinitely, and your certificate number stays verifiable on the Hack The Box certificate lookup.2
One footnote worth flagging: if you paid for the exam voucher as part of an HTB Academy subscription, the unused voucher itself can expire when the subscription lapses.3 But once you sit and pass the exam, the certification you earn is untethered from your subscription status.
How HTB Handles Exam Updates
Hack The Box does not run a formal versioning system for the CPTS. When the exam content is refreshed to reflect new techniques or updated tooling, older credential holders are not deprecated, downgraded, or asked to recertify. Your CPTS from 2024 carries the same recognition as a CPTS earned in 2026.1
How This Compares to Other Certifications
- OSCP and OSCP+: Offensive Security moved to a three-year renewal model for OSCP+, requiring continuing professional education credits or a re-exam. The classic OSCP remains lifetime. CPTS matches the lifetime model.
- CompTIA Security+ certification and PenTest+: Uses a Continuing Education program. You renew every three years through CEUs, higher-level certs, or a paid retake plus an annual CE fee.
- PNPT (TCM Security): Lifetime, no renewal, similar posture to CPTS.
For budget-conscious learners, the lifetime model is a meaningful cost saving over a career. For hiring managers, it means a CPTS date on a resume is a signal of when the person passed, not a guarantee of current practice, so pair it with recent lab work or engagement experience.
Editorial Verdict by Learner Profile
Is the CPTS worth it for my background? The answer depends heavily on where you are in your career and on How to Choose a Cybersecurity Certification. Below, we break down the certification's value for four distinct learner profiles, from complete beginners to seasoned professionals.
No IT Background: Start Elsewhere First
If you have never worked in IT and are considering the CPTS as a first step into cybersecurity, the honest answer is that this credential is not designed for you. The Hack The Box Penetration Tester Job Role Path assumes you already understand operating systems, networking, and basic security concepts. The CPTS exam does not assess foundational theory; it demands hands-on exploitation in a live Active Directory environment. Diving straight in will likely lead to frustration and wasted time.
Instead, begin with an entry-level certification like eJPT (eLearnSecurity Junior Penetration Tester) or even CompTIA Security+ and Network+ to build core knowledge. Spend at least six to twelve months in hands-on practice on cybersecurity hands-on practice platforms such as Hack The Box Starting Point machines, TryHackMe rooms, and basic IT labs before revisiting the CPTS. This path will give you the context to understand why exploitation techniques work, not just how to run a tool.
Early IT Professional: A Strong Investment with Commitment
If you work in help desk, system administration, or a SOC analyst role and have some command-line comfort, the CPTS can be an excellent next step. You already grasp Windows internals, user account management, and basic logs, which are the real-world building blocks for the exam. However, don't underestimate the time commitment. Budget four to six months to work through the full Penetration Tester Job Role Path, and supplement with additional Active Directory lab practice; building a small home lab or using platforms like Snap Labs will pay off. The credential will demonstrate practical skills that many employers value, and the total cost is lower than alternatives like OSCP once you factor in no mandatory course purchase.
Working Cybersecurity Practitioner: Comparable Depth at Lower Cost
For professionals with one to three years in security roles, including incident responders, junior pen testers, or security engineers, the CPTS often makes more sense than pursuing the OSCP. Its practical assessment goes deep into Active Directory enumeration, pivoting, and post-exploitation, mirroring the attacks you perform on real engagements. The exam is entirely hands-on, with no multiple-choice fluff, and the full training path costs a fraction of typical OSCP study materials plus exam fees. If you need an objective, lab-verified proof of penetration testing competence and don't require the legacy brand recognition of OSCP, prioritize CPTS. Employers who look beyond a keyword scan will recognize the rigor.
Experienced Specialist or Manager: Probably Not Necessary
If you have five or more years of practical penetration testing experience and already hold OSCP (or equivalent), adding CPTS likely won't move the needle on your career. Your work history speaks louder than any additional certification. Unless you have a specific need to revalidate current hands-on skills after a management stint, or you're genuinely curious about Hack The Box's methodology and want to experience the exam's lab design, the time is better spent on advanced credentials. Consider OSEP (Offensive Security Experienced Penetration Tester) for evasive techniques and code execution, CRTO (Certified Red Team Operator) for adversary simulation, or GXPN (GIAC Exploit Researcher and Advanced Penetration Tester) if your employer funds SANS training. These credentials carry more weight at the senior and principal level.
Frequently Asked Questions
Below are the most common questions candidates ask before committing to the Hack The Box Certified Penetration Testing Specialist path. Answers reflect publicly available information from Hack The Box Academy as of mid-2026. Always check pricing and policies on the official certification page before purchasing.
Explore More
- AAISM Certification Guide
- Are Cybersecurity Certifications Worth It? ROI Guide
- AWS Certified Security Specialty Guide
- Brain Dumps & Exam Ethics in Cybersecurity Certifications
- BTL1 Certification Guide
- CCSP Certification Guide
- CEH Certification Guide
- CISA Certification Guide
- Cisco CCNA Cybersecurity Certification Guide
- Cisco CCST Cybersecurity Certification Guide
- CISM Certification Guide
- CISSP Certification Guide
- Compare Cybersecurity Certifications Side by Side
- CompTIA CySA+ Certification Guide
- CompTIA PenTest+ Certification Guide (PT0-003)
- CompTIA SecAI+ Certification Guide
- CompTIA Security+ Certification Guide
- CompTIA SecurityX Certification Guide
- CRISC Certification Guide
- Cybersecurity Certification Finder
- Cybersecurity Certification Methodology
- Cybersecurity Certification Prerequisites Explained
- Cybersecurity Certification Roadmaps by Role & Level
- Cybersecurity Certification Study Plan for Working Adults
- Cybersecurity Certification vs. Certificate vs. Bootcamp
- Cybersecurity Certifications Without a Degree
- Cybersecurity Degree vs. Certification vs. Bootcamp
- eJPT Certification Guide
- GIAC AI Platform Security (GAIPS)
- GIAC GICSP Certification Guide
- GIAC GPEN Certification Guide
- GIAC GSEC Certification Guide
- GIAC GWAPT Certification Guide
- Google Cybersecurity Certificate Guide
- Google Professional Cloud Security Engineer Guide
- How to Choose a Cybersecurity Certification
- How to Prepare for a Cybersecurity Certification Exam
- ISACA CCOA Certification Guide
- ISC2 Certified in Cybersecurity (CC) Guide
- ISC2 CGRC Certification Guide
- ISC2 CSSLP Certification Guide
- ISC2 SSCP Certification Guide
- Microsoft SC-100 Certification Guide
- Microsoft SC-200 Certification Guide
- Microsoft SC-900 Certification Guide
- Online Cybersecurity Exams
- OSCP & OSCP+ Certification Guide
- OSWE Certification Guide
- PNPT Certification Guide
- Self-Study vs. Instructor-Led vs. Bootcamp Cyber Training
- Vendor-Neutral vs. Vendor-Specific Cybersecurity Certs






