Skip to content

Certifications Roadmap

Key Principle

Certifications open doors โ€” skills keep you employed. The best certification is the one that forces you to practice hands-on, not just memorize. An OSCP with genuine lab hours is worth more than three theory-only certifications.


The Landscape at a Glance

BEGINNER                    MID-LEVEL                   SENIOR/SPECIALIST
โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€           โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€        โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
CompTIA Security+           OSCP (OffSec)                OSEP (OffSec)
eJPT (eLearnSecurity)       eCPPT (eLearnSecurity)       OSED (OffSec)
CEH (EC-Council)            PNPT (TCM Security)          CRTO (Zero Point Security)
CEH Master                  eWPT (eLearnSecurity)        CRTE (Altered Security)
CNSP (SecOps Group)         GPEN (SANS)                  GXPN (SANS)
                            GWAPT (SANS)                 CRTL (Altered Security)
                                                         OSWE (OffSec)
                                                         BSCP (PortSwigger)

Beginner Certifications

CompTIA Security+

What it covers: Broad security fundamentals โ€” network security, identity management, cryptography, threats, compliance.

Exam format: Multiple choice and performance-based questions.

Value: Industry-recognized entry point. Required by many employers for junior roles, especially in government and enterprise. Covers foundational theory well.

Limitation: No hands-on component. Theory only. Doesn't differentiate you in competitive hiring.

Recommended if: You need a baseline credential and are starting your career.


eJPT โ€” eLearnSecurity Junior Penetration Tester

Provider: INE / eLearnSecurity

What it covers: Entry-level pentesting โ€” host/network discovery, enumeration, basic web attacks, Metasploit fundamentals.

Exam format: Hands-on labs โ€” you get access to a network and must answer questions by actually compromising systems.

Value: Good first hands-on pentesting credential. Affordable. Tests real skills, not just memorization.

Recommended if: You want your first hands-on pentest credential before investing in OSCP.


CEH โ€” Certified Ethical Hacker

Provider: EC-Council

What it covers: Broad coverage of attack techniques across 20 domains.

Exam format: Multiple choice (125 questions). Practical version (CEH Practical) adds a 6-hour hands-on exam.

CEH Master: Requires passing both CEH and CEH Practical. Demonstrates both knowledge and application.

Value: Widely recognized brand name. Required by many corporate and government job postings, especially in India. The underlying course material is comprehensive.

Limitation: The multiple-choice exam can be passed with memorization rather than skill. The Practical exam addresses this significantly.

Recommended if: You need to meet job posting requirements that specifically list CEH, or for initial credentialing in the Indian market.


CNSP โ€” Certified Network Security Practitioner

Provider: SecOps Group

What it covers: Network security, basic pentesting, blue team concepts.

Value: Recognized in some markets, relatively affordable.


Mid-Level Certifications

OSCP โ€” Offensive Security Certified Professional

Provider: OffSec (formerly Offensive Security)

What it covers: Practical pentesting โ€” network enumeration, web attacks, buffer overflows, privilege escalation, Active Directory.

Exam format: 24-hour hands-on exam โ€” you must compromise a set of machines in a private network and submit a professional report within the following 24 hours.

Value: The industry gold standard for offensive security. An OSCP genuinely signals that you can do the job. Universally recognized and respected. Many job descriptions list it as preferred or required.

Difficulty: Hard. Fail rate is high on first attempt. Requires genuine skill โ€” you can't memorize your way through 24 hours of hands-on exploitation.

Recommended: Essential for anyone serious about penetration testing. Do this once you have 6-12 months of foundational experience.


PNPT โ€” Practical Network Penetration Tester

Provider: TCM Security

What it covers: Practical ethical hacking โ€” OSINT, network scanning, exploitation, Active Directory attacks, web attacks, post-exploitation, reporting.

Exam format: 5-day hands-on pentest of a mock client environment, followed by professional report submission and debrief.

Value: Excellent practical credential at a fraction of OSCP's cost. Report and debrief component tests professional communication. Strong community and supporting courses.

Recommended if: You want a practical credential that tests report writing and professional process, or want an alternative/supplement to OSCP.


eWPT โ€” eLearnSecurity Web Application Penetration Tester

Provider: INE / eLearnSecurity

What it covers: Web application penetration testing โ€” OWASP Top 10, Burp Suite, manual testing methodology.

Exam format: Hands-on lab with web applications to test, report required.

Recommended if: Your focus is web application security specifically.


GPEN โ€” GIAC Penetration Tester

Provider: SANS / GIAC

What it covers: Penetration testing methodology, network attacks, web attacks, password attacks, exploitation.

Value: Highly credible, vendor-neutral. SANS training is excellent. Expensive โ€” employer sponsorship typical.

Exam format: Proctored multiple choice + performance-based questions.


GWAPT โ€” GIAC Web Application Penetration Tester

Provider: SANS / GIAC

What it covers: Web application security testing.


Senior / Specialist Certifications

CRTO โ€” Certified Red Team Operator

Provider: Zero Point Security (RastaMouse)

What it covers: Red team operations โ€” C2 (Cobalt Strike), OPSEC, evasion, initial access techniques, Active Directory attacks.

Exam format: 48-hour hands-on red team engagement in a realistic Cobalt Strike lab environment.

Value: Best practical credential for red team methodology. Excellent course material by RastaMouse. Good balance of price and quality.

Recommended for: Anyone moving toward red team or advanced AD exploitation.


CRTE โ€” Certified Red Team Expert

Provider: Altered Security (formerly Pentester Academy)

What it covers: Advanced Active Directory attacks โ€” trust attacks, constrained/unconstrained delegation, ADCS, cross-forest attacks.

Exam format: Hands-on lab โ€” compromise a multi-domain, multi-forest AD environment.

Value: The deepest practical AD credential. Complements CRTO well.

Recommended for: Those specializing in Active Directory security.


CRTA โ€” Certified Red Team Analyst

Provider: Altered Security

What it covers: Entry-level red team with AD focus.

Value: Good complement to or precursor to CRTE.


OSEP โ€” Offensive Security Experienced Penetration Tester

Provider: OffSec

What it covers: Evasion, custom shellcode, advanced lateral movement, bypassing security controls.

Exam format: 48-hour hands-on exam with modern defenses (AV, EDR, application whitelisting).

Value: Demonstrates ability to operate against hardened environments.


OSWE โ€” Offensive Security Web Expert

Provider: OffSec

What it covers: Advanced web application attacks โ€” authentication bypass chains, deserialization, SSRF chains.

Exam format: 48-hour hands-on web application exploitation exam.

Value: The hardest OffSec web credential. Highly respected.


BSCP โ€” Burp Suite Certified Practitioner

Provider: PortSwigger

What it covers: Web application security โ€” all major vulnerability classes using Burp Suite.

Exam format: 4-hour proctored exam โ€” two web apps to compromise.

Value: Validates genuine Burp Suite proficiency. Free preparation via PortSwigger Web Academy.

Recommended for: Web application specialists. The preparation (Web Academy) alone is worth it regardless of whether you take the exam.


OSCP โ†’ OSEP โ†’ CRTO Progression

This combination covers the major pentesting domains comprehensively:

1. OSCP (or PNPT)     โ†’ Foundation: methodology, network, web, basic AD
2. CRTO               โ†’ Red team: C2, OPSEC, AD attacks in depth
3. OSEP or CRTE       โ†’ Advanced evasion or advanced AD/multi-forest
4. BSCP or OSWE       โ†’ Web specialization (if web is your focus)

India-Specific Context

Most recognized by Indian enterprises: CEH, OSCP, CISA (for GRC roles)

Most recognized by MNCs in India: OSCP, GPEN/GWAPT, CISSP (for leadership)

For government/defense adjacent roles: CEH, CISSP are often explicitly required

Budget path for Indian market:

CompTIA Security+ โ†’ CEH / CEH Master โ†’ PNPT โ†’ OSCP โ†’ CRTO

Cost comparison (approximate USD):

CompTIA Security+: $370
eJPT: $200/year (INE subscription)
CEH: $950
PNPT: $400
OSCP: $1,499 (includes 90-day lab)
CRTO: $485
CRTE: $299
GPEN: $7,000+ (with SANS course) / ~$900 (exam only with self-study)


GRC and Compliance Certifications

Certification Provider Focus
CISA ISACA IT audit, control, assurance
CISSP (ISC)ยฒ Security management (requires 5yr experience)
CISM ISACA Information security management
ISO 27001 Lead Auditor Various ISO 27001 audit
ISO 27001 Lead Implementer Various ISO 27001 implementation
CRISC ISACA IT risk management
PCI-ISA PCI SSC PCI-DSS internal audit

Certification Maintenance

Most certifications require renewal:

  • CompTIA: Every 3 years via CPE credits or re-exam

  • CEH: Every 3 years, 120 CPE credits required

  • OSCP: Lifetime once earned (no renewal)

  • GIAC: Every 4 years, 36 CPE credits

  • CISSP: Every 3 years, 120 CPE credits

Maintain a CPE log. Blog posts, conference presentations, training courses, CTF participation all typically count.