Most of the CRTO reviews still ranking on Google describe an exam that no longer exists. They tell you to capture six of eight flags across a 48-hour lab. Zero-Point Security rewrote Red Team Ops in May 2025, and the CRTO certification exam that replaced it grades you on how quietly you work, not on how many flags you collect. Candidates who prepare from those older write-ups walk in with the wrong plan.
This guide covers what the exam asks for now, what it costs, and a six-week plan to get through it.
What Changed in the CRTO Certification Exam
The rewrite moved the course onto a new platform, refreshed the tradecraft, and replaced the flag hunt with a scored operation.
Candidate reports through 2025 and 2026 consistently describe the same model: a 100-point exam, split roughly half for reaching the operational objective in an Active Directory estate and half for operational security, with 85 points needed to pass. Zero-Point Security does not publish the scoring breakdown on its site, so treat the exact split as a strong consensus from people who have sat it rather than a vendor-stated figure.
The practical consequence is not in dispute. Reaching domain dominance no longer guarantees a pass. If your Beacon gets blocked, your lateral movement looks like a textbook example, or you touch LSASS the obvious way, you lose points that the objective cannot win back.
| Pre-2025 exam | Current exam | |
|---|---|---|
| Scoring | Flags collected | Objective plus OPSEC points |
| Pass condition | 6 of 8 flags | 85 of 100 points |
| Detection | Cost you time | Costs you marks |
| Reported timing | 48 hours over 4 days | 24-hour timer, pausable across 7 days |
| Retakes | Unlimited, free | Unlimited, free |
Exam Tip: Two independent 2026 candidate reviews put the current exam at a 24-hour active timer that you can pause across a seven-day window. The 48-hour figure you will find on several high-ranking pages predates the rewrite. Confirm the timer in your own exam brief before you plan your sleep.
What the CRTO Certification Costs in 2026
These prices are taken from the Zero-Point Security course catalogue on 29 August 2026.
| Course | Price |
|---|---|
| Red Team Ops (CRTO) | £399 |
| Red Team Ops II (CRTO II) | £449 |
| RTO and RTO II bundle | £848, currently £765 |
| BOF Development and Tradecraft | £199 |
| UDRL and Sleepmask Development | £299 |
The £399 covers the course, over 20 hands-on labs with no expiry, a licensed copy of Cobalt Strike inside those labs, and the exam. Exam attempts are unlimited and free, which Zero-Point Security states plainly: there is no financial penalty for failing. Pricing is adjusted by purchasing power parity and the discount is applied automatically at checkout, so the figure you see may be lower than the sterling list price depending on where you buy from.
Two other details are worth knowing before you buy. The certification does not expire, so there is no renewal fee waiting for you. And the exam cannot be attempted until seven days after purchase, which rules out buying it the night before a deadline.
Who Should Take CRTO, and Who Should Wait
CRTO sits at what Zero-Point Security calls Practitioner level, with a stated study time of 20 hours. That figure describes the lecture content, not the practice you need on top of it.
You are ready if you are comfortable in an Active Directory environment, understand Kerberos well enough to explain a ticket, and have run a command and control framework before. OSCP or HTB CPTS holders usually have that grounding already.
Wait if Active Directory is still new to you. CRTO teaches adversary simulation with Cobalt Strike, and it assumes you already know why a Kerberoast works. Learning the attack and the evasion at the same time is what turns a six-week study plan into a six-month one.
For how CRTO fits against the other post-OSCP options, we compared them in what to take after OSCP.
The 6-Week CRTO Study Plan
The course runs to 24 modules, from Getting Started through to the final exam. This plan groups them so that each week ends with something you can practise rather than something you have only read.
Week 1: Foundations and Cobalt Strike
Work through Getting Started, Law and Compliance, Malware Essentials and the Cobalt Strike Primer. Spend the back half of the week in the lab getting fluent with the client: listeners, payload generation, Beacon commands, and moving between sessions without reaching for notes.
Week 2: Defence Evasion and Initial Access
Defence Evasion is the module that decides your exam. Take it slowly. Learn which default Cobalt Strike artefacts get flagged and what you change to stop that happening. Then cover Initial Access and Persistence, and practise each payload against the lab defences rather than in a clean environment.
Week 3: Post-Exploitation to Credential Access
Post-Exploitation, Privilege Escalation, Elevated Persistence and Credential Access. This is where LSASS handling comes up, and where the quiet method and the obvious method diverge sharply. Write down both for every technique, because the exam scores the difference.
Week 4: Movement Across the Estate
User Impersonation, Discovery, Lateral Movement and Pivoting. Run each lateral movement technique twice: once to make it work, once to make it look ordinary. Note which ones generate a process network connection that a defender would question.
Week 5: Kerberos, SQL and Domain Dominance
Kerberos, Microsoft SQL Server, Domain Dominance, Active Directory Certificate Services, Forest and Domain Trusts, and AppLocker. ADCS and trusts are the two that most candidates skim and then meet in the exam. Give them a full session each.
Week 6: Reporting and a Dry Run
Cover the Reporting module, then run a full attack chain end to end against the labs on a timer, from initial access to the objective, logging every action as you go. Treat any step you cannot explain the OPSEC reasoning for as unfinished. Book the exam once the dry run holds together.
Exam Tip: Build an OPSEC log during your dry run, one line per action: what you ran, what telemetry it produced, and the quieter alternative. That log is the difference between a candidate who passes and one who reaches the objective and still drops below 85.
Protecting Your OPSEC Score on Exam Day
Every point you lose comes from something you chose to do. The recurring themes in candidate accounts are consistent and avoidable.
- Blocked execution. A payload that gets stopped is a scored event, not a free retry. Test your delivery method in the labs first.
- Default artefacts. Unmodified Cobalt Strike indicators are the cheapest points you will ever give away.
- Noisy lateral movement. Prefer the technique that resembles normal administration over the one that is quickest to type.
- LSASS access. Handle it the way the course teaches, not the way your pentest muscle memory wants to.
- Disabling controls. Turning defences off to make an attack work reads as detection, because that is exactly what it is in a real estate.
The mindset shift is the whole exam. You are not being asked whether you can compromise the domain. You are being asked whether you can compromise it without the blue team writing an incident report about you.
Frequently Asked Questions
Is CRTO harder than OSCP?
They are difficult in different ways. OSCP is broader and longer, and it tests whether you can find and chain a way in across mixed targets. CRTO is narrower and assumes you already can, then grades you on doing it quietly inside Active Directory. Most people who hold both describe OSCP as the harder endurance test and CRTO as the harder discipline test.
How much does the CRTO certification exam cost?
Nothing on its own. The exam is included in the £399 Red Team Ops course price, and attempts are unlimited and free. Zero-Point Security applies purchasing power parity automatically at checkout, so the price in your country may be lower.
Is CRTO for beginners?
No. It is a Practitioner-level course that expects working knowledge of Active Directory, Kerberos and command and control frameworks. Beginners are better served by an entry-level path first, such as CompTIA PenTest+ or a hands-on junior practical.
Does the CRTO certification expire?
No. Zero-Point Security states that its certifications do not expire, and course and lab access is lifetime with no renewal fee.
How long should I study for CRTO?
The course content is listed at 20 hours of study time. Six weeks at eight to ten hours a week gives you room to work the labs properly and run a timed dry run before you book, which is what the OPSEC scoring rewards.
Ready to Start Practising?
CRTO rewards people who have already built the fundamentals somewhere else. If penetration testing theory is the gap between you and a red team course, CertCrush has a full practice-question bank for CompTIA PenTest+ that covers the attack methodology CRTO assumes you know.
Create a free CertCrush account and start working through exam-style questions today.
