Back to blog
Study Tips8 min read

How to Pass the HTB CPTS Exam in 2026: A Study Plan for the 10-Day Practical

A week-by-week study plan for the Hack The Box CPTS exam in 2026. Learn how to clear the Penetration Tester path, capture 12 of 14 flags, and pass the professional report on the 10-day practical.

Owen Gallagher

Owen Gallagher · Study Skills & Careers Editor

21 July 2026

If you want to know how to pass the HTB CPTS exam in 2026, the honest answer is that the certification is won long before you open the exam environment. The Hack The Box Certified Penetration Testing Specialist (HTB CPTS) is a fully hands-on, 10-day practical that hands you a black-box enterprise network and asks you to compromise it and write a professional report. There are no multiple-choice questions to fall back on. You either build a repeatable methodology during your preparation, or you run out of time on day nine with half a report and a network you never quite finished.

This guide gives you a realistic week-by-week study plan for the CPTS, the exact exam facts you need to plan around, and the mistakes that sink most first attempts. It is written for the person who has bought (or is about to buy) HTB Academy and wants a structured route through the Penetration Tester path rather than 28 modules of guesswork.

What the HTB CPTS Exam Actually Involves

The CPTS is not a knowledge test. It is a simulated penetration testing engagement. You are dropped into a black-box environment of roughly eight or more Windows and Linux hosts, usually stitched together with Active Directory, and you have to work through it the way a real consultant would: enumerate, exploit, pivot, escalate, and document everything as you go.

Here are the numbers that matter when you plan your attempt.

DetailHTB CPTS (2026)
FormatFully hands-on practical engagement
Exam length10 days (covers both the pentest and the report)
EnvironmentBlack-box enterprise network, roughly 8+ hosts, Windows and Linux with Active Directory
Flags available14
Flags needed to pass12 out of 14 (80 out of 100 points)
ReportMandatory, professional-grade, assessed as part of pass or fail
Prerequisite100 percent completion of the Penetration Tester job-role path (28 modules)
RetakeSecond attempt within 14 days of examiner feedback; 14-day cool-off after a second fail
Typical costSilver Annual subscription around 490 US dollars (includes the path and a voucher); standalone voucher around 210 US dollars

Exam Tip: You must capture 12 of the 14 flags to hit the 80-point pass mark, but flags alone do not pass you. If your report does not meet professional standards, you can fail even with every flag captured. Treat the report as half the exam, not an afterthought.

The Report Is Not Optional

This is the single point that separates people who pass from people who are surprised. The CPTS report is graded. Hack The Box wants a commercial-grade penetration testing report: a clear executive summary, an attack narrative, reproducible steps for every finding, risk ratings, and remediation advice. If an examiner cannot reproduce your compromise from your notes, that finding does not count. Build your reporting habit during preparation, not on day nine.

The Prerequisite: Finish the Penetration Tester Path First

You cannot even book the CPTS exam until you have completed 100 percent of the Penetration Tester job-role path on HTB Academy. That path is 28 modules deep and ends each module with a hands-on skills assessment. This is a genuine barrier and it is also your best training. The exam is drawn directly from the concepts in that path, so completing it properly is most of your revision.

Do not skip modules to reach 100 percent faster. Every section exists because the exam tests it. The modules people most regret rushing are the Active Directory chain, pivoting and tunnelling, and Attacking Enterprise Networks. Those are exactly the skills the exam leans on hardest.

A Realistic CPTS Study Plan

Most candidates need three to six months of consistent study to pass the HTB CPTS, depending on background. Someone already working in security or holding the OSCP will move faster; a relative beginner should plan for the longer end. The plan below assumes roughly 10 to 15 hours a week. Compress or stretch the weeks to fit your own pace, but keep the order.

Weeks 1 to 4: Foundations and Enumeration

Work through the early Penetration Tester path modules covering information gathering, footprinting, and service enumeration. The goal in this phase is not speed, it is thoroughness. Enumeration failures are the number one reason people get stuck on the exam, because you cannot exploit a service you never found.

  • Build a personal enumeration checklist for every common port and service.
  • Practise turning raw scan output into a prioritised list of attack paths.
  • Start your notes system now, not later.

Weeks 5 to 8: Exploitation and Web Attacks

Move into the exploitation modules: web attacks (SQL injection, cross-site scripting, server-side template injection, file inclusion, command injection), common service exploitation, and initial foothold techniques. The CPTS web content is deep, so give it the time it deserves.

  • Redo every hands-on skills assessment without looking at the guided steps.
  • Keep a running library of working payloads and the reason each one is used.

Weeks 9 to 12: Active Directory, Pivoting and Privilege Escalation

This is the heart of the exam. The CPTS environment is an Active Directory network, and the path spends serious time on AD enumeration, credential attacks, access control list abuse, Kerberos attacks, trust relationships, and lateral movement. Pair this with the Windows and Linux privilege escalation modules.

  • Practise pivoting between network segments until tunnelling feels routine.
  • Learn to keep a clear map of a multi-host network so you never lose track of where you have access.

Exam Tip: The exam rewards the person who pillages every host fully before moving on. Credentials, config files, and hashes found on one machine are frequently the key to the next. Slow, complete looting beats fast, shallow scanning every time.

Weeks 13 to 16: Full-Scope Practice and Reporting

Now put it together. Complete the Attacking Enterprise Networks module by reading only the engagement letter and working the network from scratch, ignoring the walkthrough. This forces you to build a real methodology instead of following steps. If you can, run at least one HTB Pro Lab (Dante, Zephyr, or similar) to get comfortable operating inside a large network under your own steam.

At the same time, write a full practice report from one of these labs. Do it properly: executive summary, findings, evidence, remediation. When you can produce a report you would hand to a paying client, you are ready to book the exam.

How to Approach the 10 Days

Treat the 10 days as a real engagement with a schedule, not a marathon of panic. A workable rhythm is to spend the first six or seven days on the practical compromise and reserve the last three or four for writing and polishing the report. Do not leave the report until the end.

  1. Log everything as you go. Every command you run and every output worth keeping goes into your notes immediately, tagged to the host it came from. Reproducibility is graded.
  2. Screenshot with intent. The report values reproducible commands and code blocks over walls of screenshots, so capture what proves the finding, not everything on screen.
  3. Enumerate before you exploit, every time. When you stall, the answer is almost always more enumeration, not a new exploit.
  4. Take breaks. You have 10 days. A tired tester misses the obvious. Sleep is a legitimate exam strategy here.
  5. Write the report in parallel. Draft each finding the day you achieve it, while the steps are fresh. Assembling a report from cold notes on day 10 is where people fail.

CPTS vs OSCP: Where Does It Fit?

Candidates almost always weigh the CPTS against the OSCP, so it is worth being clear. The OSCP still carries the strongest brand recognition with recruiters and human resources filters. The CPTS is widely seen as the more modern and more technically thorough curriculum, especially on Active Directory, and its 10-day format removes the artificial pressure of the OSCP's 24-hour clock.

Many people now do the CPTS first to build deep methodology, then take the OSCP for the badge that job adverts still ask for by name. If you want the full breakdown of how these practical certifications differ, read our guide on OSCP vs OSCP+ and what changed in 2026, and browse the wider certification courses on CertCrush to see where a pentest cert sits in your roadmap.

Common Reasons People Fail the CPTS

  • Weak enumeration. They exploit what they find fast and never dig deep enough to find the rest.
  • Poor note-taking. They compromise hosts but cannot reproduce the steps in the report, so findings do not count.
  • Ignoring the report weight. They capture flags, submit a thin report, and fail.
  • Skimming the path. They rush modules to reach 100 percent and hit exam questions on skills they never practised.
  • No pivoting practice. They can own a single box but freeze when they need to tunnel into a second network segment.

Fix these in preparation and the exam becomes an exercise in patience rather than a gamble.

Ready to Start Practising?

Passing the HTB CPTS in 2026 comes down to three things: finish the Penetration Tester path properly, build a repeatable enumeration and reporting methodology, and treat the 10-day exam as a real engagement rather than a race. Do that and 12 of 14 flags plus a professional report is a realistic target, not a lucky day.

CertCrush helps you build the underlying knowledge that makes hands-on practice stick, from reinforcing core security concepts to sharpening the exam-day discipline that practical certs demand. Create your free CertCrush account to start practising today, explore the full range of certification courses, and check our plans when you are ready to go all in on your next exam.

Put in the reps now, and the 10-day practical becomes the easy part.

HTB CPTSHack The BoxCertified Penetration Testing Specialistpenetration testingstudy planOSCPActive Directoryexam prep
Owen Gallagher

Written by

Owen Gallagher · Study Skills & Careers Editor

Owen spent years as an IT trainer watching smart people fail exams they should have passed — usually because of how they studied, not what they knew. He writes about study technique, exam psychology, career strategy and the service-management certifications (ITIL, PRINCE2, APM). His articles are the ones to read before you open a single practice question.

All articles by Owen

Want a HTB CPTS practice course?

We don’t cover this exam yet — we build the most-requested courses first. One click tells us you want it.

Ready to crush this exam?

Set your exam date, follow a daily plan, and watch your readiness score climb — realistic practice with an explanation for every answer.