Most people who fail the PNPT do not fail because they cannot hack. They fail because they ran out of days, wrote a weak report, or froze in the debrief. Learning how to pass the PNPT exam means preparing for a full penetration testing engagement, not a capture the flag event, and that is a different discipline entirely.
The short answer: give yourself eight focused weeks, work the five bundled TCM Security courses in order, build a repeatable Active Directory attack chain you can run from memory, and write your report as you hack rather than after. Do that and the five days are comfortable. Treat it like an OSCP-style sprint and you will burn day one on enumeration you should have automated in week three.
This guide breaks down the exam format, the realistic study timeline, the domain-by-domain skills you need, and the two stages almost nobody prepares for properly: the professional report and the 15-minute live debrief.
What the PNPT Exam Actually Is
The Practical Network Penetration Tester (PNPT) is a professional-level certification from TCM Security. It is a full simulated engagement against a corporate network, and there is nothing multiple choice about it.
The exam structure is fixed and generous compared with most practical certifications:
- Five full days to complete the practical assessment against the target network.
- Two additional days to write a professional penetration test report.
- A live 15-minute debrief presenting your findings to senior penetration testers.
The exam costs $499, which includes the voucher, one free retake, and 12 months of access to 45+ hours of bundled on-demand training. The exam environment is non-proctored, so there is no monitoring software watching you work. Once earned, the PNPT does not expire.
Exam Tip: The PNPT contains zero flags and zero multiple-choice questions. Your deliverable is the report. If you compromise the domain controller but submit a poor report, you do not pass.
What you have to achieve
To pass, you need to perform OSINT against the target organisation, exploit an external-facing service to gain a foothold, and then move through the internal network: antivirus and egress bypassing, lateral movement, vertical privilege escalation, and finally compromise of the domain controller. Then you document all of it to a client-ready standard.
If you have read our breakdown of OSCP vs OSCP+ and what changed in 2026, the contrast is instructive. OSCP gives you 24 hours and rewards raw speed under pressure. The PNPT gives you a working week and rewards methodology, note discipline and communication.
PNPT vs the Other Practical Pentest Certifications
Candidates almost never consider the PNPT in isolation. It sits in a cluster with the eJPT, the HTB CPTS and the OSCP, and picking the wrong entry point is the most common planning mistake.
| Certification | Practical time | Report required | Live debrief | Cost | Best for |
|---|---|---|---|---|---|
| eJPT (INE) | Single sitting, 45 questions | No | No | Lower | First practical cert, absolute beginners |
| PNPT (TCM Security) | 5 days | Yes, 2 days | Yes, 15 minutes | $499 | Realistic AD engagement plus client skills |
| HTB CPTS | 10 days | Yes | No | Mid | Depth and technical breadth |
| OSCP (OffSec) | 24 hours | Yes, 24 hours | No | Highest | Maximum HR and enterprise recognition |
The PNPT is the only one of the four that makes you defend your work to a human being. That is its differentiator and, for anyone heading into consultancy, its most transferable skill.
If you are still choosing, our guides on how to pass the eJPT in 2026 and how to pass the HTB CPTS in 2026 cover the neighbouring options in the same detail.
Should you do the PJPT first?
TCM Security recommends beginners start with the PJPT (Practical Junior Penetration Tester) before attempting the PNPT. That advice is sound if you have never touched Active Directory. If you already understand Kerberos basics, SMB enumeration and local privilege escalation, you can go straight to the PNPT and save yourself several weeks.
The Bundled Training: What to Study and In What Order
The $499 bundle includes five courses totalling over 45 hours of video. TCM Security strongly recommends taking them in a specific order, and that order is not arbitrary. Each one feeds the next.
- Practical Ethical Hacking (roughly 25 hours). The foundational course. Everything else assumes it.
- Open-Source Intelligence (OSINT) Fundamentals (roughly 9 hours). Directly maps to the exam's first phase.
- External Pentest Playbook (roughly 3.5 hours). Short, but it is the bridge from OSINT to your initial foothold.
- Linux Privilege Escalation for Beginners (roughly 6.5 hours).
- Windows Privilege Escalation for Beginners (roughly 7 hours).
Exam Tip: Take the capstone sections of every course seriously and take structured notes on each one. The capstones are the closest thing to exam conditions the training provides.
Do not passively watch. Rebuild every technique in your own lab, in your own words, in your own notes. Video hours are not study hours.
The Eight-Week PNPT Study Plan
This plan assumes roughly 10 to 12 hours per week. Compress it to six weeks if you already work in security, or stretch it to twelve if you are studying around a full-time job outside IT.
Weeks 1 and 2: Foundations and Practical Ethical Hacking
Work through Practical Ethical Hacking end to end. Focus hard on the networking refresher, enumeration methodology and the Active Directory sections.
- Build your note-taking system now, before you need it. Obsidian, CherryTree or a simple structured Markdown folder all work.
- Create a template with sections for each host: services, credentials found, exploitation steps, screenshots, timestamps.
- Complete every lab in the course rather than watching the walkthrough.
Week 3: OSINT and External Reconnaissance
Work the OSINT Fundamentals course, then the External Pentest Playbook.
- Practise finding employee names, email formats and exposed credentials for a real (permitted) target such as a bug bounty scope.
- Build a personal OSINT checklist: domains, subdomains, employee enumeration, email naming convention, breach data, exposed services.
- The exam starts here, so the muscle memory matters more than most people expect.
Weeks 4 and 5: Privilege Escalation, Linux and Windows
Work both privilege escalation courses back to back so the patterns reinforce each other.
- Run through the Linux course first, then Windows.
- For each technique, record the enumeration command, the indicator you are looking for, and the exploitation step. Three lines each.
- Build a single privilege escalation cheat sheet you can read in under two minutes.
Week 6: Active Directory Attack Chains
This is the week that decides your result. The exam's internal phase is Active Directory from start to finish.
- Practise the full chain repeatedly: initial foothold, credential harvesting, lateral movement, domain escalation, domain controller compromise.
- Learn NetExec properly. Not "know it exists", but understand its modules, its authentication options and its output. It is the single most useful tool in the internal phase.
- Drill Kerberoasting, AS-REP roasting, pass-the-hash, token impersonation and NTLM relay until you can run each without looking anything up.
- Build a lab: a Windows Server domain controller and two domain-joined workstations is enough.
Week 7: Report Writing and Antivirus Evasion
Two often-neglected areas, and both are directly examined.
- Write a full practice report on a lab you have already compromised. Use TCM Security's report guidance as your structure.
- Practise antivirus and egress bypassing, because the exam environment is not wide open. Understand basic payload obfuscation and which egress ports realistically survive.
- Time yourself. If a practice report takes you eight hours, budget accordingly.
Week 8: Full Mock Engagement and Debrief Practice
- Run a complete end-to-end engagement against your own lab across two or three days, under exam-style discipline: notes as you go, screenshots as you go, no shortcuts.
- Write the report from those notes alone. If you cannot, your note-taking failed, and better to learn that now.
- Record yourself delivering a 15-minute debrief to camera. Watch it back. It will be uncomfortable and it will be the most valuable hour of the whole eight weeks.
The Report: Where Most Failures Actually Happen
The report is not an afterthought bolted onto the practical. It is the assessed deliverable, and you get two full days for it precisely because it carries real weight.
Your report should contain:
- An executive summary written for a non-technical reader. No tool names, no command output. What was the business risk, in plain language.
- A methodology section describing your approach, phase by phase.
- Detailed findings, each with a severity rating, a clear description, evidence (screenshots with timestamps), business impact, and a specific remediation recommendation.
- An attack narrative walking the reader from initial foothold to domain compromise as a coherent story.
- Appendices with supporting detail such as full command output and scan results.
Exam Tip: Write as you hack. Paste every screenshot and every command into your notes at the moment you run it. Recreating evidence on day six because you forgot to capture it on day two is how candidates lose their two report days.
The most common report weaknesses are vague remediation advice ("patch the system" tells a client nothing), missing evidence for a claimed finding, and severity ratings that are not justified. Rate each finding against real business impact and say why.
The Live Debrief: 15 Minutes That Nobody Rehearses
After you submit the report, you schedule a live 15-minute debrief with TCM Security assessors, all of whom are senior penetration testers. You present your findings as if they were the client.
This is the stage with the least published guidance and the most avoidable failure. Here is how to prepare for it:
- Structure the 15 minutes in advance. Roughly two minutes of scope and approach, eight minutes on the attack narrative and key findings, three minutes on remediation priorities, two minutes for questions.
- Lead with business impact, not technique. "An attacker could reach full domain control from the public internet without valid credentials" lands harder than a description of your Kerberoasting command.
- Know your own report cold. You will be asked follow-up questions, and answers must match what you wrote.
- Be honest about what you did not find. Assessors respect a candidate who says "I did not get to that path and here is why" far more than one who bluffs.
- Practise out loud, at least three times. Reading your report silently is not rehearsal.
Treat the assessors as a client who is technical, busy and paying for clarity. That framing gets the tone right almost automatically.
Common PNPT Mistakes to Avoid
- Rushing the OSINT phase. The initial foothold usually depends on something you find here. An hour saved on day one costs you a day later.
- Poor note-taking. The single biggest cause of a weak report and a shaky debrief.
- Ignoring the report until day six. You have two dedicated days, but they are for polishing, not for reconstructing a week of work from memory.
- Skipping antivirus and egress bypassing practice. Candidates who only ever practised in permissive labs get stuck at the foothold.
- Not learning NetExec deeply. It appears in nearly every successful exam write-up for a reason.
- Assuming the free retake means it does not matter. The retake is free, but the eight weeks are not.
Is the PNPT Worth It in 2026?
For the money, few practical certifications offer as much. At $499 including a free retake and 45+ hours of training, the cost sits well below the OSCP, and the skills tested map closely to real internal penetration testing work: most real engagements are Active Directory engagements.
The trade-off is recognition. The OSCP still carries more weight with enterprise HR filters and in government and defence hiring, while the PNPT is more respected among practitioners and at smaller consultancies who understand what each exam actually tests. A common and sensible path is PNPT first for the methodology and the cost, then OSCP later for the resume.
If you are weighing penetration testing certifications more broadly, our comparison of PenTest+ vs CEH covers the theory-led alternatives, and the full range of exam preparation material is on our courses page.
Ready to Start Practising?
The PNPT rewards preparation over improvisation. Eight weeks of structured study, a lab you have broken and rebuilt several times, a report template you have already used, and a debrief you have rehearsed will put you comfortably ahead of most candidates walking into day one.
CertCrush helps you build the underlying knowledge that makes practical exams like the PNPT achievable, with structured courses, practice questions and study plans across the certification landscape.
Create your free CertCrush account and start building the foundation your five days will rest on.
