Back to blog
Career Advice12 min read

What to Take After OSCP in 2026: OSEP vs CRTO vs CRTP vs CPTS Compared

You passed OSCP. Now what? A straight comparison of OSEP, CRTO, CRTP and CPTS on cost, exam format, difficulty and what hiring managers actually pay for, so you spend your next few thousand pounds in the right place.

Tom Ashford

Tom Ashford · Security Certifications Lead

27 July 2026

You passed OSCP. The screenshot is on LinkedIn, the adrenaline has worn off, and now you are staring at a list of four-figure follow-on courses wondering which one is not a waste of money. Choosing the best certification after OSCP is harder than choosing OSCP was, because OSCP had no real competition and its successors all do.

The short answer: if you want to move into red teaming, take CRTO. If you want to stay in penetration testing and go deeper on evasion, take OSEP. If your budget is tight and Active Directory is your gap, take CRTP. If you want breadth and a report-writing workout without the OffSec price tag, take CPTS.

The longer answer depends on what your day job looks like, what your target job adverts ask for, and how much of your own money you are prepared to spend. This guide compares all four on cost, exam format, difficulty and hiring signal, so you can pick once and commit.

Why the Post-OSCP Decision Matters More Than OSCP Did

OSCP is a checkpoint. Almost every offensive security job advert in 2026 lists it, which means passing it gets you into the pile but does not get you out of it. The certification you take next is the one that signals a direction, and that is what separates candidates at interview.

There is a second reason the decision matters more this year. On 1 April 2026, ISC2 cut its CISSP experience waiver list from roughly 50 certifications to 25, and OSCP, CEH and CISA were among those removed. If part of your long-term plan was using OSCP to shave a year off the CISSP experience requirement, that route has closed. We covered the fallout in detail in CISSP Experience Waiver Just Got Cut.

The practical effect is that your next certification has to earn its place on technical merit alone. It is no longer a stepping stone to a management credential.

Reality check: No certification after OSCP will get you hired on its own. Every one of the four below produces artefacts, whether that is a report, a set of custom payloads or a detection-aware attack chain. The artefacts are what you talk about at interview. The badge is just proof you produced them.

The Four Realistic Options, Compared

Here is the comparison at a glance. Prices are list prices at the time of writing and change regularly, so always confirm on the vendor's own site before you buy.

OSEP (PEN-300)CRTOCRTPCPTS
VendorOffSecZero-Point SecurityAltered SecurityHack The Box
FocusEvasion, antivirus bypass, advanced ADC2 tradecraft, OPSEC, red team operationsActive Directory attack fundamentalsFull penetration testing lifecycle
Indicative costSold via Learn One, around $2,749 per year£399 including course and examFrom $249 with 30 days of lab accessAround $490 for a standalone exam voucher
Exam length47 hours 45 minutes, plus 24 hours to report24 hours of lab time, usable across 7 days24 hours hands-on10 days practical, plus 10 days to report
Report requiredYesNoYesYes, commercial grade
Pass condition100 points, or access to the stated objective85 per cent, half objectives and half OPSECCommand execution on all 5 targetsAt least 12 of 14 flags
Retake costSecond attempt included in Learn OneAdditional exam voucher$99Additional voucher
Best forPentesters who keep getting caught by EDRAnyone moving into red team operationsBudget-conscious AD specialisationConsultants who need report practice

OSEP: The Evasion Specialist

OSEP, delivered through the PEN-300 course, is the certification for penetration testers whose payloads keep dying on modern endpoint protection. It covers antivirus evasion, application whitelisting bypass, phishing, and advanced Active Directory attacks, and it does so with far more depth on payload construction than OSCP ever attempts.

The exam format

The OSEP exam gives you 47 hours and 45 minutes to complete the challenge, followed by a further 24 hours to submit documentation. You pass by obtaining 100 points, or by achieving access to the objective described in your exam assignment.

That is a genuinely brutal window. Unlike CRTO, you cannot pause it and come back tomorrow. Plan sleep into your 48 hours the way you did for OSCP, because people fail OSEP on fatigue as often as on technique.

Cost and the OSCE3 question

OffSec no longer sells PEN-300 as a standalone course and exam. It comes through the Learn One subscription, which is around $2,749 per year for an individual and includes one primary course, a year of labs, and two exam attempts for that course.

OSEP is also one third of OSCE3, the composite credential awarded for holding OSWE (web exploitation, WEB-300), OSEP (evasion and Active Directory, PEN-300) and OSED (Windows exploit development, EXP-301) together. If OSCE3 is your five-year goal, OSEP is the sensible first of the three because it builds most directly on OSCP.

Who should take it

Take OSEP if you are already doing internal penetration tests professionally and your bottleneck is getting a foothold to survive. It is a poor first choice if you have never worked a real engagement, because the course assumes you already understand why evasion matters commercially.

CRTO: The Red Team Operations Choice

CRTO from Zero-Point Security has quietly become the certification that red team job adverts name most often after OSCP, and it is the best value for money on this list by a wide margin.

The course and exam together cost £399, which buys you the Red Team Ops course material and the exam attempt. That is roughly a seventh of the OffSec route for content that maps more directly to what a red team consultant actually does day to day.

The exam format changed in 2026

The CRTO exam now gives you 24 hours of lab time that you can pause and resume within a 7-day window. There is no report to write and no proctoring.

Scoring is where CRTO differs from everything else on this list. The full score is 100 per cent, split evenly: 50 per cent for achieving the exam objective and 50 per cent for OPSEC points. The pass mark is 85 per cent.

Exam Tip: The CRTO pass mark of 85 per cent means you can complete every objective and still fail. If you get detected too often, the OPSEC half of your score sinks you. Practise thinking about what your actions look like from the defender's console, not just whether they worked.

That scoring model is the whole point of the certification. CRTO is not testing whether you can compromise the domain, it is testing whether you can do it quietly. That is exactly the distinction hiring managers use to separate a penetration tester from a red team operator.

The follow-on

Zero-Point Security also offers Red Team Ops II, which awards CRTL and covers hardened command and control, EDR-aware execution and evasive tradecraft. Zero-Point recommends completing the original CRTO course before attempting it. Treat CRTL as a second-year goal rather than an alternative to CRTO.

CRTP: The Budget Active Directory Route

CRTP from Altered Security is the cheapest meaningful certification on this list and the fastest to complete. It focuses tightly on Active Directory attacks in a fully patched enterprise environment with multiple domains and forests.

The on-demand option starts at $249 with 30 days of lab access, and there is an instructor-led bootcamp option at $299 with the same lab window. You can buy 60 or 90 days of lab access instead if you are studying around a full-time job.

The exam format

The CRTP exam is 24 hours of hands-on work against 5 target servers plus a foothold student machine. You pass by achieving operating system level command execution on all 5 targets. A retake costs $99, which is the most forgiving retake price of any certification here.

Who should take it

Take CRTP if Active Directory was the part of OSCP that hurt most and you want to fix that gap for under $300. It is not a red team certification in the way CRTO is, because there is no OPSEC scoring and no C2 tradecraft component, so do not expect it to carry the same weight on a red team application.

Many people take CRTP first and CRTO second, and that sequence works well. CRTP teaches you the attack paths and CRTO teaches you how to walk them without setting off alarms. Altered Security's CRTE is the natural step up within the same family if you want to stay in that ecosystem.

CPTS: Breadth and Report Discipline

Hack The Box's CPTS is the odd one out here because it is not a step up in specialisation, it is a step sideways into professional consulting practice. It covers the complete penetration testing lifecycle: external reconnaissance, internal pivoting, Active Directory exploitation, web application attacks, privilege escalation and commercial-grade reporting.

The exam format

CPTS gives you 10 days to work through a realistic multi-host environment, then another 10 days to submit your report. You need to capture at least 12 of 14 flags across roughly 8 Linux and Windows machines in a simulated enterprise environment that includes Active Directory.

The exam voucher is around $490 standalone, and HTB expects you to complete 100 per cent of the Academy Penetration Tester job-role path before you sit it.

The report is the real exam. Plenty of candidates capture the flags and still fail because the deliverable does not read like something a client would pay for. If report writing is your weakness, and it is most people's weakness, CPTS fixes it more directly than anything else on this list.

We have a full study plan for it in How to Pass the HTB CPTS Exam in 2026.

How to Choose the Best Certification After OSCP

Work through these in order. The first one that matches your situation is your answer.

  1. Your payloads keep getting caught on real engagements. Take OSEP. This is the only certification here built specifically around defeating modern endpoint protection.
  2. You want a red team job title within 18 months. Take CRTO. The OPSEC scoring model is the closest match to how red team work is assessed, and at £399 it is the lowest-risk bet on this list.
  3. Active Directory is your weak spot and money is tight. Take CRTP. Under $300, 24 hours, and a $99 retake if it goes badly.
  4. You are moving into consultancy and your reports are weak. Take CPTS. Twenty days of exam and reporting time will teach you more about deliverables than any course module.
  5. None of the above feels urgent. Do not buy anything yet. Pull ten job adverts for the role you want, count which certifications appear under "preferred", and let that decide. This is dull advice and it is also the correct advice.

A note on stacking certifications

The most common mistake after OSCP is collecting the next three badges as fast as possible. Hiring managers read a stack of four offensive certifications earned in twelve months as evidence of exam technique, not operational experience.

One follow-on certification, plus a genuine engagement or a public write-up you can talk through, beats three certifications with nothing behind them. Pick one track and go deep.

What About PNPT and the Cheaper Alternatives?

PNPT from TCM Security sits below OSCP in difficulty rather than above it, so it is rarely the right choice as a follow-on unless you specifically want practice with the live debrief format, which is genuinely useful interview preparation. Our PNPT study plan covers what that involves.

GIAC's GXPN is technically comparable to OSEP but costs considerably more once you factor in SANS training, and it makes sense mainly if an employer is paying and you want the SANS name on your record.

If you are still weighing whether to sit OSCP or OSCP+ in the first place, our breakdown of what changed with OSCP+ covers the bonus points, Active Directory changes and renewal rules, and our 12-week OSCP study plan will get you there.

Frequently Asked Questions

Is OSEP harder than OSCP? Yes, substantially. OSEP assumes you already have OSCP-level skills and adds evasion, payload development and multi-domain Active Directory work on top. The exam window is also longer and less forgiving, at 47 hours 45 minutes plus 24 hours for documentation.

Can I skip OSCP and go straight to CRTO? Technically yes, there are no formal prerequisites. In practice you will struggle, because CRTO assumes you can already move through a network without hand-holding. If you have equivalent professional experience it is defensible, otherwise take OSCP first.

Which certification after OSCP pays best? Red team operator roles generally sit above penetration tester roles on salary, which favours CRTO. But the certification does not create the salary, the role does, and you need engagement experience to land the role regardless of which badge you hold.

Do these certifications expire? Renewal rules differ by vendor and change frequently, so check the vendor's current policy before buying. OffSec has been steadily moving its credentials towards a renewal model, so do not assume a lifetime certification.

Ready to Start Practising?

Whichever route you pick, the gap between passing OSCP and passing the next exam is closed with reps, not reading. CertCrush gives you structured practice questions and exam-day simulations across the offensive security track, so you walk into the lab knowing the material cold instead of hoping it surfaces under pressure.

Create a free CertCrush account and start practising today, or browse the full course catalogue to see what is covered for your next certification.

OSCPOSEPCRTOCRTPred teampenetration testingoffensive securitycareer advice
Tom Ashford

Written by

Tom Ashford · Security Certifications Lead

Tom spent over a decade in security operations and consulting before turning to full-time exam-prep writing. He covers the big security certifications — CISSP, CISM, CISA, Security+ and the rest of the alphabet — with a soft spot for the questions everyone gets wrong. His rule for every article: if it doesn’t help you score marks, it doesn’t go in.

All articles by Tom

Want a OSCP practice course?

We don’t cover this exam yet — we build the most-requested courses first. One click tells us you want it.

Practising for something nearby?

Try real exam-style questions free — no account needed, full explanations included.