You passed OSCP. The screenshot is on LinkedIn, the adrenaline has worn off, and now you are staring at a list of four-figure follow-on courses wondering which one is not a waste of money. Choosing the best certification after OSCP is harder than choosing OSCP was, because OSCP had no real competition and its successors all do.
The short answer: if you want to move into red teaming, take CRTO. If you want to stay in penetration testing and go deeper on evasion, take OSEP. If your budget is tight and Active Directory is your gap, take CRTP. If you want breadth and a report-writing workout without the OffSec price tag, take CPTS.
The longer answer depends on what your day job looks like, what your target job adverts ask for, and how much of your own money you are prepared to spend. This guide compares all four on cost, exam format, difficulty and hiring signal, so you can pick once and commit.
Why the Post-OSCP Decision Matters More Than OSCP Did
OSCP is a checkpoint. Almost every offensive security job advert in 2026 lists it, which means passing it gets you into the pile but does not get you out of it. The certification you take next is the one that signals a direction, and that is what separates candidates at interview.
There is a second reason the decision matters more this year. On 1 April 2026, ISC2 cut its CISSP experience waiver list from roughly 50 certifications to 25, and OSCP, CEH and CISA were among those removed. If part of your long-term plan was using OSCP to shave a year off the CISSP experience requirement, that route has closed. We covered the fallout in detail in CISSP Experience Waiver Just Got Cut.
The practical effect is that your next certification has to earn its place on technical merit alone. It is no longer a stepping stone to a management credential.
Reality check: No certification after OSCP will get you hired on its own. Every one of the four below produces artefacts, whether that is a report, a set of custom payloads or a detection-aware attack chain. The artefacts are what you talk about at interview. The badge is just proof you produced them.
The Four Realistic Options, Compared
Here is the comparison at a glance. Prices are list prices at the time of writing and change regularly, so always confirm on the vendor's own site before you buy.
| OSEP (PEN-300) | CRTO | CRTP | CPTS | |
|---|---|---|---|---|
| Vendor | OffSec | Zero-Point Security | Altered Security | Hack The Box |
| Focus | Evasion, antivirus bypass, advanced AD | C2 tradecraft, OPSEC, red team operations | Active Directory attack fundamentals | Full penetration testing lifecycle |
| Indicative cost | Sold via Learn One, around $2,749 per year | £399 including course and exam | From $249 with 30 days of lab access | Around $490 for a standalone exam voucher |
| Exam length | 47 hours 45 minutes, plus 24 hours to report | 24 hours of lab time, usable across 7 days | 24 hours hands-on | 10 days practical, plus 10 days to report |
| Report required | Yes | No | Yes | Yes, commercial grade |
| Pass condition | 100 points, or access to the stated objective | 85 per cent, half objectives and half OPSEC | Command execution on all 5 targets | At least 12 of 14 flags |
| Retake cost | Second attempt included in Learn One | Additional exam voucher | $99 | Additional voucher |
| Best for | Pentesters who keep getting caught by EDR | Anyone moving into red team operations | Budget-conscious AD specialisation | Consultants who need report practice |
OSEP: The Evasion Specialist
OSEP, delivered through the PEN-300 course, is the certification for penetration testers whose payloads keep dying on modern endpoint protection. It covers antivirus evasion, application whitelisting bypass, phishing, and advanced Active Directory attacks, and it does so with far more depth on payload construction than OSCP ever attempts.
The exam format
The OSEP exam gives you 47 hours and 45 minutes to complete the challenge, followed by a further 24 hours to submit documentation. You pass by obtaining 100 points, or by achieving access to the objective described in your exam assignment.
That is a genuinely brutal window. Unlike CRTO, you cannot pause it and come back tomorrow. Plan sleep into your 48 hours the way you did for OSCP, because people fail OSEP on fatigue as often as on technique.
Cost and the OSCE3 question
OffSec no longer sells PEN-300 as a standalone course and exam. It comes through the Learn One subscription, which is around $2,749 per year for an individual and includes one primary course, a year of labs, and two exam attempts for that course.
OSEP is also one third of OSCE3, the composite credential awarded for holding OSWE (web exploitation, WEB-300), OSEP (evasion and Active Directory, PEN-300) and OSED (Windows exploit development, EXP-301) together. If OSCE3 is your five-year goal, OSEP is the sensible first of the three because it builds most directly on OSCP.
Who should take it
Take OSEP if you are already doing internal penetration tests professionally and your bottleneck is getting a foothold to survive. It is a poor first choice if you have never worked a real engagement, because the course assumes you already understand why evasion matters commercially.
CRTO: The Red Team Operations Choice
CRTO from Zero-Point Security has quietly become the certification that red team job adverts name most often after OSCP, and it is the best value for money on this list by a wide margin.
The course and exam together cost £399, which buys you the Red Team Ops course material and the exam attempt. That is roughly a seventh of the OffSec route for content that maps more directly to what a red team consultant actually does day to day.
The exam format changed in 2026
The CRTO exam now gives you 24 hours of lab time that you can pause and resume within a 7-day window. There is no report to write and no proctoring.
Scoring is where CRTO differs from everything else on this list. The full score is 100 per cent, split evenly: 50 per cent for achieving the exam objective and 50 per cent for OPSEC points. The pass mark is 85 per cent.
Exam Tip: The CRTO pass mark of 85 per cent means you can complete every objective and still fail. If you get detected too often, the OPSEC half of your score sinks you. Practise thinking about what your actions look like from the defender's console, not just whether they worked.
That scoring model is the whole point of the certification. CRTO is not testing whether you can compromise the domain, it is testing whether you can do it quietly. That is exactly the distinction hiring managers use to separate a penetration tester from a red team operator.
The follow-on
Zero-Point Security also offers Red Team Ops II, which awards CRTL and covers hardened command and control, EDR-aware execution and evasive tradecraft. Zero-Point recommends completing the original CRTO course before attempting it. Treat CRTL as a second-year goal rather than an alternative to CRTO.
CRTP: The Budget Active Directory Route
CRTP from Altered Security is the cheapest meaningful certification on this list and the fastest to complete. It focuses tightly on Active Directory attacks in a fully patched enterprise environment with multiple domains and forests.
The on-demand option starts at $249 with 30 days of lab access, and there is an instructor-led bootcamp option at $299 with the same lab window. You can buy 60 or 90 days of lab access instead if you are studying around a full-time job.
The exam format
The CRTP exam is 24 hours of hands-on work against 5 target servers plus a foothold student machine. You pass by achieving operating system level command execution on all 5 targets. A retake costs $99, which is the most forgiving retake price of any certification here.
Who should take it
Take CRTP if Active Directory was the part of OSCP that hurt most and you want to fix that gap for under $300. It is not a red team certification in the way CRTO is, because there is no OPSEC scoring and no C2 tradecraft component, so do not expect it to carry the same weight on a red team application.
Many people take CRTP first and CRTO second, and that sequence works well. CRTP teaches you the attack paths and CRTO teaches you how to walk them without setting off alarms. Altered Security's CRTE is the natural step up within the same family if you want to stay in that ecosystem.
CPTS: Breadth and Report Discipline
Hack The Box's CPTS is the odd one out here because it is not a step up in specialisation, it is a step sideways into professional consulting practice. It covers the complete penetration testing lifecycle: external reconnaissance, internal pivoting, Active Directory exploitation, web application attacks, privilege escalation and commercial-grade reporting.
The exam format
CPTS gives you 10 days to work through a realistic multi-host environment, then another 10 days to submit your report. You need to capture at least 12 of 14 flags across roughly 8 Linux and Windows machines in a simulated enterprise environment that includes Active Directory.
The exam voucher is around $490 standalone, and HTB expects you to complete 100 per cent of the Academy Penetration Tester job-role path before you sit it.
The report is the real exam. Plenty of candidates capture the flags and still fail because the deliverable does not read like something a client would pay for. If report writing is your weakness, and it is most people's weakness, CPTS fixes it more directly than anything else on this list.
We have a full study plan for it in How to Pass the HTB CPTS Exam in 2026.
How to Choose the Best Certification After OSCP
Work through these in order. The first one that matches your situation is your answer.
- Your payloads keep getting caught on real engagements. Take OSEP. This is the only certification here built specifically around defeating modern endpoint protection.
- You want a red team job title within 18 months. Take CRTO. The OPSEC scoring model is the closest match to how red team work is assessed, and at £399 it is the lowest-risk bet on this list.
- Active Directory is your weak spot and money is tight. Take CRTP. Under $300, 24 hours, and a $99 retake if it goes badly.
- You are moving into consultancy and your reports are weak. Take CPTS. Twenty days of exam and reporting time will teach you more about deliverables than any course module.
- None of the above feels urgent. Do not buy anything yet. Pull ten job adverts for the role you want, count which certifications appear under "preferred", and let that decide. This is dull advice and it is also the correct advice.
A note on stacking certifications
The most common mistake after OSCP is collecting the next three badges as fast as possible. Hiring managers read a stack of four offensive certifications earned in twelve months as evidence of exam technique, not operational experience.
One follow-on certification, plus a genuine engagement or a public write-up you can talk through, beats three certifications with nothing behind them. Pick one track and go deep.
What About PNPT and the Cheaper Alternatives?
PNPT from TCM Security sits below OSCP in difficulty rather than above it, so it is rarely the right choice as a follow-on unless you specifically want practice with the live debrief format, which is genuinely useful interview preparation. Our PNPT study plan covers what that involves.
GIAC's GXPN is technically comparable to OSEP but costs considerably more once you factor in SANS training, and it makes sense mainly if an employer is paying and you want the SANS name on your record.
If you are still weighing whether to sit OSCP or OSCP+ in the first place, our breakdown of what changed with OSCP+ covers the bonus points, Active Directory changes and renewal rules, and our 12-week OSCP study plan will get you there.
Frequently Asked Questions
Is OSEP harder than OSCP? Yes, substantially. OSEP assumes you already have OSCP-level skills and adds evasion, payload development and multi-domain Active Directory work on top. The exam window is also longer and less forgiving, at 47 hours 45 minutes plus 24 hours for documentation.
Can I skip OSCP and go straight to CRTO? Technically yes, there are no formal prerequisites. In practice you will struggle, because CRTO assumes you can already move through a network without hand-holding. If you have equivalent professional experience it is defensible, otherwise take OSCP first.
Which certification after OSCP pays best? Red team operator roles generally sit above penetration tester roles on salary, which favours CRTO. But the certification does not create the salary, the role does, and you need engagement experience to land the role regardless of which badge you hold.
Do these certifications expire? Renewal rules differ by vendor and change frequently, so check the vendor's current policy before buying. OffSec has been steadily moving its credentials towards a renewal model, so do not assume a lifetime certification.
Ready to Start Practising?
Whichever route you pick, the gap between passing OSCP and passing the next exam is closed with reps, not reading. CertCrush gives you structured practice questions and exam-day simulations across the offensive security track, so you walk into the lab knowing the material cold instead of hoping it surfaces under pressure.
Create a free CertCrush account and start practising today, or browse the full course catalogue to see what is covered for your next certification.
