





Certifications explained
What does this mean for your project?
Not all certifications are equal. Hands-on exams — where you actually have to break in — carry more weight than theoretical tests. Here’s what each certification proves in practice.
| Certification | What it proves for your project |
|---|---|
| OSCP | Hands-on exam: 24 hours of live hacking into an isolated network. No multiple choice. Widely recognised as the industry standard — often set as a minimum requirement by enterprise clients and government bodies. |
| OSWE | Advanced web application security including source code analysis. Relevant for SaaS platforms, custom applications and API pentests where the tester needs to understand the code’s logic. |
| OSEP | Advanced network and infrastructure attacks: evasion, post-exploitation, Active Directory. Relevant if you want to test how far an attacker can get internally after an initial breach. |
| eWPT | Hands-on web pentest certification: OWASP Top 10, business logic vulnerabilities, API security. Complements OSCP for broad web coverage. |
| CEH | Widely recognised in procurements, tenders and RFP processes. Covers the full ethical hacking cycle — useful as a compliance requirement in quote processes. |
| Pentest+ | Infrastructure- and compliance-focused penetration testing in line with recognised standards. Relevant for NIS2, PCI DSS and ISO 27001 processes requiring standardised methodology. |
