Short answer. Start with OSWA (OffSec) or eWPT (INE) to build a black-box web methodology you can repeat under a clock. Add BSCP if Burp Suite is central to your work. Take OSWE or CWEE only when reading unfamiliar source code no longer feels like reading random lines. CWES is the modern hands-on alternative for candidates who want a practical web exam without the code-review emphasis. If web is only part of your job, CPTS or PNPT will cover you and you should read the penetration testing certifications guide instead.
The rest of this page compares the six web security certifications by what the exam actually asks of you, tells you which one to take first from three different starting points, and explains how to prepare for a practical web exam without collecting courses.
- The six web security certifications compared
- OSWA: the cleanest first practical web exam
- eWPT: structured methodology, INE style
- BSCP: for people who already live in Burp Suite
- CWES and CWEE: Hack The Box’s practical web route
- OSWE: the advanced web exploitation credential
- Which one to take first, by starting point
- What employers actually read into these
- How to prepare for a practical web exam
- Where our material fits
- Frequently asked questions
The six web security certifications compared
| Certification | Vendor | Exam | Emphasis | Level |
|---|---|---|---|---|
| OSWA | OffSec | 24-hour practical, report required | Black-box web testing, Burp workflow, common vulnerability classes | Entry to intermediate |
| eWPT | INE Security | Multi-day practical, report required | Methodology from recon to reporting | Intermediate |
| BSCP | PortSwigger | 4-hour practical, two applications, no report | Advanced manual exploitation inside Burp Suite | Intermediate to advanced |
| CWES | Hack The Box | Multi-day practical, report required | Modern web attacks, live applications, end-to-end chains | Intermediate to advanced |
| CWEE | Hack The Box | Multi-day practical, report required | Advanced exploitation with a white-box component | Advanced |
| OSWE | OffSec | Roughly 48-hour practical, report required | Source review and custom exploit chains | Advanced |
Two things separate these exams more than their difficulty labels. The first is whether you are given source code: OSWE and CWEE expect you to read it, the rest expect you to work black-box. The second is whether a report is graded: BSCP is the only one where it is not, which makes it a pure test of exploitation speed and everything else a test of exploitation plus communication.
OSWA: the cleanest first practical web exam
OffSec Web Assessor is the right first move if your web testing is fragmented. You may know SQL injection, cross-site scripting and directory fuzzing in isolation and still lack a process that turns them into an assessment. OSWA’s 24-hour exam gives you a set of applications to work black-box, no hints and no guided steps, and then a report to write, which is exactly the shape of a junior web engagement.
Its limitation is its value. It will not make you an application security specialist, and it is not meant to. Treat it as the foundation for BSCP or OSWE, and pair it with OSCP if you want a general pentesting role rather than a web-only one. Our OSWA page has the exam walkthrough and the finished report.
eWPT: structured methodology, INE style
eWPT rewards systematic testing rather than payload spraying. Expect information gathering, session handling, input validation, authentication weaknesses and file handling, and expect to explain business impact in a report at the end. It suits junior consultants who can find obvious bugs but need confidence explaining why a flaw exists and how to fix it.
The trade-off is recognition. eWPT does not carry the OffSec name, and in some hiring markets that matters. Strong technical output still matters more than initials, and eWPT teaches the habits that produce it. The advanced version, eWPTX, is INE’s advanced web exploitation exam. Material for both: eWPT and eWPTX.
BSCP: for people who already live in Burp Suite
The Burp Suite Certified Practitioner exam is not a broad pentesting assessment. It is four hours, two applications, and a concentrated test of whether you can find and chain sophisticated web vulnerabilities under time pressure. There is no report. You either exploit the applications in the window or you do not.
Prepare for it by working through the PortSwigger Web Security Academy labs until you can complete the practitioner and expert ones without looking up the intended path. If you cannot yet, wait. BSCP is strongest for bug bounty hunters, web-focused consultants and application security engineers who are already fluent in proxy history analysis, manual request manipulation and out-of-band techniques. Our BSCP page has the full writeups and lab notes.
CWES and CWEE: Hack The Box’s practical web route
CWES (Certified Web Exploitation Specialist) is HTB’s hands-on web exam: live applications, real servers, end-to-end attacks, and a professional report at the end. It sits between the entry exams and the code-intensive demands of OSWE, and it is the better choice than OSWA for candidates who want more scope, including APIs and authorization logic, without the OffSec name.
CWEE (Certified Web Exploitation Expert) is the advanced exam, and it is closer to OSWE in what it demands: deep understanding of vulnerability classes, a white-box component, and a grade that depends on clear, reproducible reporting as much as on exploitation. Take it when the CWES-level work is routine.
Both are on this site: CWES and CWEE.
OSWE: the advanced web exploitation credential
OSWE shifts the work from black-box testing to source-code analysis and custom exploitation. Over roughly 48 hours you are given applications with their code, and you are expected to trace data flow, find insecure assumptions, adapt or write an exploit, and document the whole chain in a report that a reviewer can reproduce.
This is not an exam to prepare for with a payload list. You need working fluency in at least one common web language and enough code-reading skill to follow an unfamiliar application without a map. The payoff is that OSWE signals you can find what scanners and checklists routinely miss. If it is your objective, make source review, exploit reproduction and clean evidence collection part of every lab session from now on. Our OSWE page has the Akount writeup, white-box review notes and the finished report.
Which one to take first, by starting point
You test web applications occasionally as part of general pentesting. Skip the dedicated web ladder for now. CPTS and PNPT both include enough web exploitation, and OSCP does too at a basic level. Come back to OSWA or BSCP when web becomes the majority of your work.
You want a web-focused role and have fundamentals but no methodology. OSWA or eWPT. Choose OSWA if the OffSec name matters in your market, eWPT if you want the more thorough reporting emphasis. Either will fix the gap that fails most first attempts: a missed parameter, an untested role, a hidden API route.
You already solve advanced web labs and read code comfortably. Go to BSCP if Burp is your daily tool and you want a fast, respected credential, or straight to OSWE or CWEE if you want the credential that proves source-level capability. Doing BSCP first is still worth it: it is short, and it sharpens exactly the manual skills OSWE assumes.
Do not choose on difficulty alone. A targeted intermediate exam that closes a real skill gap produces better near-term career results than an advanced exam attempted too early.
What employers actually read into these
Hiring managers use web certifications as a filter, not a verdict. OSWE and BSCP are the two that get recognised on sight for web-specialist roles. OSWA and eWPT show that you have a process. CWES and CWEE are read correctly by teams that know Hack The Box, which increasingly is most of them. In every case the interview will come down to whether you can explain a finding, reproduce it cleanly and recommend a fix. The certification gets the attention; that ability keeps the opportunity.
How to prepare for a practical web exam
Build a workflow you can repeat under exam conditions, and run it on every target.
- Map first, exploit second. Record hosts, directories, parameters, JavaScript endpoints, API routes, authentication states, roles, upload functions and unusual error messages before you test anything.
- Establish a two-user baseline. Most authorization flaws are invisible with one account. Test every function as a low-privilege user against a higher-privilege user’s data.
- Test hypotheses one at a time and keep the failed paths in your notes. Failed attempts prevent duplication and explain why a later payload worked.
- Capture evidence as you go: the request, the response, the payload, the role, the affected endpoint and the impact, at the moment you validate the issue. Reconstructing it at the end is where reports fall apart.
- Time-box rabbit holes. Decide in advance how long one suspected vulnerability gets before you move on and return later.
- Write findings while you test, in the format the exam grades. Our pentest report guide has the structure and a finding written out in full.
Exam-specific walkthroughs and a finished report in the expected format shorten the research cycle. They should show you the workflow and the level of evidence expected, not replace the work of validating each exploit yourself.
Where our material fits
For each web certification above we sell the full walkthrough of the exam targets and a ready-to-submit report in that vendor’s format, and for candidates who want to sit the exam themselves, remote support during the window. Delivery is by email within about thirty seconds of payment and there is no account to create.
- OSWA and OSWE from OffSec
- BSCP from PortSwigger
- CWES and CWEE from Hack The Box
- eWPT and eWPTX from INE Security
The proofs page shows real orders and the reviews those buyers left, including OSWA.
Frequently asked questions
Is OSWA enough to get a web application pentesting job?
Rarely on its own. It demonstrates a practical foundation, and alongside lab work and a clean portfolio it gets interviews. Dedicated web roles usually expect BSCP, CWEE or OSWE, or experience that substitutes for them.
Should I take eWPT or BSCP first?
eWPT first if you need broad assessment methodology and reporting practice. BSCP first only if you already solve advanced Web Security Academy labs without the solution and want a fast, recognised credential.
Is OSWE harder than OSCP?
They test different things. OSCP is broader across networks, operating systems, enumeration and privilege escalation. OSWE is narrower and much deeper in source review and web exploitation. Candidates with weak programming or code-reading skills find OSWE the harder of the two.
CWES or OSWA?
CWES for scope and modern application coverage, OSWA for the OffSec name and a shorter exam. Both are black-box exams with a graded report, so preparation for one transfers almost entirely to the other.
How long should I prepare?
A candidate with web fundamentals can be ready for OSWA, eWPT or CWES in a focused block of weeks. BSCP depends entirely on how many Academy labs you have already done. OSWE and CWEE take months of sustained code review and lab work for most people.
