If you are asking what is cpts certification, the short answer is that CPTS stands for HTB Certified Penetration Testing Specialist, Hack The Box’s intermediate, heavily practical credential that proves you can plan, execute, and report a full-scope ethical hack against an enterprise-like environment. It is not a multiple-choice exam. You earn it by working through HTB Academy’s Penetration Tester job-role path and then passing a 10-day hands-on assessment that ends with a commercial-grade penetration test report. That combination is what separates CPTS from theory-first certificates and what makes it attractive to people who want proof of real offensive capability.
Table of contents
What CPTS validates and how it is issued
CPTS is issued by Hack The Box and positioned as an intermediate-level, practical penetration testing qualification. Its purpose is narrow and useful: it confirms you can move beyond single-CVE exploits into full attack chains, combining multiple weaknesses to demonstrate realistic business impact, and then translate that work into a professional report.
HTB describes CPTS as a highly hands-on certification that assesses skills rather than quiz knowledge. Holders are expected to show competency across the ethical hacking and penetration testing lifecycle, covering both technical execution and risk communication. The curriculum and exam together span:
- Penetration testing processes and methodology
- Information gathering and reconnaissance
- Attacking Linux and Windows hosts
- Active Directory penetration testing
- Web application penetration testing
- Manual and automated exploitation
- Vulnerability assessment, pivoting, and lateral movement
- Post-exploitation enumeration and privilege escalation
- Vulnerability and risk communication through formal reporting
That breadth is deliberate. A credential grounded in practical engagements is more relevant for aspiring penetration testers, red teamers, and security consultants than an exam built around isolated facts. If you want a concrete look at how the exam plays out end to end, our CPTS exam writeup and support materials break down the workflow, common blockers, and reporting expectations so your preparation targets the right skills.
The HTB Academy path behind CPTS
You cannot simply sit the CPTS exam on demand. HTB ties the certification to a structured training path inside HTB Academy, and eligibility depends on it. To qualify, you enroll in the Penetration Tester job-role path and complete all included modules to 100%.
HTB indicates this path is composed of 28 modules, each with labs that mirror realistic penetration testing tasks. The path moves through reconnaissance, service enumeration, exploitation, post-exploitation, privilege escalation, and reporting in a sequence that closely prepares you for the exam environment. Only after finishing the job-role path do you gain access to purchase and use a CPTS exam voucher.
That design makes CPTS two things at once: a structured learning journey and a capstone exam that proves you can apply the learning from start to finish. The gating requirement is not busywork. It guarantees that every candidate has been exposed to HTB’s recommended methodology, tools, and report structure before entering the exam. For time-constrained professionals who need to compress that ramp-up, mentor-backed resources and our CPTS exam support offering can shorten the path while you still build practical skill and methodology awareness.
How the CPTS exam works
HTB describes the CPTS exam as a 10-day, highly hands-on assessment in which you carry out a simulated penetration test against an enterprise-like network. During that window you connect to a black-box environment that behaves like a small corporate infrastructure, with multiple Linux and Windows hosts and several web applications.
Independent reviews and community guidance report consistent characteristics of the current format:
| Exam element | What to expect |
|---|---|
| Duration | 10-day practical window |
| Environment | Enterprise-like network, approximately eight Windows and Linux machines |
| Flags | 14 flags distributed across the environment |
| Scoring | Points-based, 100 total points |
| Reported pass threshold | Around 85 points, roughly 12 of 14 flags, plus an accepted report |
The exam is effectively a large, narrative-style CTF that mimics a corporate network, but it demands full penetration testing methodology rather than random flag hunting. Getting shells is only half the job. HTB’s official guidance emphasizes that you must produce a commercial-grade penetration test report following the structure taught in the Academy modules. After the exam period, you upload the report, and an HTB instructor verifies both that you reached the minimum points and that the report meets defined quality standards before awarding the certification.
HTB notes a review timeframe of up to 20 business days for results, during which technical findings and reporting quality are evaluated together. That is a meaningful detail: a strong technical score with a weak report can still cost you the pass. If you want a ready-made reporting and enumeration checklist plus mentor feedback on attack paths, explore our CPTS exam writeup and support to move faster without losing focus on the exam’s practical goals.
What CPTS actually tests
Understanding the mechanisms behind CPTS helps you judge whether it matches your strengths.
End-to-end methodology. The exam expects the full pentest lifecycle: interpreting the engagement letter, scoping, reconnaissance, exploitation, post-exploitation, and reporting. It rewards candidates who think in attack paths and kill chains rather than isolated vulnerabilities.
Breadth of technical coverage. Official overviews show CPTS examining Windows and Linux exploitation, Active Directory attacks, web application testing with manual and automated techniques, pivoting, privilege escalation, and enumeration. That range is a strong indicator you can handle varied consulting environments.
A realistic, connected environment. Reviews describe the lab as a coherent mini-enterprise: hosts share context, services interrelate, and credentials can be reused or pivoted. This structure tests your ability to chain findings, not to solve disconnected puzzles.
Scored flags plus strict reporting. You earn points by capturing flags, but the final decision hinges on both your score and report quality. Missing critical details, screenshots, or remediation guidance can jeopardize your result even when you hit the minimum technical score.
Mandatory Academy preparation. The 100% completion requirement ensures every candidate has seen HTB’s methodology, tooling, and report format before the exam. For candidates who lack time to reverse-engineer all of this from scratch, our study materials and mentor feedback cover exam-style workflows, common pitfalls, and reporting expectations so limited practice hours go further.
Is CPTS the right move for you now
The real decision behind what is cpts certification and is it for me comes down to skill level, time, and career direction. Weigh these criteria before you commit a voucher.
- Current technical depth. CPTS assumes comfort with Linux and Windows, basic scripting, network fundamentals, and introductory experience with tools like Nmap, Burp, and common exploitation frameworks. If those are unfamiliar, invest more time in Academy modules first.
- Time for a 10-day exam. The window is long enough for methodical work but demanding alongside a full-time job or family obligations. You need focused blocks for reconnaissance, exploitation, note-taking, and report writing.
- Comfort with a structured path. Because the Penetration Tester job-role path is mandatory, CPTS suits candidates who accept a vendor-defined curriculum rather than fully ad hoc learning.
- Career alignment. If your work or ambition involves hands-on penetration testing, red teaming, or offensive consulting, CPTS maps directly onto those responsibilities. For purely defensive or governance roles, it is less directly applicable.
- Reporting comfort. Professional reporting is a core requirement. CPTS favors people who can document findings clearly, with risk ratings and remediation guidance. Weak reporting can be the deciding factor.
CPTS is well aligned with aspiring penetration testers preparing for OffSec-style certifications, working IT and security professionals who want proof of hands-on offensive capability, and ethical hackers moving from CTF-only experience into client-facing engagements. If your goal is to own an internal Active Directory environment, pivot across segments, and then explain the business impact to stakeholders in a concise report, CPTS is built to reflect that skill set.
Many professionals also weigh CPTS against paths like the OSCP certification overview or start with a lighter credential such as the eJPT exam writeup to build fundamentals first. If you meet the technical baseline but lack time for exhaustive Academy study, combining HTB’s official path with our CPTS exam support and report templates is an efficient way to reach exam readiness on limited hours and move from learning to passing.
Frequently asked questions
What is CPTS certification in simple terms?
CPTS is Hack The Box’s hands-on penetration testing certification that proves you can compromise and document an enterprise-like environment using professional methodology and reporting, rather than answering theory questions.
How long is the CPTS exam?
HTB specifies a 10-day practical exam window during which you conduct the entire engagement and produce your report.
How is CPTS scored?
Community reviews and exam templates describe a 100-point system with 14 flags, where candidates typically need at least 12 flags (around 85 points) and an accepted report to pass.
What do I need before I can attempt CPTS?
You must complete the Penetration Tester job-role path on HTB Academy, finishing all required modules to 100%, and then acquire an exam voucher.
Is CPTS suitable for beginners?
CPTS is labeled intermediate. Motivated beginners can reach it through HTB Academy, but prior exposure to Linux, Windows, networking, and basic scripting makes both the path and the exam more manageable.
