OSEPOffensive Security Experienced Penetration Tester
Created per CertMap methodology · About the editorial team → · Official page ↗

▾ Jump to …4 sections
What is OSEP?
The OffSec Experienced Penetration Tester (OSEP) is based on the PEN-300 course and addresses advanced techniques around antivirus evasion, Active Directory attacks, and living-off-the-land methods. The fully practical 48-hour exam (47:45 hrs exam + 24 hrs report) in a simulated enterprise environment is the key difference from knowledge-based certifications–it tests real attack capabilities. OSEP is considered credible proof of high-level offensive competence in red team circles, but requires solid OSCP knowledge. Together with OSED and OSWE, OSEP forms the OSCE³ trio.
Suitable for
Quick facts
Cost, prerequisites, exam & renewal
Prerequisites
No formal prerequisites. PEN-300 course recommended. OSCP-level knowledge required.
Exam format
Practical: 47 hours 45 min. hands-on exam (evasion, AD attacks, advanced exploitation) + report. Proctored.
Renewal & maintenance
Valid indefinitely. No renewal required.
CertMap score and matching roles
Rating
Matching NICE roles
More certifications
From OffSec
OSAI+OffSec AI Security ProfessionalOSCC-SECOffSec CyberCore Certified - Security EssentialsOSCC-SJDOffSec CyberCore Certified - Secure Java Development EssentialsOSCE3Offensive Security Certified Expert 3OSCPOffensive Security Certified ProfessionalOSCP+OffSecIn Pentesting / Red Team
CEHEC Council Certified Ethical HackerCPENTEC Council Certified Penetration Testing ProfessionalECESEC Council Certified Encryption SpecialisteCPPTINE Security Certified Professional Penetration TestereJPTINE Security Junior Penetration TestereMAPTINE Security Mobile Application Penetration TesterFrom the knowledge base
View all articles →CISSP or CISM? Two Careers, One Decision
Both require five years of experience, both cost roughly the same at first glance. Yet CISSP and CISM lead to different professions. The comparison with the numbers that course providers don't show.
CISM or CISA? Two ISACA paths, one directional decision
Both come from ISACA, both require five years of experience, and both cost almost the same. The difference is not the price but the role: managing or auditing. The comparison with the numbers and the role mapping.
CC or Security+? The Free Entry Point and the Job-Market Classic
Both are entry-level certifications with no admission barrier, both cover the fundamentals of cybersecurity, and yet they stand for different strategies: one as a low-threshold, temporarily free start, the other as an established credential with weight in the job market. The comparison with the numbers and the opposing cost logic.