OSEPOffensive Security Experienced Penetration Tester
Created per CertMap methodology · About the editorial team →

▾ Jump to …4 sections
Overview
What is OSEP?
The OffSec Experienced Penetration Tester (OSEP) is based on the PEN-300 course and addresses advanced techniques around antivirus evasion, Active Directory attacks, and living-off-the-land methods. The fully practical 48-hour exam (47:45 hrs exam + 24 hrs report) in a simulated enterprise environment is the key difference from knowledge-based certifications–it tests real attack capabilities. OSEP is considered credible proof of high-level offensive competence in red team circles, but requires solid OSCP knowledge. Together with OSED and OSWE, OSEP forms the OSCE³ trio.
Suitable for
Quick facts
Key details
Cost, prerequisites, exam & renewal
Prerequisites
No formal prerequisites. PEN-300 course recommended. OSCP-level knowledge required.
Exam format
Practical: 47 hours 45 min. hands-on exam (evasion, AD attacks, advanced exploitation) + report. Proctored.
Renewal & maintenance
Valid indefinitely. No renewal required.
Classification
CertMap score and matching roles
Rating
Matching NICE roles
More certifications
More certifications
From OffSec
OSAI+OffSec AI Security ProfessionalOSCC-SECOffSec CyberCore Certified - Security EssentialsOSCC-SJDOffSec CyberCore Certified - Secure Java Development EssentialsOSCPOffensive Security Certified ProfessionalOSCP+OffSecOSIROffSec Incident ResponderOSTHOffSec Threat HunterIn Pentesting / Red Team
CEHEC-CouncilGPENGIACOSCPOffSecOSCP+OffSecPECB LEHPECBPECB LPTPPECBPenTest+CompTIAThis page follows CertMap methodology: editorial content is curated by hand. Score, costs and NICE mapping are aggregated from official provider documents. Score methodology → · TCO methodology →
Transparency: CertMap is operated by Daniel Thomas Heessel, who is also managing director of Threat‑Informed, a company specialising in Threat‑Informed Defense. CertMap currently receives no commissions from certification providers, no affiliate links, no sponsored placements. Podcast and interview guests are not paid for appearances and receive no affiliate commissions.
From the knowledge base
View all articles →CISSP or CISM? Two Careers, One Decision
Both require five years of experience, both cost roughly the same at first glance. Yet CISSP and CISM lead to different professions. The comparison with the numbers that course providers don't show.
CISM or CISA? Two ISACA paths, one directional decision
Both come from ISACA, both require five years of experience, and both cost almost the same. The difference is not the price but the role: managing or auditing. The comparison with the numbers and the role mapping.
CC or Security+? The Free Entry Point and the Job-Market Classic
Both are entry-level certifications with no admission barrier, both cover the fundamentals of cybersecurity, and yet they stand for different strategies: one as a low-threshold, temporarily free start, the other as an established credential with weight in the job market. The comparison with the numbers and the opposing cost logic.

1:1 with the CISO
Need the full picture for your case?
Personal strategy instead of weeks of self-research. Vendor-independent, with auditable recommendations and transparent sources.