PenTest+CompTIA PenTest+
Created per CertMap methodology · About the editorial team →

▾ Jump to …4 sections
Overview
What is PenTest+?
PenTest+ is CompTIA's vendor-neutral penetration testing certification and covers the full engagement lifecycle: scoping and legal groundwork, reconnaissance, vulnerability analysis, exploitation and client-facing reporting. Unlike pure lab certifications such as OSCP, it also examines the commercial and documentation side of a pentest, which makes it relevant for consultancies and internal testing teams. The exam combines multiple-choice with performance-based questions but does not replace a multi-hour practical proof of exploitation. Version PT0-003 has been current since 17 December 2024; the predecessor PT0-002 retired on 17 June 2025. Within the CompTIA stack it sits alongside CySA+ at the analyst level and shares its recertification load of 60 CEUs per three-year cycle.
Quick facts
Key details
Cost, prerequisites, exam & renewal
Cost over 5 years
Prerequisites
No formal prerequisites. Recommended: 3 to 4 years of experience in a penetration tester job role plus Network+ and Security+ or equivalent knowledge.
Exam format
Max. 90 questions (multiple-choice + performance-based), 165 minutes, proctored via Pearson VUE. Pass score: 750 on a scale of 100 to 900.
Renewal & maintenance
Valid for 3 years. Renewal through 60 CEUs or higher-level CompTIA cert (stacking) or re-exam.
Classification
CertMap score and matching roles
Rating
Matching NICE roles
No NICE roles assigned.
More certifications
More certifications
This page follows CertMap methodology: editorial content is curated by hand. Score, costs and NICE mapping are aggregated from official provider documents. Score methodology → · TCO methodology →
Transparency: CertMap is operated by Daniel Thomas Heessel, who is also managing director of Threat‑Informed, a company specialising in Threat‑Informed Defense. CertMap currently receives no commissions from certification providers, no affiliate links, no sponsored placements. Podcast and interview guests are not paid for appearances and receive no affiliate commissions.
From the knowledge base
View all articles →CISSP oder CISM? Zwei Karrieren, eine Entscheidung
Beide verlangen fünf Jahre Erfahrung, beide kosten auf den ersten Blick ähnlich viel. Trotzdem führen CISSP und CISM in verschiedene Berufe. Der Vergleich mit den Zahlen, die Kursanbieter nicht zeigen.
CISM oder CISA? Zwei ISACA-Wege, eine Richtungsentscheidung
Beide kommen von der ISACA, verlangen fünf Jahre Erfahrung und kosten fast dasselbe. Der Unterschied liegt nicht im Preis, sondern in der Rolle: steuern oder prüfen. Der Vergleich mit den Zahlen und der Rollen-Abbildung.
CC oder Security+? Der Gratis-Einstieg und der Arbeitsmarkt-Klassiker
Beide sind Einsteiger-Zertifikate ohne Zulassungshürde, beide decken die Grundlagen der Cybersicherheit ab, und trotzdem stehen sie für verschiedene Strategien: das eine als niedrigschwelliger, zeitweise kostenloser Start, das andere als etablierter Nachweis mit Gewicht im Arbeitsmarkt. Der Vergleich mit den Zahlen und der gegenläufigen Kostenlogik.

1:1 with the CISO
Need the full picture for your case?
Personal strategy instead of weeks of self-research. Vendor-independent, with auditable recommendations and transparent sources.