// CERTIFICATIONS

Penetration tester certifications: which ones mean something

A penetration tester certification is proof that a person passed an exam set by one of the issuers. The exams differ fundamentally in format, though: some require the candidate to actually break into a prepared environment, others are a multiple-choice test. For a client, that difference decides more than the acronym in the proposal itself, and you can tell it from what the candidate has to do during the exam.

// 01

What does a certification tell a client, and what does it not?

A certification is not a guarantee of quality. It’s proof that a person once passed an exam, not that they’ll deliver a good test for you. It says nothing about how they work under a deadline, how they write a report, or whether they’ll notice something nobody asked about.

It is useful all the same, in two ways. It narrows the field, because a vendor without a single hands-on exam on the team is a different case from one whose people got through an environment they had to actually break into. And it says what the qualification covers, which you can’t read from the company name or the length of the proposal.

It’s used badly when it’s counted. Ten acronyms in a proposal don’t mean a test ten times better: they can overlap, they can be ten years old, and they can belong to a person who won’t be on your engagement.

// 02

How do you tell that a real break-in stands behind a certification?

What decides is what the candidate does during the exam and what they hand in afterward. Both are usually in the issuer’s public exam description, and that says more than any ranking of certifications.

What the candidate does in the examHow long it takesWhat they hand inWhat the client learns from it
Picks an answer from several optionsTens of minutes to hoursNothing; the result is a scoreThat they know their way around the terms and procedures
Breaks into a prepared environmentHours to several daysEvidence from compromised systemsThat they can use the techniques, not just describe them
Breaks into a prepared environment and writes a deliverableSeveral days plus time for writingA report in the form it would go to a clientThat they can also do what the client ends up holding

The third row is the most valuable for a client and nobody talks about it in proposals. From a penetration test you don’t get a score or a list of captured systems; you get a report. An exam that requires and grades a report verifies exactly the part of the work you will eventually see.

A hands-on exam guarantees nothing either. Proof that someone once broke into a prepared environment over a weekend isn’t proof that they’ll find the same at your company. The exam environment is built to be breakable. Your network isn’t built that way.

Knowledge exams aren’t useless; they just measure something else. For roles that don’t run tests, meaning security management, compliance, and vendor oversight, breadth is more useful than the ability to break one system. The problem starts only where a knowledge certification is passed off as proof that someone can test.

// 03

Why can’t you tell from the certification’s description at first glance?

The acronym says nothing about the format, and neither does the word “certified” in it. One exam that ends with a submitted report has the word in its official name. Another that ends with submitting flags doesn’t.

It’s also misleading that industry usage and the issuer’s official form routinely diverge. With one issuer, the official exam name contains neither the word “certified” nor the acronym by which the certification is referred to in proposals. The acronym was coined by the industry, not the issuer.

The practical consequence is simple: look for the issuer’s exam description, not an interpretation of the acronym. The description is public and tells you what the candidate had to do.

// 04

What does each certification cover?

Certifications also differ in subject, and that difference gets lost in proposals entirely. One exam verifies testing of web applications, another networks and domain environments, another cloud accounts and permissions, another running a scenario-based operation, and the newest additions are exams on systems with AI and machine learning.

An exam on web applications says nothing about Active Directory, and vice versa. When you’re asking for an internal network test, a certification on applications is no use to you, however demanding it was. So ask about qualification for what you’re ordering, not qualification in general.

// 05

Does a mandatory course mean a weaker exam?

No, and it’s the most common snap judgment you’ll hear in this area.

A mandatory course says nothing by itself about the difficulty of the exam. There are demanding hands-on exams for which the issuer requires its own course and allows no other route, and there are tests that can be passed without any preparation from the issuer at all. With the widespread knowledge certifications, the course is often just one of two routes, the other being documented experience.

What tells you about the exam is what the candidate has to do during it, not how they got to it.

// 06

How long does a certification stay valid?

That depends on the issuer, and for a specific certification you’ll find it in their exam description. For a client, though, another date matters more: when the holder passed it. The field has moved on, so an exam from several years ago says less about today’s work than a recent one, even if the certificate itself never expired.

// 07

Company certification, or a person’s certification?

Proposals regularly mix these two things up, yet they are two different claims. ISO/IEC 27001 is a certification of an information security management system, meaning the company and its processes. It says nothing about whether a specific tester can break into your application.

A personal certification, on the other hand, is proof about a person and says nothing about how the vendor handles your data. Both make sense; they just answer different questions. What an auditor expects to see for the standard has its own entry: certification of the company, not the person.

// 08

What to ask a vendor instead of counting acronyms?

Acronyms are the weakest of the available clues. Three questions say more, and none of them requires you to know your way around certifications.

  • Who specifically will be on the engagement, and what qualification they have for what you’re ordering.
  • Which methodology the test will follow, and what exactly is in scope.
  • What the report looks like. Ask to see a real deliverable, not a slide from a presentation.

The last question is the most telling and the least asked. The report is the only thing you keep from the engagement, and the difference between vendors shows in it sooner than in certifications: whether a finding can be reproduced from its description and whether the remediation priority makes sense. We describe what a deliverable that shows real quality looks like with the service, and which methodology the test follows has its own entry.

The criterion from the second section measures us too, so we apply it to ourselves: the certifications we hold are all hands-on, two of them also require written work to be submitted and graded, and in one of those the report is in the form it would go to a client. Who actually runs our tests is listed on the team page. And if you’d like to look at a report before asking us anything, request a sample from our test infrastructure: there is no client in it, so we can send it to anyone.

// 09

Frequently asked questions

Not automatically. A certification documents that a person passed an exam, not that they’ll deliver a good test for you. Experience without certification exists and is common. What a certification does reveal is the exam format: whether the candidate had to actually break into an environment or picked an answer from several options. That is information the word “certified” alone doesn’t carry.

In a knowledge exam the candidate answers questions and the result is a score. In a hands-on exam they get access to a prepared environment and have to actually compromise it. Among hands-on exams there is a second difference: some end with submitting evidence from captured systems, others require a report in the form it would go to a client. The second format is the closest to what you would actually receive.

No, and it isn’t the same thing as a tester’s qualification. ISO/IEC 27001 is a certification of an information security management system, meaning the company and its processes, typically including how it handles your data. It says nothing about a specific person’s ability to break into your application. You can ask for both; each just answers a different question.

No. Certifications can overlap, they can be old, and above all they can belong to a person who won’t be on your engagement. More useful than the count is whether the person is qualified for what you’re ordering: an exam on web applications says nothing about Active Directory, and a cloud certification says nothing about an internal network.

Decree No. 409/2025 Coll. asks you to document who ran the test, not what acronym they hold. In the higher obligations regime it requires a record of when testing took place and which specific individuals performed it. What exactly is expected of whom, and which regime you fall under, are covered on our page on the NIS2 Directive (Directive (EU) 2022/2555) and Act No. 264/2025 Coll., on Cybersecurity (the Czech Cybersecurity Act).

From the issuer’s public exam description. Look for three things: what the candidate does during the exam, how long it takes, and what they hand in. If the answer is a multiple-choice test and a score, it’s a knowledge exam. If the answer is access to an environment and a submitted report, it’s the exam closest to a real engagement.

Related pages

Updated September 5, 2026.

// SAMPLE REPORT

Request a sample report from our test infrastructure

You can try the advice from the last section on us right away. We’ll send you a sample report from our test infrastructure, an environment we built ourselves. There is no client in it, so you don’t have to ask whose data you’re reading.