GetPentest

CREST, OSCP and pentest certifications

Certifications are the easiest thing to compare on a vendor page and one of the weaker signals available to you. They are worth reading correctly rather than ignoring, because the difference between a practical exam and a multiple-choice one tells you something real.

Last reviewed 2026-09-01Written by Jacob Masse, TrazTech Inc.

Two things matter and the rest is noise. Whether the certification was earned by passing a practical exam against live systems, which OSCP and the GIAC practical tracks are, and whether it is held by the firm or by the individual, which is what separates CREST from everything else. A redacted sample report tells you more than any acronym. If you are comparing three vendor pages at midnight, this is how to read them.

Practical The only exam format that evidences testing skill

Firm-level What makes CREST different, and UK and EU relevant

Named testers Ask which ones are on your engagement, not the company total

What each one actually is

Penetration testing certifications and how much weight to give them
CertificationHeld byFormatWeight
OSCPIndividualLong hands-on exam compromising live machines, plus a reportStrong. The common baseline for a working tester
OSWEIndividualHands-on, white box web exploitation from sourceStrong for application work specifically
OSEPIndividualHands-on, evasion and advanced network exploitationStrong for red team and mature internal work
GPEN, GWAPT, GXPNIndividualGIAC exams, with practical components in the higher tracksStrong. Expensive to hold, so more common at larger firms
PNPTIndividualHands-on network exam with a report and a debriefGood, and increasingly common at boutiques
CREST registered and certified titlesIndividual and the firmExaminations plus, at firm level, assessment of methodology, quality and data handlingStrong where your buyer is UK or EU, or a bid names it
CEHIndividualMultiple-choice knowledge exam. A separate practical version exists and is far less commonWeak on its own. Widely held because job postings ask for it
CISSPIndividualBroad security management examNot a testing credential. Fine on a leader, uninformative on a tester
ISO 27001 Lead AuditorIndividualAudit methodologyIrrelevant to whether somebody can test

Saying the quiet part about CEH

CEH is the most widely held certification in this list and the least informative about testing ability. The standard version is a multiple-choice knowledge exam, not a demonstration that somebody can compromise anything. Many excellent testers hold one because an employer or a government job posting required it, alongside an OSCP. The failure mode is a vendor page that leads with CEH and lists nothing practical, which usually means the practical qualifications are not there to list.

CREST, and why it is a different kind of thing

Every other entry in that table is a person's qualification. CREST also accredits the company, assessing methodology, quality processes, complaint handling and how client data is managed. That is why it appears in procurement documents: a buyer can require it of a supplier, which cannot sensibly be done with an individual certification.

It is the recognised mark for UK and EU buyers and appears in some Canadian public-sector and financial-services bids. It is uncommon among small Canadian firms: accreditation costs real money and the Canadian market has not demanded it. Its absence here says little. Its presence says the firm has been audited by somebody other than its own marketing department. If you sell into the UK or the EU, ask. If your customers are Canadian and American, do not filter on it, and see SaaS penetration testing in Canada for what those buyers do ask about.

How to use this on a call

  1. Ask which certifications the assigned testers hold, not what the company holds collectively. A firm with forty certifications across thirty staff tells you nothing about the two people on your engagement. This is question one on questions to ask a penetration testing vendor.
  2. Ask when they were earned. A practical certification from twelve years ago against systems that no longer exist is weaker evidence than one from last year, though continuous client work counts for more than either.
  3. Weigh the sample report higher. A redacted report showing an authorisation failure found by reasoning about the application beats every acronym on this page.
  4. Ignore counts. "Our team holds over 60 certifications" is a sentence with no information in it.
  5. Check it is the right specialism. An OSCP-heavy team is strong on networks and may be thinner on mobile, thick client or embedded work. Match the qualification to your surface.

When certifications are the wrong filter entirely

For specialist surfaces there is often no relevant certification at all. Nobody issues a meaningful credential for testing an industrial controller, a medical device or a proprietary desktop application, so filtering on acronyms in those categories eliminates exactly the firms you want. Ask instead for two anonymised examples of comparable work and the names of the people who did it. On a routine external network engagement, well-run firms with practical certifications are interchangeable. Choose on availability, retest terms and price.

The Canadian picture

Canada has no licensing regime for penetration testers. Anybody may sell the service, so the evaluation burden sits with the buyer, and this site publishes a method rather than a ranking. The one place credentials become a hard requirement is federal work, where personnel security screening under the Contract Security Program is specified in the contract itself, and provincial public-sector procurement, which is covered on public sector penetration testing in Ontario.

Everywhere else, treat certifications as one of the five documents to ask for alongside the methodology, the sample report, the retest terms and the insurance certificate. That full method is on penetration testing companies in Canada, and the vocabulary is on the penetration testing glossary.

Compare firms on more than acronyms

One written scope in front of Canadian firms, so you can compare the answers rather than the vendor pages.

Get matched

Common questions

Is OSCP or CEH better for a penetration tester?

OSCP, clearly, as evidence of testing ability. It is earned by compromising live machines in a long practical exam and writing a report. The standard CEH is a multiple-choice knowledge exam. Many good testers hold CEH because an employer or a government posting required it, so its presence is not a negative. A vendor page that lists CEH and nothing practical is.

Do we need a CREST-accredited firm in Canada?

Usually no. CREST is the recognised mark for UK and EU buyers and appears in some Canadian public-sector and financial-services bids, but it is uncommon among small Canadian firms because the market has not demanded it. Its absence tells you little here. Ask for it if your customer is in the UK or the EU, or if a bid document names it.

What is the difference between a firm accreditation and a tester certification?

A tester certification says one person passed an exam. A firm accreditation, which in this market means CREST, assesses the company's methodology, quality processes and handling of client data. Procurement documents can require the second of a supplier, which is why it shows up in bids, and why it is the only entry on this list a contract can sensibly demand.

Does a CISSP mean someone can run a penetration test?

No. CISSP is a broad security management credential covering governance, risk and architecture. It is a reasonable thing for a practice lead or a security manager to hold and says nothing about whether the holder can find a broken authorisation check. If a proposal offers CISSP as the testing qualification, ask what practical certifications the assigned testers hold.

Are penetration testers licensed in Canada?

No. There is no licensing regime, so anybody may sell penetration testing here. That is why the practical checks matter: a redacted sample report, the named testers and their practical certifications, the methodology, the retest terms and a certificate of insurance. Federal contracts are the exception, where personnel security screening is specified in the contract.