<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic What are some industry-recognized certifications for penetration testers? in Tech Talk</title>
    <link>https://community.isc2.org/t5/Tech-Talk/What-are-some-industry-recognized-certifications-for-penetration/m-p/77880#M4734</link>
    <description>&lt;P&gt;I am interested in advancing my career in penetration testing and want to know which certifications are most valuable in the industry.&lt;/P&gt;</description>
    <pubDate>Fri, 14 Mar 2025 07:39:38 GMT</pubDate>
    <dc:creator>williamxavier</dc:creator>
    <dc:date>2025-03-14T07:39:38Z</dc:date>
    <item>
      <title>What are some industry-recognized certifications for penetration testers?</title>
      <link>https://community.isc2.org/t5/Tech-Talk/What-are-some-industry-recognized-certifications-for-penetration/m-p/77880#M4734</link>
      <description>&lt;P&gt;I am interested in advancing my career in penetration testing and want to know which certifications are most valuable in the industry.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Mar 2025 07:39:38 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/What-are-some-industry-recognized-certifications-for-penetration/m-p/77880#M4734</guid>
      <dc:creator>williamxavier</dc:creator>
      <dc:date>2025-03-14T07:39:38Z</dc:date>
    </item>
    <item>
      <title>Re: What are some industry-recognized certifications for penetration testers?</title>
      <link>https://community.isc2.org/t5/Tech-Talk/What-are-some-industry-recognized-certifications-for-penetration/m-p/77886#M4736</link>
      <description>&lt;P&gt;Industry-recognized certifications for penetration testers include the Offensive Security Certified Professional (OSCP), which is a hands-on certification requiring candidates to demonstrate practical penetration testing skills by successfully attacking and penetrating live machines in a controlled environment. Another notable certification is the GIAC Penetration Tester (GPEN) offered by the Global Information Assurance Certification (GIAC), which focuses on assessing a candidate's ability to conduct effective penetration testing. Additionally, CompTIA offers the PenTest+ certification, which is an intermediate-level credential covering risk analysis, threat detection, penetration testing, and ethical hacking methodologies. For those interested in any CompTIA certification, utilizing a CompTIA practice test by P2PExams is essential for successful exam preparation. These certifications are widely recognized in the cybersecurity industry and can enhance a professional's credentials in the field.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Mar 2025 11:08:42 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/What-are-some-industry-recognized-certifications-for-penetration/m-p/77886#M4736</guid>
      <dc:creator>marinahart</dc:creator>
      <dc:date>2025-03-14T11:08:42Z</dc:date>
    </item>
    <item>
      <title>Re: What are some industry-recognized certifications for penetration testers?</title>
      <link>https://community.isc2.org/t5/Tech-Talk/What-are-some-industry-recognized-certifications-for-penetration/m-p/77891#M4737</link>
      <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/1449614653"&gt;@marinahart&lt;/a&gt;&amp;nbsp; &amp;nbsp;Thank you.&amp;nbsp; I have never heard anything bad about the OSCP or eJPT.&amp;nbsp; My employer does not recognize them but does not recognize any certification without a continuing education component.&amp;nbsp; ISC2 did have the CCFP for a while but retired it and was probably more theory than hands on.&amp;nbsp; SANS certifications are recognized but are way too expensive for an individual to want to spend and sometimes have odd renewal requirements.&amp;nbsp; We usually have our folks do PenTest+.&amp;nbsp; I do recommend to them to also do CySA+ because CompTIA says that they share 30% of the same material.&amp;nbsp; I think that helps if they understand the defensive side as well.&amp;nbsp; The sad part is that people want those positions, but there are very few of them.&amp;nbsp; It does not help the profit margin unless work at a company that is hired as a third party to do it for others.&amp;nbsp; I do appreciate the one omission.&amp;nbsp; I do not even like seeing that acronym anymore and would never recommend it.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Mar 2025 14:17:05 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/What-are-some-industry-recognized-certifications-for-penetration/m-p/77891#M4737</guid>
      <dc:creator>nkeaton</dc:creator>
      <dc:date>2025-03-14T14:17:05Z</dc:date>
    </item>
    <item>
      <title>Re: What are some industry-recognized certifications for penetration testers?</title>
      <link>https://community.isc2.org/t5/Tech-Talk/What-are-some-industry-recognized-certifications-for-penetration/m-p/77893#M4738</link>
      <description>Hiya. They have the OSCP+ now.&lt;BR /&gt;&lt;A href="https://www.offsec.com/products/oscp-plus/" target="_blank"&gt;https://www.offsec.com/products/oscp-plus/&lt;/A&gt;&lt;BR /&gt;I would take a look at that one as they added a continuous learning to OSCP+&lt;BR /&gt;&lt;A href="https://help.offsec.com/hc/en-us/articles/29840452210580-Changes-to-the-OSCP#h_01J6E5VRJD0VDSYK43DKSGRKRP" target="_blank"&gt;https://help.offsec.com/hc/en-us/articles/29840452210580-Changes-to-the-OSCP#h_01J6E5VRJD0VDSYK43DKSGRKRP&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Cheers!&lt;BR /&gt;&lt;BR /&gt;-Dr. B</description>
      <pubDate>Fri, 14 Mar 2025 14:39:47 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/What-are-some-industry-recognized-certifications-for-penetration/m-p/77893#M4738</guid>
      <dc:creator>Dr_B</dc:creator>
      <dc:date>2025-03-14T14:39:47Z</dc:date>
    </item>
    <item>
      <title>Re: What are some industry-recognized certifications for penetration testers?</title>
      <link>https://community.isc2.org/t5/Tech-Talk/What-are-some-industry-recognized-certifications-for-penetration/m-p/77896#M4739</link>
      <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/676611201"&gt;@williamxavier&lt;/a&gt;&amp;nbsp;I'm not a pentester, but from my friends who are, these are the certs they mention.&lt;BR /&gt;&lt;BR /&gt;*OSCP certs et al from Offensive Security, the folks behind Kali Linux.&amp;nbsp; However, I've been hearing things that some have issues with them.&lt;BR /&gt;&lt;BR /&gt;* Hack the Box certs.&amp;nbsp; This is a new group doing pentest certs, but have been hearing more and more about them, and some feeling they are BETTER then OSCP.&lt;BR /&gt;&lt;BR /&gt;* GPEN from SANS/GIAC.&amp;nbsp; Yes, SANS courses are expensive (there are ways to get around it), but certainly the quality and respectability is there for this one.&amp;nbsp; And this one IS DOD approved, so if they approve it, so will other government agencies....&lt;BR /&gt;&lt;BR /&gt;*Pentest+ from CompTIA.&amp;nbsp; I wasn't certain about this one, because let's face it, CompTIA is NOT an infosec org.&amp;nbsp; But I've heard good things about it, just be aware this is an entry level cert and if you can get any of the above, that would be better.&lt;BR /&gt;&lt;BR /&gt;That said, there are several other groups out there doing pentest certs.&amp;nbsp; Am just not certain their reputation.&amp;nbsp; And keep in mind, its often NOT your peers you need these certs for, but HR/hiring managers.&lt;BR /&gt;&lt;BR /&gt;Hope this helps.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Mar 2025 16:41:07 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/What-are-some-industry-recognized-certifications-for-penetration/m-p/77896#M4739</guid>
      <dc:creator>emb021</dc:creator>
      <dc:date>2025-03-14T16:41:07Z</dc:date>
    </item>
    <item>
      <title>Re: What are some industry-recognized certifications for penetration testers?</title>
      <link>https://community.isc2.org/t5/Tech-Talk/What-are-some-industry-recognized-certifications-for-penetration/m-p/77907#M4741</link>
      <description>&lt;P&gt;Hmmm.&amp;nbsp; Hadn't heard of this OSCP+.&lt;BR /&gt;&lt;BR /&gt;I see that this is identical to the OSCP, but expires after 3 years and requires CPEs to maintain.&lt;BR /&gt;&lt;BR /&gt;This makes me think they might be pursuing ANSI/ISO/IEC 17024 certification for the OSCP, as these are standard requirements for that.&amp;nbsp; They don't say they are doing that, but it makes me think they are.&amp;nbsp; Doing so would allow the OSCP+ to be including on the DoD 8140 list, making it one of the required certs, and once there, other government agencies would also be asking for it.&amp;nbsp; CompTIA went thru this several years ago, as originally their certs did not expire, but they changed to expiring/requiring CPEs, and this was done for the same reason.&amp;nbsp; Now that CompTIA certs are 17024 certified, they are on the DoD list.&lt;BR /&gt;&lt;BR /&gt;Time will tell on this.&lt;BR /&gt;&lt;BR /&gt;(for what its worth, many of the certs from CompTIA, ISC2, ISACA, SANS/GIAC, and EC-Council are 17024 certified and thus on the DoD list)&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Mar 2025 20:24:47 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/What-are-some-industry-recognized-certifications-for-penetration/m-p/77907#M4741</guid>
      <dc:creator>emb021</dc:creator>
      <dc:date>2025-03-14T20:24:47Z</dc:date>
    </item>
  </channel>
</rss>

