CREST Registered Penetration Tester (CRT)

Classification & Context

The CREST Registered Penetration Tester (CRT) is a two-part, intermediate-level certification that primarily validates core operational skills in network infrastructure and web application penetration testing. Its structure is quite different from single-exam certifications (like the OSCP or CPTS) because it is modularly tied to a theoretical foundation. CREST classifies successful CRT candidates as individuals with the practical skills needed to handle operational "hands-on Pen Test Roles." The expected skill level assumes a minimum of three years of practical penetration testing experience.

Technical Focus & Methodology

Theoretical Foundation (CPSA): Passing the CREST Practitioner Security Analyst (CPSA) exam is a strict prerequisite. This is a 120-minute multiple-choice exam taken at a standardized testing center (Pearson VUE), covering theoretical knowledge of network concepts, operating systems, common vulnerability classes, and cryptography basics.

Practical Assessment (CRT): You can only achieve CRT status after passing the CPSA exam. There are two distinct paths to get there:

  • Native CREST Exam: This is a 2.5-hour exam with an extra 15 minutes of reading time. It combines multiple-choice questions, short-form answers, and trophy answers (specific flags or results from defined tasks in a closed lab environment). You must have a valid CPSA status to take it. The exam costs £600 per attempt and can be retaken after an 8-week waiting period if failed.
  • Equivalency Pathway: If you hold a valid OffSec Certified Professional (OSCP) certification, you can apply directly for CRT status by submitting your OSCP credential and passing the theoretical CPSA exam. This path comes with strict rules: your OSCP certificate must not be older than three years when you apply, and the CPSA qualification must be achieved through an independent exam.

Since the CPSA is mandatory in both cases, the total costs for the CRT vary significantly depending on your chosen path. Using the equivalency pathway with an existing OSCP, total costs sit around £375 (the CPSA exam fee plus a £100 equivalency processing fee). For the native CRT exam, total costs jump to roughly £875, covering both the CPSA and the standalone CRT exam fees.

A defining feature of the native CRT exam is its highly restrictive closed-book format. It runs in a browser-based virtual machine, often at Pearson VUE testing centers. Internet access is completely blocked. Candidates have to work in a CREST-provided Kali environment and only have access to their own cheat sheets or scripts if they uploaded them beforehand to the CRESTDrive, which is capped at 100 megabytes. This restriction fits into an overall rigid exam structure. Compared to multi-day exams with open, explorable enterprise labs, the CRT tasks are isolated and require you to submit specific answers or flags on a tight schedule. The focus is clearly on reproducibility and standardization rather than the complex exploit chaining you would expect from a hacker mindset. The combination of no internet access and strict task logic is especially jarring when compared to the daily reality of a penetration tester, who relies heavily on current vulnerability databases, public exploit repositories, and increasingly on AI-assisted research tools. This gap between the exam and reality is a bigger issue than it seems. Rather than focusing on a modern pentester’s actual core skills like efficiently using external resources and independently chaining vulnerabilities, the exam tests pure factual knowledge under time pressure. This only partially lives up to the certification's own claim of validating true operational competence.

Market Value

The market value of the CRT comes less from its technical training value and more from its integration into regulatory frameworks.

The CRT's real value stands out especially in the UK within the CREST ecosystem. In the British NCSC CHECK Scheme, working as a Check Team Member requires a recognized technical credential ("Competence A Certificate") alongside a UK Cyber Security Council Security Testing Professional Title at a minimum Practitioner level [https://www.ncsc.gov.uk/sites/default/files/documents/CHECK-Scheme-Standard.pdf]. CREST explicitly lists the CRT as a Competence A certificate for this purpose. CHECK service providers can only run these assessments with registered, qualified Team Members. Because of this, the CRT holds concrete formal market value for CHECK-relevant roles. Note that the equivalency pathway via CPSA and OSCP (or OSCP+) is explicitly excluded for Check Team Members. If you need the CRT as proof of competence in a CHECK context, you have to pass the native CRT exam, even if you already have an OSCP.

In the DACH region, direct demand for the CRT in standard job postings is noticeably lower than for the OSCP or national credentials like the BSI certification for IT security service providers. Its market value here relies more on specific international clients and compliance contexts than on general HR recognition. One potential use case is in the regulated financial sector: TIBER-EU outlines a threat-led penetration testing approach aligned with DORA, while TIBER-DE adapts this framework for the German financial sector and provides procurement guidelines for external red team and threat intelligence providers. The CRT can act as an extra competency signal here, as long as the specific tender considers CREST qualifications. However, this does not mean DORA, TIBER-EU, or TIBER-DE officially mandate or recognize the CRT or CPSA across the board. The actual value depends entirely on the client and the procurement process.

To keep the CRT active, CREST requires revalidation every three years. This means passing either the CPSA plus the native CRT exam, or the CPSA plus the OSCP or OSCP+. This time-limited validity follows a similar model to the new OSCP+ recertification rule and faces the same basic criticism: it ensures continuous learning, but it also creates a recurring financial and administrative burden for the certificate holder.

Conclusion & Assessment

From a senior pentester's perspective, the native CRT exam is technically solid but falls short of the operational depth seen in modern certifications. The highly regulated closed-book format in a testing center is more punishing for forgetting syntax commands than for having a poor testing methodology.

For individuals, the best route depends entirely on your target market. If you need a CRT title for international tenders or client-specific skill matrices and already have a valid OSCP or OSCP+, the equivalency pathway makes the most sense. Whether this gives you an edge in DORA, TIBER-EU, or TIBER-DE engagements depends on the specific tender; it doesn't grant blanket regulatory recognition of the equivalency-based CRT.

On the other hand, if you need to be certified for the British CHECK scheme or similar UK-specific programs, there is no way around the native CRT exam. The equivalency pathway simply isn't accepted for this use case, no matter how much deeper the technical scope of the OSCP might be.

Compared to competitors like the HTB CPTS, the native CREST training path is technically less deep and methodologically focused more on standardized testing than on creative exploit chaining. This is by design, reflecting the certification's main goal: it exists to validate reproducible, auditable testing procedures, not to push for maximum technical excellence.

For companies, this makes the CRT primarily a strategic tool to meet compliance requirements in international tenders and heavily regulated industries (like finance, government, or critical infrastructure). Ultimately, the value of the CRT lies less in the individual technical depth of the tester and more in the company's ability to provide a standardized, accredited credential to regulatory authorities and clients.

Section Navigation

binsec academy GmbH – Advanced Pentest Training Lab

binsec academy GmbH operates the Pentest Training Lab, a highly practical online platform dedicated to real penetration testing. Simulating complex corporate networks and advanced real-world attack scenarios within isolated lab environments, it is engineered to sharpen the skills of aspiring and professional penetration testers. Upon conquering our rigorous, fully practical examination, participants earn the distinguished Binsec Academy Certified Pentest Professional (BACPP) designation — proving their technical capability to methodically uncover and evaluate vulnerabilities in modern IT infrastructures.

Explore the Pentest Training Lab

binsec GmbH – Experts in Penetration Testing

binsec GmbH is a highly specialized penetration testing provider and the operative pentesting core of the binsec group. Since 2013, the company has focused exclusively on high-end, human-led penetration tests (pentests) and advanced red team simulations. Rejecting automated scans, our team of permanently employed, certified senior pentest experts delivers manual deep-dive assessments of critical digital systems: from web applications and APIs to mobile apps, complex network infrastructures, and cloud environments. As a dedicated assessment partner for highly regulated sectors such as Payment, Banking, and Healthcare, binsec GmbH provides clear risk evaluations and actionable reports to effectively secure business-critical systems.

Get Manual Expert Penetration Testing Services

Contact

binsec GmbH
Clemensstraße 6-8
60487 Frankfurt am Main
Germany

Legal notice

Director: Patrick Sauer
Authorized Officer: Dominik Sauer, Florian Zavatzki
Registration: Frankfurt am Main, HRB97277
Turnover Tax Identification No.: DE290966808