
How to Verify a Pentester's Certifications (OSCP, OSWE, CRTO)
The short answer: Every major penetration testing certification has a public or request-based verification portal. Ask the vendor for the tester's full name and certification ID, then cross-check it against the issuing body's official lookup tool. If a vendor deflects, delays, or cannot produce a verifiable credential number, treat it as a disqualifying red flag.
Certification fraud in cybersecurity is not hypothetical. It is routine enough that hiring managers, procurement teams, and CISOs need a repeatable process for catching it before a contract is signed — not after a breach occurs. When comparing penetration testing companies, credential verification is one of the twelve evaluation criteria that produce a defensible vendor decision.
Why Verification Matters
Certifications serve two purposes in penetration testing: they signal that a tester has met a defined technical standard, and they give buyers a way to compare vendors on an objective axis. Both purposes collapse the moment verification is skipped.
Fake and Expired Credentials Are More Common Than Buyers Assume
A résumé listing "OSCP certified" costs nothing to fabricate. Certification badges copied from LinkedIn, PDF certificates generated with free tools, or simply lying on a proposal — all of these happen. Beyond outright fraud, certifications expire. An OSCP earned in 2018 with no evidence of continuing professional development is a different signal than one earned and maintained this year.
Certifications Distinguish Hands-On Skill from Theoretical Knowledge
Not all credentials carry equal weight. The cybersecurity industry has two broad categories of certification:
- Exam-based (multiple choice): Tests recall of concepts. Relatively easy to prepare for with study guides. CEH falls largely in this category.
- Lab/exam hybrid (practical): Requires exploiting real systems under controlled conditions with no internet access to solutions. OSCP, OSWE, OSED, GPEN, and CRTO fall in this category.
When evaluating a penetration testing vendor, practical certifications are the ones that predict real-world performance. Knowing which category each credential belongs to — and then verifying it is genuine — is the core of a sound vendor evaluation process.
Certification Verification: Step-by-Step by Issuing Body
Offensive Security (OSCP, OSWE, OSED, OSEP, OSDA)
Verification URL: credly.com
Offensive Security issues its digital credentials through Credly. Anyone can look up a certification by the holder's name or by the credential URL shared on LinkedIn. The OSCP (OffSec Certified Professional), OSWE (OffSec Web Expert), and OSED (OffSec Exploit Developer) badges are linked to a public Credly profile that you can independently access.
Steps:
- Ask the tester or vendor for the full name as it appears on the certification, plus the Credly badge URL or credential ID.
- Navigate to the Credly badge link, or search credly.com for the holder's name.
- Confirm the name, certification title, and issue date match what was represented.
- Check for expiry — OffSec certifications do not expire, but the date tells you how recent the training was.
GIAC (GPEN, GWAPT, GXPN, GREM, GCIH)
Verification URL: giac.org/certified-professional
GIAC certifications are widely held in enterprise security teams. GPEN (GIAC Penetration Tester) and GXPN (GIAC Exploit Researcher and Advanced Penetration Tester) are the most relevant for offensive testing engagements.
Steps:
- Request the tester's GIAC certification number or Analyst ID, visible on their GIAC profile.
- Visit the GIAC Certified Professional Directory at
giac.org/certified-professionaland search by candidate name or Analyst ID. - The directory returns the certification status and confirms whether the credential is current. GIAC certs expire every four years and require CPE credits to renew — check the status carefully.
Zero-Point Security (CRTO — Certified Red Team Operator)
Verification method: Zero-Point Security does not publish its own public verification lookup page. Verification relies on the Credly or Badgr digital badge assertion issued to the holder, or a direct confirmation request sent to Zero-Point Security.
The CRTO is increasingly recognized as a credible, practical red team certification. It uses Cobalt Strike in a realistic Active Directory lab and validates real adversary simulation skills. Badge assertions are issued via Badgr.
Steps:
- Ask the holder to share their Badgr badge assertion link.
- Open the link — it will display the badge, holder name, issuer (Zero-Point Security), and issue date.
- You can also email Zero-Point Security directly to confirm a candidate's credential; they respond to employer verification requests.
EC-Council (CEH, CPT, CPENT)
Verification URL: aspen.eccouncil.org/verify
The CEH (Certified Ethical Hacker) is one of the most widely listed credentials in the industry. It is also one of the most misunderstood — the standard version is largely multiple choice. The CEH Practical (CPENT) involves a real lab exam and is a stronger signal. Verify which version a candidate holds.
Steps:
- Request the EC-Council member ID or certificate number.
- Visit the EC-Council verification portal and enter the ID.
- Confirm the specific certification title (CEH vs. CEH Practical vs. CPENT), active/expired status, and issue date.
ISC² (CISSP, CCSP, CSSLP)
Verification URL: isc2.org/verify
CISSP is a management and architecture credential, not a hands-on hacking cert. It is relevant when evaluating consultants who will produce governance deliverables, compliance frameworks, or risk assessments alongside a pentest. It should not substitute for OSCP or GPEN when hands-on exploitation skill is the requirement.
Steps:
- Request the ISC² member number.
- Go to
isc2.org/verify, enter the member number and last name. - Active, CPE-compliant status will display. ISC² requires annual CPE submission and a three-year recertification cycle.
CREST (CRT, CCT, CCSAS)
Verification URL: crest-approved.org
CREST is a UK-based accreditation body whose individual certifications (CRT — CREST Registered Tester; CCT — CREST Certified Tester) and company certifications are publicly searchable. If you are procuring penetration testing in the UK, EU, or from a globally operating firm that holds CREST company status, this verification is particularly relevant.
Steps:
- Visit
crest-approved.organd search by individual name or company. - The directory confirms both individual credential status and company-level CREST accreditation.
- For regulated sectors (financial services, CNI) in the UK, CREST company certification is often a contractual requirement.
Certification Comparison Table
| Certification | Issuing Body | Verification URL | What It Proves | Practical Exam | Difficulty |
|---|---|---|---|---|---|
| OSCP | Offensive Security | credly.com | Network pentest skills (real lab, 24h exam) | Yes | High |
| OSWE | Offensive Security | credly.com | Web application exploitation (source-code review) | Yes | Very High |
| OSED | Offensive Security | credly.com | Windows exploit development | Yes | Very High |
| GPEN | GIAC | giac.org/certified-professional | Pentest methodology, Active Directory attacks | Partial (proctored) | Medium-High |
| GXPN | GIAC | giac.org/certified-professional | Advanced exploitation, fuzzing | Partial (proctored) | High |
| CRTO | Zero-Point Security | Credly/Badgr badge assertion | Red team ops with Cobalt Strike, AD | Yes | Medium-High |
| CEH | EC-Council | aspen.eccouncil.org/verify | Ethical hacking concepts | No (standard) | Medium |
| CPENT | EC-Council | aspen.eccouncil.org/verify | Pentest practical skills | Yes | Medium-High |
| CISSP | ISC² | isc2.org/verify | Security architecture & management | No | Medium |
| CRT | CREST | crest-approved.org | UK pentest baseline standard | Yes | Medium |
| CCT | CREST | crest-approved.org | Senior pentest technical skills | Yes | High |
Red Flags During Vendor Evaluation
Verification is not just a post-proposal step. The vendor's behavior during the sales process reveals a great deal about how they operate:
- "We don't share individual cert numbers for privacy reasons." Privacy is not a legitimate reason to withhold a credential number from a paying client. Legitimate certifications are designed to be verified. This is a deflection.
- Vague language like "our team is certified." Demand specifics: which certifications, held by which named individuals who will be assigned to your engagement. A team of ten means nothing if the two testers on your project are uncertified.
- Certifications listed without dates. An undated CEH on a résumé or proposal is a yellow flag. Ask for the issue date. An expired GPEN (if not renewed) means the tester has not met CPE requirements for years.
- Inability to name the tester assigned pre-contract. Vendors who cannot commit to named, credentialed testers before signing may be subcontracting to unknown parties or over-representing their bench.
- Only management-track certs on the team. A CISSP-heavy team proposal that lacks a single OSCP or GPEN holder is not an offensive security team — it is a compliance consulting team with a pentest label.
Building Verification Into Your RFP Process
The time to ask for credentials is before the contract is signed, not after the work begins. A straightforward protocol:
In your RFP, require:
- Full name and certification ID for every tester proposed for the engagement
- Certification title and version (e.g., "CEH Practical v4" not just "CEH")
- Issue date and expiration date (or statement of non-expiry)
- Verification URL or badge link for each credential
After receiving proposals:
- Run every credential through the issuing body's verification portal
- Confirm the certified individual is named in the Statement of Work, not just the proposal
- Add a contract clause requiring notification if a named tester is replaced mid-engagement
This takes under 30 minutes per vendor and eliminates credential fraud as a variable before work begins.
Transparency about credentials is a baseline standard for any reputable provider. A vendor that provides verification numbers at any stage of the sales process — without delays or vague references to "a certified team" — is demonstrating the kind of operational maturity that carries over into the engagement itself. When evaluating providers, ask to see the named testers assigned to your engagement, their specific credentials, and the Credly badge links or certification IDs needed to verify each one independently before signing.
For example, WhiteJaguars publishes team certifications and provides verification numbers on request. To verify an individual consultant's OSCP, search their name on Credly (credly.com) — the OffSec badge will appear with issue date and credential details if the certification is genuine. This approach works for any provider: if they hold OffSec credentials issued after 2020, the Credly record is publicly accessible.
Red Flags During Certification Verification
The verification process itself surfaces behavior patterns that predict how a vendor will perform during the engagement. These are the red flags to watch for.
PDF certificates emailed by the vendor. PDFs are trivially forgeable — a certificate template downloaded from the internet and edited in any PDF editor is indistinguishable from a genuine one to the naked eye. Credly badge assertion links (for OffSec credentials), the GIAC verification portal, the CREST company directory, and the EC-Council member lookup are the only acceptable verification methods. If a vendor's response to your credential request is a PDF attachment, treat it as unverified until you cross-check it against the issuing body's portal directly.
Certification dates that do not align with claimed experience. A tester claiming ten years of offensive security experience with an OSCP dated 2023 is possible — some experienced practitioners take certifications late in their careers to formalize skills they already hold. But it warrants a direct follow-up question: what was the tester doing in the years before certification, and can they point to prior engagements, CVEs, or published research to corroborate the claimed experience level?
Certifications that expired and were not renewed. GIAC requires CPE credits and renewal every four years. EC-Council requires annual CPE submission for CEH maintenance. An expired GIAC certification means the tester has not met continuing education requirements — ask specifically about the current status, not just the original issuance date.
Team-level certification claims. A firm claiming "we are an OSCP-certified firm" is a meaningless statement. Certifications are held by individuals, not organizations. The correct question is: which specific testers will be assigned to your engagement, and what are their individual credential IDs? Any vendor who cannot answer with named individuals and verifiable IDs is either hiding something or has not thought carefully about the operational question.
CISSP or CISM presented as offensive credentials. Both are governance and management certifications with no hands-on exploitation component. Holding a CISSP does not mean a person can exploit a JWT authentication bypass, chain a SSRF into an RCE, or conduct an Active Directory privilege escalation. When evaluating offensive testing vendors, these credentials are irrelevant to the technical question. They may be relevant if a governance deliverable is part of the engagement scope, but they must not substitute for OSCP, GPEN, CRTO, or equivalent hands-on credentials on the testing team.
Frequently Asked Questions
Are there certifications more important than OSCP for web application testing?
For web application penetration testing specifically, OSWE (OffSec Web Expert) is considered a higher bar than OSCP. The OSWE exam requires the candidate to perform white-box web application exploitation from source code review — a skill that directly maps to finding business logic flaws and complex authentication bypasses that automated scanners will never surface. BSCP (Burp Suite Certified Practitioner) from PortSwigger is another respected web-specific credential that requires practical hands-on exploitation of a live web application under exam conditions. OSCP covers network penetration testing broadly and includes some web content, but OSWE is the specialist credential for web application engagements.
How do I verify a CREST certification?
CREST (Council of Registered Ethical Security Testers) maintains a public directory at crest-approved.org where both individual testers and member companies are searchable. Individual CREST certifications include CRT (CREST Registered Tester), CCT App (CREST Certified Tester in Application), and CCT Inf (CREST Certified Tester in Infrastructure). Search by the tester's full name to confirm active membership status and certification level. Company-level CREST accreditation is separately searchable and is often a contractual requirement for penetration testing in UK-regulated sectors including financial services and critical national infrastructure. If a vendor claims CREST company accreditation, verify it in the directory — the company name will appear with its accreditation scope.
Can a tester without certifications still be highly skilled?
Yes. Certifications are proxies for skill, not perfect measures of it. Some of the most capable penetration testers have built their skills through bug bounty programs, CTF competitions, published CVE research, or years of engagement experience and have not pursued formal certifications. Evaluating uncertified testers requires alternative signals: a documented CVE track record (searchable in the NVD), verifiable bug bounty hall-of-fame listings (HackerOne, Bugcrowd), published security research, or references from organizations with the technical sophistication to assess engagement quality. These signals require more effort to verify than a Credly badge link, but they are legitimate indicators of real-world skill.
What is the difference between OSCP and OSWE?
Both are OffSec (Offensive Security) practical certifications verified through Credly (credly.com). OSCP (OffSec Certified Professional) covers network penetration testing: enumeration, exploitation of services, privilege escalation on Linux and Windows, Active Directory basics, and pivoting. The exam is a 24-hour live network with five target machines. OSWE (OffSec Web Expert) covers advanced web application security: white-box source code review, authentication bypass, SQL injection chains, prototype pollution, and deserialization attacks. The exam is a 48-hour white-box web application assessment requiring the candidate to identify and exploit vulnerabilities from source code without hints. OSWE is narrower in scope but substantially harder in its domain. For organizations whose primary concern is web application security, OSWE is the more relevant credential on a tester's profile.
Should I require specific certifications in my RFP?
Yes, with one important caveat: specify certification categories, not specific titles, to avoid inadvertently excluding highly qualified uncertified testers or accepting less-qualified holders of the named cert. A well-drafted RFP requirement might read: "All testers assigned to this engagement must hold at minimum one practical, lab-based offensive security certification (examples: OSCP, OSWE, GPEN, CRTO, CPENT, or equivalent) verified by a credential ID provided in the proposal response." This framing accepts legitimate equivalents, requires verifiability, and clearly excludes management-only credentials like CISSP and CISM from satisfying the requirement. Including this clause in the RFP also signals to vendors that you are a sophisticated buyer — and typically improves the quality of the proposals you receive.
Verify First, Then Engage
The certification verification process outlined here takes less time than reviewing a proposal. Do both. The combination of verified credentials and a clear scope of work is the foundation of a pentest engagement that produces actionable results rather than a PDF that sits in a compliance folder. The checklist for choosing a pentest provider structures this verification step alongside the seven other criteria that separate credible vendors from weak ones.
If you have questions about the verification process or want to share feedback on this guide, editorial contact options are available. For a structured evaluation framework that incorporates credential verification alongside seven other vendor criteria, the checklist for choosing a pentest provider is the logical next step.
Looking for a reliable pentesting provider?
Check our comparison guide with the key criteria for evaluating providers: verifiable certifications, methodology, SLAs, reporting and support. Make an informed decision.
Independent analysis · No commercial sponsorship · Based on verifiable criteria