Hello, you are using an old browser that's unsafe and no longer supported. Please consider updating your browser to a newer version, or downloading a modern browser.
Everything you need to know about CompTIA's hands-on penetration testing certification as of 2026, covering the five PT0-003 domains, the performance-based exam format, recommended experience, career paths, DoD 8140 status, and how PenTest+ compares to CEH and OSCP. A complete reference guide for anyone weighing the PenTest+ or trying to understand what it covers.
Scoping, rules of engagement, and reporting. 13% of the exam.
Footprinting, discovery, and enumeration. 21% of the exam.
Scanning, validation, and prioritizing what matters.
The heaviest domain at 35%. Exploiting networks, apps, cloud, and more.
Persistence, escalation, pivoting, and clean exit.
PenTest+ is CompTIA's hands-on penetration testing certification, first launched in 2018 and now in its third version, PT0-003.
It validates the skills to plan, scope, and run a full penetration test, then analyze the findings and report them in a way a business can act on. The point isn't any single tool. It's proving you can carry an engagement end to end the way a working tester has to, from rules of engagement through exploitation to a written report.
The credential is vendor-neutral, ISO/ANSI accredited under ISO/IEC 17024, and approved under DoD 8140, with performance-based questions that make you carry out simulated testing tasks rather than just answer about them. PenTest+ is issued and maintained by CompTIA, the vendor-neutral body behind Security+, Network+, and the rest of the lineup.
Four things that set PenTest+ apart from a knowledge-only exam when you are moving into hands-on offensive work.
PenTest+ blends multiple-choice questions with performance-based items, so you analyze tool output, work through attack scenarios, and carry out simulated testing tasks inside the exam. That hands-on format gives a hiring manager direct evidence you can do the work, not just describe it.
Five domains cover scoping and legal work, reconnaissance, vulnerability analysis, exploitation, and reporting. PenTest+ tests the full testing lifecycle, not just the exploit, which is exactly what a real engagement demands of a tester.
As of 2026, US penetration testing roles commonly land in the $100,000 to $150,000 range, with senior and niche work going higher. Our guide to the highest paid cybersecurity jobs breaks down where the offensive track leads.
PenTest+ is an approved qualification under DoD Manual 8140.03, mapped to ten work roles in the DoD Cyber Workforce Framework (DCWF) at the Intermediate and Advanced proficiency levels, spanning the Cybersecurity, Cyberspace Effects, and IT elements.
That covers roles like Exploitation Analyst, Vulnerability Assessment Analyst, and Cyber Defense Analyst, so PenTest+ can qualify you for cyber-coded federal and contractor positions. Current qualification matrices are published at the DoD Cyber Exchange.
Everything you need to know about the certification, the exam structure, and how to maintain PenTest+ as of 2026.
PenTest+ proves you can run an engagement. From there most professionals either go deeper on offense, step up to advanced technical security, or round out the picture with defensive analysis. None of these require PenTest+ first, but they build naturally on it.
CompTIA's advanced security certification, formerly CASP+, is the senior technical step in the CompTIA lineup. It suits practitioners moving toward security architect and senior engineer roles who want to stay hands-on rather than pivot to management.
EC-Council's Certified Ethical Hacker is the broad ethical-hacking credential many government and enterprise job postings name by title. Paired with PenTest+, it covers both the hands-on skills and the compliance checkbox that some employers screen for.
CompTIA's Cybersecurity Analyst certification covers threat detection and response from the defender's side. Adding the blue-team view to PenTest+ red-team skills rounds out the analyst profile employers like for SOC and detection roles.
PenTest+ sits in the middle of an offensive-security path. It builds on foundational CompTIA credentials and leads into advanced technical, ethical-hacking, or defensive-analyst specializations.
Build the baseline
The offensive pivot
Two questions to answer before you commit: can you certify, and should you pursue PenTest+ specifically. Here's a straight answer to both.
Anyone can register and sit the exam.
PenTest+ has no required certification or documented experience gate. You buy the voucher and schedule the exam through Pearson VUE, at a test center or online. That makes it more accessible than experience-gated credentials and a realistic target for anyone already working in or studying security.
Open entry doesn't mean easy entry.
CompTIA recommends three to four years in a penetration tester role, and the performance-based questions assume you can actually use the tools. Candidates coming in cold can pass, but they spend more prep time in a lab building the practical skills the exam expects you to demonstrate, not just describe.
PenTest+ maps to offensive and analyst roles across the private sector and the federal cyber workforce. Several of these are DCWF work roles where PenTest+ is an approved qualification.
Plans and runs authorized tests against networks, applications, and cloud, then reports what an attacker could reach. Maps to DCWF work role 121, Exploitation Analyst, where PenTest+ qualifies at the Advanced level.
Scans for and validates weaknesses across systems and prioritizes them for remediation. DCWF work role 541, where PenTest+ is an approved qualification at the Intermediate level.
Monitors for and analyzes intrusions, using attacker knowledge to recognize what a real compromise looks like. DCWF work role 511, a common landing spot for PenTest+ holders.
Detects, contains, and investigates active incidents. DCWF work role 531, Cyber Defense Incident Responder, where the offensive perspective PenTest+ builds pays off directly.
Evaluates whether security controls actually hold up under testing. DCWF work role 612, grounded in the hands-on assessment skills PenTest+ validates.
Plans and runs security testing of systems before they go live. DCWF work role 671, System Testing and Evaluation Specialist, where PenTest+ qualifies at the Intermediate level.
All three are offensive-security credentials, but they prove different things. Here's how they line up.
| PenTest+ | CEH | OSCP | |
|---|---|---|---|
| Issuer | CompTIA | EC-Council | OffSec |
| Focus | Hands-on testing, full lifecycle | Ethical hacking methodology, broad | Real-world exploitation under pressure |
| Prerequisites | None (3 to 4 yrs recommended) | 2 yrs experience or official training | None formal |
| Exam Format | 90 items max, 165 min, MC plus PBQ | 125 multiple choice, 4 hrs | 23 hrs 45 min practical plus report |
| Passing Score | 750 of 900 | 60% to 85% (variable cut score) | 70 of 100 points |
| Renewal | 60 CEUs over 3 years | 120 ECE credits over 3 years | Does not expire |
| DoD 8140 Approved | Yes (10 DCWF roles) | Yes (7 DCWF roles) | No |
| Best For | Hands-on testers needing an 8140 credential | Compliance and government-adjacent roles | Technical testers proving exploitation skill |
Pricing and renewal details vary by region and membership status. DoD 8140 status reflects the Qualification Matrix V2.1, dated September 19, 2025. Many testers eventually hold more than one of these credentials.
Our official CompTIA PenTest+ boot camp covers all five PT0-003 domains over five days, with hands-on labs, authorized courseware, and your exam voucher included, so you leave exam-ready.
Exam prep, certification strategy, salary data, and career outcomes for the offensive-security track.
A consultant's honest read on when a certification actually opens doors in offensive security, when demonstrable skills matter more, and how PenTest+ and CEH fit a real pentest career.
How PenTest+ stacks with Security+ and CySA+ into the CNVP and CNSP credentials, and where the offensive track sits in CompTIA's broader certification pathways.
What penetration testers and offensive-security roles actually pay, the certifications that move the number, and where PenTest+ fits among the credentials employers reward.
A ranked field guide to the credentials worth your time, how to match a certification to the role you want, and where PenTest+ and CEH land for offensive-security careers.
Which credentials show up in real contract language, why DoD 8140 work roles drive the requirements, and where PenTest+ fits for penetration testing and offensive roles.
The salary math behind the Security+ baseline and the specialization tracks that build on it, including the offensive path that runs through PenTest+.
How the CompTIA certifications connect, when a boot camp beats self-study, and where PenTest+ sits among the credentials that map to real cybersecurity roles.
The PenTest+ PT0-003 objectives are organized into five domains, each carrying its own weight on the exam. Click any domain for what it covers.
Pre-engagement activities, scoping, rules of engagement, legal and compliance considerations, and the reporting and communication that turns a test into something a client can act on.
Passive and active information gathering, footprinting, host and service discovery, and the enumeration techniques that build the target picture before any exploitation begins.
Vulnerability scanning, validating findings, ruling out false positives, and the analysis that prioritizes which weaknesses are worth pursuing on an engagement.
The heaviest domain on the exam. Exploiting network, wireless, application, cloud, and host weaknesses, plus social engineering, and adapting tools and techniques to the target in front of you.
Persistence, privilege escalation, pivoting and lateral movement, credential collection, and the cleanup that leaves a tested environment the way you found it.
Domains and weights reflect the CompTIA PenTest+ PT0-003 exam objectives, launched December 17, 2024. CompTIA updates exam objectives on a regular cycle.
The questions candidates ask most often when researching the CompTIA PenTest+ certification.
PenTest+ is CompTIA's vendor-neutral penetration testing certification. It validates the hands-on skills to plan, scope, and perform a full penetration test across networks, applications, cloud, and wireless, then analyze the results and report them, and it sits at the intermediate level of CompTIA's cybersecurity lineup.
PenTest+ fits security professionals moving into offensive work: penetration testers, vulnerability analysts, and red-team members, plus defenders who want attacker perspective. CompTIA recommends three to four years of hands-on security experience, though there's no formal prerequisite, so motivated candidates with Security+ level knowledge can pursue it.
The PenTest+ PT0-003 exam voucher costs approximately $425 USD as of 2026. CompTIA sets the pricing and it can vary by region. Many boot camps fold the exam voucher into the course price, so check what's included before paying separately.
The PT0-003 exam has a maximum of 90 questions delivered over 165 minutes. It mixes multiple-choice questions with performance-based items, so you both answer conceptual questions and carry out simulated penetration testing tasks. You need a score of 750 on a 100 to 900 scale to pass.
There's no formal prerequisite. CompTIA recommends three to four years of hands-on experience in a penetration tester role, along with Network+ and Security+ or equivalent knowledge. Candidates who already work in security can sit the exam directly.
Under the PT0-003 objectives the five domains are Engagement Management (13 percent), Reconnaissance and Enumeration (21 percent), Vulnerability Discovery and Analysis (17 percent), Attacks and Exploits (35 percent), and Post-exploitation and Lateral Movement (14 percent). Attacks and Exploits carries the most weight by a wide margin.
PenTest+ is valid for three years. You renew it by earning 60 Continuing Education Units (CEUs) across the cycle and paying the CompTIA continuing education fee, by passing a higher CompTIA certification, or by retaking the current exam before it expires.
Yes. PenTest+ appears on the DoD 8140 Qualification Matrix V2.1, mapped to ten DCWF work roles at the Intermediate and Advanced proficiency levels, including Exploitation Analyst, Vulnerability Assessment Analyst, and Cyber Defense Analyst. That makes it a qualifying credential for several cyber-coded federal and contractor positions. See the full DoD 8140 work role paths.
PenTest+ is a vendor-neutral CompTIA exam that blends multiple-choice and performance-based questions across the full testing lifecycle. CEH from EC-Council is a broad multiple-choice exam centered on ethical hacking methodology. OSCP from OffSec is a long hands-on practical exam focused on real-world exploitation. PenTest+ and CEH are both DoD 8140 approved; OSCP is not on the Matrix.
The current version is PT0-003, also called V3, which launched on December 17, 2024. It replaced PT0-002, which retired on June 17, 2025. V3 adds coverage for AI-based attacks, expanded cloud and API exploitation, and modern post-exploitation techniques.
Common next steps are CompTIA SecurityX for advanced technical security, EC-Council CEH for broader ethical-hacking recognition, and CompTIA CySA+ to round out the offensive picture with defensive analysis. Many penetration testers also pursue OffSec's OSCP for a deeper hands-on credential.
Most candidates spend two to three months preparing, depending on hands-on background. The performance-based questions reward lab time over memorization, so the strongest preparation pairs structured study with practice against real tools and target systems. A boot camp compresses the instruction and the labs into a focused block.
For professionals moving into hands-on offensive security, yes. PenTest+ is vendor-neutral, ISO/ANSI accredited, approved under DoD 8140, and its performance-based format gives employers direct evidence of skill. It's a strong intermediate credential, though candidates targeting elite red-team roles often add a deeper hands-on certification on top of it.
Whether you're weighing the certification, working out funding, or planning training for a team, tell us where you are and we'll help you map out the right path.