OSEP (OffSec Experienced Penetration Tester)
OSEP covers penetration testing against hardened corporate networks: client-side attacks, antivirus and EDR evasion, lateral movement, advanced Windows tradecraft and persistence. It follows the PEN-300 course, which OffSec places at its 300 level and aims at learners who have completed PEN-200 and OSCP+ or have equivalent skills. OSEP is one of the three certifications that together award OSCE3.
Exam Details
Proctored online exam in a private VPN that simulates one corporate network with several machines. Grading is based on proof files and a written report.
Course and exam bundle (PEN-300 access plus one exam attempt). Learn One costs $2,749 per year with two attempts. OffSec sells a standalone exam only for OSCP+, not for OSEP.
Requirements and Renewal
Prerequisites
No formal prerequisite. OffSec recommends completing PEN-200 and passing OSCP+ or equivalent knowledge, plus scripting in Bash, Python and PowerShell, Active Directory knowledge and familiarity with C#.
Renewal
Does not expire.
Certification Lists
Related Tool Categories
Frequently Asked Questions
What does OSEP stand for?→
OSEP stands for OffSec Experienced Penetration Tester. It is earned by passing the exam tied to the PEN-300 course.
How long is the OSEP exam?→
The exam lasts 47 hours and 45 minutes, and candidates then have 24 hours to upload their documentation. All OSEP exams are proctored.
Does OSEP expire?→
No. OffSec lists OSEP among its certifications that do not expire. Passing the OSEP exam also counts as a qualifying exam for renewing OSCP+.
How does OSEP relate to OSCE3?→
OSCE3 is granted automatically to anyone who holds OSEP, OSWE and OSED. No additional exam is required.
Sources
Exam details are checked against official OffSec pages. Fees, exam versions, and renewal rules change; confirm with OffSec before registering. OSEP is a trademark of its owner. This site is not affiliated with or endorsed by OffSec.