Exploit Labs
OFFSEC LEARN ENTERPRISE

The full OffSec library for your entire security team - on one enterprise licence.

Exploit Labs is an official OffSec Learning & Channel Partner. We deliver Learn Enterprise with EUR invoicing from a German GmbH - backed by certification-path guidance from active penetration testers, not a catalogue salesperson.

Get in touch
SCOPE

What the licence includes

One platform, the entire OffSec course landscape, managed for a growing team.

Full OffSec content library

PEN-200/OSCP, OSEP, OSWE, OSDA, OSIR, OSAI (AI red teaming) and CyberCore SEC-100 - all in one licence.

Six exam attempts per year

Six exam attempts per certification per year - enough headroom for a team pursuing multiple certifications in parallel.

Admin dashboard and reporting

Per-employee progress reporting - usable as audit evidence for your ISMS or training-record obligations.

Licence reassignment

When staff change roles or leave, reassign the licence directly - no contract renegotiation required.

Hands-on labs and Proving Grounds

Real attack environments instead of multiple choice - your team practices on machines, not slides.

Vendor-ready documentation

EUR invoicing, VAT ID and DPA to clear your procurement and vendor-approval processes.

WORKFORCE PIPELINE

From baseline to a validated exercise - instead of competing for scarce staff.

Enterprise Team Readiness is not just licences, it is the staged path behind them. Every stage defines who enters and what is demonstrably mastered at the end - documented for your ISMS and your regulator.

  1. Stage 1 - Baseline

    CyberCore SEC-100

    Enters: IT administrators, SOC analysts and career changers with no offensive background.

    By the end: A solid grounding in attack techniques, tooling and methodology.

  2. Stage 2 - Practitioner

    OSCP

    Enters: Graduates of the baseline stage, or staff with equivalent hands-on practice.

    By the end: Independent execution of network and system pentests, verified by a hands-on exam.

  3. Stage 3 - Specialist

    OSEP / OSWE / OSDA / OSIR

    Enters: Certified practitioners specialising in evasion, web exploitation, defensive analytics or incident response.

    By the end: Depth in a specific discipline, for example bypassing modern endpoint defence or detection engineering.

  4. Stage 4 - AI security

    OSAI

    Enters: Specialists who also need to secure and attack models, pipelines and AI-enabled applications.

    By the end: Competence in the attack surface of LLMs and AI systems, relevant under the EU AI Act.

  5. Stage 5 - Validation

    Live TIBER-EU / DORA exercise

    Enters: Certified internal teams working alongside Exploit Labs operators.

    By the end: Demonstrable participation in an actual red team validation exercise.

Discuss the pipeline model and your talent gap

COMPARISON

Buying direct vs. through Exploit Labs

The learning content is identical. The difference is in invoicing, the contracting entity, and the guidance you get between courses.

CriterionDirect from OffSecExploit Labs (Official Partner)
InvoicingUS credit card
EUR invoice from a German GmbH
Contracting entityOffSec (US)
Exploit Labs GmbH (Germany)
VAT ID & DPANot available
Provided on request
Language of supportEnglish
German and English
Certification-path adviceSelf-service
Guidance from active penetration testers
Optional validation engagementNone
TIBER-EU / DORA TLPT available
Onboarding helpDocumentation
Guided onboarding per team
OUR APPROACH

Practitioner-led, not catalogue-led

Our trainers and advisors are active penetration testers and red teamers. Recommendations for your team's learning path come from weaknesses we actually see in live engagements - not from a generic course catalogue.

PROCUREMENT

Procurement pack

Everything your legal, procurement and finance teams need to clear the licence.

  • EUR invoice from a German GmbH
  • VAT ID and DPA available on request
  • Standard vendor onboarding documentation
  • Net payment terms
  • No US credit card required
PRICING

Pricing

Learn Enterprise is tiered by team size in volume bands. Rather than listing a per-seat price, we produce a written EUR quote after a short workforce assessment, sized to your team and certification needs.

FAQ

Frequently asked questions

What's included in the Learn Enterprise licence?+

The full OffSec content library (including PEN-200/OSCP, OSEP, OSWE, OSDA, OSIR, OSAI, CyberCore SEC-100), six exam attempts per certification per year, an admin dashboard with progress reporting, and hands-on labs plus Proving Grounds.

Why buy through Exploit Labs instead of direct from OffSec?+

You get a EUR invoice from a German GmbH instead of a US credit-card charge, a contracting entity with a VAT ID and DPA, and certification-path guidance from active penetration testers instead of pure self-service.

Can licences be reassigned when staff change roles?+

Yes. Learn Enterprise licences are bound to the team, not permanently to one person - when someone leaves the team or role, you reassign the licence through the admin dashboard.

What does Learn Enterprise cost?+

Licensing is tiered by team size. After a short workforce assessment you receive a written EUR quote - there is no publicly listed per-seat price.

Do you support our procurement vendor-approval process?+

Yes. We provide a VAT ID, DPA, standard vendor onboarding documentation and net payment terms - aligned to regulated procurement processes across DACH, MENA and GCC.

Does Learn Enterprise support compliance programmes like TIBER-EU or DORA?+

Learn Enterprise upskills your internal team. Where independent validation is required, we can add an optional TIBER-EU or DORA TLPT engagement - we're TIBER-EU dual-accredited (RTT + TIP) and were among the first to complete a DORA TLPT, in 2024.

Equip your team with a single assessment.

One short conversation is enough to size team, certification needs, and a written EUR quote.

Get in touch
Strategic overview: AI Security Workforce