WEB-200: Foundational Web Application Assessments - on the way to OSWA.
WEB-200 is OffSec's black-box web course leading to OSWA: injection classes, authentication and session flaws, access control, SSRF, deserialisation and chaining multiple weaknesses.

- Certification
- OSWA - OffSec Web Assessor
- Level
- Intermediate
- Discipline
- Attack
- Audience
- Teams and individuals
Who this course is for
People entering application security, developers with a security remit, and testers who want a structured route into web attacks.
Not the right course yet if
- -You have source access and want code review - go to WEB-300
- -You are not yet comfortable with HTTP fundamentals
OSWA interview: what you take away from the course
A conversation with a recent OSWA holder about the exam, the learning path and what really matters in the report.
Watch on YouTube- →Systematically assess a web application without source access
- →Chain weaknesses into credible attack paths
- →Document findings with reproducible evidence
- ·HTTP and web technology fundamentals
- ·Basic understanding of a scripting language
Not sure whether you meet them? We run a short placement conversation before you buy.
What WEB-200 covers.
- Injection and template attacks
- Authentication, session, access control
- SSRF and deserialisation
Course content, labs and the OSWA exam are provided by OffSec. Precedence always sits with the official course description. This page reviewed: 2026-08-12.
Labs and format
Modular labs per vulnerability class plus challenge labs with complete applications.
Exam and credential
Practical exam against several applications, with a report. Passing awards the OSWA certification.
The packages that include WEB-200.
Prices in EUR, net, plus statutory VAT. Invoiced through a German entity. Your course is pre-selected at checkout.
You have a focused block of time and want to sit the exam soon.
- ▸ 90 days of course access including labs
- ▸ 1 exam attempt
- ▸ Exactly this course
Study alongside a job, without lab time pressure.
- ▸ 365 days of course access including labs
- ▸ 2 exam attempts
- ▸ Proving Grounds Practice, KLCP and OSWP included
Several people in a team, with evidenced progression.
- ▸ The full OffSec catalogue
- ▸ Learning paths and reporting
- ▸ Reassignable from 5 seats
- +Exercises against your own technology stack
- +A bridge into OWASP ASVS and WSTG test routines
For security teams
Multiple people, role paths, reporting and procurement run through OffSec Learn Enterprise.
See Learn EnterpriseTeam capability development
Badges, learning paths and evidence across attack, defend, build and govern.
See the capability mapOther hackers also bought ... ;)
If your day job is web applications, OSWA. If you test infrastructure, OSCP.
Basics are enough. Deep coding only becomes necessary in WEB-300.
Not sure whether WEB-200 is the right course?
We run a short placement conversation: background, study time, goal. Then we recommend a course and package - even when it is the cheaper one.
From training to the engagement: our testing services
- Red TeamingThreat intelligence-led red teaming: attack paths, detection testing and proven business impact.Read more
- Pentest as a ServiceContinuous testing at release cadence instead of one audit per year.Read more
- Hybrid PentestAutomated coverage plus manual depth - evidence for ISMS, DORA and NIS2.Read more
- DORA TLPTThreat-led penetration testing under DORA: scoping, run-through and regulator documentation.Read more