One certification proves one person. We build coverage.
Pins, badges and certifications are not a checklist that ends after one or two certificates. They are a continuous journey: pins and progress badges as the weekly signal, path badges for every newly opened domain, certifications as a level reached - and then the next path starts. Because every person sits at a different point on that journey, the track is tailored to their position in the team.
Four tiers, four cadences.
100% of a skill path. Issued only inside the OffSec portal.
Partial progress inside a learning path - the signal that someone is still moving.
Learning path completed: 80% assessment flags in one attempt plus 80% module labs. Examples: PEN-100, SOC-100, WEB-100, OWASP Top 10-2021, Cloud Essentials.
Course plus a proctored exam: OSCP/PEN-200, OSEP/PEN-300, OSWA/WEB-200, OSWE/WEB-300, OSED/EXP-301, OSDA/SOC-200, OSTH/TH-200, OSIR/IR-200, OSAI/AI-300, OSCC-SEC/SEC-100, OSCC-SJD/SJD-100.
Schematic illustration. No OffSec badge artwork.
Certifications and badges are issued through Accredible, not Credly. Pins exist only inside the OffSec portal. Physical certificates are discontinued except OSCE3.
Attack, defend, build - and govern as our layer on top.
The matrix shows which courses and path badges populate a cell. A team is not ready when one person holds OSCP - it is ready when every column is staffed at every relevant level.
| Level | AttackIdentify and exploit vulnerabilitiesOffSec taxonomy | DefendHarden defences and detectOffSec taxonomy | BuildArchitect and ship securelyOffSec taxonomy | GovernEvidence for regulators and the boardXPLT layer |
|---|---|---|---|---|
| Baseline |
|
|
|
|
| Practitioner |
|
|
|
|
| Senior |
|
|
|
|
| Lead |
|
|
|
|
Attack, defend and build are OffSec's own skill categories. Govern is our addition - OffSec does not run a governance domain.
Tailored to the position in the team, not to the catalogue.
- 1LLM Red Teaming
- 2Skill Pins
- 3OSAI / AI-300
- 4Validation Engagement
- 1PEN-100
- 2OSCP / PEN-200
- 3OSEP / PEN-300
- 4Red Team Engagement
- 1WEB-100
- 2OSWA / WEB-200
- 3OSWE / WEB-300
- 4Code-Review-Mandat
- 1SOC-100
- 2OSDA / SOC-200
- 3OSTH / TH-200
- 4OSIR / IR-200
- 1SSD Essentials
- 2Intermediate Secure Dev I + II
- 3DevSecOps Essentials
- 4GitOps / Kubernetes
- 1CyberCore SEC-100
- 2OSCC-SEC
- 3PEN-100
- 4Erste Domäne wählen
Individual path badges map directly to MITRE ATT&CK tactics.
That lets you argue coverage tactic by tactic instead of course by course. The strip is schematic - which tactics your team can actually evidence comes out of your own account reporting.
What Learn Enterprise actually gives an admin role.
Reassignable licences
From five seats you reassign licences from the admin account - the path follows the role, not the person.
Real-time usage reporting
Progress per person and per domain, usable as training evidence for your ISMS.
Cyber Range and Proving Grounds
Practice surfaces between certifications - including CyberCore and the full learning library.
Six exam attempts per year
Per certification, per year. Enough headroom for a team running several paths in parallel.
Okta SSO
Access runs through your identity management, not private logins.
Learn Unlimited ends 2026
On 1 January 2026 Learn Unlimited folds into Learn Enterprise - a good moment to recut how paths are distributed.
Training data is not evidence yet. An attack is.
1. Telemetry
Pins, badges and certifications per role and domain, consolidated into a quarterly capability report.
2. Gaps
Empty cells in the matrix become the next path assignment - not the next course purchase.
3. Validation
A pentest or red team engagement checks whether capability actually changed under pressure. For regulated firms via DORA TLPT or TIBER-EU.
Discuss a capability programme
We look at your role distribution and cut the paths to fit it - including licence allocation through Learn Enterprise.
Not ready to talk yet? The Scope Check returns exercise type, tester-days and a budget range in two minutes - no email gate.