Skip to content
Exploit Labs
Capability development

One certification proves one person. We build coverage.

Pins, badges and certifications are not a checklist that ends after one or two certificates. They are a continuous journey: pins and progress badges as the weekly signal, path badges for every newly opened domain, certifications as a level reached - and then the next path starts. Because every person sits at a different point on that journey, the track is tailored to their position in the team.

Credential ladder

Four tiers, four cadences.

Pinweekly

100% of a skill path. Issued only inside the OffSec portal.

Progress badgecontinuous

Partial progress inside a learning path - the signal that someone is still moving.

Path badgemonthly to quarterly

Learning path completed: 80% assessment flags in one attempt plus 80% module labs. Examples: PEN-100, SOC-100, WEB-100, OWASP Top 10-2021, Cloud Essentials.

Certificationannual

Course plus a proctored exam: OSCP/PEN-200, OSEP/PEN-300, OSWA/WEB-200, OSWE/WEB-300, OSED/EXP-301, OSDA/SOC-200, OSTH/TH-200, OSIR/IR-200, OSAI/AI-300, OSCC-SEC/SEC-100, OSCC-SJD/SJD-100.

ReconWebADCloudSOCIRBuild

Schematic illustration. No OffSec badge artwork.

Certifications and badges are issued through Accredible, not Credly. Pins exist only inside the OffSec portal. Physical certificates are discontinued except OSCE3.

Capability matrix

Attack, defend, build - and govern as our layer on top.

The matrix shows which courses and path badges populate a cell. A team is not ready when one person holds OSCP - it is ready when every column is staffed at every relevant level.

Capability matrix: attack, defend, build and govern capability domains across four seniority levels.
LevelAttackIdentify and exploit vulnerabilitiesOffSec taxonomyDefendHarden defences and detectOffSec taxonomyBuildArchitect and ship securelyOffSec taxonomyGovernEvidence for regulators and the boardXPLT layer
Baseline
  • PEN-100
  • OSWP / PEN-210
  • SOC-100
  • WEB-100
  • OWASP Top 10-2021
  • Security-Awareness-Nachweis
Practitioner
  • OSCP / PEN-200
  • OSDA / SOC-200
  • SSD Essentials
  • Cloud Essentials
  • Vulnerability Management Foundations
Senior
  • OSWA / WEB-200
  • OSEP / PEN-300
  • OSTH / TH-200
  • OSIR / IR-200
  • Intermediate Secure Development I + II
  • DevSecOps Essentials
  • ISMS- und Audit-Nachweisführung
Lead
  • OSWE / WEB-300
  • OSED / EXP-301
  • OSAI / AI-300
  • Cyber-Range-Szenarien leiten
  • Offensive Cloud Foundations
  • Kubernetes Foundations
  • DORA TLPT / NIS2 Reporting

Attack, defend and build are OffSec's own skill categories. Govern is our addition - OffSec does not run a governance domain.

Role tracks

Tailored to the position in the team, not to the catalogue.

AI Red Team
  1. 1LLM Red Teaming
  2. 2Skill Pins
  3. 3OSAI / AI-300
  4. 4Validation Engagement
Enterprise Pentest
  1. 1PEN-100
  2. 2OSCP / PEN-200
  3. 3OSEP / PEN-300
  4. 4Red Team Engagement
Web & AppSec
  1. 1WEB-100
  2. 2OSWA / WEB-200
  3. 3OSWE / WEB-300
  4. 4Code-Review-Mandat
Defensive Analysis & IR
  1. 1SOC-100
  2. 2OSDA / SOC-200
  3. 3OSTH / TH-200
  4. 4OSIR / IR-200
Secure Build / DevSecOps
  1. 1SSD Essentials
  2. 2Intermediate Secure Dev I + II
  3. 3DevSecOps Essentials
  4. 4GitOps / Kubernetes
Junior Baseline
  1. 1CyberCore SEC-100
  2. 2OSCC-SEC
  3. 3PEN-100
  4. 4Erste Domäne wählen
ATT&CK coverage

Individual path badges map directly to MITRE ATT&CK tactics.

That lets you argue coverage tactic by tactic instead of course by course. The strip is schematic - which tactics your team can actually evidence comes out of your own account reporting.

TA0043Recon
TA0042Res Dev
TA0001Initial Access
TA0002Execution
TA0003Persistence
TA0004Priv Esc
TA0005Def Evasion
TA0006Cred Access
TA0007Discovery
TA0008Lateral
TA0009Collection
TA0011C2
TA0010Exfil
TA0040Impact
From person to organisation

What Learn Enterprise actually gives an admin role.

Reassignable licences

From five seats you reassign licences from the admin account - the path follows the role, not the person.

Real-time usage reporting

Progress per person and per domain, usable as training evidence for your ISMS.

Cyber Range and Proving Grounds

Practice surfaces between certifications - including CyberCore and the full learning library.

Six exam attempts per year

Per certification, per year. Enough headroom for a team running several paths in parallel.

Okta SSO

Access runs through your identity management, not private logins.

Learn Unlimited ends 2026

On 1 January 2026 Learn Unlimited folds into Learn Enterprise - a good moment to recut how paths are distributed.

Learn Enterprise licence details

Evidence layer

Training data is not evidence yet. An attack is.

1. Telemetry

Pins, badges and certifications per role and domain, consolidated into a quarterly capability report.

2. Gaps

Empty cells in the matrix become the next path assignment - not the next course purchase.

3. Validation

A pentest or red team engagement checks whether capability actually changed under pressure. For regulated firms via DORA TLPT or TIBER-EU.

Confidential

Discuss a capability programme

We look at your role distribution and cut the paths to fit it - including licence allocation through Learn Enterprise.

Not ready to talk yet? The Scope Check returns exercise type, tester-days and a budget range in two minutes - no email gate.