CPTS Study Plan
A 10-day marathon through an enterprise network. A free, day-by-day CPTS schedule built from the official HTB Academy: Penetration Tester Job Role Path syllabus, scaled to your exam date and weekly hours.
- Approx. cost
- $490–$1,260
- Difficulty
- ♥♥♥♥♥
- Study time
- about 391h
- Start level
- Junior
> How long does CPTS take?
The plan assumes about 391 study hours. Here is how that stretches across different weekly schedules.
| Hours per week | Time to finish |
|---|---|
| 5 hours | about 79 weeks (18.2 months) |
| 10 hours | about 40 weeks (9.2 months) |
| 15 hours | about 27 weeks (6.2 months) |
| 20 hours | about 20 weeks (4.6 months) |
| 30 hours | about 14 weeks (3.2 months) |
> CPTS exam format
Hack The Box · HTB Academy: Penetration Tester Job Role Path
- 10 days total: the hacking and the report both fit in the window
- Capture at least 12 of 14 flags
- Commercial-grade penetration test report required
- 100% of the Penetration Tester path required first
- Covers external, web, internal & Active Directory
> CPTS syllabus and study hours
Every topic in the plan, in order, with its baseline hours. The planner shrinks or stretches these to fit your dates.
Recon & Foundations
Methodology, enumeration and footprinting.
- Penetration Testing Process8h · learn
- Getting Started13h · learn
- Network Enumeration with Nmap7h · learn
- Footprinting12h · learn
- Information Gathering - Web Edition10h · learn
- Vulnerability Assessment9h · learn
Exploitation Toolkit
Shells, transfers, passwords and pivots.
- File Transfers6h · learn
- Shells & Payloads9h · learn
- Using the Metasploit Framework8h · learn
- Password Attacks14h · learn
- Attacking Common Services10h · learn
- Pivoting, Tunneling, and Port Forwarding10h · learn
Active Directory
The biggest single module in the path.
- Active Directory Enumeration & Attacks26h · learn
Web Gauntlet
Proxies, fuzzing and the web vuln classes.
- Using Web Proxies8h · learn
- Attacking Web Applications with Ffuf7h · learn
- Login Brute Forcing7h · learn
- SQL Injection Fundamentals9h · learn
- SQLMap Essentials6h · learn
- Cross-Site Scripting (XSS)6h · learn
- File Inclusion6h · learn
- File Upload Attacks6h · learn
- Command Injections7h · learn
- Web Attacks10h · learn
- Attacking Common Applications18h · learn
Privilege Escalation
From user to root / SYSTEM.
- Linux Privilege Escalation15h · learn
- Windows Privilege Escalation18h · learn
Reporting & Capstone
Write it up, then attack a full network.
- Documentation & Reporting6h · learn
- Attacking Enterprise Networks16h · lab
Training Grounds
Reinforce the path with real boxes.
- Retired HTB boxes (CPTS-style)30h · lab
- Multi-host network practice (e.g. Pro Labs)30h · lab
- Active Directory chains20h · lab
Final Boss Prep
The exam rewards stamina and reporting.
- Build module cheat sheets & methodology10h · review
- Report practice (SysReptor / template)10h · review
- 10-day exam game plan4h · review
> Where to practise for CPTS
Each task in your plan lists practice labs for its own topic. These are the best places to put in extra hands-on hours:
- TJ Null lists of OSCP-like boxes (HTB, PG, VulnHub) (Community)
- PG Practice (OffSec practice machines) (Proving Grounds)
- Retired machines and Pro Labs (Hack The Box)
- Offensive Pentesting path (TryHackMe)
> CPTS exam-day checklist
General logistics for exam week. The official exam guide always takes priority if it differs.
One to two weeks before
- Schedule your exam and add the start time, time zone and deadline to your calendar
- Read the official exam guide end to end: rules, allowed and banned tools, and what counts as proof
- Plan your 10-day window: set a daily schedule and leave days for the report
- Track flags as you go: you need at least 12 of 14
- Complete a full-length timed practice run on your exam setup
- Finalize your note-taking setup and templates (see the notes starter below)
- Build and review your cheat sheets and command references
- Arrange time off, tell people you will be unavailable, and plan your meals ahead
Machine and network
- Charge and test a backup device or phone hotspot, and know how to contact support if your connection drops
- Plug in your laptop and turn off sleep, updates and notifications for the exam
- Test the VPN or lab connection early and know how to reconnect after a drop
- Update your attack VM, take a clean snapshot and keep a spare
- Install and test every tool you plan to use, and check none of them are banned
- Test your screenshot hotkeys and make sure you have plenty of free disk space
During the exam
- Sleep well the night before, and skip last-minute cramming
- Prepare food and water, and set timers for break reminders
- Read the brief and scope carefully before you touch anything
- Write notes and capture proof as you go, not at the end
- Time-box each target and move on when stuck. You can come back later
- Stop new attacks with enough time left to verify your evidence
Report and submission
- Copy your report template and fill in the easy parts (scope, methodology) while you work
- Check every finding has reproducible steps and screenshots
- Proofread: could someone else follow each step?
- Export in the exact format and naming the exam guide requires
- Submit with a buffer before the deadline and confirm it was received
Suggested exam-day rhythm
- Day 1. Read the brief, set up notes and enumerate everything. Do not rush into exploitation.
- Days 2 to 8. Fixed daily rhythm: two or three focused blocks of about 3 hours, breaks between them, and a proper stop at night.
- End of each day. Update notes, list your next three ideas and back up your evidence.
- Last 2 days. Stop new attacks. Verify every finding, then write and proofread the report.
- Submission. Submit with a buffer before the deadline and confirm it was received.
▶ Open the interactive CPTS exam kit
The kit lets you tick items off, download a notes starter and report template, and see a readiness score from your plan progress.
> Passed CPTS with PWN PATH
No CPTS debriefs yet
Passed a cert? A short debrief helps the next learner plan their own run, and it only takes a couple of minutes.
▶ Share my debriefDebriefs are self-reported. See all pass stories.
> Frequently asked questions
How long does it take to prepare for CPTS?
PWN PATH builds the CPTS plan on about 391 study hours. At 10 hours a week that is roughly 40 weeks, and at 20 hours a week roughly 20 weeks. Your own timeline depends on how much of the material you already know.
What is the CPTS exam like?
10 days total: the hacking and the report both fit in the window. Capture at least 12 of 14 flags. Commercial-grade penetration test report required. 100% of the Penetration Tester path required first. Covers external, web, internal & Active Directory.
How hard is CPTS?
We rate CPTS 4 out of 5. It suits people who want the deepest pentest curriculum for the money and a report-heavy exam. Comfortable in Linux and networking. A lot of reading and note-taking ahead.
How much does CPTS cost?
HTB Academy subscription plus a $210 exam voucher. Silver Annual is about $490–550 with a voucher included; some advanced paths need Gold. Prices are approximate, in US dollars unless a currency is shown, and change often. Confirm with the vendor before you buy.
What should I study first for CPTS?
Start with the "Recon & Foundations" phase: Penetration Testing Process, Getting Started, Network Enumeration with Nmap. The planner puts topics in a sensible order and scales the hours to the time you have.
What are the prerequisites for CPTS?
Comfortable in Linux and networking. A lot of reading and note-taking ahead.
What should I do the week before the CPTS exam?
Re-read the official exam guide for rules and banned tools, test your machine, network and VPN or lab connection, finish a full timed practice run, finalize your notes and cheat sheets, and plan your meals, breaks and sleep. The exam-day checklist on this page covers it step by step.
How should I handle breaks and sleep during the CPTS exam?
Day 1: Read the brief, set up notes and enumerate everything. Do not rush into exploitation. Days 2 to 8: Fixed daily rhythm: two or three focused blocks of about 3 hours, breaks between them, and a proper stop at night. End of each day: Update notes, list your next three ideas and back up your evidence. Last 2 days: Stop new attacks. Verify every finding, then write and proofread the report.
What should I take after CPTS?
Common next steps are OSCP+, CAPE, CWEE. See the roadmap to compare them.
Is the PWN PATH study planner free?
Yes. There are no accounts and no sign-up. Your plan and progress are saved in your browser, and you can export a backup file, add the schedule to your calendar or print it.
> Plan your path
Good stepping stones before CPTS:
Where it leads:
More in network pentesting:
Not sure CPTS is right for you? Take the one-minute cert quiz.