Why I'm Not Rushing Into the OSCP
My current thoughts on certifications, HTB Academy, and why I'm choosing to build skills before chasing another exam.
On this page
Why I’m Not Rushing Into the OSCP
Over the past few months, I’ve been spending most of my time working through the Hack The Box Certified Penetration Testing Specialist (CPTS) path.
When I first started, I expected it to be another certification I’d complete and move on from.
I couldn’t have been more wrong.
The deeper I got into the Academy, the more I realized that I wasn’t simply preparing for an exam—I was slowly changing the way I approached problems.
Learning Instead of Memorizing
One thing I’ve genuinely come to appreciate about the CPTS path is how little it rewards memorization.
Almost every module introduces concepts that seem straightforward at first, only to become much more challenging once you’re asked to apply them.
There have been days where I’ve spent hours trying to understand a single technique.
Sometimes I fail.
Sometimes I end up reading documentation, watching talks, experimenting in my lab, and breaking things several times before something finally clicks.
Surprisingly…
Those have become my favorite days.
Because that’s when it feels like I’m actually learning.
Every Module Creates More Questions
A funny thing started happening after every module.
Instead of feeling like I had learned everything I needed, I finished with even more questions.
Why does this work?
Why is this attack possible?
How would this look in a real environment?
Is there another way to approach this?
At first I found that frustrating.
Now I think it’s probably one of the best parts of learning cybersecurity.
The more I learn, the more I realize how much I still don’t know.
And I think that’s a healthy mindset to have.
Why I’m Not Rushing Into the OSCP
Over the past few months, I’ve been spending most of my time working through the Hack The Box Certified Penetration Testing Specialist (CPTS) path.
When I first started, I expected it to be another certification I’d complete and move on from.
I couldn’t have been more wrong.
The deeper I got into the Academy, the more I realized that I wasn’t simply preparing for an exam—I was slowly changing the way I approached problems.
Learning Instead of Memorizing
One thing I’ve genuinely come to appreciate about the CPTS path is how little it rewards memorization.
Almost every module introduces concepts that seem straightforward at first, only to become much more challenging once you’re asked to apply them.
There have been days where I’ve spent hours trying to understand a single technique.
Sometimes I fail.
Sometimes I end up reading documentation, watching talks, experimenting in my lab, and breaking things several times before something finally clicks.
Surprisingly…
Those have become my favorite days.
Because that’s when it feels like I’m actually learning.
Every Module Creates More Questions
A funny thing started happening after every module.
Instead of feeling like I had learned everything I needed, I finished with even more questions.
Why does this work?
Why is this attack possible?
How would this look in a real environment?
Is there another way to approach this?
At first I found that frustrating.
Now I think it’s probably one of the best parts of learning cybersecurity.
The more I learn, the more I realize how much I still don’t know.
And I think that’s a healthy mindset to have. One of the biggest reasons I’m interested in both CAPE and CWEE is that they focus on two completely different sides of offensive security.
Why CAPE and CWEE?
CAPE is centered around enterprise network penetration testing, Active Directory, and the kinds of internal environments that many organizations rely on. It teaches you how to assess networks, move laterally, escalate privileges, and think like an attacker in complex corporate infrastructures.
On the other hand, CWEE focuses on modern web application exploitation. It goes far beyond finding basic vulnerabilities—it dives into understanding how applications are built, identifying complex attack chains, and exploiting real-world web security issues that developers and security professionals deal with today.
I don’t want to become someone who’s only comfortable attacking networks or only comfortable testing web applications.
I want to be confident in both.
By studying CAPE, I’ll strengthen my understanding of enterprise infrastructure and Active Directory. By studying CWEE, I’ll deepen my knowledge of modern web security, secure application design, and advanced web exploitation techniques.
To me, these certifications complement each other perfectly.
Together, they provide a much broader perspective on offensive security than focusing on just one specialization.
Instead of becoming good at one area, I want to understand how attackers approach different environments, adapt to different technologies, and think critically regardless of whether the target is a corporate network or a web application.
Why This Makes Sense to Me
If I compare both the time and financial investment, I keep asking myself one question:
Would I benefit more from earning a single certification, or from spending that same amount of money building stronger skills across multiple domains?
For me, right now, the second option feels more valuable.
The cost of pursuing the OSCP is significant.
For roughly the same investment, I could subscribe to the HTB Annual plan, continue using Academy and Labs throughout the year, complete both CAPE and CWEE, and spend hundreds of additional hours practicing in realistic environments.
That feels like a better return on investment for where I currently am in my journey.
Instead of preparing for one exam over a limited period, I’d be continuously learning, practicing, and improving across multiple disciplines for an entire year.
By following this path, I can continue developing skills in:
- Network Penetration Testing
- Active Directory
- Web Application Security
- Enumeration
- Modern attack techniques
- Real-world lab environments
Those are skills I’ll carry with me regardless of which certification I eventually earn.
The Cost Matters
There’s another factor that people don’t always like talking about.
Cost.
The OSCP isn’t cheap.
For many people—including me—that isn’t a small decision.
If I’m going to invest that amount of money, I want to know that I’m truly ready to get the most out of the experience.
I’d rather spend more time strengthening my fundamentals first than rush into an expensive certification simply because everyone says I should.
That doesn’t mean I won’t pursue the OSCP.
It simply means I want to approach it when I feel that I’ve already built a solid foundation and can truly make the most of the training and the exam.
Does That Mean I’m Skipping the OSCP?
Not at all.
I’m not against the OSCP.
In fact, I fully expect to pursue it in the future.
I’m simply choosing not to rush toward it.
I want to arrive at the OSCP because my skills naturally led me there—not because I felt pressured to follow the same roadmap as everyone else.
If I eventually earn it, I want it to represent the experience I’ve built, not just another badge on my profile.
This Is Just My Perspective
These are simply my thoughts today.
Maybe a year from now I’ll look back at this post and disagree with parts of it.
Honestly…
I hope I do.
Because that would mean I’ve continued learning.
Cybersecurity changes.
People change.
Opinions change.
And that’s exactly why I wanted to write this down.
Maybe one day I’ll revisit this post after earning the OSCP and smile at how differently I saw things back then.
Until then, I’ll keep learning, asking questions, and enjoying the process.
“The goal isn’t to collect certifications. The goal is to become someone worthy of them.”