- What "Requirements" Actually Means for C)PTC
- No Mandatory Training or Hard Prerequisites
- The Suggested Background, Piece by Piece
- The Two-Part Assessment You Must Clear
- Mapping the 12 Curriculum Headings to Readiness
- Exam Combo Mechanics and Fee Caution
- Exam Conditions: Follow the Instructions You Are Given
- A Qualification Plan Built Around the Curriculum
- Keeping the Credential: Three-Year Cycle and Renewal
- Frequently Asked Questions
- Mile2 does not make purchasing or completing its training mandatory for the Certified Penetration Testing Consultant (C)PTC) assessment.
- Suggested preparation is C)PEH and C)PTE or equivalent knowledge, two years of networking experience, and sound TCP/IP and hardware knowledge.
- Certification has two parts: a hands-on penetration test with a written report, plus online MACS assessments.
- The knowledge exam is 100 multiple-choice questions in two hours, with a 70% requirement.
What "Requirements" Actually Means for C)PTC
When candidates search for C)PTC requirements, they usually want to know one of three things: who is allowed to sit the assessment, what they should already know, and what they must do to earn the credential. For the Certified Penetration Testing Consultant credential issued by Mile2, those three questions have three different answers, and mixing them up is the fastest way to waste money or underprepare.
This guide covers all three for Certified Penetration Testing Consultant specifically. Several unrelated credentials share a similar acronym, and their rules do not apply here. Everything below is drawn from Mile2's own published materials for this certification, using the issuer's currently linked, undated course outline. Issuer sources were last checked on October 2, 2026. If you want a broader orientation first, see What Is C)PTC Certification? or the shorter What Does C)PTC Stand For?
No Mandatory Training or Hard Prerequisites
The most important eligibility fact is also the one candidates most often assume incorrectly: Mile2 states that purchasing or completing its training is not mandatory. The certification assessment is available without the five-day course. The course and its 40 CEUs are training measures, not examination requirements and not examination timing.
That does not mean the credential is easy to approach cold. The issuer publishes suggested preparation, and the word "suggested" matters. It is guidance about what makes success realistic, not a gate that a registrar checks before letting you test. A candidate with strong equivalent experience can reasonably skip formal training, while a candidate with thin exploitation experience should treat the suggested background as a minimum honest bar.
The Suggested Background, Piece by Piece
Mile2's suggested preparation has four elements. Here is what each one realistically means for this credential.
C)PEH and C)PTE or Equivalent Knowledge
The issuer points to two of its earlier credentials, C)PEH and C)PTE, as the natural stepping stones, while accepting equivalent knowledge. In practice, "equivalent" means you can already do the fundamentals those courses cover: reconnaissance, scanning, enumeration, basic exploitation and an understanding of how a penetration test is structured. If you cannot comfortably run a scan, interpret the output and choose a sensible next step, work on that before pursuing the consultant-level material. Our comparison of the entry-level pathway in How Hard Is the C)PTC Exam? explains where candidates tend to feel the jump in difficulty.
Two Years of Networking Experience
The suggested two years of networking experience is there because so much of the curriculum assumes you can reason about traffic, services and hosts without stopping to look things up. NMAP output, for example, is only useful if you understand what an open port implies about a service and its neighbors.
Sound TCP/IP Knowledge
Sound TCP/IP knowledge is the one element that touches nearly every domain. Scanning, fuzzing network services, exploiting remote vulnerabilities and writing findings all lean on it. Be able to explain the handshake, common flag combinations, how services bind to ports and what a scanner is actually sending.
Computer-Hardware Knowledge
Hardware knowledge sounds oddly basic for a penetration testing credential, but it underpins the memory-focused material. Stack behavior, registers, address spaces and protections such as DEP and ASLR make far more sense if you have a working mental model of how a processor and memory interact.
| Suggested Background | Why It Matters for C)PTC | Self-Check |
|---|---|---|
| C)PEH and C)PTE or equivalent | Establishes scanning, enumeration and basic exploitation fluency | Can you run a scan, interpret it and pick a next step unaided? |
| Two years of networking experience | Lets you reason about hosts, services and traffic quickly | Can you explain what an open port implies? |
| Sound TCP/IP knowledge | Underpins scanning, fuzzing and remote exploitation | Can you describe what a scan actually sends? |
| Computer-hardware knowledge | Supports stack, memory and protection concepts | Can you sketch how a stack frame is laid out? |
The Two-Part Assessment You Must Clear
Qualifying for the credential means clearing both parts of Mile2's certification assessment. Treating it as a single multiple-choice exam is the most common misunderstanding about C)PTC requirements.
Part One: The Hands-On Penetration Test
The first part is practical. According to the issuer's outline, you must successfully exploit four of five lab systems, identify flags and produce a complete written report. Three details deserve attention:
- The threshold is four of five. You are not required to compromise everything, but you cannot lean on just one or two wins.
- Flags are part of the evidence. Identifying them demonstrates that you actually reached the objective rather than merely observed something suspicious.
- The report is a graded deliverable. A complete written report is a requirement, not an afterthought, which is why the final curriculum heading is Penetration Testing Report Writing.
A practical-assessment time limit was not verified in the sources checked, so this guide does not state one. Rely on the instructions Mile2 provides for your specific assessment rather than on timers quoted by third parties.
Part Two: Online Assessments Through MACS
The second part runs through Mile2's Assessment and Certification System (MACS) and has two components: flag-selection questions and a 100-question multiple-choice knowledge examination. The knowledge examination allows two hours and requires 70%. That 70% and that two-hour limit describe the written knowledge component only. They are not the standard for the practical work, the report or the flag-selection assessment. For deeper detail on scoring, read our C)PTC passing score guide.
Mapping the 12 Curriculum Headings to Readiness
Mile2's Detailed Outline, on pages 3 and 4 of its Certified Penetration Testing Consultant PDF, lists twelve headings. These are unweighted preparation curriculum headings, not an official count of exam domains or a weighted blueprint, and they do not guarantee exhaustive exam coverage. Still, they are the best published map of what the credential expects you to be able to do, and they work well as a self-assessment checklist for eligibility. Our C)PTC exam domains guide covers each in depth.
Pentesting Team Foundation
Expect to demonstrate you understand how an authorized engagement is organized, not just how to attack a host.
- Project metrics and how progress is tracked
- Team roles within an authorized lab or engagement
- Scoping and rules of engagement concepts
NMAP Automation
Scanning is a prerequisite skill that this heading pushes toward repeatable, automated workflows.
- Scripting and automating scans
- Interpreting NMAP report output to choose targets
- Turning scan data into an attack plan
Exploitation Processes and Privilege Escalation
These two headings, Exploitation Processes and Privilege Escalation, are the backbone of the practical test.
- Moving from a vulnerability to a working foothold
- Reviewing and refining exploitation attempts
- Escalating from limited access toward higher privileges
Fuzzing with Spike
Spike fuzzing introduces structured input testing to discover crashes you can later study.
- Building fuzzing templates for network services
- Recognizing a crash worth investigating
Memory Exploitation Headings
Five headings cluster around memory: Stack Based Windows Buffer Overflow, Linux Stack Smashing, Linux Address Space Layout Randomization, Windows Exploit Protection, and Getting Around SEH and ASLR (Windows).
- Windows and Linux stack concepts
- Protections such as DEP, SEH, SafeSEH, SEHOP and ASLR
- Why each protection exists and how it changes an exploit
Web Application Security and Exploitation
This heading explicitly references OWASP Top 10-2017, so study it as the vulnerability classes the outline names rather than assuming a newer list is being tested.
- Common web vulnerability categories
- Exploiting and then documenting web findings
Penetration Testing Report Writing
The report is a requirement of the practical assessment, so this is eligibility-critical, not optional polish.
- Remediation-focused findings a client can act on
- Clear evidence tied to each exploited system
Exam Combo Mechanics and Fee Caution
Mile2 sells an Exam Combo for this credential. According to the issuer, it includes an exam-preparation guide, practice questions or a simulator, and two exam attempts. Because training is optional, the Exam Combo is the route for candidates who want to qualify on the strength of their own experience and preparation.
A caution on fees: the current initial package price could not be independently confirmed from the retrievable issuer listing, so this article does not quote a figure, and you should be skeptical of any site that does with unwarranted confidence. Check Mile2's own Exam Combo page for the live price before budgeting. The one dollar figure in the sources is a renewal figure, covered below, and it is not the initial examination fee. For a full breakdown of what to verify, see our C)PTC certification cost guide.
Two attempts included in the combo is worth treating as a safety net, not a plan. Walking in expecting to use the second attempt tends to produce a thinner first preparation. Our pass-rate discussion explains why no one should lean on unverified statistics either way.
Exam Conditions: Follow the Instructions You Are Given
Candidates often ask whether the assessment is proctored and whether it is open-book. The honest answer is that Mile2's published materials are not perfectly uniform. The general Policies and Procedures document, dated May 26, 2026, describes open-book examinations but uses broad proctoring language. The current FAQ, meanwhile, describes most standard exams as on-demand without a live proctor.
Because those descriptions differ in emphasis, do not assume that every component of the C)PTC assessment is unproctored, and do not assume the reverse either. The safest requirement to adopt is simple: follow the instructions assigned to the exact C)PTC assessment you are scheduled to take, and read them before test day rather than during it. If anything is unclear, ask Mile2 directly.
A Qualification Plan Built Around the Curriculum
Generic study advice is not the point here; sequencing is. Because the curriculum builds from planning and scanning toward memory exploitation and finally reporting, a candidate who ignores that order tends to stall on the memory material. One reasonable way to schedule your preparation:
Foundations and Reconnaissance
- Pentesting Team Foundation: roles, metrics, authorized-lab discipline
- NMAP Automation: build and read scan reports until interpretation is fast
Getting In and Moving Up
- Exploitation Processes and Privilege Escalation on practice labs
- Web Application Security and Exploitation against the OWASP Top 10-2017 categories
Memory Exploitation Block
- Fuzzing with Spike, then Stack Based Windows Buffer Overflow
- Linux Stack Smashing and Linux ASLR
- Windows Exploit Protection, then Getting Around SEH and ASLR
Report and Rehearsal
- Write a full remediation-focused report from a practice engagement
- Run through multiple-choice practice in the two-hour, 100-question format
The memory block gets the most time because it is where unfamiliar concepts stack on top of each other: you need fuzzing to find a crash, stack knowledge to understand it, and protection knowledge to know why a naive exploit fails. Practice on authorized labs and systems you own or have explicit permission to test. When you want to check recall on the written side, our C)PTC practice tests are built for that purpose, and the C)PTC cheat sheet works well as a final-week refresher.
Key Takeaway
Write your practice reports early, not last. Because a complete written report is a requirement of the hands-on part, candidates who only practice exploitation often discover too late that documenting findings clearly is its own skill.
Keeping the Credential: Three-Year Cycle and Renewal
Qualifying is not the end of the requirements, because the certification has a three-year validity cycle. Mile2 offers two ways to renew:
- The CEU route: 60 documented CEUs over the cycle, the applicable renewal purchase and compliance with ethics and policy requirements.
- The exam route: passing the current full certification examination again.
Mile2's FAQ lists USD 200 as the U.S. regional fee for the CEU renewal route. That is a renewal fee, not the initial examination fee, and it should not be quoted as the cost to get certified. The FAQ also says annual membership is not required. Regional pricing can differ, so confirm the figure for your location on Mile2's Certification Renewal Program and Renewal Paths pages.
If you are weighing whether the maintenance effort is worth it, our ROI analysis and salary guide discuss career considerations without relying on unsupported pay premiums, and C)PTC jobs covers the kinds of roles that value hands-on exploitation skills.
Frequently Asked Questions
No. Mile2 states that purchasing or completing its training is not mandatory. The five-day course and its 40 CEUs are training measures, not examination requirements, so candidates with equivalent knowledge can pursue the assessment through the Exam Combo.
The issuer suggests C)PEH and C)PTE or equivalent knowledge, two years of networking experience, sound TCP/IP knowledge and computer-hardware knowledge. These are suggestions rather than enforced gates, but they reflect what the hands-on material assumes you already know.
The assessment has two parts. First, a hands-on penetration test where you exploit four of five lab systems, identify flags and deliver a complete written report. Second, online MACS assessments covering flag selection and a 100-question multiple-choice knowledge exam with a two-hour limit and a 70% requirement.
No. The two-hour limit and 70% requirement apply to the written knowledge examination only. They are not the standard for the practical work, the report or the flag-selection assessment, and a practical time limit was not verified in the sources checked.
It has a three-year validity cycle. You can renew by documenting 60 CEUs, completing the applicable renewal purchase and meeting ethics and policy requirements, or by passing the current full certification examination. Annual membership is not required.