- What C)PTC Actually Means
- Who Issues It and What It Tests
- The Two-Part Assessment Explained
- The 12 Curriculum Headings
- Outline Quirks Worth Knowing
- Suggested Background and Training Options
- Fees, Renewal and the Three-Year Cycle
- How It Compares With Neighboring Credentials
- Who Hires for This Skill Set
- Sequencing Your Preparation by Domain
- Frequently Asked Questions
- C)PTC means Certified Penetration Testing Consultant, issued by Mile2, and it is a different credential from every other "CPTC" you may find online.
- Certification combines a hands-on lab test (four of five systems plus a written report) with online assessments in Mile2's MACS system.
- The knowledge exam is 100 multiple-choice questions, two hours, 70% required; that limit does not describe the practical work.
- Mile2 training is not mandatory, though C)PEH and C)PTE knowledge or equivalent is suggested.
What C)PTC Actually Means
In this article, C)PTC stands for Certified Penetration Testing Consultant, a professional certification offered by Mile2. The acronym is shared with other, unrelated programs. A transplant-coordinator certification uses similar letters, and the Collegiate Penetration Testing Competition is commonly abbreviated CPTC as well. Neither has anything to do with the credential covered here, and details such as fees, exam formats or pass marks from those programs should never be applied to this one.
If you are still sorting out terminology, our short explainers on what C)PTC stands for and the C)PTC meaning cover the naming question from a few angles. This page goes further and walks through how the certification is structured, what it covers and how to approach it.
Who Issues It and What It Tests
Mile2 is both the issuer and the examining body. The certification sits in the offensive-security track, and its curriculum is built around the mechanics of exploitation rather than only tool usage. Candidates are expected to run a penetration test as a consultant would: organize a team, scan and enumerate with automation, exploit systems, escalate privileges, understand memory-corruption defenses and document everything in a report a client can act on.
That last point matters. The title says "Consultant," and the outline ends with report writing. A candidate who can pop a shell but cannot explain the finding, its business impact and its remediation is only partway through the skill set the credential describes. For a broader overview of the topic, see our pages on C)PTC certification and what C)PTC certification involves.
The Two-Part Assessment Explained
According to the issuer's outline, certification is not a single sitting. It has two parts, and candidates should understand each before booking anything.
Part one: the hands-on penetration test
The practical component requires successful exploitation of four of five lab systems, identification of flags, and delivery of a complete written report. Note the combination: exploitation alone is not enough. The flags demonstrate that you reached the objectives, and the report demonstrates that you can communicate what you did. A practical-assessment time limit was not verified from the issuer's materials, so we do not quote one here. Be wary of third-party "practical timers" that claim a specific duration without citing Mile2.
Part two: the online assessments in MACS
The second part runs through Mile2's Assessment and Certification System (MACS). It includes flag-selection questions and a 100-question multiple-choice knowledge examination. The knowledge exam allows two hours and requires 70%. Those figures belong to the written component only; they do not describe the practical test, the report or the flag-selection assessment.
| Component | What the issuer's outline says | What is not confirmed |
|---|---|---|
| Hands-on penetration test | Exploit four of five lab systems, identify flags, submit a complete written report | A practical time limit |
| Flag-selection questions (MACS) | Part of the online assessments | Question count and timing |
| Knowledge examination (MACS) | 100 multiple-choice questions, two hours, 70% to pass | Per-topic question distribution |
For a candid look at the effort involved, read How Hard Is the C)PTC Exam?, and for the numbers around scoring see C)PTC Passing Score.
The 12 Curriculum Headings
The topic scope below reproduces the 12 headings in the Detailed Outline on pages 3-4 of Mile2's Certified Penetration Testing Consultant PDF, currently linked from the issuer's course outline page. These are unweighted preparation headings, not an official 12-domain exam count and not a weighted blueprint. They do not guarantee exhaustive coverage of every exam question, but they are the best published map of what the course teaches. For a deeper walkthrough, see C)PTC Exam Domains: All 12 Content Areas.
Domain 1: Pentesting Team Foundation
The consulting side of testing: scoping, roles and measuring progress.
- Define an authorized lab or engagement and its rules of engagement
- Assign team roles such as lead, exploit developer and report owner
- Track project metrics so the engagement stays on schedule
Domain 2: NMAP Automation
Scanning at scale and turning raw output into decisions.
- Script and chain scans rather than running one-off commands
- Interpret NMAP reports: open ports, service banners, version hints
- Feed scan results into target prioritization
Domain 3: Exploitation Processes
The repeatable workflow from finding to foothold.
- Match identified services to candidate vulnerabilities
- Verify before exploiting, and record what you did
- Know why an exploit failed and how to adjust
Domain 4: Fuzzing with Spike
Finding crashes in network services by sending malformed input.
- Understand how Spike structures protocol templates
- Recognize a crash that suggests a controllable overflow
- Connect fuzzing results to the exploit development steps that follow
Domain 5: Privilege Escalation
Moving from limited access to administrative control.
- Review local misconfigurations and weak permissions
- Distinguish Windows and Linux escalation paths
- Document each step so the finding is reproducible
Domain 6: Stack Based Windows Buffer Overflow
The foundational memory-corruption skill on Windows.
- Control the instruction pointer through a stack overflow
- Understand how the stack is laid out and why overwriting works
- Build a working proof of concept in an authorized lab
Domain 7: Web Application Security and Exploitation
Web flaws as part of a broader assessment.
- The outline explicitly references the OWASP Top 10-2017 list
- Understand the vulnerability classes that list describes
- Explain how each class is exploited and fixed
Domain 8: Linux Stack Smashing
Stack-based overflows on Linux targets.
- Compare Linux stack behavior with the Windows case in Domain 6
- Follow the path from crash to controlled execution
Domain 9: Linux Address Space Layout Randomization
How randomization complicates exploitation on Linux.
- Explain what ASLR randomizes and why it breaks fixed addresses
- Review the concepts used to work around it
Domain 10: Windows Exploit Protection
The defensive mitigations Windows applies to memory corruption.
- Know DEP, SafeSEH, SEHOP and Windows ASLR and what each blocks
- Be able to reason about which protection stops which technique
Domain 11: Getting Around SEH and ASLR (Windows)
Exploitation concepts for hardened Windows targets.
- Understand structured exception handling and how it can be abused
- Combine SEH knowledge with ASLR and the protections from Domain 10
Domain 12: Penetration Testing Report Writing
Turning technical work into a deliverable.
- Lead with remediation, not just proof of compromise
- Write for two audiences: technical staff and executives
- Remember that a complete report is a stated requirement of the practical
Outline Quirks Worth Knowing
The issuer's own materials contain a small inconsistency, and candidates who study from different documents may notice it. The summary on page 1 of the PDF uses alternative labels for some modules: for instance, it lists Simple Buffer Overflow for Module 5, where the detailed outline says Privilege Escalation, and it uses a different heading than the detailed outline for Module 8 (Linux Stack Smashing & Scanning rather than Linux Stack Smashing). The detailed outline's sequence is the one used on this page, and the two lists should not be blended into a single syllabus.
Also remember that Module 7 explicitly references the OWASP Top 10-2017. The outline is undated, so it would be inaccurate to describe the web content as freshly aligned to a current OWASP release. Supplement your reading with whatever vulnerability classes your lab work surfaces.
Key Takeaway
Treat the detailed outline on pages 3-4 as your master list and the page-1 summary as a convenience overview. When the two disagree, the detailed outline wins. Use the C)PTC cheat sheet for a compact refresher once you know the terrain.
Suggested Background and Training Options
Mile2 does not make purchasing or completing its training mandatory. The issuer's suggested preparation is advisory rather than a formal gate: knowledge equivalent to C)PEH and C)PTE, roughly two years of networking experience, sound TCP/IP knowledge and general computer-hardware knowledge. Our C)PTC requirements guide explains how to read that list in practice.
The instructor-led course is described as five days and carries 40 CEUs. Those are training measures, not examination timing, so do not confuse the five-day course length with how long any assessment lasts. Details on formats and what to expect from the classroom option are in our C)PTC training overview.
The Exam Combo packages an exam-preparation guide, practice questions or a simulator, and two exam attempts. To reinforce the written component independently, you can also work through the timed questions on the main practice test site.
Fees, Renewal and the Three-Year Cycle
The current initial price of the Exam Combo could not be independently confirmed from the retrievable issuer listing, so we do not publish a figure here. Check the Exam Combo page on Mile2's site for the live price. For a fuller discussion of how the pieces add up, see the C)PTC certification cost breakdown.
Certification is valid on a three-year cycle. Renewal works through one of two routes:
- CEU route: 60 documented CEUs over the cycle, the applicable renewal purchase, and compliance with Mile2's ethics and policy requirements.
- Exam route: passing the current full certification examination.
Mile2's FAQ lists USD 200 as the U.S. regional fee for the CEU renewal route. That figure is a renewal fee, not an initial examination fee, and the same FAQ states annual membership is not required.
How It Compares With Neighboring Credentials
Candidates often weigh this certification against others. Two comparisons come up most, and the safest way to frame them is by emphasis rather than by invented rankings.
| Comparison | Where the emphasis differs |
|---|---|
| C)PTC vs C)PTE | C)PTE is listed among the suggested foundations; C)PTC builds on that base with deeper exploit-development topics (fuzzing, stack overflows, exploit mitigations) and consulting-style reporting. |
| C)PTC vs OSCP | Both involve hands-on exploitation, but they come from different issuers with different formats, and a candidate should compare the published exam structures directly rather than rely on reputation alone. |
Whether the investment pays off depends on your goals, which we examine in Is the C)PTC Certification Worth It?.
Who Hires for This Skill Set
The skills in the outline map to roles in security consulting firms, internal red teams, managed security providers and vulnerability-assessment groups. Typical job titles include penetration tester, security consultant, red team operator and vulnerability analyst. Because the credential emphasizes both exploitation and reporting, it fits especially well where findings are delivered to clients or auditors. Browse our notes on C)PTC jobs for role types, and see the C)PTC salary guide for how we discuss compensation. We do not cite specific salary premiums here because no verified figure ties pay directly to this certification.
Sequencing Your Preparation by Domain
Generic study advice matters less than ordering the material sensibly. Because later modules assume earlier ones, a dependency-based sequence works well. Adjust the pacing to your own background.
Foundations and recon
- Domains 1-2: team structure, project metrics, NMAP automation and report interpretation
- Reason: every later domain depends on accurate scanning and clear scoping
Exploitation core
- Domains 3-6: exploitation workflow, Spike fuzzing, privilege escalation and the Windows stack overflow
- Reason: Domain 6 is the conceptual anchor for the memory-corruption material that follows
Hardened targets and the web
- Domains 7-11: web security, Linux stack smashing, Linux ASLR, Windows exploit protection, SEH and ASLR bypass concepts
- Reason: protections only make sense once you can exploit an unprotected target
Reporting and review
- Domain 12: practice writing remediation-focused findings from your own lab notes
- Run timed multiple-choice sets against the 100-question, two-hour format
For a full plan with resource suggestions, read our C)PTC study guide, and check C)PTC exam dates for scheduling considerations. For data-focused readers, C)PTC pass rate explains what can and cannot be said about outcomes.
Frequently Asked Questions
Here it stands for Certified Penetration Testing Consultant, a Mile2 certification. Other programs share the same letters, but they are unrelated and have different formats and requirements.
In two parts: a hands-on penetration test (four of five lab systems exploited, flags identified, complete written report) and online MACS assessments including flag-selection questions and a 100-question multiple-choice exam of two hours with a 70% requirement.
No. Purchasing or completing Mile2 training is not mandatory. The issuer suggests C)PEH and C)PTE knowledge or equivalent, about two years of networking experience, solid TCP/IP knowledge and computer-hardware knowledge.
Three years. You can renew with 60 documented CEUs, the applicable renewal purchase and ethics/policy compliance, or by passing the current full certification exam.
The issuer's currently linked outline is undated, and Module 7 references OWASP Top 10-2017, so it should not be treated as a newly revised 2026 syllabus. Always confirm details on Mile2's own pages before you register.
If you are comparing definitions or just landing here for the first time, our companion pages on what C)PTC is, what a C)PTC is and what C)PTC means offer shorter takes on the same question.