OSWA
OffSec

Offensive Security Web Assessor

Intermediate Practical web assessment exam + report Pass: Objective/report-based; exact threshold may vary … $1,499

OSWA is a practical web-assessment certification focused on finding and exploiting web vulnerabilities in realistic environments. For 2026 readiness, focus on API-first testing, auth logic flaws, and report clarity.

Official Page
IssuerOffSec
FormatPractical web assessment exam + report
Duration48h exam window + report window (indicative)
Pass ScoreObjective/report-based; exact threshold may vary …
Valid For3y
Prerequisites
Recommended: HTTP/HTTPS fundamentals, web app architecture basics, JavaScript familiarity, and hands-on exposure to OWASP Top 10 style issues.
Syllabus Overview

5 exam domains — click "Syllabus" tab for full breakdown

Web Recon & Attack Surface Mapping 20%
Input Validation & Injection 25%
Authentication, Session & Access Control 25%
Business Logic & Modern Web Risks 15%
Reporting & Patch Verification 15%