Stackable · ● Active · Professional · CompTIA
Stackable credential — not a standalone exam. Awarded upon earning and maintaining both Security+ (SY0-701) and PenTest+ (PT0-002) simultaneously. No separate CNVP exam exists; achievement badge issued via Credly when prerequisites are met.
Exam facts
| Field | Value |
|---|---|
| Cost | $425 per exam (Security+); $425 per exam (PenTest+). Total: $850 for both exams. |
| Duration | Security+: 90 minutes; PenTest+: 165 minutes (2 hours 45 minutes). Total study: ~300+ hours recommended. |
| Questions | Security+: ~90 questions (multiple choice & multiple response); PenTest+: maximum 85 questions (multiple choice & performance-based). |
| Passing | Security+: 750/900 scaled score; PenTest+: vendor-scaled; both required to hold CNVP badge. |
| Format | Multiple choice · Multiple response · Performance-based questions (PBQs) |
| Delivery | Pearson VUE (online ProctorU or test center) · OnVUE |
| Languages | English (English-only delivery as of 2026) |
| Valid | 3 years from most recent passing date. Both certs must be held simultaneously. |
| Renewal | Continuing Education (CE) credits or retake exams before expiration. CompTIA allows 40 CE credits per 3-year cycle; alternative: pass CySA+ to bundle into CNSP (broader stack). |
| Prerequisites | CompTIA recommends 2–5 years hands-on IT/security experience. No hard prerequisite, but practical networking and systems knowledge assumed. |
| Released | CNVP stackable badge introduced ~2019; refined 2023–2026. Individual exams (Security+ SY0-701, PenTest+ PT0-002) are current versions as of 2026. |
| Retiring | No retirement announced for Security+ or PenTest+ as of May 2026. Stackable badge status: Active. |
Vendor source — CompTIA Stackable Certifications ↗
Security+ exam guide — CompTIA Security+ (SY0-701) ↗
PenTest+ exam guide — CompTIA PenTest+ (PT0-002) ↗
Stackable badge details — CNVP Digital Badge ↗
About
The CompTIA Network Vulnerability Assessment Professional (CNVP) is a stackable credential that recognizes professionals who have mastered both foundational security (Security+) and offensive penetration-testing skills (PenTest+). Unlike a standalone exam, CNVP is an achievement badge awarded by CompTIA when you hold both Security+ and PenTest+ certifications simultaneously. Earners demonstrate the ability to scan applications and systems to identify vulnerabilities, assess risk, and provide remediation guidance—a critical role in modern cybersecurity operations. The CNVP is designed for IT professionals and operations specialists with 2–5 years of hands-on experience.
Domain context — Security / Vulnerability Assessment
Penetration testing and vulnerability assessment are core practices in modern cybersecurity, sitting at the intersection of defensive security (assessment) and offensive tactics (testing). CNVP holders validate competency across threat identification, exploitation techniques, and security controls.
Read full deep dive — Security Domain →
Topics covered
Security+ (SY0-701) — Exam objectives
- General Security Concepts (~13%) — Attack frameworks, threat actors, vulnerability management, incident response
- Threats, Vulnerabilities, and Mitigations (~24%) — Types of attacks, malware, application/network exploits, mitigation techniques
- Security Architecture (~21%) — CIA triad, cryptography, access control, identity/authentication
- Security Operations (~16%) — Incident response, security monitoring, threat hunting, SOAR/SIEM
- Governance, Risk, and Compliance (~16%) — Risk management, regulatory frameworks (HIPAA, PCI-DSS, SOC 2), policy
Source: CompTIA Security+ Exam Objectives ↗
PenTest+ (PT0-002) — Exam objectives
- Penetration Testing Fundamentals (~12%) — Scope, rules of engagement, legal/ethical frameworks, tools overview
- Reconnaissance (~13%) — Information gathering, passive/active scanning, enumeration techniques
- Scanning and Enumeration (~14%) — Vulnerability scanning, exploitation frameworks, target profiling
- Exploitation (~25%) — Web-application exploitation, network attacks, privilege escalation, post-exploitation
- Post-Exploitation and Reporting (~16%) — Proof-of-concept development, evidence documentation, report writing, risk communication
- Tools and Code Analysis (~20%) — Metasploit, Burp Suite, Python/Bash scripting, packet analysis
Source: CompTIA PenTest+ Exam Blueprint ↗
Common skills at Security / Vulnerability Assessment · Professional
Shared competencies across penetration testing and vulnerability assessment roles at the Professional level.
- Threat modeling and risk quantification
- Vulnerability scanning and remediation prioritization
- Exploitation technique execution (SQLi, XSS, command injection, privilege escalation)
- Network-traffic analysis and protocol exploitation
- Web-application security assessment (OWASP Top 10)
- Post-exploitation persistence and lateral movement
- Secure reporting and executive communication
- Legal and ethical boundary testing (scope, ROE, compliance)
Recommended courses at Security / Vulnerability Assessment · Professional
| Provider | Title | Cost | URL |
|---|---|---|---|
| CompTIA Official (A Cloud Guru / Linux Academy) | CompTIA Security+ (SY0-701) + PenTest+ (PT0-002) bundle | $500–$800 | ↗ |
| Professor Messer | CompTIA Security+ SY0-701 video series | Free (YouTube) | ↗ |
| Professor Messer | CompTIA PenTest+ PT0-002 video series | Free (YouTube) | ↗ |
| Udemy (Jason Dion) | CompTIA Security+ (SY0-701) Complete Course and Exam | $15–$45 | ↗ |
| Udemy (Jason Dion) | CompTIA PenTest+ (PT0-002) Complete Course | $15–$45 | ↗ |
| TCM Security | Practical Ethical Hacking (hands-on lab) | $99–$199 | ↗ |
| Pluralsight | CompTIA Security+ Path | $399/year | ↗ |
| CBT Nuggets | CompTIA PenTest+ Certification (Video + Labs) | $399–$599 | ↗ |
| INE (Offensive Security) | Introduction to Penetration Testing (EN101) | $249–$499 | ↗ |
Course-selection rule: Link courses explicitly tied to SY0-701 and PT0-002, not generic "security" content. Hands-on labs (TCM, INE) highly recommended given the practical nature of PenTest+.
Practice exams
| Provider | Title | Cost | URL |
|---|---|---|---|
| CompTIA Official (via partner) | CompTIA Security+ SY0-701 practice exam | $95–$125 | ↗ |
| Boson ExSim-Max | CompTIA Security+ (SY0-701) practice exams (90-day access) | $99 | ↗ |
| Boson ExSim-Max | CompTIA PenTest+ (PT0-002) practice exams | $99 | ↗ |
| Whizlabs | CompTIA Security+ (SY0-701) practice tests | $49–$79 | ↗ |
| Whizlabs | CompTIA PenTest+ (PT0-002) practice tests | $49–$79 | ↗ |
| MeasureUp | CompTIA Security+ (SY0-701) official practice exam | $119 | ↗ |
| MeasureUp | CompTIA PenTest+ (PT0-002) official practice exam | $119 | ↗ |
Books
| Title | Author | Publisher | Year | ISBN | URL |
|---|---|---|---|---|---|
| CompTIA Security+ Study Guide (Exam SY0-701) | Mike Chapple, James Michael Stewart | Sybex (Wiley) | 2024 | 978-1-119-90620-7 | ↗ |
| CompTIA PenTest+ Study Guide (Exam PT0-002) | Jon Hill, Clinton Foster | Sybex (Wiley) | 2023 | 978-1-119-90688-6 | ↗ |
| The Web Application Hacker's Handbook: Finding and Exploiting Security Flaws | Stuttard & Pinto | Wiley | 2011 | 978-1-118-02635-8 | ↗ |
| Penetration Testing: A Hands-On Introduction to Hacking | Georgia Weidman | No Starch Press | 2014 | 978-1-593-27564-7 | ↗ |
| The Hacker Playbook 3: Practical Guide to Penetration Testing | Peter Kim | CreateSpace | 2018 | 978-1-980901-15-3 | ↗ |
Typical job titles at Security / Vulnerability Assessment · Professional
Penetration Tester · Vulnerability Assessor · Security Analyst · Application Security Engineer · Network Security Analyst · Security Consultant · Offensive Security Specialist · Red Team Operator
(Job titles drawn from current job-board postings that list Security+ and PenTest+ as required or strongly preferred.)
Salary
| Region | Range | Source |
|---|---|---|
| USD | $119,000 – $154,000 | PayScale ↗ · Glassdoor ↗ · Indeed ↗ |
| ZAR | R483,918 – R851,221 | PayScale ZA ↗ · SalaryExpert ZA ↗ · Glassdoor ZA ↗ |
| GBP | £36,430 – £60,000 | PayScale UK ↗ · IT Jobs Watch ↗ · Glassdoor UK ↗ |
Salary rule: Ranges reflect roles requiring Security+ and PenTest+ or equivalent offensive/defensive certifications. Senior penetration testers and vulnerability assessors (7+ years) can exceed these ranges significantly. Regional variation reflects cost of living and demand; UK and ZA data sparser than USD due to smaller certified pool.
Skills validated
Distinct technical competencies this credential combination validates.
- Nmap / Nessus / OpenVAS vulnerability scanning and reporting
- Metasploit Framework exploitation and post-exploitation
- Burp Suite web-application penetration testing
- SQLi, XSS, command injection, directory traversal exploitation
- Network reconnaissance (DNS enumeration, port scanning, service fingerprinting)
- Windows and Linux privilege escalation techniques
- Active Directory exploitation and lateral movement
- Payload generation and encoding (evasion, obfuscation)
- Python and Bash scripting for security automation
- Cryptographic concepts and their weaknesses
- Wireless network testing (WPA/WPA2 cracking)
- OWASP Top 10 vulnerability identification and remediation
- Firewall evasion and IDS/IPS bypass
- Post-exploitation reporting and risk communication
- Legal and ethical compliance in authorized testing (scope, ROE, NDA)
Related certifications
- Stacks with: CompTIA Security+ (SY0-701) ↗ + CompTIA PenTest+ (PT0-002) ↗
- Pathway to: CompTIA Network Security Professional (CNSP) ↗ — add CySA+ to extend CNVP into broader monitoring/threat-hunting stack
- Adjacent roles: GIAC Certified Ethical Hacker (CEH) ↗, Offensive Security Certified Professional (OSCP) ↗
- Vendor overview: CompTIA Overview ↗
Sources
- CompTIA Stackable Certifications: https://www.comptia.org/certifications/which-certification/stackable-certifications
- CompTIA Security+ (SY0-701): https://www.comptia.org/certifications/security
- CompTIA PenTest+ (PT0-002): https://www.comptia.org/certifications/pentest
- CNVP Digital Badge (Credly): https://www.credly.com/org/comptia/badge/comptia-network-vulnerability-assessment-professional-cnvp-stackable-certification
- PayScale Penetration Tester (US): https://www.payscale.com/research/US/Job=Penetration_Tester/Salary
- Glassdoor Penetration Tester (US): https://www.glassdoor.com/Salaries/penetration-tester-salary-SRCH_KO0,18.htm
- Indeed Penetration Tester (US): https://www.indeed.com/career/penetration-tester/salaries
- PayScale Penetration Tester (ZA): https://www.payscale.com/research/ZA/Job=Penetration_Tester/Salary
- SalaryExpert Penetration Tester (ZA): https://www.salaryexpert.com/salary/job/penetration-tester/south-africa
- Glassdoor Penetration Tester (Cape Town): https://www.glassdoor.com/Salaries/cape-town-penetration-tester-salary-SRCH_IL.0,9_IM1026_KO10,28.htm
- PayScale Penetration Tester (UK): https://www.payscale.com/research/UK/Job=Penetration_Tester/Salary
- IT Jobs Watch (UK): https://www.itjobswatch.co.uk/jobs/uk/penetration%20tester.do
- Glassdoor Penetration Tester (UK): https://www.glassdoor.co.uk/Salaries/penetration-tester-salary-SRCH_KO0,18.htm
- CompTIA Exam Costs 2026: https://www.stationx.net/comptia-certifications-cost/
- CompTIA Security+ SY0-701 Study Guide (Sybex): https://www.wiley.com/en-us/CompTIA+Security%2B+Study+Guide%3A+Exam+SY0-701-p-9781119906207
- CompTIA PenTest+ PT0-002 Study Guide (Sybex): https://www.wiley.com/en-us/CompTIA+PenTest%2B+Study+Guide%3A+Exam+PT0-002-p-9781119906886
- The Web Application Hacker's Handbook (Wiley): https://www.wiley.com/en-us/The+Web+Application+Hacker%27s+Handbook%3A+Finding+and+Exploiting+Security+Flaws%2C+2nd+Edition-p-9781118026359
- Penetration Testing Hands-On (No Starch): https://nostarch.com/penetrationtesting
- Professor Messer Security+ Playlist: https://www.youtube.com/playlist?list=PLMYfBzPqLp74u3iHEhAm4YV2BxJ2LFZoY
- Professor Messer PenTest+ Playlist: https://www.youtube.com/playlist?list=PLMYfBzPqLp75BXqB8aYNUfgvKQiJf-C6H
- Boson ExSim Security+ Practice: https://www.boson.com/practice-exam/sy0-701-security-plus-practice-exam
- Boson ExSim PenTest+ Practice: https://www.boson.com/practice-exam/pt0-002-pentest-plus-practice-exam
Last verified: 2026-05-01 Parent ecosystem: CompTIA Stackable Certifications Parent domain: Security / Vulnerability Assessment Vendor overview: CompTIA Overview