Certified Tester - Application
CREST logo

Certified Tester - Application

CCT APP

Validate your application security skills with CREST's Certified Tester - Application. A globally recognized penetration testing certification.

Exam syllabus, organized by domain

Syllabus overview

Exam summary

The CREST Certified Tester - Application (CCT APP) certification validates advanced skills in application security testing, including web application penetration testing, vulnerability identification, and exploitation. It is designed for experienced penetration testers who can demonstrate hands-on ability to identify and exploit application-level vulnerabilities under realistic conditions. The certification is divided into written and practical examination components, testing both theoretical knowledge and real-world application security skills. Achieving CCT APP demonstrates a tester has met rigorous industry standards set by CREST, a globally recognized not-for-profit accreditation body. The certification covers the OWASP Top 10, advanced exploitation techniques, and professional reporting standards. Candidates must understand secure coding principles and have the ability to comprehensively test web applications, APIs, and mobile app backends. The practical exam typically lasts three hours and requires candidates to identify multiple vulnerabilities across a complex target application. The certification must be renewed every three years through continuing professional development activities. CREST certifications are particularly valued in the UK, Europe, Australia, and Asia-Pacific regions for both government and commercial sector engagements.

Mastery levels

Frequently asked questions

Key facts about the Certified Tester - Application certification and how to prepare for it.