BSCP
MEDIUM
Web Security PortSwigger Industry Standard

BSCP

Burp Suite Certified Practitioner

Price

$99

Exam

4 Hours

Valid For

5 Years

Format

Proctored

Reviewed & Verified By

1 What is BSCP?

The Burp Suite Certified Practitioner (BSCP) is PortSwigger's official web security certification. It validates your ability to identify and exploit real-world web vulnerabilities using Burp Suite Professional.

The exam is 100% hands-on-no multiple choice. You get 4 hours to compromise two web applications, each with three sequential stages. You must complete all six stages to pass; five out of six is a fail.

2026 Update: BSCP has become the gold standard for web application security certifications. At just $99 per attempt, it offers incredible value. The free Web Security Academy training is world-class, and employers increasingly recognize BSCP as proof of practical web security skills.

Why BSCP Matters in 2026

Web applications are everywhere, and so are their vulnerabilities. BSCP proves you can actually find and exploit them-not just answer questions about theory. Bug bounty hunters, pentesters, and security engineers all benefit from this certification.

The Good

  • Free training via Web Security Academy
  • Affordable exam ($99 per attempt)
  • Open book-use notes, internet, tools
  • Practical, real-world vulnerabilities
  • Highly respected in web security

The Tough

  • Requires Burp Suite Pro ($499/year)
  • 4-hour time limit is tight
  • No partial credit-all or nothing
  • Proctored exam environment
  • 203 labs to complete for prep

2 Exam Structure

Exam Format

  • Two deliberately vulnerable web applications
  • 2 hours per application (4 hours total)
  • 3 stages per app = 6 stages total
  • Must complete ALL 6 stages to pass
  • Open book, proctored via webcam

What's Allowed

  • Burp Suite Professional (required)
  • Any BApp extensions
  • Third-party tools (ysoserial, etc.)
  • Internet access for research
  • Your notes and cheatsheets

💡 Pro Tip: Don't use more than 2 monitors-it can cause proctoring issues. Allocate ~35-45 minutes per stage and stick to it. If you're stuck, move on and come back.

🧠 Exam Strategy (What Actually Works)

These insights come from someone who passed BSCP with 50 minutes to spare. Here's what actually worked:

1. Don't jump to complex exploits early

Don't look for OS Command Injection on the login page. Start from the basics-try to get into a user account first. The exam has a logical flow. Complete the first step before moving to the second. Jumping to "big exploits" early just wastes time.

2. No directory brute-forcing needed

I didn't run gobuster or ffuf even once. If you need directory discovery, use Burp's Content Discovery tool-that's more than enough.

3. Intercept and analyze everything

Seriously. Watch every request, every parameter. The vulnerability is almost always hiding in plain sight. Don't skip intercepting requests-lab practice builds that sixth sense.

4. Lab patterns repeat-you'll start recognizing them

For example:

  • Advanced search filters often have SQL injections
  • Search boxes that reflect input → test for XSS or SSTI

5. Two users minimum

Every exam app will likely involve Carlos and an Administrator. Use the Academy's default wordlists for username & password brute-force. Don't overthink this-stick to what worked in the labs.

6. Don't mess with lab or lab-analytics cookies

These are for exam functionality. Don't waste time trying to tamper with them-you're barking up the wrong tree.

7. Maintain a personal cheat sheet

During prep, make notes for:

  • XXE payloads (external DTDs, file reads)
  • Deserialization (keep ysoserial handy)
  • SQL injection (null-based, blind, error-based)
  • SSTI (Jinja2 tricks, etc.)
  • Cookie manipulation examples

In the exam, you don't have time to Google every payload.

8. Scanner & Intruder are your best friends

Found reflected input? Set up Intruder, define insertion points, and run a targeted scan (XSS, SQLi only). Don't go full-blast with all checks-it'll just slow things down.

9. Assume misconfigurations. Try "stupid" things

I ignored a bypass because I thought, "No way this will work." Guess what? It worked. Remember: It's a deliberately broken lab. Even "dumb" things can be valid exploits.

📝 Real Exam Experience

The exam structure follows exactly what you see in the Exam Preparation Path-no crazy rabbit holes, no unexpected CVEs. Just good old-fashioned web security bugs: SQL injections, broken access controls, IDORs, privilege escalations.

The key is chaining them logically and not wasting time on overcomplicated routes. Both applications followed familiar patterns from the Academy labs.

Time management: Finishing all six tasks with 50 minutes to spare is achievable if you stay focused. Use extra time to double-check steps and replay requests.

Pro tip: Create request groups in Repeater for App 1 and App 2. Save Intruder logs to your project file. Zip everything before submitting.

💡 Bottom line: The exam rewards methodical thinking and pattern recognition from lab practice. If you've solved the Academy labs (especially Mystery Labs), you'll recognize the attack patterns. Trust your prep and don't overthink.

3 The 3 Stages

Each application has three sequential stages. You must solve them in order-you can't skip ahead.

1 Get Access to Any User Account

Log in as ANY non-admin user (not always "carlos")

XSS DOM Vulnerabilities Authentication Flaws Web Cache Poisoning Host Header Attacks Request Smuggling

2 Escalate to Admin or Steal Data

Reach /admin or compromise the administrator account

SQL Injection CSRF Insecure Deserialization OAuth Flaws JWT Attacks Access Control

3 Read the Secret File

Read /home/carlos/secret and submit it

SSRF XXE SSTI Path Traversal File Upload OS Command Injection

4 Study Resources

Official Resources

GitHub Study Repos

Video Content

Lab Requirements

  • • Apprentice labs: 52 (all required)
  • • Practitioner labs: 151 (all required)
  • • Expert labs: 36 (optional but helpful)

📋 BSCP Exam Cheatsheet

21 sections covering all exam vulnerabilities with copy-paste payloads ready for the exam.

5 BSCP vs OSWE

Aspect BSCP OSWE
Price $99 + Burp Pro ($499/yr) $1,649+
Exam Duration 4 hours 48 hours
Focus Exploitation Code review + exploitation
Proctored Yes No
Training Cost FREE Included in price
Best For Bug bounty, pentesting Advanced web security

💡 Bottom line: BSCP is the best entry point for web security. It's affordable, practical, and respected. OSWE is harder and more comprehensive, but also more expensive. Many people do BSCP first, then OSWE later.

6 FAQ

Do I really need Burp Suite Pro?

Yes, Burp Suite Community Edition is not sufficient. The exam requires Pro features like the scanner and certain extensions. Budget $499/year for the license.

How long does preparation take?

Most people need 2-4 months to complete all 203 labs (52 Apprentice + 151 Practitioner). Do 2-3 labs per day consistently. Expert labs are optional but valuable.

Is the practice exam worth it?

Absolutely! The practice exam is structurally identical to the real exam. Take it multiple times until you're consistently passing. It's the best predictor of exam success.

What happens if I fail?

You can retake immediately for another $99. There's no waiting period. Many people fail the first attempt-it's a tough exam. Use the experience to identify weak areas.

Is BSCP recognized by employers?

Yes, especially in web security and bug bounty contexts. PortSwigger is the creator of Burp Suite, so the certification carries significant weight. It's increasingly listed in job requirements.

Start Your BSCP Journey

The Web Security Academy is free-start today. Connect with others preparing for BSCP.