GWAPT Wasn't Worth the Money for Me, But Might Be Worth It to Get Hired
An honest review of the GWAPT certification's actual value, how little I studied for it, and why I still don't think teaching you something is the point of a certification.
I want to be honest about the GWAPT (GIAC Web Application Penetration Tester) certification, since the marketing around it doesn’t quite match the reality I experienced, at least not for where I was in my career when I took it. You can view my actual badge on Credly if you want to see it firsthand.
The Cost
The exam itself runs $999 as a standalone attempt (a retake is $899, and renewing it every four years is another $499), and that’s before you factor in the SANS course it’s normally paired with. SEC542 currently lists at $8,780 on its own. Pricing has clearly crept up since I took the cert, so the ~$7,000 I remembered may well have been accurate at the time. Either way, I didn’t take the course, I just sat the exam. My company paid for it, and I’m genuinely grateful and fortunate to work somewhere that encourages self-development and puts money behind it. That made the whole thing an easy call.
How I Actually Studied
I didn’t study for this exam so much as I prepared for it the night before. GWAPT is open-book, so the whole “studying” process was really just building a good reference sheet:
- Took one practice test.
- Printed out the topics I got wrong or wasn’t confident on.
- Skimmed those printouts the night before the exam.
That’s it. All in, including the actual testing time, I probably spent about four hours on the entire certification, which felt like a solid return given how many years of hands-on experience I was already bringing to it.
Taking the Exam
Because it’s open-book, you’re allowed to bring in printed notes and reference material, which is exactly why the “studying” step above worked as well as it did. Having my weak spots printed out and in front of me during the test genuinely helped. It also meant the exam was testing whether I could find the right answer in my notes, not whether I knew the material cold, which is a fair tradeoff for a practitioner-level cert aimed at people already doing the work.
What I Actually Got Out of It
By the time I sat for GWAPT I’d already been a pentester for about three years, so I was walking in with a lot more real-world web app testing experience than the exam was built to measure. I didn’t come away having learned much new material, but that’s really a function of timing more than a knock on the cert itself.
I went looking for GIAC’s own stated prerequisites to see if that assumption was fair, and there really aren’t any. GIAC’s GWAPT page doesn’t list a formal experience requirement at all, just exam mechanics (82 questions, 3 hours, 71% to pass). SANS rates the paired SEC542 course as “Intermediate” skill level, but the actual prerequisite listed is just “basic working knowledge of the Linux command line,” not years of pentesting. The “you should have a couple years of experience first” expectation is really just an informal industry norm (third-party aggregators like Navy COOL peg it around 2+ years), not something GIAC or SANS actually gatekeeps on.
GWAPT is probably a much bigger lift, and probably teaches a lot more, if you’re newer to the field and pairing it with the course it’s designed to go with. For where I was, it worked more like a formal stamp on skills I already had.
Takeaways
- Certifications certify. They don’t teach. I knew the material before I sat for GWAPT, and I still know it now, whether or not the certification itself is current.
- The value of a certification is mostly in the prep process, not the credential. I barely had a prep process here, and that tracks with how experienced I already was going in.
- The resume checkbox and the learning are two separate transactions. Even without learning much new, having GWAPT on my resume is worth something to recruiters and hiring managers who are scanning for it. That’s a legitimate reason to get it on its own.
- If your company is footing the bill, there’s very little downside to taking a well-regarded cert like this, even years into your career. If you’re footing the bill, the SEC542 course itself will genuinely be better, but there are likely better and cheaper courses out there if you shop around instead of defaulting to SANS.
