Get a Proposal → 💬 WhatsApp Us
💻 Information Technology  ·  Executive

Certified Penetration Testing Expert

Online Certification  ·  12 Week  ·  Globally Recognised  ·  (CPEN2)

✅ 2026 Edition 🎓 CPD Accredited 🌍 100+ Countries 📜 Digital + Physical Certificate 100% Online
Executive Summary

Certified Penetration Testing Expert

Designed for today’s high-impact professionals, the Certified Penetration Testing Expert (CPEN2) delivers a rigorous Executive-level curriculum that equips participants with the knowledge, tools and frameworks needed to excel in information technology, software, data and digital systems.

This 12 Week programme is structured around ITIL, ISO/IEC and recognised technology and cybersecurity standards, ensuring every graduate applies internationally validated methods to real-world challenges.

GLI’s CPEN2 holders are recognised by leading organisations across Africa, the Gulf, Europe and the Americas as qualified, results-driven professionals. Whether you are advancing your current career or transitioning into new responsibilities, this certification provides the competitive edge you need in 2026 and beyond.

Programme Overview

Certification at a Glance

Certification
Certified Penetration Testing Expert
Acronym
CPEN2
Category
Information Technology
Level
Executive
Duration
12 Week
Delivery Mode
100% Online
Assessment
Online Examination
Certificate
Digital + Physical
CPD Eligibility
CPD Accredited
Alumni Benefits
GLI Network Access
Self-Paced
USD 399
Live Virtual
USD 599
Target Audience

Who Should Enrol?

  • Access, Identity and Privilege — applied to your own work
  • Protecting Personal Data — applied to your own work
  • Infrastructure and Exposure — applied to your own work
  • Building Security into Requirements — applied to your own work
  • Response, Recovery and Lifecycle — applied to your own work
  • Fundamentals and the Human Factor — applied to your own work
Programme Inclusions

Everything Included in Your Enrolment

  • All study materials and study guide
  • Access to GLI online learning portal
  • Online examination and assessment
  • Digital certificate and digital badge
  • Physical certificate (shipped to you)
  • CPD credits for professional bodies
  • GLI alumni network membership
  • Facilitator and tutor support
  • Resource downloads and reference library
  • Automatic enrolment confirmation
Certification Benefits

Why This Certification Matters for Your Career

Career Advancement
Accelerate your career towards senior engineering, architecture and IT leadership roles
Professional Recognition
Credential aligned with ITIL, ISO/IEC and recognised technology and cybersecurity standards
Operational Excellence
Apply world-class frameworks to improve performance and outcomes
Strategic Thinking
Develop the analytical and strategic skills demanded at the executive level
Compliance Readiness
Master the standards, compliance and ethical governance central to information technology
Global Employability
Qualify for information technology roles across technology firms, corporates, startups and public institutions worldwide
Competency Framework

Core Competencies You Will Develop

Systems, Architecture and Infrastructure
Software Development and Application Delivery
Data, Analytics and Emerging Technologies
Networks, Cloud and Platform Engineering
IT Service Management and Governance
Professional Ethics and Governance
Course Curriculum

Programme Modules

Click any module to explore the detailed curriculum topics included in this certification.

1
Foundations and Strategic Context of Certified Penetration Testing Expert
  • Certified Penetration Testing Expert: industry context, trends and professional standards
  • Computing fundamentals and IT concepts
  • The role of IT in business and value creation
  • IT operating models and organisation
  • Hardware, software and systems overview
  • The technology landscape and trends
  • IT professional roles and standards
  • Digital transformation and IT strategy
  • Ethics, responsibility and digital citizenship
  • IT service and product mindset
  • Career pathways and professional development
2
Access, Identity and Privilege
  • Correlation, causation and experiment design
  • Systems integration and the single source of truth
  • Cloud, infrastructure and the connectivity constraint
  • Automation and where it genuinely pays
  • Analytical techniques and bias
  • Measuring ERP value
  • Managing technology teams and technical work
  • Interpreting financial statements
  • Reporting quality and governance
  • Management accounts and dashboards
  • Performance and optimisation
  • Budget vs actual and variance
  • Cost and profitability analysis
  • Forecasting and planning
  • Smart contracts and dApps
3
Protecting Personal Data
  • Data protection and privacy by design
  • Cybersecurity fundamentals and the human factor
  • Data quality and the fitness-for-purpose test
  • Data visualisation for finance
  • Communicating financial results
  • Professional roles, boundaries and settings
  • Innovation management and R&D
  • Ethical principles and codes of practice
  • Ethical and responsible technology
  • IT service management and ITIL
  • Service strategy, design and transition
  • Incident, problem and change management
  • Managing boundaries and dual relationships
  • Peer support and consultation
  • Configuration and asset management
4
Infrastructure and Exposure
  • Cloud, infrastructure and the connectivity constraint
  • Cybersecurity fundamentals and the human factor
  • Technical debt and system lifecycle
  • Continuous improvement and DevOps metrics
  • Sustaining ethical, effective practice
  • Ethical frameworks and codes of practice
  • Driving measurable IT improvement
  • The business analysis discipline and role
  • Record-keeping and data protection
  • Process modelling and mapping
  • Complaints, accountability and fitness to practise
  • Stakeholder and gap analysis
  • Data and information requirements
  • Legal responsibilities and professional bodies
  • Client feedback and satisfaction
5
Building Security into Requirements
  • Requirements and the specification gap
  • Cybersecurity fundamentals and the human factor
  • Data protection and privacy by design
  • System performance and reliability metrics
  • Quality, defects and reliability
  • Managing scope and change
  • Bridging business and technology
  • Capstone scoping: a real technology problem
  • Requirements and analysis
  • Designing a technical solution or system
  • Risk, security and feasibility analysis
  • Evidence-based improvement
  • Lessons learned and development
  • Driving effective, ethical outcomes
  • Data structures and algorithms
6
Response, Recovery and Lifecycle
  • Technical debt and system lifecycle
  • Cybersecurity fundamentals and the human factor
  • Delivering technology change that people adopt
  • Containerisation and Kubernetes
  • Serverless and microservices
  • Platform engineering and reliability (SRE)
  • Monitoring, observability and logging
  • Network security and zero trust
  • Cost, performance and capacity management
  • ETL/ELT and data pipelines
  • Big data platforms (Spark, Hadoop)
  • Streaming and real-time data
  • Data architecture and integration
  • Cloud data platforms
  • Statistics and exploratory data analysis
7
Fundamentals and the Human Factor
  • Cybersecurity fundamentals and the human factor
  • Data protection and privacy by design
  • Delivering technology change that people adopt
  • Designing and facilitating groups
  • Psychoeducation and workshops
  • Cost, performance and FinOps
  • Working with organisations on wellbeing
  • IT operations and service management
  • Designing an intervention or programme
  • Ethical, risk and feasibility considerations
  • Incident and problem management
  • Professional case study and presentation
  • Patching and change management
  • Evidence-based practice
  • Performance tuning and optimisation
8
Legal and Regulatory
  • Data ethics, privacy and protection
  • Regulatory awareness (GDPR and beyond)
  • Vendor, contract and asset management
  • Regulatory and privacy requirements
  • Risk and regulatory considerations
  • Data privacy and protection
  • Visitor and contractor management
  • Data protection in surveillance
  • Legal and ethical investigation
  • Guard force and contractor management
  • Legal and ethical protection
  • Regulatory liquidity ratios (LCR, NSFR)
  • Regulatory compliance in operations
  • Regulatory capital for credit
  • Recovery and legal remedies
9
Delivery and Projects
  • Continuous improvement in delivery
  • IT project and portfolio management
  • Leading IT projects and change
  • Project governance and risk
  • Agile delivery and iterative development
  • Agile and product operating models
  • Programme management principles
  • Programme governance and assurance
  • Measuring programme success
  • Leading project teams
  • Risk assessment and safety planning
  • Route planning and optimisation
  • Sales and operations planning (S&OP)
  • Planning performance and service
  • Continuous improvement of delivery
10
Leadership and Decisions
  • Turning insight into decisions
  • Scaling technology and teams
  • CI/CD and release management
  • Risk management and security frameworks
  • IT financial management and value
  • Team leadership in technology
  • Identity and access management
  • Vulnerability management
  • Cyber risk management
  • Training and change management
  • Vendor and partner management
  • Supervised and unsupervised learning
  • Upgrades and roadmap management
  • Turning analysis into a decision
  • IT service management and support operations
11
Capability and Training
  • Web and mobile application development
  • Software development lifecycle (SDLC)
  • Front-end and back-end development
  • Artificial intelligence: capability, limits and responsible use
  • Building digital capability in an organisation
  • Version control and collaborative development
  • Managing resistance and capability building
  • Category management and strategy development
  • Supplier development and improvement
  • Real estate development and project appraisal
  • Proposal development and donor reporting
  • Knowledge management and capability building
  • Creating a coaching culture
  • Delegating for development
  • Attachment and developmental theory
12
Change and Adoption
  • Digital transformation strategy
  • Managing resistance and upskilling
  • Measuring digital transformation impact
  • Digital transformation roadmaps
  • User adoption and change
  • Data literacy and adoption
  • Habit change and behaviour design
  • Change control and configuration
  • Organisational change management
  • Change and adoption in projects
  • Agile and digital transformation projects
  • Measuring CX transformation impact
  • Digital transformation in banking
  • Managing resistance and reskilling
  • Foreign exchange and treasury operations
13
Operations and Service
  • Natural language processing
  • Self-service analytics
  • APIs and service design
  • Quality assurance and code review
  • Continual service improvement
  • Incident response process
  • ERP concepts and business processes
  • Process optimisation and RPA
  • Testing, quality assurance and defect economics
  • Software design patterns and quality
  • The procurement cycle and operating models
  • Service quality and the passenger experience in transport
  • Tariffs, regulation and the economics of essential services
  • Mineral processing and beneficiation
  • Quality management on site: inspections, hold points and defects
14
Cost and Investment
  • Finance, procurement and supply modules
  • Roadmapping and investment
  • Innovation and technology investment
  • Goal setting and contracting
  • Impact, blended and concessional finance
  • Total cost of ownership
  • Investment principles and objectives
  • Investment strategy and allocation
  • Alternative investments
  • Financial risk types and management
  • Fleet management and costs
  • Legal, cost and feasibility analysis
  • Make-versus-buy and total cost of ownership
  • Cost and price analysis
  • Investigation principles and process
15
Stakeholders and Vendors
  • Stakeholder mapping and business partnering
  • Presenting and influencing
  • Negotiation with vendors
  • ERP platforms and vendors
  • Vendor selection and managing technology suppliers
  • Data products and stakeholder value
  • Categories of spend and stakeholders
  • Vendor and technology management
  • Strategic customer relationships
  • Vendor, venue and supplier contracting for events
  • Subcontractor and supplier management
  • Negotiation and influencing
  • Relationship management and cross-selling
  • Wealth, SME and corporate relationships
  • Stakeholder communications
16
Communication and Documentation
  • Professional and technical documentation
  • Cryptography and secure communications
  • Reporting and enterprise analytics
  • Dashboards, reporting and the metric that misleads
  • Data storytelling and communicating findings
  • Business intelligence and reporting
  • Vehicle documentation, compliance and consumer protection
  • The media and telecommunications landscape
  • Treatment planning and review
  • Financial reporting frameworks (IFRS/GAAP)
  • Integrated and sustainability reporting
  • Board reporting and information flows
  • Governance of ESG and reporting
  • Management and board reporting
  • Safety communication and campaigns
17
Users and Customers
  • Scaling innovation to production
  • Digital user experience and accessibility
  • Managing user and customer expectations
  • Comparable sales analysis and market evidence
  • Insurance products and lines of business
  • Policy administration and customer service in insurance
  • Destination, venue and experience products
  • Event planning timelines, run sheets and production schedules
  • Vehicle specifications, trims and options in customer language
  • Customer retention in the vehicle ownership cycle
  • Maintenance in production: preventive, predictive and breakdown
  • Customer experience transformation
  • Professional ethics in customer service
  • Customer service and CX strategy
  • Designing voice-of-customer programmes
18
Strategic Context
  • IT strategy and business alignment
  • Business models for new tech
  • Ethics and responsible innovation
  • Innovation and experimentation culture
  • Data-driven and platform business models
  • Automated testing strategies
  • Emerging threats and defensive strategy
  • Procurement’s contribution to organisational strategy
  • Sourcing strategies and portfolio (Kraljic)
  • Negotiation strategy and planning
  • Manufacturing strategies: make-to-stock, make-to-order and batch versus flow
  • Designing a marketing or sales strategy
  • Marketing strategy and the mix
  • Brand strategy, identity and equity
  • Pricing strategy
19
Security
  • Awareness and security culture
  • Cloud and data security
  • Security by design
  • Managing complexity and comorbidity
  • Data security and confidentiality
  • Fraud risk and controls
  • Valuation and security analysis
  • Security governance and management systems
  • Ethics and professional conduct in security
  • Physical security design and layered defence
  • Security intelligence collection and analysis
  • Workplace and organisational contexts
  • Cybersecurity and fraud technology
  • Digital forensics and cybercrime
  • Security operations management
20
Performance Measurement
  • Performance and load testing
  • Measuring IT value and performance
  • System performance and tuning
  • KPIs and metric design
  • Scalability, availability and performance
  • IT KPIs, SLAs and scorecards
  • Concurrency and performance
  • Social performance and outreach
  • Credit risk measurement
  • Performance measurement and attribution
  • Logistics KPIs and cost control
  • Coaching for performance
  • Banking KPIs and branch scorecards
  • Credit risk measurement and mitigation
  • Sales performance and pipeline management
21
Procurement and Supply
  • Third-party and supply-chain risk
  • Procurement and contract management
  • Supply market analysis
  • Supply-network design
  • Supply analysis, gaps and scenario planning
  • Procurement and supply chain: scope and value
  • Public versus private procurement
  • Supply markets and the enabling environment
  • Digital procurement and the future of the profession
  • Sustainable procurement principles and standards
  • Fair trade and responsible supply
  • Change talk and readiness
  • Goal setting and action planning
  • Procurement and stock management for health commodities
  • Conflicts of interest and procurement ethics
22
Workforce
  • Employee engagement models and drivers
  • The employee lifecycle and HR value chain
  • Workforce and shift management in retail
  • Workforce management and scheduling
  • Workforce planning and scheduling
  • Employee experience and engagement
  • Customer and employee satisfaction
  • Employee engagement and what actually drives it
  • Talent, succession and workforce learning
  • Applicant tracking systems and recruitment analytics
  • Digital HR and the employee experience platform
  • Employee relations, discipline and fair process
  • Workforce planning and the capability gap
  • Belonging, culture and employee resource groups
  • Future of work and workforce transformation
23
Ethics and Standards
  • Digital ethics and algorithmic accountability
  • Professional ethics in technology
  • Embedding responsible business
  • Ethics, confidentiality and professional conduct in HR
  • Data ethics, privacy and responsible analytics
  • Ethics and duty of care
  • Professional ethics and duty of care
  • Legal and regulatory responsibility
  • Ethical decision-making under pressure
  • Sustainability and climate responsibility
  • Ethics and responsible leadership
  • Professional standards and ethics (CIPS)
  • Sustainability and responsible sourcing
  • Corporate responsibility and community
  • Ethics and treating customers fairly in insurance
24
Sustainability
  • Sustainability and green IT
  • Responsible and sustainable governance
  • ESG principles and frameworks
  • Sustainability strategy and materiality
  • Environmental governance and climate risk
  • Sustainability standards (GRI, ISSB)
  • Accountability and follow-through
  • Sustainability and environmental duty
  • Environmental management systems (ISO 14001)
  • Environmental legal compliance
  • Continuous environmental improvement
  • Monitoring, evaluation and sustainability plan
  • Sustainability certification and standards
  • Responsible and sustainable banking
  • Sustainable and green banking
25
Learning and Knowledge
  • Deep learning and neural networks
  • Training needs analysis and learning strategy
  • Instructional design and blended learning
  • Learning technologies and the LMS
  • Learning transfer and capability building
  • Monitoring, evaluation and learning for accountability
  • Lessons learned and knowledge management
  • Wellbeing and resilience coaching
  • Complaint data and learning
  • Instructional design models (ADDIE, SAM)
  • Cognitive load and learning science
  • Motivation and self-directed learning
  • Learning strategy and roadmaps
  • Building the learning brand
  • Aligning learning to performance
26
Health and Safety Context
  • Driving measurable safety improvement
  • Designing a safety programme or control
  • Job safety analysis (JSA) and task risk
  • Measuring coaching outcomes
  • Contractor and visitor safety
  • Predictive safety analytics
  • Automation and safety technology
  • Resilience, wellbeing and stress management
  • Event risk, safety and contingency planning
  • Industrial utilities, energy and process safety interfaces
  • Strengths, flow and engagement
  • Customer and brand health metrics
  • Brand health and measurement
  • Regulatory compliance and biosafety
  • Feedback, challenge and psychological safety in coaching
27
Technology Foundations
  • Big data technologies and platforms
  • Network design, LAN/WAN and topologies
  • Systems analysis, design and modelling
  • Digital accessibility and inclusion
  • Emerging-technology evaluation
  • LAN, WAN and network design
  • Technology selection and deployment
  • Equipment and technology
  • Bancassurance and digital insurance models
  • How networks work: from fibre and towers to the customer
  • Telehealth and digital care delivery
  • Drones, sensors and detection technology
  • Meaning, purpose and values
  • Practice management systems
  • Ethics of technology in practice
28
Data and Evidence
  • Predictive and prescriptive analytics
  • Servers, storage and data centres
  • Metrics, velocity and flow
  • Master data and configuration
  • Data and interoperability
  • Data modelling and database design
  • NoSQL and modern data stores
  • Data warehousing and data lakes
  • ETL, data pipelines and engineering
  • Data analytics and visualisation
  • Evaluation metrics and monitoring
  • Dashboards and data storytelling
  • Decision support and insight
  • Psychodynamic and psychoanalytic approaches
  • Outcome and process measures
29
Governance and Risk
  • Governance, compliance and standards (ISO 27001)
  • IT governance frameworks (COBIT)
  • Enterprise architecture governance
  • Risk, compliance and audit
  • Compliance and audit in ERP
  • Governance, risk and compliance
  • In-process quality control and inspection
  • Ground control and strata management
  • Evidence-based practice and research literacy
  • Duty of care and risk management
  • Managing risk and difficult cases
  • Data, records and confidentiality tech
  • Model risk and provisioning (IFRS 9)
  • Regulatory compliance and central-bank rules
  • Regulatory reporting and audits
30
Professional Leadership Practice
  • Locks, keys and credential management
  • Report writing and case management
  • Key account management
  • Travel risk management
  • Journey management and tracking
  • Property management and facility operations
  • Programme cycle management in NGOs
  • Grant compliance and restricted funding management
  • Reinsurance and capacity management
  • Disruption management: delays, claims and recovery
  • Energy efficiency and demand management
  • Renewals and churn management
  • Field sales and territory management
  • Tender and bid management
  • Reporting to leadership
Learning Outcomes

What You Will Achieve

  • Access, Identity and Privilege — applied to your own work
  • Protecting Personal Data — applied to your own work
  • Infrastructure and Exposure — applied to your own work
  • Building Security into Requirements — applied to your own work
  • Response, Recovery and Lifecycle — applied to your own work
  • Fundamentals and the Human Factor — applied to your own work
Enrolment Process

How to Get Certified

🎯
Step 1: Choose Your Certification
You are viewing Certified Penetration Testing Expert — one of GLI's 1,990+ globally recognised professional certifications.
💳
Step 2: Enrol & Pay Online — Instantly
Click Enrol & Study Online to register and pay securely via Paystack, Visa, Mastercard, M-Pesa or bank transfer. Access is granted the moment payment is confirmed.
📚
Step 3: Study in the GLI Learning Portal
Work through 30 structured modules and 150 lessons at your own pace, with downloadable resources and expert-designed content — all inside the LMS.
🎓
Step 4: Pass, Get Certified & Verified
Sit your final examination online, earn your certificate instantly, and receive a globally verifiable Certificate ID — plus GLI Alumni Network access.
🎓 Enrol & Study Online — Instant Access
Secure checkout · Instant LMS access · Globally verifiable certificate
Frequently Asked Questions

Common Questions

What is the CPEN2 certification?

Yes. GLI certifications are recognised across 100+ countries and are aligned with ITIL, ISO/IEC and recognised technology and cybersecurity standards. Graduates receive a digital certificate, a physical certificate and CPD credits recognised by employers worldwide.

Who should enrol in the CPEN2?

This certification is ideal for IT and Systems Professionals, Software Developers and Engineers, Data and Analytics Specialists and IT Managers and Solution Architects, and other professionals seeking to formalise their expertise in information technology, software, data and digital systems with a globally recognised credential.

How long does the CPEN2 certification take to complete?

The programme is structured over 12 Week and offers flexible learning modes. Self-paced learners can progress at their own schedule, while live virtual participants follow a structured cohort schedule with facilitator-led sessions.

Is the CPEN2 internationally recognised?

Yes. GLI certifications are recognised across 100+ countries and are aligned with ITIL, ISO/IEC and recognised technology and cybersecurity standards. Graduates receive a digital certificate, a physical certificate and CPD credits recognised by employers worldwide.

What is the cost of the CPEN2 certification?

The Certified Penetration Testing Expert is offered in two formats: Self-Paced at USD 399 and Live Virtual at USD 599. Corporate group rates are available for organisations enrolling 5 or more participants. Contact GLI for a bespoke corporate training quotation.

What does the CPEN2 certification include?

Enrolment includes all study materials and study guides, access to GLI's online learning portal, online examination, digital certificate and badge, physical certificate (posted), CPD credits, GLI alumni network membership, and ongoing facilitator support.

What is the assessment format for the CPEN2?

The Certified Penetration Testing Expert is assessed through an online examination consisting of multiple-choice questions, case study analysis, and practical application assignments. The assessment is designed to evaluate real-world competency, not just theoretical recall.

What CPD credits do I earn from the CPEN2?

The Certified Penetration Testing Expert carries Continuing Professional Development (CPD) credits, which can be applied towards professional body requirements including recognised international professional associations.

Can I study the CPEN2 while working full-time?

Absolutely. The self-paced option is designed for busy working professionals and allows you to study when and where it suits you. Live virtual sessions are typically scheduled in the evenings or on weekends to accommodate professional commitments.

What career outcomes can I expect from the CPEN2?

Graduates progress towards senior engineering, architecture and IT leadership roles. The CPEN2 strengthens your expertise in information technology, software, data and digital systems and positions you for advancement across technology firms, corporates, startups and public institutions.

Graduate Voices

What Our Alumni Say

The curriculum was directly applicable to my daily work. I immediately applied what I learned and saw results within weeks of completing the programme.

IT Director
Private Sector

GLI's certification is the most practical professional programme I have attended. The international frameworks gave me credibility with my employer and clients.

Solutions Architect
NGO Sector

I earned my CPEN2 while working full-time. The self-paced format made it possible, and the quality of the content is genuinely world-class.

Data Lead
Government
Related

You May Also Like

All Information Technology Certifications →
💬 WhatsApp 📝 Proposal
💬