CSTM Exam: The Straight‑Up Guide
NOTE 2: As to keep the exam fair for everyone, this guide will not disclose anything that is not already publicly accessible on The Cyber Scheme's website. However, I aim to provide more insight into what to expect on the day to help participants feel more confident, and any techniques that will helpful in tackling the exam
Introduction
The Cyber Scheme Team Member (CSTM) Exam is becoming increasingly popular in the UK. Due to the requirements to perform CHECK penetration testing services, the CSTM is the quickest way forward into achieving this. The CSTM also allows you to become a Cyber Essentials Plus Lead Assessor, another scheme owned by the National Cyber Security Centre (NCSC), which is also in high demand.
The CSTM exam is aimed to be introductory and focused for beginners, but this does not mean that it is not challenging.
You are expected to know what the vulnerabilities you discover are, how they work, and what the business implications of them to an organisation are. You NEED to know this. If you fail to explain how you discovered something, you cannot evidence your findings, or fail to explain how that vulnerability works, you run the risk of losing points or failing the exam altogether. This means that your technical ability needs to be just as good as your practical ability.
Personally, I sat and accomplished the Cyber Scheme Team Member certification in November of 2025. While preparing for this exam, there was very little online about what to expect and where I should divert my attention. This guide aims to support Cyber Security professionals into tackling this exam and what to expect on the day. It will also focus on what you will need to prepare going forward.
All offical Cyber Scheme resources will be linked throughout the blog to ensure that you can find the official copies. However, be aware that these are also subject to change, and may not be updated for a while.
Pre-requisites
There are a few pre-requisites that you will need to be aware of on the day of the exam. Without these, you run the risk of not being able to sit the exam or failing to complete certain questions. These are the following:
- A Laptop with an Ethernet Adapter and HDMI Output - This is needed to connect to the CSTM Exam network and be monitored by the invigilator.
- An RJ45 Ethernet Cable - These were provided on the day, but it's best practice to bring one.
- A Valid form of UK Photo ID. (Passport or Drivers License) - Very important. Without this, you will not be allowed to sit the exam
- A valid version of the Nessus Vulnerability Scanner. Be aware that Nessus Essentials has a limit to 5 IPs Addresses that can be used, so, if already working as a Penetration Tester, a paid version is better.
- A Linux Operating System - Personally, I sat the exam with a base Kali OS. I think this is easier than running a VM, and it comes pre-installed with everything you need.
- Typical Penetration Testing Toolkit - Vague as not to give away too much, but think of anything that you may use in a Penetration Test or Capture-The-Flag Style event.
- Organised Notes around the major topics of the exam - This is an open-book exam, therefore notes are allowed. Bring as many on the main topics that you can.
As per the Cyber Scheme website, the pre-required skillset for the web applicaton and infrastructure test are as follows:
NETWORKING:- Understanding common networking protocols such as SMTP, NFS, FTP, DNS.
- Service enumeration.
- The ability to map a network.
- Port scanning.
- Identification of valuable hosts on a network.
- Understanding basic web application vulnerabilities such as SQLi, XSS, LFI/RFI.
- Understanding of differences between OS’s.
- Identification of server vulnerabilities.
- Exploitation of server vulnerabilities.
- Basic methods of privilege escalation.
What to Expect on the Day: Practical Exam
With no additional extra time, the CSTM exam runs for 2 hours and 30 minutes and is aimed at testing your ability to enumerate and exploit both a small web application and infrastructure estate. If you are elligible for extra exam time, the exam will run for 3 hours.
For the exam you will be required to connect to their network that does not have DHCP. You are given the network details that you will need to configure on your device. You do not need to do this through the command-line interface (CLI) anymore, so do not waste your time doing it that way. In my opinion, it is more pain than it is worth, and will not grant you extra points. You want to make the exam as easiest and as less stressful as you can. This is done during the exam, after the time has started, and you MUST be able to do this. If you cannot configure your laptop's network settings and connect to the network, you WILL fail before the exam properly begins. However, if you have very basic networking knowledge, this is very easy and will not take longer than a minute, just practice this before hand at home if you're unsure.
After successfully connecting to the Cyber Scheme network, the practical exam component officially begins. You will be given a sheet of questions to guide you, and IP / Domain information of the machines. You will not need to play detective too much, but you will be expected to know of common application pitfalls, and where to find the vulnerabilities listed on the question sheet. The questions will be vague, for instance, "Find the SQL Injection Vulnerability". This tells you what to look for, but the rest is up to you.
You can tackle the questions in any order, but I recommend tackling them in the order presented on the question sheet, as some information enumerated may be relevant later on in the question set. You are expected to evidence all testing and keep track of any findings, and or useful information that you have discovered.
Similarly, the infrastructure part of the questions is very similar, it will be told what is expected of you, but you must use the scoping sheet provided as to not scan or exploit any machines that are out-of-scope. Moreover, the scoping sheet will provide all relevant IP / Domain information needed for the questions.
As stated on The Cyber Scheme website, they're expecting you to know of common network protocols, their pitfalls, functionality, and any common vulnerabilities associated with that service. I would advise that you do not go around brute-forcing protocols straight away, but analyse the information you have at hand and always take the most sensible and fastest option to the solution first. You're expected to have a more advanced level of knowledge here and it's crucial that you do not waste time.
What to Expect on the Day: Technical Exam
As per the new format of the exam, at the start of the day, you will be given a question sheet of 6 out of 100+ technical questions that are readily available on The Cyber Scheme's website. You should receive one question per topic. This is linked here It is vital that you learn or memorise the answers to these questions. Some of them are easier than others, depending on your skillset or knowledge.
The Cyber Scheme do not expect you to be an expert on all of the questions, but they do expect you to know them to a satisfactory level. As daunting as it seems, the invigilator is very fair and will prompt you if they feel that you know the answer. They're very aware of the exam nerves on the day, and that you're doing this without use of the Internet.
The technical interview will run for about 5-10 minutes and will be voice recorded for marking purposes.
What to Expect on the Day: Report Writing
During your practical exam, you're expected to write a small executive summary detailing what you have found and the business implications for the mock organisations. It is really important that you keep this to an executive level and do not go overboard with too much technical detail.
Depending on your writing ability, I would leave at least 10-15 minutes of the exam time for this exam element. This is to make sure that you do not stress and rush it. If the examiner deems the report writing element satisfactory, then you can fail the entire exam, despite maybe fully completing both the practical and technical aspects.
What is Required to Pass the Exam?
You will be happy to know that The Cyber Scheme do not expect you to pass or know everything that is on the exam. However, they do expect you to know most of it. Listed below will be the passing criteria for the exam, and I will explain what that means for you as a candidate. Please see below:
| Criteria | Score Required |
|---|---|
| Practical and Viva | 6 / 7 |
| Report Writing | 2 / 3 |
| Technical Interview | 5 / 6 |
Table 1: CSTM Passing Criteria
As you can see from Table 1, you are not required to pass every aspect of the exam, however, it is close.
Please see below, the different elements that the exam is marked on. This means you can fail at least one element from the bolded criteria.
| Criteria | FAIL | PASS | Comment |
|---|---|---|---|
| Practical and Viva | |||
| Application Enumeration | |||
| Application Information Disclosure | |||
| Application Exploitation and Mitigation | |||
| Network Mapping and Associated Protocols | |||
| Enumeration and Exploitation of Windows Devices | |||
| Enumeration and Exploitation of Linux Devices | |||
| Post Exploitation | |||
| Report Writing | |||
| Business Risks / Implications | |||
| Summary | |||
| Coherent, Well Written Report Element | |||
| Technical Interview | |||
| Current Technology | |||
| Older Technology | |||
| Networking | |||
| Protocols | |||
| Mitigation | |||
| Laws, Ethics, Scope and Risk |
Table 2: CSTM Passing Criteria
Conclusion & Takeaways
In conclusion, the exam is far from easy, however, it is very well doable with a moderate amount of preparation time. If you are currently working as a penetration tester, then most of the concepts will not be new to you.
The exam not only challenges your practical ability, it asseses whether you can communicate the vulnerabiliies to a wide range of audiences and whether you know why you're doing something or if you're following learning from a CTF.
If there are any elements that you do not feel confident on from this post, then you know that you should make this a focus point. However, remember that all exam will be stressful, but the inviglators are extremely fair and will do their best to put your mind at ease.
I hope this blog helped, and, if you're sitting the exam soon, then Good Luck! You will smash it!
References & Resources
Please find below a list of useful references and resources that you can use to prepare for this exam.