How to Become a Hardware Pentester: Skills, Training, Kit
How to become a hardware pentester: what the job involves, the skills to build, real training and certifications, a portfolio and a junior toolkit.
A hardware pentester tests the security of physical things such as routers, IoT devices, access badges and industrial equipment, with the permission of their manufacturer or owner. Most people get there through software, through electronics, or through a self-taught path built on CTFs. This guide describes the job, the skills, the training that actually exists, and how to build a portfolio that convinces an employer.
What a hardware pentester actually does
The title covers several realities. In most security consultancies, hardware is one part of the work alongside web, network or mobile testing. A few teams do it full time, notably at device manufacturers, evaluation labs and consultancies that specialise in embedded security.
A typical IoT engagement looks like this:
- Scoping. A signed contract defines the scope: which device, which interfaces, which actions are allowed. No paperwork, no engagement.
- Teardown and mapping. Open the device, identify the components (processor, flash memory, radio chip) and look for debug interfaces such as UART or JTAG.
- Firmware extraction. Through the serial console, by reading the memory chip directly, or from a downloaded update.
- Analysis. Hunt for hard-coded secrets, exposed services, unsigned update mechanisms, poorly protected radio protocols.
- Controlled exploitation. Demonstrate impact on the test unit, without touching production systems outside scope.
- Reporting. The deliverable: every vulnerability described, rated and reproducible, with a fix recommendation. It is often the longest part.
Beyond IoT, there is also physical red teaming, where you test access to a client's premises: badges, locks, radio. It always happens with an authorisation letter signed by the client, which the tester carries on them.
Many clients only hire accredited providers. In the UK, schemes such as CREST and the NCSC's CHECK shape what employers expect; in France, the equivalent for providers is ANSSI's PASSI qualification. These accredit companies or individuals rather than replace a degree, but they explain why serious firms care so much about method and report quality.
The skills: electronics, radio, embedded, writing
| Area | What you need to be able to do | Where to start |
|---|---|---|
| Electronics | Read a schematic and a datasheet, use a multimeter, solder and desolder cleanly | Electronics kits, Arduino, then repairing old devices |
| Buses and interfaces | UART, SPI, I²C, JTAG/SWD: recognise, observe, connect | A logic analyser and a development board |
| Embedded systems | Embedded Linux, bootloaders, firmware file systems, microcontrollers | An old router, a Raspberry Pi, an ESP32 |
| Reverse engineering | Read ARM or MIPS assembly, use Ghidra, understand a binary without source | Reverse engineering CTF challenges |
| Radio | ISM bands, modulation, SDR, BLE, RFID/NFC | An RTL-SDR receiver, a Proxmark3 |
| Writing | Write a clear report, rank risks, explain to a non-specialist | Publishing your write-ups |
Two observations. First, nobody masters all of this on day one: a candidate strong in embedded Linux and reverse engineering, with basic electronics, is already employable. Second, beginners underrate writing. A brilliant technician who writes poorly still looks junior to a client.
For the practical side, our guide to the hardware hacking starter kit covers the four disciplines and a first set of tools.
Training: degrees, certifications, self-taught
Degrees
There is no degree called "hardware pentesting". People usually come from:
- cybersecurity degrees, many of which include embedded systems security modules;
- electronics and embedded systems degrees, adding security afterwards;
- general computer science or networking degrees, specialising later.
In the UK, the NCSC certifies some cybersecurity degrees; in France, ANSSI awards the SecNumedu label. Both publish their lists, which is a useful filter when comparing courses.
Professional certifications and training
Hardware-specific certifications are fewer and less established than in web or network pentesting. The ones we checked:
| Training / certification | Provider | Hardware content |
|---|---|---|
| Practical IoT Pentest Associate (PIPA) | TCM Security | Hands-on exam: firmware, logic analyser capture and design review of an embedded Linux device, with a report |
| SEC556: IoT Penetration Testing | SANS Institute | Serial and SPI interfaces, logic analysis, firmware extraction and analysis. Expensive, usually employer-funded |
| hardwear.io trainings | hardwear.io | Multi-day hands-on courses alongside the conference, in the Netherlands and the US |
General pentest certifications such as OffSec's OSCP don't cover hardware, but employers still value them, because most roles mix hardware with other work.
The self-taught path
Many people in the field took this route. It takes consistency and the right order:
- Software basics. The Linux command line, Python, some C. Online CTFs are ideal; ANSSI's Hackropole even has a hardware category.
- Electronics basics. An Arduino, a multimeter, a few circuits.
- Your first devices. An old router, a second-hand IP camera: find the UART, read the boot log, dump the firmware. Our guide to finding a UART port is a good place to start.
- The reference books. The Hardware Hacking Handbook (Jasper van Woudenberg and Colin O'Flynn, No Starch Press, 2021) and Practical IoT Hacking (No Starch Press, 2021).
- The community. Hardware villages and workshops at security conferences, hardwear.io, local hackerspaces and in-person CTFs.
Building a portfolio: CTFs, write-ups, home labs
For a first job, a portfolio often weighs as much as a degree. It shows three things: you can do the work, you can explain it, and you respect boundaries.
What belongs in it
- CTF write-ups, especially in the hardware, reverse engineering and forensics categories.
- Projects on your own devices: "I found the UART on this router, dumped the firmware, and here is what I learned." Photos, diagrams, commands, conclusions.
- A documented realistic lab, for example on CyberCTF, our sister platform of free, open-source pentest labs, written up as a client report. It is the best demonstration of your writing.
- Open-source contributions: a sigrok decoder, a documentation fix, a firmware analysis script.
What doesn't
Anything involving a device or system you had no permission to test. A serious employer will treat it as a red flag, and it may well be a criminal offence, under the UK's Computer Misuse Act 1990 or article 323-1 of the French Penal Code, for example. If you find a flaw in a commercial product you own, report it to the manufacturer, wait for the fix, then publish with their agreement or after a reasonable delay.
The junior pentester's toolkit
No need to buy everything on day one. Here is a sensible progression.
| Step | Tools | What they let you do |
|---|---|---|
| 1. Basics | Multimeter, 3.3 V USB-UART adapter, jumper wires and test hooks | Find and read a serial console |
| 2. Observation | 8-channel logic analyser | Decode UART, SPI and I²C in PulseView |
| 3. Memory | SPI programmer with a SOIC clip | Read a flash chip in place |
| 4. Soldering | Temperature-controlled iron, flux, braid, magnifier | Fit a header, lift a chip |
| 5. Radio and RFID | SDR receiver, Proxmark3 | Analyse wireless protocols and badges |
| 6. Advanced debugging | JTAG/SWD probe | Get to the heart of a microcontroller |
For physical access and radio reconnaissance work, we are preparing a field kit, the Physical Access & RF Recon Kit, planned for 2027 at €279.99: a documented tool selection for authorised engagements that deliberately doesn't cover network or Wi-Fi. It is on the waitlist.
If you are looking for a present for a pentester you know, our gift guide for pentesters lists the tools that actually get used.
Your first 90 days
To turn this guide into a plan, here is a realistic split at a few hours a week.
- Days 1 to 30. Complete around twenty easy challenges on picoCTF or Hackropole, including a few hardware ones. Buy a multimeter and a USB-UART adapter.
- Days 31 to 60. Buy an old second-hand router. Find its UART, read its boot log, identify its flash chip. Write a clean write-up.
- Days 61 to 90. Dump the firmware, analyse it with
binwalk, look for anything that could be a problem. Publish your analysis, without exploitable detail if the device is still on sale, and contact the manufacturer if needed.
At the end you will have three write-ups, an end-to-end project and a clear sense of what you enjoy in the job. That is a solid base for an internship, an apprenticeship or a first role.
Where to go next
Hardware pentesting rewards patience and curiosity more than certificates, as long as you practise within the law and can explain what you did. If you manage a team and want to bring juniors up to speed on hardware, our offer for teams covers onboarding kits, one-day workshops and custom hardware CTFs.
Frequently asked questions
Can you become a hardware pentester without a degree?
Yes, but it takes longer. Employers look first at what you can do: a portfolio of write-ups, documented projects and CTF results partly make up for the lack of a degree. A background in electronics, embedded systems or computer science is still a real accelerator, especially for a first job.
Is there a certification specific to hardware pentesting?
There are a few, less established than in network or web pentesting. TCM Security offers the Practical IoT Pentest Associate (PIPA), focused on firmware, logic analyser captures and design review of an embedded Linux device. SANS runs the SEC556 IoT Penetration Testing course. Trainings at specialist conferences such as hardwear.io are also well regarded.
Do I need to know how to solder?
Eventually, yes. Soldering a header onto UART pads or lifting a memory chip is part of the job. You can start without it, though: many exercises work with test hooks, development boards and solder-free puzzles.
What hardware should I buy first?
A multimeter, a 3.3 V USB-UART adapter, an 8-channel logic analyser and an SPI programmer with a clip cover most first exercises on a modest budget. Radio (SDR) and RFID (Proxmark3) come later, depending on your interests.