There is a gap nobody warns you about. You finish a learning path, you solve twenty practice boxes, and then you open the scoreboard of a real CTF competition and freeze. The challenge names mean nothing. The category list has something called "pwn" in it. Three hundred teams are already on the board and the clock says 46 hours remaining. That gap is smaller than it looks, and this guide is about crossing it. If you want somewhere to warm up first, the HackerDNA challenge library runs the same flag-submission loop in the browser, with no team and no deadline.
Below: the three competition formats you will run into, how to read CTFtime without guessing, five events that are genuinely worth a beginner's weekend, what the 48 hours actually feel like hour by hour, and the preparation that pays off. If you are earlier than this and still wondering what a flag even is, start with our beginner's guide to Capture The Flag and come back.
TL;DR: A CTF competition is a timed hacking contest where you find hidden strings called flags in deliberately vulnerable systems and submit them for points. Most events are jeopardy-style, online, free, and open to anyone: you register on the organizer's site, find the event on CTFtime, and play solo or with a team. Your first competition is not about placing well. It is about solving one challenge and reading the write-ups for the rest.
What Is a CTF Competition?
A CTF competition is a time-boxed contest in which teams score points by extracting hidden flags from intentionally vulnerable software. A flag is just a marker string, usually shaped like flag{something_here}, planted where only a successful attack will reveal it. You paste it into the scoreboard, the scoreboard checks it, and your team's score goes up.
The format is older than most people playing it. According to Wikipedia's history of the format, the first major cybersecurity CTF ran at DEF CON in 1996, with custom vulnerable services on a shared system. Thirty years later the same idea runs hundreds of times a year, mostly online and mostly free.
Here is the part that trips up newcomers: a competition is not a course. Nothing is taught, nothing is scaffolded, and there is no hint button on most challenges. What you get instead is a problem somebody spent weeks designing to be solvable and non-obvious, plus a public scoreboard proving other humans solved it. That combination teaches faster than any tutorial, which is exactly why hiring managers keep asking about it.
One correction to the mental model you probably arrived with: competitions do not test what you have memorized. Everyone is reading documentation and everyone has forty tabs open. What gets measured is how fast you go from "this binary does something weird" to "this binary trusts a length field."
The Three CTF Competition Formats
Before you register for anything, know which of these three you are signing up for. The difference decides whether a beginner has a good weekend or a miserable one.
Jeopardy: Where You Should Start
A board of independent challenges sorted into categories, each worth points. You pick one, solve it, submit the flag, pick another. Nothing you do affects other teams, nothing breaks if you go to sleep, and you can solve exactly one challenge and still have had a real competition.
Nearly every event a beginner should enter is jeopardy-style. The categories are stable across events: web exploitation, cryptography, forensics, reverse engineering, binary exploitation, and OSINT, with a miscellaneous bucket for anything strange. Our breakdown of CTF categories and what each one demands covers which to attack first.
Attack-Defense: Not Your First Event
Every team gets an identical copy of the same vulnerable services. You patch yours while exploiting everybody else's, in rounds, for hours. It is the most exciting format to watch and the worst possible introduction, because it punishes the one thing beginners lack: infrastructure. You need scripted exploits, automated flag submission, traffic capture, and a teammate who does nothing but keep services alive.
DEF CON CTF finals are the reference example, and the structure tells you everything: the DEF CON CTF Qualifier 2026 ran May 22 to 24 in jeopardy format with 673 teams, and only the top finishers reached the attack-defense finals at DEF CON in Las Vegas in August. Nobody walks in off the street.
King of the Hill and Mixed Events
Hybrids. King of the Hill hands everyone the same box and scores you for every minute you hold root on it, which means kicking other players out and keeping them out. Mixed events bolt a jeopardy board onto a live attack phase. Both are worth trying once you have a few jeopardy events behind you and know how you personally work under time pressure.
How to Find CTF Competitions on CTFtime
CTFtime is the calendar and ranking system the CTF world runs on. It does not host challenges. It lists events, tracks team results across them, and assigns each event a weight that feeds a global team ranking. Everything else follows from those three jobs.
Open the upcoming events list and you get a table: name, date, format, location, weight, notes. Four of those columns matter to you.
- Format tells you jeopardy or attack-defense. Filter to jeopardy and you have already removed most of the events that would waste your first weekend.
- Location is either "On-line" or a city. Online events are open to anyone with an account.
- Weight is CTFtime's difficulty and prestige multiplier, roughly 0 to 100. In late September 2026 the upcoming board had ASIS CTF Finals at 99.38, Hack.lu CTF at 94.74, and HITCON CTF at 91.16, against CubeCTF at 24.71. High weight means the organizers have a track record and the challenges will be brutal.
- Notes is where organizers flag a beginner division, a student-only rule, or a country restriction. Read it before you register, not after.
My advice, and it is the opposite of what the ranking encourages: for your first three events, ignore anything above weight 50. A 25-weight event run by a university club will have a gentle difficulty curve and a helpful Discord. A 95-weight event will have six challenges, four of which nobody solves, and the "easy" one is a heap exploit.
Two mechanics are worth knowing so you do not misread the scoreboard. CTFtime's rating page states that only your ten best results count toward the yearly rating, and an event's points depend on its weight, your score relative to the winner's, your placement, and how many teams scored at all. A mid-table finish at a heavy event can beat a podium at a light one. Weights themselves come from public voting among teams that competed, and CTFtime's FAQ bars organizers and winners from voting on their own event.
Grab the event's Discord or Matrix link too, usually linked from the CTFtime page. Challenge clarifications and downtime notices go there, and missing them costs more time than any tool.
Five CTF Competitions Worth a Beginner's First Weekend
These recur annually. Dates move, so treat the ones below as the shape of the calendar rather than a promise, and confirm on the organizer's page before you plan around them.
| Competition | Typical timing | Format | Cost | Good for |
|---|---|---|---|---|
| picoCTF | March (ran Mar 9-19, 2026) | Jeopardy | Free | Absolute beginners, students |
| Fetch the Flag (Snyk) | February (ran Feb 12-13, 2026) | Jeopardy, 24h | Free | First timed event |
| HTB Cyber Apocalypse | Mid-year (ran Jul 24-29, 2026) | Jeopardy, 120h | Free | Huge category spread |
| CSAW CTF Quals | September (ran Sep 18-20, 2026) | Jeopardy | Free | Students, a real step up |
| DEF CON CTF Quals | May (ran May 22-24, 2026) | Jeopardy | Free | Watching, not winning |
picoCTF is the one I recommend without hesitation. Carnegie Mellon's CyLab ran the 13th annual picoCTF from March 9 to 19, 2026, aimed at middle school, high school, and college students and open globally. The difficulty starts genuinely low, challenges stay online for practice afterward (since May 2026 on CMU's CyLab Security Academy, which picoctf.org now points to), and the write-up culture around it is enormous. Our picoCTF walkthrough covers the platform in detail.
Fetch the Flag, hosted by Snyk with NahamSec, is the cleanest 24-hour on-ramp I know. The 2026 edition ran February 12 to 13, free, with more than 20 challenges across web, AI, crypto, pwn, reversing, and forensics, plus ISC2 CPE credits. A single day is long enough to feel like a competition and short enough that you will not wreck your sleep.
Cyber Apocalypse is the big free one. Hack The Box's 2026 event ran July 24 to 29, 120 hours, teams of 1 to 30, with more than 40 challenges across 12 categories and a stated range of Very Easy to Insane. The Very Easy tier is real, and five days means you can afford to be slow. The flip side of a $130,000 prize pool is that every serious team turns up, so do not read your placing as a verdict on your skill.
CSAW CTF, run by NYUSEC at NYU Tandon, is the classic student competition: quals in September (the 18th to the 20th in 2026), finals in November. Harder than picoCTF, still designed to be learned from. DEF CON CTF Quals belongs here for one reason only: register, open the board, and spend an hour understanding why you cannot solve anything. It is the cheapest calibration exercise in the hobby.
What a CTF Weekend Actually Looks Like
The event opens, usually at an awkward hour in your timezone, and every challenge goes live at once. Here is the honest shape of the next 48 hours.
- First 30 minutes: read everything. Do not start solving. Open every challenge, read every description, note the point value, and write down the three that sound closest to something you have done before.
- Hour 1 to 4: the easy tier falls. Sanity-check challenges, a base64 chain, a directory listing somebody forgot, an EXIF field. Take them. Points are points and momentum is real.
- Hour 4 to 12: you hit your actual ceiling. This is the part that matters. Pick one medium challenge and stay on it long past the point where you want to quit.
- Hour 12 to 40: sleep. Genuinely. The single most common beginner mistake is grinding until 4am and then being useless for the entire second day.
- Final 2 hours: stop starting new challenges. Clean up your notes instead, because they are about to become your write-up.
Why the Points Keep Moving
Most modern scoreboards use dynamic scoring: a challenge starts high and drops as more teams solve it, so something worth 500 points on Friday can be worth 120 by Sunday. That is the scoreboard measuring difficulty by revealed preference, and it means a still-unsolved challenge late in the event is worth more than it looks. Many events also announce "first blood" for the first solve, which is a nice thing to chase once and a terrible thing to plan a weekend around.
Write Up What You Solved
Within a few days of most events, teams publish write-ups: step-by-step accounts of how each challenge fell. Read the ones for challenges you failed, and publish your own for the ones you solved, even the easy ones, even badly.
Writing forces you to reconstruct why the attack worked rather than that it worked, which is the difference between a trick you used once and a technique you own. It is also the best portfolio a self-taught candidate can build. In practice, a repository of fifteen honest write-ups beats a CV bullet claiming CTF experience every time.
Solo or Team: How to Enter
Registration is per-event and always on the organizer's own site. CTFtime lists the event and tracks the result, but you create the account, the team, and the password somewhere else, on a different scoreboard platform every time.
Solo is a legitimate way to start, and for a first event I would argue it is better. You see every challenge, you cannot hide behind a stronger teammate, and you find out what you are actually weak at. The cost is scope: five solves where a team of five gets eighteen.
When you want a team, the paths in rough order of how well they work:
- The event Discord. Almost every CTF has a looking-for-team channel that fills up in the first hours.
- A university or local security club. Steady teammates, recurring practice, and usually a student division to enter.
- Two friends at your level. Underrated. Three beginners splitting web, crypto, and forensics learn faster than one beginner attached to a strong team who never touches a hard challenge.
- An established team. They will want to see write-ups before they answer. See the previous section.
One piece of CTFtime housekeeping: if you and your teammates registered under different team names and want the results combined, CTFtime's FAQ says merge requests go through a form and must be submitted within two weeks of the event, and teams that both played the same contest can never be merged. Sort out one team name before you register, not after.
How to Prepare for Your First CTF Competition
You cannot prepare for the specific challenges. You can absolutely prepare for everything around them, and that is where beginners lose the most time.
Have a working environment before the event, not during it. A Linux machine or VM you can actually use, Python 3 with requests and pwntools installed, Burp Suite Community running, and CyberChef bookmarked. Our rundown of the tools worth installing before a CTF covers the full list. Installing a decompiler at hour three of a 48-hour event is a real and avoidable way to lose a challenge.
Build the reflexes that transfer. Roughly in order of return on time invested for a jeopardy board:
- Encoding fluency. Recognizing base64, hex, ROT13, and URL encoding on sight shows up in every category.
- The Linux command line.
grep,strings,file,xxd, and pipes solve more forensics challenges than any dedicated tool. - Web basics. Requests, cookies, parameters, and how to intercept them. Web exploitation is the most beginner-accessible category on most boards.
- Enough Python to script badly. Not clean code. A loop that sends 200 requests and prints the ones with a different response length.
Then put a rep in every day rather than cramming the week before. HackerDNA's free Daily Hack is built for exactly this: one self-contained challenge a day, ten minutes, no Docker and no VPN. If you want the underlying theory alongside the practice, the Hacking 101 course covers the fundamentals every category assumes you already have.
Last thing, and it is a mindset rather than a skill. Set your success condition before the event starts, and set it low: one flag. Beginners who go in aiming for a placing quit on Saturday afternoon. Beginners who go in aiming for one flag get their flag, stay curious, and come back for the next event.
Last verified: September 2026. Event dates confirmed on each organizer's official page and CTFtime event listings.
Legal and Ethical Considerations
Critical reminder: Your authorization in a CTF competition covers the challenge infrastructure the organizers gave you, and nothing else. Always get explicit written authorization before testing any system.
The boundary is sharper in competitions than in practice labs, because there are other people on the network. Standard rules across essentially every event:
- No attacking the scoreboard, the organizers' infrastructure, or other teams' machines unless the format explicitly says to.
- No denial of service, including accidental. Unthrottled fuzzing against a challenge container is the most common way beginners get disqualified.
- No flag sharing or flag selling. Scoreboards detect it, and a ban follows you across events.
- Report unintended solutions to the organizers rather than exploiting them quietly. They will usually thank you publicly.
- Techniques you learn here are only legal outside the event against systems you own or have written permission to test.
Read each event's rules page. They are short, and the specifics differ: some events allow automated scanners, some forbid them outright, and some restrict prize eligibility by age or country.
Frequently Asked Questions
Are CTF competitions free to enter?
Most of the well-known ones are. picoCTF, CSAW CTF, DEF CON CTF Qualifiers, Hack The Box's Cyber Apocalypse, and Snyk's Fetch the Flag all had free entry in 2026. Paid or invite-only events exist, mostly on-site finals and corporate competitions. Check the CTFtime listing and the organizer's rules page before registering.
Do I need a team to compete in a CTF?
No. Nearly every online jeopardy event allows a team of one, and plenty of people play permanently solo. Teams score more because they parallelize across categories, not because solo entry is restricted. If you want teammates, the event's Discord almost always has a looking-for-team channel.
What skill level do I need for my first CTF competition?
Less than you think. If you can use a Linux terminal, read an HTTP request, and write a short Python script, you can solve the bottom tier of most jeopardy boards. Events with an explicit beginner focus, picoCTF above all, are built for people with no prior competition experience.
How long does a CTF competition last?
Usually 24 or 48 hours, running from a weekend morning to the following evening. Some run much longer: Hack The Box's Cyber Apocalypse 2026 ran 120 hours across five days. Beginner-oriented events sometimes run for a week or more, and picoCTF 2026 ran from March 9 to March 19.
What does the weight number on CTFtime mean?
It is a multiplier, roughly 0 to 100, that scales how many rating points an event awards. Weights are set by voting among teams that competed, and per CTFtime's FAQ, organizers and the winning team cannot vote on their own event. Treat weight as a difficulty warning: above 50, expect challenges written for experienced teams.
Do CTF competitions help you get a cybersecurity job?
The competition itself is a weak signal. The write-ups you publish afterward are a strong one, because they show how you think through an unfamiliar problem rather than which tools you can name. A public repository of honest write-ups, including failed attempts, is the most useful thing a self-taught candidate can build.
What should I do if I cannot solve anything?
Finish the event anyway, then read the write-ups for the challenge you got closest on. Solve it yourself afterward using the write-up as a hint rather than a script. Two or three cycles of that and the next event will look different, which is the normal path rather than a shortcut.
Your Next Steps
Entering your first CTF competition is a smaller decision than it feels like. Pick a jeopardy event under weight 50, register solo, aim for one flag, sleep on the Saturday night, and write up whatever you solved. That sequence works, and it works on your first attempt.
Between now and the event, keep your hands moving. The HackerDNA challenge library gives you the same find-the-flag loop across web, crypto, forensics, and privilege escalation, with a guided path when a challenge stops making sense, and the daily hacks keep a ten-minute rep in the calendar. Everything runs in the browser with no VM to build and no VPN to configure, and the free tier needs no credit card. Solve one today, and the scoreboard at your first competition will look a lot less like a wall.
More CTF guides:
- CTF for Beginners
- CTF Categories
- CTF Tools
- CTF Competitions
- Hacking Games
- picoCTF Guide