CISSP Certification Guide for Beginners
·11 min read
A plain-English beginner's guide to CISSP — the eight domains, CAT exam format, experience rules, costs and the exact process from booking to endorsement.
Continue readingSourced 2025–2026 salary data for CEH holders, why published averages disagree by $60K+, and how role, region and experience move the number.

Here is the awkward truth every "CEH average salary" article glosses over: the major published sources disagree with each other by more than $60,000 a year. Depending on which survey you read, the average Certified Ethical Hacker (CEH) holder in the United States earns around $96,000 — or around $161,000. Both numbers are real, current and sourced. Neither is wrong. Understanding why they differ tells you far more about your own earning potential than any single blended figure could, so that is where this guide starts.
One scope note before the data: this article covers pay evidence only. Whether the certification justifies its cost is a separate question answered in is CEH worth it in 2026?, and the roles and follow-on certifications behind these pay cheques are mapped in the CEH career path.
Three reputable US sources published CEH-holder pay data in 2025–2026:
| Source | Figure (US) | As of |
|---|---|---|
| ZipRecruiter | $161,013/year average for "Certified Ethical Hacker" roles; 25th–75th percentile $122,000–$214,000; 90th percentile $237,000 | February 2026 |
| Infosec Institute | ~$126,547 average total pay for CEH professionals | June 2025 |
| Payscale | $96,490 average salary with CEH certification | 2026 |
Treat the spread itself as the finding. These are not competing estimates of one quantity; they measure different things from different populations, which is why quoting a single "CEH salary" is misleading.
The gap comes down to what each source counts.
Job-listing data skews high. ZipRecruiter's $161,013 reflects advertised pay for roles matching the "Certified Ethical Hacker" label. Employers who write "ethical hacker" into a listing are typically hiring for security-focused, often senior, positions — and advertised ranges lean toward what top candidates might accept. If you are an experienced professional targeting roles that explicitly ask for ethical-hacking skills, this is the market segment you are negotiating in.
Self-reported certification data skews low. Payscale's $96,490 averages salaries reported by individuals who hold the CEH certification — including SOC analysts, IT professionals who added CEH to a generalist role, and early-career holders whose pay reflects their experience level more than their credential. If you are earning CEH near the start of a security career, this population looks more like you.
Aggregated estimates land in between. Infosec Institute's ~$126,547 (June 2025) blends sources into a mid-range figure for working CEH professionals.
The honest synthesis: as of 2025–2026, sourced US figures for CEH holders run from roughly $96,000 to $161,000 depending on methodology, with the certification-holder average nearer the bottom of that band and advertised specialist roles nearer the top. Where you land depends mostly on three variables — role, experience and location — which the certification influences but does not control.
The pack of job titles behind these averages spans a wide pay hierarchy. Broadly, CEH holders work as security analysts and SOC analysts (typically the entry band), penetration testers and ethical hackers (mid band and up), and security consultants or specialists (upper band, especially with niche expertise). ZipRecruiter's percentile spread — $122,000 at the 25th percentile to $214,000 at the 75th and $237,000 at the 90th for ethical-hacker-labelled roles — shows how far the same credential stretches across seniority and specialisation within just one segment of the market. Published surveys do not break out a per-title figure for CEH holders specifically, so resist any article that offers you a precise "CEH penetration tester salary": that number is being invented.
None of these sources suggests CEH itself sets your pay; experience does the heavy lifting. Notice that EC-Council's own eligibility rules (two years of information-security experience, or official training) mean many CEH holders arrive with meaningful experience already — one reason even the "low" Payscale average sits near six figures in the US. A holder with five years of hands-on work and CEH will interview — and negotiate — in a different bracket from a holder fresh off the training route with the same certificate.
All figures above are United States figures. Pay for equivalent roles differs substantially by country and, within countries, by region and city — and no reliable CEH-specific averages for the UK or other markets were verifiable for this guide. If you are researching UK pay (a common search), use current listings on major UK job boards for the specific role and city you want rather than converted US averages: US security salaries do not translate across the exchange rate, because the underlying markets differ. The same advice applies anywhere outside the US. Remote roles complicate this further, as employers may anchor pay to their location, yours, or a hybrid.
Averages set expectations; listings set offers. A practical 30-minute exercise beats every survey:
Candidates often weigh CEH against OffSec's OSCP partly on pay, so one sourced anchor belongs here: ZipRecruiter lists average US pay for OSCP-tagged roles at $119,895 a year ($57.64/hour) as of July 2026. Set beside ZipRecruiter's $161,013 for ethical-hacker-labelled roles, the naive reading — "CEH pays more" — is exactly the kind of cross-methodology comparison this guide warns against: the two figures describe different role populations sampled at different times, not a controlled experiment on two certifications. The defensible conclusion is only that both credentials appear in six-figure US markets. The full pay-and-progression picture for OffSec's credential lives in the OSCP career path and salary guide, and the head-to-head buying decision in OSCP vs CEH.
Before you trust any CEH salary figure — including the ones above — run it through four checks. This is a transferable habit, but it especially matters in certification marketing, where inflated pay claims sell courses.
That last point deserves a scenario. Two candidates pass CEH in the same month. One is a career changer entering a first SOC role; local listings for that role set the band regardless of certification. The other is a security analyst with four years' experience using CEH to move into an advertised ethical-hacking position; ZipRecruiter's $122,000–$214,000 percentile band for that segment describes her negotiation space. Same certificate, different markets — and if either of them is still preparing, free CEH sample questions are a lower-stakes way to gauge readiness than the exam fee.
There is no single defensible average. As of 2025–2026, sourced US figures span roughly $96,490 (Payscale, self-reported certification holders) to $161,013 (ZipRecruiter, ethical-hacker-labelled listings, February 2026), with Infosec Institute's estimate around $126,547 (June 2025) in between. Quote the source and population, or the number means little.
No reliable UK-specific CEH average could be verified for this guide, and converting US figures misleads. Search live UK listings for your target role and region for a current picture.
No published source isolates a CEH pay premium, so treat any claimed uplift percentage with suspicion. The credible mechanism is indirect: CEH helps holders reach interviews for better-paid roles (particularly where employers name it), and the role change moves the salary.
No verified salary data separates CEH Master holders from knowledge-exam-only holders. Hands-on evidence generally strengthens candidacy for the better-paid offensive roles, but no specific figure can honestly be attached to it.
The sourced record supports this much: CEH holders in the United States work in markets where averages run from roughly $96,000 to $161,000 depending on how you measure, advertised specialist roles reach well past $200,000 at the top percentiles, and role, experience and location — not the certificate — decide where in that span you land. It does not support a universal "CEH salary", a UK figure, a per-role breakdown, or a causal pay rise from certification alone. Anchor your expectations to live listings in your own market, use the survey figures only as rough national context, and let the pay question inform — not replace — the career-track decision that actually drives earnings.
Exam facts in this guide were checked against official certification-provider pages on . Fees, exam codes and policies change — confirm on the provider’s own site before you book.
Put it into practice
Reading about an exam only takes you so far. Work through practice questions for your certification and find the gaps before exam day does.
·11 min read
A plain-English beginner's guide to CISSP — the eight domains, CAT exam format, experience rules, costs and the exact process from booking to endorsement.
Continue reading·9 min read
A practical CISSP exam preparation guide covering the managerial mindset, how to choose study materials, and how to use practice tests to measure readiness.
Continue reading·7 min read
What actually makes the CISSP exam hard — breadth, adaptive testing and managerial judgement — who struggles most, and how it compares with SSCP and CCSP.
Continue reading