Exampractice
Cybersecurity

How Hard Is the OSCP Exam?

An honest look at OSCP exam difficulty — the 24-hour format, 70-point scoring maths, proctoring pressure and the reasons capable candidates still fail.

Alexander Novak · 7 min read
Pressure gauge drawn as a 24-hour clock with the needle approaching a red zone, symbolising mounting pressure during the OSCP exam

Short answer: the OSCP is one of the hardest widely-held certifications in security — not because the individual techniques are exotic, but because you must perform them, unassisted and proctored, against unfamiliar machines for 24 hours, then prove everything in a formal report. Nothing is multiple choice; nothing is partial-effort; the scoring maths leaves little room to hide a weak skill area.

That is the honest verdict. The rest of this article earns it — by walking through what the format actually demands, why the point structure is less forgiving than it looks, and the specific ways in which prepared, capable people still fail. It deliberately does not tell you how to study (that is covered in our OSCP preparation roadmap) or whether the suffering is justified (see is OSCP worth it?). This is purely a difficulty assessment, so you can gauge where you stand.

What you are actually up against

OffSec's exam is a hands-on penetration test: a private VPN environment containing three standalone machines and one Active Directory set, a webcam-and-screen-share proctor watching for the entire ~24-hour window, and a professional report due afterwards. You score 100 possible points — 20 per standalone machine for initial access plus privilege escalation, and 40 for the Active Directory environment, where partial credit is available. Passing requires 70.

Three properties of this design generate most of the difficulty:

  • Nothing is recognisable. The machines are not ones you have practised on. Every target is a fresh puzzle to be enumerated from zero, so memorised walkthroughs are worthless — only transferable method survives contact with the exam.
  • Every point is binary-ish. On a written exam, half-knowing a topic earns you some questions. Here, half-compromising a standalone machine can mean a clean zero for the escalation you never landed. Competence must be complete enough to finish, under pressure, with no hints.
  • The clock never pauses your stress. Twenty-four hours sounds generous until you have spent four of them on a rabbit hole. Fatigue, doubt and time pressure compound in a way no four-hour multiple-choice exam reproduces.

The scoring maths is harsher than it looks

Do the arithmetic and the exam's real constraint appears: the three standalone machines are worth 60 points in total, and the pass mark is 70. You cannot pass on standalones alone. Some meaningful progress on the 40-point Active Directory set is mandatory, no matter how strong your single-machine skills are.

That single fact reshapes the difficulty profile. Candidates whose practice consisted entirely of one-off boot-to-root machines discover that the exam's centre of gravity — a small domain environment demanding chained, multi-stage compromise — is exactly what they practised least. Conversely, sweeping the AD set plus two standalones clears 70, so the exam does forgive one machine that simply will not fall. It does not forgive a missing skill category.

One more scoring fact worth internalising: since 1 November 2024 there are no bonus points. OffSec removed the old 10 points awarded for course exercises and lab completion, so your score now comes entirely from what happens inside the exam window. Pre-2024 write-ups describing a 10-point cushion — often alongside other outdated advice about the exam's content — describe an easier scoring regime than the one you will face.

Is there an official OSCP pass rate?

No. OffSec does not publish pass or failure rates for the OSCP, so any percentage you see quoted online is an estimate, a survey of self-selected respondents, or an invention. Treat all of them accordingly. What can be said without numbers: the exam is widely failed on first attempts, retakes are common enough that OffSec builds a second attempt into its Learn One subscription, and the community norm of writing "how I passed on attempt three" posts exists for a reason. Difficulty here is better judged by the format's demands than by an unverifiable statistic.

The 24-hour experience: where the pressure actually bites

The format's difficulty is easiest to see hour by hour. A composite of how attempts commonly unfold:

The first hours feel controlled — scans running, notes forming, a target chosen. The distinctive OSCP pressure arrives mid-exam, in one of two shapes. Either a machine's foothold refuses to appear and you must decide, with points ticking away, whether you are one enumeration pass from a breakthrough or three hours into a dead end. Or you have a low-privilege shell and the privilege escalation — worth the points that make the machine count — will not yield.

By the late hours, fatigue becomes its own adversary. Commands get mistyped, obvious findings get overlooked, and the judgement needed to abandon a failing approach deteriorates precisely when it matters most. Candidates who perform beautifully in relaxed practice sessions can unravel here, because most practice never simulates hour nineteen. Add the awareness of a proctor watching your screen and webcam throughout — harmless in principle, distracting in practice for people who have never worked observed — and the exam tests composure as much as technique.

And when the VPN window closes, you are not finished. The professional report, with reproducible steps and complete evidence for every compromise, is a pass/fail component in its own right. Producing documentation of that standard after a 24-hour effort is a difficulty multiplier that candidates consistently underestimate — exhausted people write bad reports, and a compromise you cannot evidence properly is a compromise at risk of not counting.

Why people fail the OSCP

The recurring failure causes are remarkably consistent across community post-mortems, and most are not raw skill deficits:

  1. Shallow enumeration. The classic OSCP failure. The foothold was findable, but the candidate stopped digging too early, or scanned once and never revisited. The exam punishes impatience more than ignorance.
  2. Rabbit-holing. Sinking four or five hours into one stubborn attack path out of stubbornness or sunk-cost bias, starving the remaining targets of time. Time discipline fails before technique does.
  3. Weak privilege escalation on one operating system. Many candidates are strong on Linux escalation and shaky on Windows, or vice versa. The exam samples both; the weak side surfaces.
  4. Underestimating Active Directory. Treating the 40-point AD set as a bonus rather than the mathematical necessity it is — an unbalanced preparation history made visible.
  5. Poor evidence hygiene. Missing proof captures or unreconstructable notes discovered only at report-writing time, when the environment is gone and nothing can be recovered.
  6. Collapse of nerves or stamina. Panic at the first dead end, no eating or break plan, no sleep strategy — the logistics of a 24-hour effort failing before the knowledge does.

Notice the pattern: the exam is hard less because any one technique is advanced, and more because it stress-tests method, judgement and endurance simultaneously — and a lapse in any one of them can cost a pass.

How hard is the OSCP for beginners?

Honestly: for a genuine beginner, the distance is large. There are no formal prerequisites, but OffSec itself recommends arriving with solid TCP/IP networking, Windows and Linux administration, and basic Bash and Python scripting. The PEN-200 course — the official route to the exam, covering enumeration through Active Directory attacks across 20-plus modules — assumes that baseline rather than teaching it.

A useful self-assessment: difficulty scales with how much of the exam's activity is already familiar. A working penetration tester faces an endurance-and-pressure test of skills they use weekly. A system administrator or network engineer faces new offensive techniques built on familiar foundations — hard but tractable. A candidate who has never administered Linux or read a Python script faces both the offensive material and its foundations at once, under a format that punishes every gap. None of these people is barred from passing; they are simply attempting different-sized climbs. What the full journey involves — course, formats, costs and enrolment — is laid out in our OSCP certification guide.

For calibration against the other certification most commonly weighed alongside it: EC-Council's Certified Ethical Hacker is a four-hour multiple-choice exam, and the rigour gap between the two formats is examined in CEH vs OSCP: which is more advanced?

So — are you ready for this level of difficulty?

Strip away the folklore and the OSCP's difficulty has a clear shape: an unfamiliar-target, no-hints, proctored 24-hour practical where 70/100 points must come from complete compromises, where Active Directory progress is mathematically unavoidable, where endurance and time discipline fail candidates as often as technique does, and where the report can undo a strong practical performance.

If reading that produced a plan rather than dread — you know your enumeration is patient, both escalation surfaces are covered, and you have worked under a clock before — you are the profile that passes. If it exposed gaps, that is useful information, not a verdict; the preparation roadmap exists precisely to close them. Either way, make timed, self-tested practice part of your assessment: working through security questions under exam-like conditions, then analysing which domains leaked points, is the cheapest reality check available — the free sample questions overview shows how to start benchmarking without spending anything.

Exam facts in this guide were checked against official certification-provider pages on . Fees, exam codes and policies change — confirm on the provider’s own site before you book.

Put it into practice

Test what you have just read

Reading about an exam only takes you so far. Work through practice questions for your certification and find the gaps before exam day does.

You may also like