CISSP Certification Guide for Beginners
·11 min read
A plain-English beginner's guide to CISSP — the eight domains, CAT exam format, experience rules, costs and the exact process from booking to endorsement.
Continue readingA clear-eyed 2026 verdict on the CEH certification: what it really costs, where employers value it, and who should take it or skip it.

Type "penetration tester" or "security analyst" into a job board and count how many listings name the Certified Ethical Hacker (CEH) by name. That single exercise explains why a multiple-choice exam that hands-on practitioners often criticise still sells at premium prices: CEH is one of the few security certifications that recruiters and HR filtering software recognise on sight. Whether that recognition justifies what EC-Council charges for it in 2026 is a genuinely close call — and the answer depends far more on who you are than on the certification itself.
Short answer: CEH is worth it in 2026 if a specific employer, contract or government-aligned role names it as a requirement, or if you need an HR-recognised credential to get past applicant screening into security interviews. It is hard to justify on technical merit alone: the knowledge exam is multiple-choice, the total cost can exceed most rival certifications several times over, and hands-on credentials earn more respect from practitioners. Pay for CEH when it opens a named door — not to prove you can hack.
Any honest verdict has to start with the bill, because CEH's price is the strongest argument against it. As of 2026, EC-Council lists the exam voucher at $1,199 for Pearson VUE delivery or $950 through its own remote-proctored ECC Exam Portal. Self-study candidates who skip official training also pay a $100 eligibility application fee and must show two years of information-security work experience.
That is the cheap route. EC-Council's preferred route is a training bundle, listed as "starting at" $1,699 for single on-demand training, $2,499 for live online and $3,499 for unlimited on-demand — with final quotes handled through a sales form, so regional pricing varies. Exact bundle pricing beyond those "starting at" figures is not published, so treat any fixed number you see elsewhere with caution and confirm directly with EC-Council.
The spending does not stop at the pass, either. CEH is valid for three years under EC-Council's Continuing Education (ECE) scheme, which by widely reported accounts requires 120 credits per cycle plus an annual membership fee of around $80 — figures that come from reputable secondary guides rather than a published EC-Council policy page, so verify the current terms before you budget. Either way, CEH is a recurring cost, not a one-off purchase.
For comparison, OffSec's PEN-200 course-and-exam bundle for OSCP — a far more demanding hands-on credential — costs $1,749. When a multiple-choice exam plus training can cost more than the industry's benchmark practical certification, the value question becomes unavoidable.
CEH's defenders and critics are usually both right, because they are describing different things. Critics judge it as a technical test; defenders judge it as a market signal. In 2026, its value sits almost entirely in three places.
CEH appears by name in job descriptions more often than almost any other offensive-security credential. Recruiters who cannot evaluate a home lab or a GitHub profile can match a certification string, and applicant tracking systems do exactly that. If your CV is being filtered out before a human reads it, CEH functions as a keyword that keeps you in the pile. That is not glamorous, but for career changers and early-career candidates it is often the entire point.
CEH is commonly cited in connection with United States Department of Defense workforce requirements (the DoD 8570/8140 framework), which is a major reason contractors and government-adjacent employers keep asking for it. The precise category mappings change, so if a defence-sector role is your target, verify CEH's current status for that specific role against the official DoD cyber workforce resources before spending anything — but the pattern is real: in that ecosystem, an approved certification list beats technical fashion every time.
The current version, CEH v13, is marketed by EC-Council as "CEH AI", weaving AI-driven hacking techniques and AI-assisted reconnaissance and analysis content through the curriculum. There is no separate AI exam — the base credential is still earned by passing the standard knowledge exam of 125 multiple-choice questions in four hours. As a structured survey of attack techniques, tools and terminology, it gives generalists, analysts, auditors and managers a common vocabulary. What it does not do is prove you can exploit a live system; the optional six-hour, 20-challenge CEH Practical exam (leading to CEH Master when combined with the knowledge exam) exists precisely to patch that gap.
Fairness demands the prosecution's argument in full, because it is substantial.
None of these criticisms makes CEH worthless. They make it a poor fit for one audience — people trying to prove practical exploitation skill to technical hiring managers — while leaving its value intact for another.
Rather than accept anyone's blanket verdict, score CEH against your circumstances on five factors:
Two realistic scenarios show how differently this scores. A network engineer targeting a cleared security role with a US defence contractor finds CEH named in the contract's certification requirements: the credential is close to mandatory, the employer will likely fund it, and the verdict is an easy yes. A self-taught web developer aiming at a boutique penetration-testing firm finds no listings mentioning CEH and every interviewer asking about methodology and lab work: for that candidate, the same money buys more elsewhere.
A yes verdict still deserves cost discipline. The ECC remote-proctored voucher at $950 undercuts the Pearson VUE option by $249 for the same certification. The self-study eligibility route saves thousands versus training bundles if you already have the required two years of experience and can learn independently. And do not sit the exam cold at these prices: work through the objectives, then use timed practice questions to find weak domains before booking rather than after failing — CEH practice questions let you benchmark readiness, with free samples available before committing to anything. A full study plan is its own subject, covered in how to prepare for the CEH exam.
What CEH leads to afterwards — roles, follow-on certifications and progression — is deliberately outside this article's scope; the CEH career path article maps it, and the CEH salary guide covers pay evidence in detail.
By employers, broadly yes — especially HR teams, large enterprises, consultancies and government-aligned organisations that work from certification checklists. By hands-on practitioners, respect is more grudging: many view the knowledge exam as too theoretical. Both audiences may sit in your hiring process, which is why the "named demand" test above matters more than anyone's opinion.
Modestly. The "CEH AI" curriculum keeps the credential current with AI-assisted attack and defence techniques, which helps its relevance in 2026 job descriptions. But the exam format and the certification's fundamental character — a broad multiple-choice knowledge test — are unchanged, so the worth-it logic is the same as before.
The eligibility rules force the question: without two years of information-security experience you must buy official training, which raises the cost substantially. At that price, be certain the roles you want actually ask for CEH before committing.
No — CEH Master requires both, and the Practical is positioned as an add-on to the knowledge exam rather than a replacement. Standalone Practical pricing is not published on EC-Council's official pages, so confirm current terms with EC-Council directly.
Take CEH in 2026 if: your target roles or contracts name it; you work (or want to work) in defence, government or heavily regulated sectors; your employer funds it; or you need a recognised credential to convert adjacent IT experience into security interviews.
Skip it if: you are building toward hands-on penetration-testing roles where technical interviewers hold the keys; nothing in your target market asks for it; or the full self-funded cost would crowd out lab time and practical credentials that would serve you better.
CEH's worth was never really about the exam. It is about whose checklist you need to be on — and only you can see the checklist.
Exam facts in this guide were checked against official certification-provider pages on . Fees, exam codes and policies change — confirm on the provider’s own site before you book.
Put it into practice
Reading about an exam only takes you so far. Work through practice questions for your certification and find the gaps before exam day does.
·11 min read
A plain-English beginner's guide to CISSP — the eight domains, CAT exam format, experience rules, costs and the exact process from booking to endorsement.
Continue reading·9 min read
A practical CISSP exam preparation guide covering the managerial mindset, how to choose study materials, and how to use practice tests to measure readiness.
Continue reading·7 min read
What actually makes the CISSP exam hard — breadth, adaptive testing and managerial judgement — who struggles most, and how it compares with SSCP and CCSP.
Continue reading