CISSP Certification Guide for Beginners
·11 min read
A plain-English beginner's guide to CISSP — the eight domains, CAT exam format, experience rules, costs and the exact process from booking to endorsement.
Continue readingIs OSCP worth the money and the grind? A candid verdict on OffSec's flagship penetration testing certification, by candidate profile, with 2026 pricing.

Nobody drifts into the OSCP. Between the price of entry, hundreds of hours in the labs and a 24-hour proctored exam, the Offensive Security Certified Professional demands a deliberate decision — and that decision looks very different for a working security analyst than for a student with no offensive experience.
Short answer: for anyone serious about hands-on offensive security work, OSCP is one of the few certifications where the pain is the point — the credential is widely respected precisely because it cannot be crammed, and the plain OSCP never expires. It is worth it if you want to do penetration testing, red teaming or hands-on security assessment. It is usually not worth it if you want a defensive, governance or purely managerial career, or if you only need a certification to pass an HR keyword filter.
The rest of this article earns that verdict: what OSCP actually costs in money and time, what you get for it, and — profile by profile — who should book PEN-200 and who should spend the money elsewhere.
The OSCP is awarded by OffSec (formerly Offensive Security) after passing the exam attached to its PEN-200 course, "Penetration Testing with Kali Linux". As of 2026, OffSec's pricing works in bundles rather than cheap standalone vouchers:
Prices vary over time, so confirm current figures on OffSec's PEN-200 page before budgeting. The money, though, is only half the bill. PEN-200 lists over 320 hours of content across 20+ modules — enumeration, exploitation, web attacks, privilege escalation and Active Directory attacks. There is no official "study hours" figure and you should distrust anyone who promises one; what is certain is that this is a months-not-weeks commitment for most people, layered on top of a job or studies.
One structural change matters to the value calculation. Since November 2024, passing the exam awards two credentials at once: the classic OSCP, which never expires, and the OSCP+, which expires three years from issue and is maintained through a recertification exam, another qualifying OffSec exam or OffSec's CPE programme. If the "+" lapses, you keep the plain OSCP for life. Compared with certifications that go dark entirely unless you keep paying renewal fees, a lifetime core credential meaningfully improves the long-term return on that $1,749.
The 24-hour exam format gets the headlines — you attack real machines in a private VPN under webcam proctoring, then write a professional report — but the format is a symptom of what makes OSCP respected, not the cause. You need 70 of 100 points, earned from three standalone machines (60 points, split between initial access and privilege escalation) and an Active Directory set worth 40 points with partial credit. Since November 2024 there are no bonus points from course exercises: the score comes entirely from what you compromise on the day.
That design has a consequence employers understand: an OSCP holder demonstrably broke into machines under time pressure and documented it. A multiple-choice certification proves you recognised correct answers; OSCP proves you produced them. Hiring managers in offensive security treat the two very differently, which is a large part of why "OSCP preferred" appears so often in penetration testing job adverts. If you want the full picture of how brutal the exam experience is, that lives in our companion piece on how hard the OSCP exam really is.
There is a second, less discussed payoff: the preparation changes how you work. Building an enumeration methodology, keeping engagement notes, chaining privilege-escalation paths and writing a findings report are the literal daily activities of a junior penetration tester. Even a failed first attempt leaves you with skills that transfer directly into assessments, CTFs and security engineering — which is not something you can say about most exam prep.
A balanced verdict needs the drawbacks stated plainly:
None of these kill the case for the right candidate. All of them should kill it for the wrong one.
Work through these honestly; the certification only pays off when most answers point the same way.
The working security analyst moving towards offensive work — worth it. This is the ideal profile. You have fundamentals, context and probably some employer support. OSCP converts "interested in pentesting" into evidence, and the preparation itself makes you better at your current job.
The self-taught practitioner with lab experience but no credential — worth it. If you already spend weekends on vulnerable machines, OSCP is the recognised stamp on skills you largely have. Your marginal cost is lower than anyone else's.
The career changer with no IT background — not yet. The certification is worth it eventually, but buying PEN-200 as a first step is buying a marathon entry before learning to run. Build networking, Linux and scripting foundations first — inexpensively — then commit.
The student deciding between OSCP and broader credentials — it depends on conviction. If you are certain about offensive security, OSCP early is a powerful differentiator at graduate level. If you are still exploring, a broader security certification costs less and forecloses nothing.
The defender, auditor or manager — usually not. Respect for OSCP does not make it relevant. The money buys more career progress spent on credentials aligned with defensive or governance tracks, such as advanced defensive certifications — browse the certification exams directory to compare what actually maps to your role.
The keyword-filter optimiser — no. If the only goal is passing automated CV screens for generalist security roles, cheaper multiple-choice certifications do that job; OSCP is a scalpel, not a stamp.
What OSCP actually does for pay bands and role progression is deliberately outside this article's scope — that analysis, including advancement to OSEP and beyond, lives in the OSCP career path and salary guide.
Two practical notes for those who conclude it is worth it. First, do not book until you are genuinely close to ready — lab access windows and exam attempts are the scarce resources, and our OSCP preparation roadmap covers how to sequence the build-up so the clock starts at the right moment. Second, pressure-test your fundamentals before the money leaves your account. Timed practice questions on core security topics are a cheap way to expose weak domains early; ExamPractice offers free sample questions across security certifications, with fuller sets and a timed simulation mode for subscribers via its practice test overview. Practice questions test your understanding of objectives — they are a diagnostic, not a shortcut, and OSCP in particular cannot be shortcut.
OSCP is worth it when three things line up: you want offensive security work, you can realistically reach exam readiness within your access window, and the roughly $1,749-plus cost will not break you if the first attempt fails. When they do line up, few certifications return more — a lifetime credential, genuine skills and instant credibility with the people who actually interview penetration testers. When they do not, the honest advice is the unfashionable one: not yet, or not this certification. The exam will still be there when you are ready, and the plain OSCP you eventually earn will never expire on you.
Yes. Its reputation rests on the hands-on 24-hour exam format, which has if anything become stricter — bonus points were removed in November 2024, so passing now depends entirely on exam-day performance. Technical hiring managers continue to treat it as strong evidence of practical ability.
The plain OSCP never expires. The OSCP+ designation awarded alongside it since November 2024 lasts three years and is maintained via a recertification exam, another qualifying OffSec exam or OffSec's CPE programme — but letting it lapse still leaves you with the lifetime OSCP.
Yes — OffSec lists a standalone exam at $1,699 as of 2026. For almost everyone it is poor value: for $50 more the bundle adds 90 days of the labs the exam is built to test.
Budget for that possibility rather than being deterred by it. OffSec publishes no pass rates, but failed attempts are common and the preparation retains its value; Learn One's two included attempts exist precisely because retakes are a normal part of the journey.
Exam facts in this guide were checked against official certification-provider pages on . Fees, exam codes and policies change — confirm on the provider’s own site before you book.
Put it into practice
Reading about an exam only takes you so far. Work through practice questions for your certification and find the gaps before exam day does.
·11 min read
A plain-English beginner's guide to CISSP — the eight domains, CAT exam format, experience rules, costs and the exact process from booking to endorsement.
Continue reading·9 min read
A practical CISSP exam preparation guide covering the managerial mindset, how to choose study materials, and how to use practice tests to measure readiness.
Continue reading·7 min read
What actually makes the CISSP exam hard — breadth, adaptive testing and managerial judgement — who struggles most, and how it compares with SSCP and CCSP.
Continue reading