CISSP Certification Guide for Beginners
·11 min read
A plain-English beginner's guide to CISSP — the eight domains, CAT exam format, experience rules, costs and the exact process from booking to endorsement.
Continue readingWhat the OSCP certification involves — the PEN-200 course, 24-hour practical exam, OSCP vs OSCP+, pricing options and requirements, explained clearly.

The Offensive Security Certified Professional (OSCP) is OffSec's flagship penetration-testing certification, earned by completing a single 24-hour hands-on exam in which you compromise real machines over a VPN and then document everything in a professional report. It is tied to OffSec's PEN-200 course, "Penetration Testing with Kali Linux", and since November 2024 a passing attempt awards two credentials at once: the lifetime OSCP and the three-year OSCP+.
This guide is a complete orientation: what the certification actually certifies, how the PEN-200 course is structured, exactly what happens during the exam, what it costs under each purchase option, and what the requirements are before you book. If you already know the basics and want to judge the exam's brutality or build a study plan, those questions have their own dedicated guides, linked below.
The OSCP is a practical penetration-testing certification from OffSec — the training company formerly known as Offensive Security, which rebranded in 2023. Unlike knowledge-based certifications that test recall through multiple-choice questions, the OSCP is earned entirely by doing: you sit at a keyboard for 24 hours, attack a set of target machines through a private VPN, and prove each compromise with evidence.
That design is the reason the credential carries the reputation it does among hiring managers for offensive-security roles. A certificate that can only be earned by gaining initial access to machines, escalating privileges and writing up the findings tells an employer something a written exam cannot. Whether that reputation justifies the price and effort for your particular situation is a separate question — our verdict on whether the OSCP is worth it weighs that trade-off by candidate profile.
The certification's relationship to its course matters for how you buy it. OffSec does not sell the OSCP as a cheap standalone voucher the way many providers do. The standard route is to purchase PEN-200 — the course, lab access and an exam attempt together — and treat the exam as the capstone of the training.
This is the single most misunderstood point about the certification today, so it is worth settling early. Effective 1 November 2024, passing the current exam awards both:
The OSCP+ did not replace the OSCP; you receive both from one passing attempt. The "+" signals to employers that your skills have been demonstrated recently. To keep it, you can pass a recertification exam within six months of expiry, pass another qualifying OffSec exam (OSEP, OSWA, OSED or OSEE), or complete OffSec's continuing-education programme. If you let the "+" lapse, nothing dramatic happens — you simply keep the plain, lifetime OSCP.
This split reflects OffSec's broader model: its classic certifications (OSCP, OSWE, OSEP) do not expire, while the newer "+" designations carry a three-year clock. That is worth knowing if you are comparing providers, because it is roughly the reverse of schemes like EC-Council's, where every certification renews on a continuing-education cycle.
PEN-200, "Penetration Testing with Kali Linux", is the official course behind the certification. As of 2026, OffSec lists it at more than 20 modules and roughly 321 hours of content. The syllabus walks through the working method of a professional penetration tester:
OffSec's listing also includes cloud-focused (AWS) content. The course is delivered alongside lab environments where you practise the techniques against vulnerable machines — the labs are where most candidates spend the bulk of their time, because the exam mirrors the lab experience rather than the reading.
The Active Directory material deserves particular attention: as the next section shows, a full 40% of your exam score rides on a single Active Directory environment, so the AD modules are not optional background reading.
How you should sequence the course, structure lab time and layer in outside practice is its own topic — our OSCP preparation roadmap covers the study side in depth.
The exam is a proctored, hands-on penetration test conducted in a private VPN environment over 24 hours. You connect from your own machine, a proctor watches via webcam and screen sharing for the duration, and you attack the targets in whatever order you choose. When the connection window closes, you write and submit a professional penetration-test report documenting how you compromised each target.
The exam is scored out of 100 points, and you need 70 to pass:
| Component | Points | What it involves |
|---|---|---|
| Three standalone machines | 60 (20 each) | Initial access plus privilege escalation on each independent target |
| One Active Directory set | 40 | Compromising a small AD environment, with partial credit available |
| Passing score | 70/100 | Score comes solely from exam performance |
Two practical consequences follow from this structure. First, there is no path to 70 that ignores Active Directory entirely — the three standalones alone max out at 60 points, so you need at least partial progress on the AD set. Second, the arithmetic forgives one bad machine: full marks on the AD set plus two standalones would clear the bar.
If you read exam write-ups from before November 2024, discard their scoring advice. OffSec previously offered 10 bonus points for completing course exercises and lab machines; those were removed effective 1 November 2024. Your score now comes entirely from what you accomplish during the exam window. Older blog posts describing "banking" bonus points before exam day describe an exam that no longer exists.
Passing is not only about popping shells. After the hands-on window, you must submit a professional report with the evidence of each compromise — the steps you took, the proof you collected, and enough detail that a technical reader could reproduce your work. A compromise you cannot document properly is a compromise that may not count. OffSec's official exam guide sets out the exact evidence requirements and submission process; read it in full before your attempt rather than relying on second-hand summaries.
How punishing this format is in practice — the time pressure, the proctoring, the ways strong candidates still fail — is examined honestly in our companion piece on how hard the OSCP exam really is.
OffSec sells training and exam attempts together rather than as separate cheap vouchers. As of 2026, the published US-dollar options are:
| Option | Price (USD) | What you get |
|---|---|---|
| PEN-200 Course & Cert bundle | $1,749 one-time | 90 days of course and lab access + 1 exam attempt |
| Learn One subscription | $2,749/year | 12 months of access + 2 exam attempts, plus additional content |
| OSCP+ standalone exam | $1,699 | Exam attempt only — no course, no labs |
| Learn Unlimited | Higher tier | All OffSec courses, unlimited attempts (confirm current price with OffSec) |
Prices change and can vary by region, so treat these as a 2026 snapshot and confirm the current figures on OffSec's PEN-200 page before you buy.
A simple way to choose:
Notice the pricing tells you something about the exam itself: the standalone exam costs nearly as much as the course-plus-exam bundle. OffSec is pricing the credential, not the content, and steering virtually everyone through the training.
There are no formal prerequisites. You do not need a degree, a prior certification, an employer sponsor or documented work experience to buy PEN-200 and sit the exam. That makes the OSCP unusually accessible on paper for a credential of its standing.
In practice, OffSec recommends candidates arrive with:
Treat these recommendations as a genuine baseline rather than a formality. The course teaches penetration testing; it does not teach you Linux from scratch. If you are weighing how far your current background is from that baseline — and what the gap means for your odds — the difficulty guide looks at exactly who struggles and why.
Consider a system administrator with three years of experience managing Windows servers and a home lab habit. She already meets the informal baseline: daily Linux use, comfortable in PowerShell and Bash, understands AD because she runs one. For her, the sensible sequence is: buy Learn One for the year of runway, work through PEN-200 module by module with the labs, and book the exam only after she can compromise practice machines without walkthroughs.
Contrast that with a career-changer coming from a non-technical role. Nothing stops him buying PEN-200 tomorrow — but the 90-day bundle would mostly be spent learning Linux fundamentals the course assumes. His better route is months of free groundwork (networking, Linux, scripting) before spending anything with OffSec. Same certification, same rules, very different starting lines — which is why "how long does OSCP take?" has no honest universal answer, and why OffSec publishes none.
Passing gives you the lifetime OSCP plus the three-year OSCP+, and opens OffSec's advanced track. The recognised next steps are PEN-300 (the OSEP, "OffSec Experienced Penetration Tester", with a 48-hour exam focused on evasion and breaching defences) and WEB-300 (the OSWE, "OffSec Web Expert", centred on white-box web exploitation). Both currently follow the classic model — the certifications do not expire.
What the credential does for job prospects and pay is deliberately outside this guide's scope: the OSCP career path and salary guide maps the roles it unlocks and realistic compensation bands. And if you are choosing between the OSCP and EC-Council's Certified Ethical Hacker rather than committed to OffSec, the OSCP vs CEH comparison makes that buying decision directly.
Yes. OffSec sells a standalone OSCP+ exam attempt for $1,699 as of 2026. But because the full course-and-exam bundle is only $50 more, going without the course and labs almost never makes financial or practical sense.
The plain OSCP never expires. The OSCP+ awarded alongside it expires after three years unless renewed via a recertification exam, another qualifying OffSec exam or OffSec's continuing-education programme. Losing the "+" does not affect the lifetime OSCP.
Yes — it is a proctored, approximately 24-hour hands-on exam in a private VPN, with webcam and screen-share proctoring throughout, followed by a written report. You manage your own breaks within the window. Check OffSec's official exam guide for the precise timing and report-submission rules before your attempt.
No formal barriers exist, but the exam presumes networking, Linux/Windows and scripting fluency. Most successful candidates arrive with hands-on IT or security experience, self-taught or professional.
You now have the complete picture: a hands-on 24-hour exam scored 70/100 across three standalone machines and an Active Directory set, reached through the PEN-200 course, priced from $1,749 with training, with no formal prerequisites but a real informal baseline — and one pass yielding both a lifetime OSCP and a three-year OSCP+.
If you are still surveying the field before committing to a penetration-testing credential, browse the certification exams directory to compare what else exists in security and beyond. And once you are actively studying, building the habit of testing yourself under timed conditions matters more for this exam than almost any other — the practice test simulation overview explains how timed practice exposes weak areas before exam day does.
Exam facts in this guide were checked against official certification-provider pages on . Fees, exam codes and policies change — confirm on the provider’s own site before you book.
Put it into practice
Reading about an exam only takes you so far. Work through practice questions for your certification and find the gaps before exam day does.
·11 min read
A plain-English beginner's guide to CISSP — the eight domains, CAT exam format, experience rules, costs and the exact process from booking to endorsement.
Continue reading·9 min read
A practical CISSP exam preparation guide covering the managerial mindset, how to choose study materials, and how to use practice tests to measure readiness.
Continue reading·7 min read
What actually makes the CISSP exam hard — breadth, adaptive testing and managerial judgement — who struggles most, and how it compares with SSCP and CCSP.
Continue reading