Exampractice
Cybersecurity

OSCP vs CEH

OSCP or CEH? Compare exam formats, real total costs, renewal models and employer weight, then use a decision framework to pick the right one for you.

Alexander Novak · 10 min read
Split illustration contrasting a four-hour multiple-choice exam sheet with a 24-hour hands-on terminal session, representing CEH versus OSCP

You have roughly $1,000–$2,000 to spend, one shot at picking well, and two certifications that sound like they do the same job. They do not. The Certified Ethical Hacker (CEH), from EC-Council, is a four-hour multiple-choice exam that gets you through HR filters and onto compliance-driven shortlists. The Offensive Security Certified Professional (OSCP), from OffSec, is a 24-hour hands-on exploitation exam that proves to a technical interviewer you can actually compromise machines. Which one you should buy depends far less on "which is better" than on who you need to convince, how you learn, and what your budget genuinely covers once renewal fees are counted.

This article treats the choice as a purchasing decision: exam style, total cost of ownership, and employer weight. If your real question is how far apart the two sit on the difficulty ladder, that comparison lives in our companion piece on whether OSCP is more advanced than CEH.

The two exams are different products, not rivals at the same job

Start with what each credential actually tests, because the formats explain almost everything downstream.

CEH (exam 312-50) is a knowledge exam: 125 multiple-choice questions in 4 hours, sat at a Pearson VUE centre or through EC-Council's remote-proctored ECC Exam Portal. The current version as of 2026 is CEH v13, which EC-Council markets as "CEH AI" — artificial-intelligence-driven techniques are woven into the curriculum and the knowledge exam itself, not split into a separate AI exam. EC-Council does not publish a single pass mark; it uses banded cut scores between 60% and 85% depending on the difficulty of the question form you draw. There is also an optional 6-hour, 20-challenge CEH Practical on EC-Council's iLabs Cyber Range; passing both awards the CEH Master designation. For a full orientation to eligibility, format and versions, see the CEH certification guide for beginners.

OSCP is the certification attached to OffSec's PEN-200 course, "Penetration Testing with Kali Linux". The exam is a proctored, roughly 24-hour hands-on assessment in a private VPN: you attack three standalone machines worth 60 points (initial access plus privilege escalation) and one Active Directory set worth 40 points with partial credit available, and you need 70 of 100 to pass — followed by a professional report. Since 1 November 2024, the old 10 bonus points for course exercises are gone; your score comes entirely from exam performance. One important naming detail: passing the current exam awards both the lifetime OSCP and the OSCP+, a 3-year designation. If the "+" lapses, you keep the plain OSCP forever. The OSCP certification guide covers PEN-200 and the exam mechanics in full.

So the buyer's question is really: do you want to buy a knowledge credential with strong HR recognition or a practical credential with strong technical credibility? They overlap surprisingly little.

Side-by-side comparison

FactorCEH (EC-Council)OSCP (OffSec)
Exam style125 multiple-choice questions, 4 hours (optional 6-hour Practical for CEH Master)~24-hour hands-on exploitation exam + professional report
Difficulty characterBreadth and recall under moderate time pressureDepth, persistence and methodology under extreme time pressure
PrerequisitesOfficial training, or a $100 eligibility application with 2 years of infosec experienceNo formal prerequisites; OffSec recommends TCP/IP, Windows/Linux administration and basic Bash/Python
Core cost (2026, USD)Exam voucher $1,199 (Pearson VUE) or $950 (ECC Portal); training bundles from "starting at" $1,699PEN-200 Course & Cert bundle $1,749; Learn One subscription $2,749/year; standalone exam $1,699
RenewalValid 3 years under EC-Council's ECE continuing-education scheme (ongoing credits and a widely reported annual membership fee)Plain OSCP never expires; the OSCP+ designation expires after 3 years unless maintained
Best forPassing HR filters, compliance-driven and government-adjacent roles, SOC/analyst hybridsTechnical penetration-testing and red-team roles where interviewers probe hands-on skill
Career pathAnalyst and ethical-hacking roles; EC-Council ladder (e.g. security analyst tracks)Junior/mid pentester; OffSec ladder to OSEP, OSWE and the OSCE³ pathway
Skills provenFamiliarity with attack concepts, tools and terminology across many domainsAbility to enumerate, exploit, escalate privileges and document findings on live targets

What each one really costs

Sticker prices mislead in both directions here, so it is worth building the totals properly.

CEH: cheaper entry, ongoing costs

As of 2026, the CEH exam voucher is listed at $1,199 for Pearson VUE delivery or $950 for EC-Council's remote-proctored portal (prices vary by region — confirm on EC-Council's store before budgeting). If you self-study rather than buy official training, add a $100 eligibility application fee, and you must show 2 years of information-security work experience to qualify. Official training bundles are listed as "starting at" $1,699 for single on-demand courseware, $2,499 for live online and $3,499 for unlimited on-demand — final quotes come through EC-Council's sales process, so treat those as floors, not prices.

Then there is renewal. CEH is valid for 3 years under the EC-Council Continuing Education (ECE) scheme. Holders are widely reported to need 120 ECE credits per cycle plus an annual EC-Council membership fee of around $80 — figures that come from reputable secondary guides rather than a confirmed official policy page, so verify current requirements in EC-Council's ASPEN portal. Either way, CEH is a subscription in practice: budget for maintenance, not just the voucher.

OSCP: expensive entry, mostly one-off

OffSec does not sell cheap standalone vouchers as its main model; it sells training-plus-exam packages. The 2026 options: the PEN-200 Course & Cert bundle at $1,749 one-time (90 days of course and lab access plus one exam attempt), or the Learn One subscription at $2,749 per year (12 months of access, two exam attempts and additional content). A standalone OSCP+ exam attempt exists at $1,699 with no course or labs — technically an option, rarely a wise one, because the exam assumes the PEN-200 methodology.

The renewal picture is the mirror image of EC-Council's. Your plain OSCP is lifetime. Only the OSCP+ designation carries a 3-year expiry, maintained by a recertification exam, by passing another qualifying OffSec exam such as OSEP or OSWE, or through OffSec's CPE programme — and if you let it lapse, the OSCP itself survives. A realistic 3–5 year total cost for OSCP is therefore close to the entry price; a realistic total for CEH keeps growing.

One honest caveat on OSCP economics: many candidates need more than 90 days or more than one attempt. OffSec publishes no pass rates (never trust a quoted percentage), but if you are not already comfortable with Linux, networking and scripting, price in Learn One or a second bundle rather than assuming the $1,749 path.

Which do employers actually reward?

This is where the two certifications stop competing and start serving different masters.

CEH's strength is the filter, not the interview. CEH has been around long enough, and is embedded deeply enough in compliance frameworks, that it appears verbatim in a large number of job postings — it is commonly cited in connection with US Department of Defense workforce requirements, though specific DoD 8140 category mappings change and should be verified on official DoD sources before you rely on them. If your target roles are government, defence-contractor, or large-enterprise positions where an applicant-tracking system screens CVs against a checklist, CEH gets you through doors OSCP sometimes cannot, simply because the checklist names it. Salary data reflects healthy demand, though the spread across sources is wide: ZipRecruiter put average US "Certified Ethical Hacker" pay at $161,013/year as of February 2026, while Payscale's 2026 US figure for CEH holders is $96,490 — pay varies enormously by role, region and experience, so treat these as source-specific snapshots, not promises. Our CEH salary guide breaks the figures down properly.

OSCP's strength is the technical interview. Among working penetration testers and the people who hire them, a 24-hour proctored exploitation exam carries a weight no multiple-choice exam can. When a hiring manager for a pentest or red-team role sees OSCP, they read it as "this person has actually popped shells under pressure and written a report about it". ZipRecruiter's US average for OSCP-tagged roles was $119,895/year as of July 2026 — note that comparing this to the CEH figures above says more about differing job mixes and methodologies than about one cert out-earning the other. For role mapping and progression, see the OSCP career path and salary guide.

The blunt summary: CEH is optimised for the systems that screen you; OSCP is optimised for the humans who grill you. The best-recognised profile in offensive security is often both — but almost nobody should buy both at once, which brings us to the decision itself.

A decision framework: five questions before you spend

Work through these in order. Most readers reach a clear answer by question three.

  1. Does a specific job you want name a specific cert? If a posting, contract vehicle or government requirement explicitly lists CEH, that settles it — no amount of hands-on credibility substitutes for a named compliance box. If postings say "OSCP preferred" or describe hands-on pentest duties, that settles it the other way.
  2. Who makes the hiring decision in your target role? HR-led and compliance-led pipelines (government, defence, big consultancies' analyst tracks) reward CEH. Practitioner-led pipelines (boutique pentest firms, red teams, bug-bounty-adjacent roles) reward OSCP.
  3. Can you realistically survive a hands-on exam right now? OSCP has no formal prerequisites, but OffSec recommends solid TCP/IP networking, Windows and Linux administration, and basic Bash or Python scripting. If those are shaky, an OSCP purchase today buys frustration; either build those skills first or take the knowledge-first CEH route and return to OSCP later. Our sibling article on how hard the OSCP exam is will help you gauge this honestly.
  4. Is your budget one-off or ongoing? If you can spend once but not annually, OSCP's lifetime credential fits better than CEH's 3-year ECE renewal cycle. If your employer pays for training and renewals, CEH's maintenance cost stops mattering.
  5. Do you actually want to do offensive work? CEH serves people whose ethical-hacking knowledge supports a broader role — SOC analysts, auditors, incident responders. If defence appeals more than offence, EC-Council's blue-team catalogue may fit better than either; its Certified Incident Handler exam sits on that side of the house, and the wider EC-Council exam hub shows the range. OSCP serves people who want exploitation to be the job itself.

Two candidates, two right answers

Candidate A is a service-desk-turned-SOC analyst with 3 years' experience, aiming at a security analyst role with a defence contractor that lists CEH in every posting. The right buy is CEH via the eligibility-application route: $950–$1,199 voucher plus the $100 application, self-study, and disciplined practice testing. OSCP would impress no one in that pipeline enough to justify its price or its pain.

Candidate B is a developer who scripts comfortably in Python, runs Linux daily, and wants to move into a boutique penetration-testing firm. The right buy is PEN-200 — probably Learn One for the second attempt and longer runway. CEH first would spend $1,000+ proving breadth that no practitioner-interviewer at that firm will weigh heavily.

If neither profile is you, the honest tiebreak is sequencing rather than either/or: knowledge-first candidates often take CEH now and OSCP two years in; hands-on-first candidates skip CEH entirely unless a compliance checklist later demands it. Whether CEH justifies its cost on its own merits in 2026 gets a full verdict in Is CEH worth it in 2026?, and OSCP's equivalent reckoning is in Is OSCP worth it?

Preparing differently for two very different exams

Because the formats differ, so should your preparation spend — and mispreparing is the most expensive mistake in this comparison.

For CEH, the risk is breadth: 125 questions ranging across many domains means untested blind spots fail candidates, not lack of depth. Structured question practice matters here — not to memorise answers, but to expose which domains you consistently miss and to rehearse 4-hour pacing. ExamPractice offers free sample questions for EC-Council exams, including the Certified Ethical Hacker practice questions page (note that listing reflects an earlier exam version — always study against the current v13 objectives on EC-Council's site), with fuller question sets and a timed practice-test simulation available to subscribers. Analyse your results by domain, target the weak ones, and only book the exam when timed runs are consistently comfortable. A complete study plan lives in how to prepare for the CEH exam.

For OSCP, multiple-choice practice is nearly irrelevant; preparation means lab hours — enumeration habits, privilege-escalation methodology, Active Directory attack paths and note-taking discipline — which is why the course-and-labs bundle is the real product and the exam almost a formality of it. The OSCP preparation roadmap covers that lab-first approach.

The choice, settled by circumstance

There is no universal winner here, and anyone who declares one is selling something. Buy CEH if a named requirement demands it, if HR-screened or compliance-driven pipelines are your route in, if your hands-on foundations are still forming, or if ethical-hacking knowledge supports a broader defensive role. Buy OSCP if practitioner-led hiring is your route, if you can already operate comfortably in Linux and on networks, if you want a lifetime credential with a one-off cost, and above all if hands-on exploitation is the actual job you want. Skip both for now if you are still building fundamentals — the money keeps, and both certifications reward candidates who arrive ready rather than hopeful.

Whichever you choose, verify current pricing and policies on EC-Council's and OffSec's official pages before paying — both providers changed material details as recently as late 2024, and both will again.

Exam facts in this guide were checked against official certification-provider pages on . Fees, exam codes and policies change — confirm on the provider’s own site before you book.

Put it into practice

Test what you have just read

Reading about an exam only takes you so far. Work through practice questions for your certification and find the gaps before exam day does.

You may also like