Updated September 2026: EC-Council’s Certified Ethical Hacker is on version 13, which EC-Council now markets as “CEH AI.” The knowledge exam is code 312-50. EC-Council says it releases a new CEH version every 12 to 18 months, so check which version your course and practice tests cover before you buy them.
CEH is one of the best-known ethical hacking certifications. It tests breadth: how attackers do reconnaissance, scanning, enumeration, system hacking, malware, social engineering, web and wireless attacks, cloud, IoT and OT, and cryptography, plus how to detect and stop them. The core exam is multiple choice. An optional six-hour practical adds hands-on proof and, together with the knowledge exam, earns the CEH Master title.
This guide covers who CEH is for, the exam facts, how eligibility works, real costs, a study plan, career value, and how CEH compares with PenTest+, OSCP and Security+. Still building fundamentals? Start with our Network+ guide.
Don’t Miss the Policy Changes That Affect Security Decisions
Get the key CISA actions, new regulations, guidance, and risk shifts in a quick daily brief.
By subscribing you agree to our Privacy Policy.
Free. Weekday mornings. 5 minutes or less.
Who CEH is for
- SOC analysts, vulnerability assessment analysts and incident responders who need to understand attacker techniques
- Government and defense contractor staff: CEH is recognized under DoD 8140 for several cyber defense work roles
- Security auditors and administrators who want a broad offensive-security vocabulary
- Aspiring penetration testers who want a structured, widely recognized first step before hands-on certs
EC-Council recommends at least two years of IT security experience and says the course won’t teach you basics such as what a port is (EC-Council). If you’re not there yet, build networking and Security+-level knowledge first.
CEH v13 exam facts (2026)
| Item | Details |
|---|---|
| Current version | CEH v13 (“CEH AI”) |
| Exam code | 312-50 |
| Format | 125 multiple-choice questions |
| Time limit | 4 hours |
| Passing score | A cut score set per exam form, ranging from 60% to 85% |
| Where you test | EC-Council’s remote-proctored ECC Exam Center or Pearson VUE test centers |
| Eligibility | Complete official EC-Council training, or apply with at least 2 years of information security work experience |
| Application fee | $100, non-refundable (for the self-study route; official training includes it) |
| Exam voucher | $950 for the remote-proctored exam, from the EC-Council store; valid for one year |
| Optional practical | CEH Practical: 6 hours, 20 real-world challenges. Passing both exams earns CEH Master. |
| Renewal | Every three years: 120 EC-Council Continuing Education (ECE) credits, plus an $80 annual fee |
Sources: EC-Council’s CEH page, CEH exam information and exam voucher listing, the CEH candidate handbook and EC-Council’s continuing education fee article.
What the CEH covers: 20 modules
CEH v13 is organized into 20 modules. EC-Council says the program covers more than 550 attack techniques and includes 221 hands-on labs.
| Modules | Topics |
|---|---|
| 1 to 5 | Introduction to ethical hacking; footprinting and reconnaissance; scanning networks; enumeration; vulnerability analysis |
| 6 to 10 | System hacking; malware threats; sniffing; social engineering; denial of service |
| 11 to 15 | Session hijacking; evading IDS, firewalls and honeypots; hacking web servers; hacking web applications; SQL injection |
| 16 to 20 | Hacking wireless networks; hacking mobile platforms; IoT and OT hacking; cloud computing; cryptography |
EC-Council doesn’t publish a weight per module the way CompTIA does per domain. Plan for breadth. Every module can show up, and the exam rewards knowing which tool or technique fits which phase of an attack.
How CEH eligibility works
- Official training route: Train through EC-Council (iClass), an Authorized Training Center or an academic partner. You don’t submit a separate eligibility application.
- Self-study route: Apply for exam eligibility with proof of at least two years of information security work experience and pay the $100 non-refundable application fee. EC-Council says processing usually takes 5 to 10 working days once your verifiers respond, and an approved application is valid for three months.
- Then book the exam: Buy a voucher and schedule the remote-proctored exam or a Pearson VUE seat.
What CEH costs in 2026
- Self-study: $100 application fee plus the $950 remote-proctored voucher from the EC-Council store, so $1,050 before study materials.
- Official training: EC-Council lists single on-demand courses starting at $1,699 and live online courses starting at $2,499. Pricing varies by package and region, and some packages include free retakes.
- CEH Practical: Optional. Take it if you want hands-on proof alongside the knowledge exam; check EC-Council for current pricing.
- Renewal: $80 a year in continuing education fees, plus 120 ECE credits every three years.
CEH costs noticeably more than CompTIA’s PenTest+ ($439 US retail). If an employer requires CEH, ask whether they’ll pay for it before you do.
An 8-week CEH study plan
- Week 1: set up. Get the official blueprint for your version and build a lab you’re allowed to attack (EC-Council’s labs if you bought training, or your own VMs). Make a tool sheet: tool name, what it does, which phase it belongs to.
- Weeks 2 to 3: recon, scanning and enumeration (modules 1 to 5). Nmap options and output, DNS and SNMP enumeration, vulnerability scoring. These show up constantly.
- Weeks 4 to 5: system and network attacks (modules 6 to 12). Password attacks, privilege escalation, malware types, sniffing, social engineering, DoS and evasion. Run each attack in the lab once so it sticks.
- Week 6: web, wireless and mobile (modules 13 to 17). OWASP-style web attacks, SQL injection types, WPA2 attacks and mobile platform risks.
- Week 7: IoT, OT, cloud and crypto (modules 18 to 20). Know the terms, the protocols and the classic attacks.
- Week 8: practice exams. Timed 125-question sets. Review every miss and update your tool sheet. Aim for comfortable margins, since the cut score depends on your exam form.
Is CEH worth it? Jobs and salary
EC-Council maps CEH to dozens of job titles, from SOC analyst and vulnerability assessment analyst to penetration tester. Under DoD 8140, CEH is recognized for these work roles: 111 All-Source Analyst, 141 Warning Analyst, 511 Cyber Defense Analyst, 531 Cyber Defense Incident Responder, 541 Vulnerability Assessment Analyst and 661 Research and Development Specialist (EC-Council).
- Ethical hacker pay (self-reported): EC-Council, citing Glassdoor as of July 2026, says ethical hackers in the U.S. earn about $174,000 a year, with reported salaries from about $132,000 to $233,000 (EC-Council). These are self-reported figures quoted by the certification body, so treat them as a rough guide.
- Government data: BLS doesn’t publish a separate ethical hacker category. Information security analysts had median pay of $129,180 in May 2025, and BLS projects 21% growth from 2025 to 2035 (BLS).
CEH gets you through HR filters, and it can be a hard requirement on government and contractor jobs. On its own it won’t prove you can run a penetration test. That’s what lab work, the CEH Practical or a hands-on cert like OSCP is for.
CEH vs PenTest+ vs OSCP vs Security+
- CEH vs PenTest+: PenTest+ is $439 (US retail), has no eligibility process, and mixes up to 90 multiple-choice and performance-based questions into 165 minutes (CompTIA). CEH is 125 multiple-choice questions in four hours, with a broader tool-and-technique scope and an optional practical. Choose CEH if your target employers ask for it by name; otherwise PenTest+ is the cheaper structured option. See our PenTest+ guide.
- CEH vs OSCP: OffSec’s OSCP+ exam is 24 hours of hands-on hacking: three standalone machines (60% of the points) and an Active Directory set (40%) (OffSec). It’s the stronger proof of practical skill. CEH is the stronger proof of broad knowledge and often the one written into government requirements. Many testers end up with both.
- CEH vs Security+: Security+ is the broad defensive baseline and a common first cert. CEH assumes that baseline and goes deep on offensive techniques. Do Security+ first unless you already have the experience CEH expects.
- Beyond: For SOC work, look at CySA+. For leadership later on, CISSP. Changing careers? Read How to Transition to a Cybersecurity Career at Any Age.
Planning your next certification? See the full certification roadmap for the order to take them by career goal.
What I would tell a friend starting CEH
Make a tool sheet on day one and keep it with you until exam day. Run every attack at least once in a lab. Don’t buy materials for an older version. And after you pass, keep learning in the open: CEH gives you the map, but attackers publish new routes every week.
Attack techniques change faster than CEH versions. The CyberExperts Daily Brief covers what attackers are actually doing and why it matters, in five minutes, weekday mornings. Get tomorrow’s brief.
Frequently asked questions
How many questions are on the CEH exam?
The CEH knowledge exam (312-50) has 125 multiple-choice questions and a 4-hour time limit. The optional CEH Practical is a separate 6-hour exam with 20 challenges.
What is the passing score for CEH?
It depends on your exam form. EC-Council sets a cut score for each form, ranging from 60% to 85%. Your cut score and your score appear on your transcript right after the exam.
How much does CEH cost in 2026?
Self-study candidates pay a $100 non-refundable application fee plus $950 for the remote-proctored exam voucher from the EC-Council store. Official training starts at $1,699 for on-demand courses and includes eligibility.
Can I take CEH without official training?
Yes. Apply for exam eligibility with at least two years of information security work experience and pay the $100 application fee. EC-Council says processing takes about 5 to 10 working days once your verifiers respond.
Is CEH better than PenTest+ or OSCP?
They prove different things. CEH shows broad knowledge and is recognized under DoD 8140; PenTest+ is cheaper and adds performance-based questions; OSCP is a 24-hour hands-on exam that proves practical skill. Pick based on the jobs you’re targeting.
How do I renew CEH?
Earn 120 EC-Council Continuing Education (ECE) credits every three years and pay the $80 annual fee.
What is CEH Master?
CEH Master is awarded when you pass both the CEH knowledge exam and the optional CEH Practical exam.
Sources
- EC-Council, Certified Ethical Hacker (CEH) v13: exam details, eligibility, DoD 8140 roles: eccouncil.org
- EC-Council Certification, CEH exam information (312-50, cut scores, eligibility): cert.eccouncil.org
- EC-Council Store, CEH exam voucher (remote proctored): store.eccouncil.org
- EC-Council, CEH candidate handbook (ECE renewal): cert.eccouncil.org
- EC-Council Support, Continuing education fees: eccouncil.zendesk.com
- CompTIA, PenTest+ exam details: comptia.org
- OffSec, PEN-200 and the OSCP+ exam: offsec.com
- BLS, Information security analysts: bls.gov
Start your morning with the signal that matters.
Get the biggest cybersecurity developments, why they matter, and where to go deeper on CyberExperts.
By subscribing you agree to our Privacy Policy.
Free. Weekdays. Built for operators.