Updated September 2026: Since November 1, 2024, passing the OSCP exam earns you two certifications: OSCP, which never expires, and OSCP+, which expires after three years unless you maintain it (OffSec). OffSec now maintains OSCP+ through a CPE program with a $145 annual maintenance fee, a recertification exam, or a qualifying higher-level exam. We didn’t find any announced change to the OSCP+ exam format for 2026 on OffSec’s site.
The OffSec Certified Professional (OSCP), formerly the Offensive Security Certified Professional, is the best-known hands-on penetration testing certification. There’s no multiple choice. You get just under 24 hours to break into a live lab network, then another 24 hours to write a professional penetration test report. If you can’t actually get a shell, you don’t pass.
This guide covers who OSCP is for, how the exam works and is scored, what it costs, how OSCP+ maintenance works, a study plan, career value, and how OSCP compares with PenTest+ and CEH. If networking is still shaky, start with our Network+ guide.
Don’t Miss the Policy Changes That Affect Security Decisions
Get the key CISA actions, new regulations, guidance, and risk shifts in a quick daily brief.
By subscribing you agree to our Privacy Policy.
Free. Weekday mornings. 5 minutes or less.
Who OSCP is for
- Aspiring and junior penetration testers who need proof they can do the work
- SOC analysts, sysadmins and developers moving into offensive security
- PenTest+ or CEH holders ready for a practical exam
- Red teamers and consultants whose clients or employers ask for OSCP by name
OffSec says there are no formal prerequisites, but it strongly recommends a solid understanding of TCP/IP networking, reasonable Windows and Linux administration experience, and familiarity with basic Bash or Python scripting (OffSec). Take that seriously: the exam assumes you can already move comfortably around both operating systems.
OSCP+ exam facts (2026)
| Item | Details |
|---|---|
| Course | PEN-200: Penetration Testing with Kali Linux |
| Exam length | 23 hours 45 minutes of hacking, plus 24 hours to submit your report |
| Proctoring | Always proctored, connected to a private exam VPN |
| Targets | 3 standalone machines (60 points) and 1 Active Directory set of 3 machines (40 points) |
| Passing score | 70 out of 100 points |
| Report | Required; a professional penetration test report detailed enough to reproduce every attack |
| Prerequisites | None formally; networking, Windows and Linux administration, and scripting strongly recommended |
| Result | OSCP (never expires) plus OSCP+ (expires after 3 years unless maintained) |
| Price | $1,749 Course + Cert Bundle; $2,749 a year for Learn One; $1,699 for a standalone OSCP+ exam attempt |
| OSCP+ maintenance | 120 CPE credits over 3 years plus annual coverage ($145 AMF or $299 AMP), or a recertification or qualifying exam |
Sources: OffSec’s OSCP+ Exam Guide, PEN-200 page, pricing page and CPE and annual maintenance handbook.
How the OSCP+ exam is structured and scored
From OffSec’s exam guide:
- Three standalone machines, 60 points: 20 points each, 10 for initial access (local.txt) and 10 for privilege escalation to root or Administrator (proof.txt).
- One Active Directory set, 40 points: three machines worth 10, 10 and 20 points. You start with a username and password, simulating an assumed breach.
- 70 points to pass. For example, the full AD set plus three local.txt flags, or 10 AD points plus all three standalone machines fully compromised.
- Proof has to be exact: each flag must be shown in an interactive shell on the target (web shells don’t count), in a screenshot that includes the target’s IP address, and submitted in the exam control panel.
- Documentation can cost you points: weak or incomplete reports can mean reduced or zero points, and once you submit, you can’t add missing screenshots.
Tool rules to know before exam day
- Metasploit is limited to one target. You can use Metasploit modules or Meterpreter against a single machine of your choice. msfvenom and multi/handler are allowed everywhere.
- Banned: automatic exploitation tools (including sqlmap), mass vulnerability scanners (such as Nessus or OpenVAS), commercial tools such as Burp Pro, spoofing, and AI chatbots or LLMs of any kind.
- Allowed: Nmap and its scripts, Nikto, Burp Suite Community, DirBuster and similar tools.
What OSCP costs in 2026
- Course + Cert Bundle: $1,749 one time for 90 days of PEN-200 and lab access plus one exam attempt (OffSec pricing).
- Learn One: $2,749 a year for one year of access to one 200- or 300-level course and labs, plus two exam attempts. OffSec lists discounts for existing OffSec certification holders and full-time students.
- Standalone exam: $1,699 for an OSCP+ exam attempt without training materials, per OffSec’s PEN-200 page.
- Keeping OSCP+: a $145 annual maintenance fee (AMF), or a $299-a-year Annual Membership Program (AMP) that includes AMF coverage plus labs and CPE content (OffSec). The base OSCP never expires and needs no fee.
Two exam attempts in Learn One often make it the better value for first-timers. OffSec itself notes that not everyone passes on the first try.
How OSCP+ renewal works
OSCP+ is valid for three years. To keep the “+”, OffSec offers three routes (CPE handbook):
- CPE: earn 120 CPE credits during the three-year cycle and keep annual coverage through AMF or AMP every year of the cycle.
- Recertification exam: available to OSCP and OSCP+ holders starting up to six months before your OSCP+ expires. One attempt is valid for 120 days from purchase (OffSec).
- A qualifying higher-level exam: passing OSWA, OSEP, OSWE, OSED, OSMR, OSEE or OSAI+ also renews OSCP+.
OffSec says annual coverage applies to the retake and higher-level routes too “where applicable under the program rules,” and missed years must be covered if you renew later (OffSec AMF FAQ). If you let OSCP+ lapse, you still hold OSCP for life.
A 16-week OSCP study plan
This assumes 10 to 15 hours a week and that you’re already comfortable on Linux and Windows. OffSec publishes its own 12-week and 24-week PEN-200 learning plans; pick the pace that fits your schedule.
- Weeks 1 to 3: foundations. Work through the early PEN-200 modules: information gathering, vulnerability scanning, web attacks (XSS, SQL injection, directory traversal, file uploads) and client-side attacks. Take notes you can search on exam day.
- Weeks 4 to 6: exploitation and privilege escalation. Public exploits, fixing exploits, password attacks, and Windows and Linux privilege escalation. Build your own checklists for each.
- Weeks 7 to 9: pivoting and Active Directory. Port forwarding and tunneling, then AD enumeration, authentication attacks and lateral movement. The AD set is 40% of the exam, so don’t rush this.
- Weeks 10 to 13: challenge labs. PEN-200 includes 9 challenge labs, and OffSec says three are designed to closely replicate the exam environment. Do those under exam-like conditions.
- Weeks 14 to 15: extra practice. More standalone boxes and AD practice. Practice writing a full report for every machine you root.
- Week 16: mock exam and rest. Run a full 24-hour simulation with a report, fix your weak spots, then rest before the real thing. Plan sleep and meal breaks for exam day.
Is OSCP worth it? Jobs and career value
OSCP is widely treated as the practical proof for penetration testing roles, because you can’t pass without compromising real machines and documenting it. OffSec lists roles such as penetration tester, SOC analyst, security consultant, incident responder and vulnerability analyst for OSCP holders (OffSec).
BLS doesn’t publish a separate penetration tester category in its Occupational Outlook Handbook. Its closest profile, information security analysts, shows a May 2025 median pay of $129,180 and 21% projected growth from 2025 to 2035 (BLS).
OSCP vs PenTest+, CEH and SecurityX
- OSCP vs PenTest+: PenTest+ is a multiple-choice and performance-based exam that covers the whole engagement process, and it costs far less. OSCP is 24 hours of real hacking. Many people take PenTest+ first for the structure, then OSCP when they can root lab machines on their own.
- OSCP vs CEH: CEH proves broad knowledge and is often written into government requirements. OSCP proves practical skill. Many testers end up with both.
- OSCP vs SecurityX: SecurityX is CompTIA’s advanced certification for security architects and engineers. It’s defensive and architectural; OSCP is offensive.
- Before OSCP: If you haven’t done Security+ or equivalent study, the fundamentals will help, and if you’re planning a career move into security, see How to Transition to a Cybersecurity Career at Any Age.
Planning your next certification? See the full certification roadmap for the order to take them by career goal.
What I would tell a friend starting OSCP
Enumerate more than you think you need to, and write everything down as you go. Most failed attempts come from missing something on the first scan or running out of time on the report, not from a lack of exploits. Build a methodology, practice it until it’s boring, and then keep up with new vulnerabilities: the techniques that show up in real breaches today become the lab machines of tomorrow.
New CVEs drop every day. Know which ones attackers are actually using. The CyberExperts Daily Brief covers what changed in security and why it matters, in five minutes, weekday mornings. Get tomorrow’s brief.
Frequently asked questions
How long is the OSCP exam?
You get 23 hours and 45 minutes to attack the exam network, then another 24 hours to submit your penetration test report.
What score do you need to pass OSCP?
70 out of 100 points. The exam has three standalone machines worth 60 points in total and an Active Directory set of three machines worth 40 points.
How much does OSCP cost in 2026?
OffSec’s Course + Cert Bundle is $1,749 for 90 days of PEN-200 access and one exam attempt. Learn One is $2,749 a year with two exam attempts. A standalone OSCP+ exam attempt is listed at $1,699.
What is the difference between OSCP and OSCP+?
Passing the exam earns both. OSCP never expires. OSCP+ expires after three years unless you maintain it through CPE credits and annual coverage, a recertification exam, or a qualifying higher-level OffSec exam.
Does OSCP expire?
The OSCP certification does not expire. The OSCP+ designation expires three years after it’s issued unless you renew it.
Can I use Metasploit on the OSCP exam?
Only against one target machine of your choice. You can use msfvenom and multi/handler against all targets, but automatic exploitation tools, mass vulnerability scanners and AI chatbots are banned.
Should I take PenTest+ or OSCP first?
If you’re new to offensive work, PenTest+ is a structured, lower-cost first step. OSCP makes more sense once you can already compromise lab machines on your own.
Sources
- OffSec, PEN-200 and the OSCP+ certification: offsec.com
- OffSec, Pricing: offsec.com
- OffSec Support, OSCP+ Exam Guide: help.offsec.com
- OffSec Support, CPE Program and Annual Maintenance Handbook: help.offsec.com
- OffSec Support, Annual Maintenance Fee (AMF) FAQ: help.offsec.com
- OffSec Support, Recertification Exam FAQ: help.offsec.com
- OffSec blog, Everything you need to know about the OSCP+ (September 2024): offsec.com
- BLS, Information security analysts: bls.gov
Start your morning with the signal that matters.
Get the biggest cybersecurity developments, why they matter, and where to go deeper on CyberExperts.
By subscribing you agree to our Privacy Policy.
Free. Weekdays. Built for operators.