OffSec OSCP in 2026: Exam Guide, Cost and Study Plan

By Donald Korinchak, MBA, PMP, CISSP, SecurityX, ITILv3   Published: 09/26/26   9 min read

Updated September 2026: Since November 1, 2024, passing the OSCP exam earns you two certifications: OSCP, which never expires, and OSCP+, which expires after three years unless you maintain it (OffSec). OffSec now maintains OSCP+ through a CPE program with a $145 annual maintenance fee, a recertification exam, or a qualifying higher-level exam. We didn’t find any announced change to the OSCP+ exam format for 2026 on OffSec’s site.

The OffSec Certified Professional (OSCP), formerly the Offensive Security Certified Professional, is the best-known hands-on penetration testing certification. There’s no multiple choice. You get just under 24 hours to break into a live lab network, then another 24 hours to write a professional penetration test report. If you can’t actually get a shell, you don’t pass.

This guide covers who OSCP is for, how the exam works and is scored, what it costs, how OSCP+ maintenance works, a study plan, career value, and how OSCP compares with PenTest+ and CEH. If networking is still shaky, start with our Network+ guide.

Who OSCP is for

OffSec says there are no formal prerequisites, but it strongly recommends a solid understanding of TCP/IP networking, reasonable Windows and Linux administration experience, and familiarity with basic Bash or Python scripting (OffSec). Take that seriously: the exam assumes you can already move comfortably around both operating systems.

OSCP+ exam facts (2026)

ItemDetails
CoursePEN-200: Penetration Testing with Kali Linux
Exam length23 hours 45 minutes of hacking, plus 24 hours to submit your report
ProctoringAlways proctored, connected to a private exam VPN
Targets3 standalone machines (60 points) and 1 Active Directory set of 3 machines (40 points)
Passing score70 out of 100 points
ReportRequired; a professional penetration test report detailed enough to reproduce every attack
PrerequisitesNone formally; networking, Windows and Linux administration, and scripting strongly recommended
ResultOSCP (never expires) plus OSCP+ (expires after 3 years unless maintained)
Price$1,749 Course + Cert Bundle; $2,749 a year for Learn One; $1,699 for a standalone OSCP+ exam attempt
OSCP+ maintenance120 CPE credits over 3 years plus annual coverage ($145 AMF or $299 AMP), or a recertification or qualifying exam

Sources: OffSec’s OSCP+ Exam Guide, PEN-200 page, pricing page and CPE and annual maintenance handbook.

How the OSCP+ exam is structured and scored

From OffSec’s exam guide:

Tool rules to know before exam day

What OSCP costs in 2026

Two exam attempts in Learn One often make it the better value for first-timers. OffSec itself notes that not everyone passes on the first try.

How OSCP+ renewal works

OSCP+ is valid for three years. To keep the “+”, OffSec offers three routes (CPE handbook):

OffSec says annual coverage applies to the retake and higher-level routes too “where applicable under the program rules,” and missed years must be covered if you renew later (OffSec AMF FAQ). If you let OSCP+ lapse, you still hold OSCP for life.

A 16-week OSCP study plan

This assumes 10 to 15 hours a week and that you’re already comfortable on Linux and Windows. OffSec publishes its own 12-week and 24-week PEN-200 learning plans; pick the pace that fits your schedule.

Is OSCP worth it? Jobs and career value

OSCP is widely treated as the practical proof for penetration testing roles, because you can’t pass without compromising real machines and documenting it. OffSec lists roles such as penetration tester, SOC analyst, security consultant, incident responder and vulnerability analyst for OSCP holders (OffSec).

BLS doesn’t publish a separate penetration tester category in its Occupational Outlook Handbook. Its closest profile, information security analysts, shows a May 2025 median pay of $129,180 and 21% projected growth from 2025 to 2035 (BLS).

OSCP vs PenTest+, CEH and SecurityX

Planning your next certification? See the full certification roadmap for the order to take them by career goal.

What I would tell a friend starting OSCP

Enumerate more than you think you need to, and write everything down as you go. Most failed attempts come from missing something on the first scan or running out of time on the report, not from a lack of exploits. Build a methodology, practice it until it’s boring, and then keep up with new vulnerabilities: the techniques that show up in real breaches today become the lab machines of tomorrow.

New CVEs drop every day. Know which ones attackers are actually using. The CyberExperts Daily Brief covers what changed in security and why it matters, in five minutes, weekday mornings. Get tomorrow’s brief.

Frequently asked questions

How long is the OSCP exam?

You get 23 hours and 45 minutes to attack the exam network, then another 24 hours to submit your penetration test report.

What score do you need to pass OSCP?

70 out of 100 points. The exam has three standalone machines worth 60 points in total and an Active Directory set of three machines worth 40 points.

How much does OSCP cost in 2026?

OffSec’s Course + Cert Bundle is $1,749 for 90 days of PEN-200 access and one exam attempt. Learn One is $2,749 a year with two exam attempts. A standalone OSCP+ exam attempt is listed at $1,699.

What is the difference between OSCP and OSCP+?

Passing the exam earns both. OSCP never expires. OSCP+ expires after three years unless you maintain it through CPE credits and annual coverage, a recertification exam, or a qualifying higher-level OffSec exam.

Does OSCP expire?

The OSCP certification does not expire. The OSCP+ designation expires three years after it’s issued unless you renew it.

Can I use Metasploit on the OSCP exam?

Only against one target machine of your choice. You can use msfvenom and multi/handler against all targets, but automatic exploitation tools, mass vulnerability scanners and AI chatbots are banned.

Should I take PenTest+ or OSCP first?

If you’re new to offensive work, PenTest+ is a structured, lower-cost first step. OSCP makes more sense once you can already compromise lab machines on your own.

Sources

Donald Korinchak, MBA, PMP, CISSP, SecurityX, ITILv3

Donald Korinchak is a Cybersecurity Professional in the Washington DC area. Donald holds an MBA from the University of Pittsburgh Katz School of Business. Donald is considered a thought leader in business, leadership, and cybersecurity issues.