OSCP+ certification is OffSec’s current practical penetration-testing credential tied to the PEN-200 learning path and updated OSCP exam. Candidates must compromise real systems, escalate privileges, work through an Active Directory environment, and submit professional documentation. The exam is performance-based rather than multiple-choice, requires 70/100 points to pass, and awards both OSCP and OSCP+ when passed. OSCP remains lifetime-valid, while OSCP+ expires after three years unless maintained through OffSec’s recertification or continuing-education options. It targets aspiring and working penetration testing professionals.
OSCP+, or OffSec Certified Professional Plus, is a hands-on offensive security certification designed to validate practical penetration-testing ability rather than theoretical knowledge alone.
The certification is associated with PEN-200: Penetration Testing with Kali Linux, OffSec’s core penetration-testing training path. The course covers vulnerability discovery, enumeration, web attacks, exploitation, privilege escalation, Active Directory attacks, and professional penetration-testing reporting.
The biggest distinction is how candidates are assessed. Instead of answering only multiple-choice questions, you work inside a controlled network containing vulnerable systems and must demonstrate that you can:
Enumerate systems and services
Identify exploitable weaknesses
Gain initial access
Perform Windows and Linux privilege escalation
Attack an Active Directory environment
Collect required proof files
Record commands, evidence, and screenshots
Produce a reproducible penetration-testing report
This practical approach is why OSCP offensive security certification is commonly pursued by penetration testers, ethical hackers, security consultants, red-team professionals, and security analysts who need demonstrable technical skills.
OffSec introduced the OSCP+ designation on November 1, 2024. Candidates who pass the current examination earn both OSCP and OSCP+.
Feature
OSCP
OSCP+
Issuer
OffSec
OffSec
Assessment
Practical
Practical
Current exam
Same current examination
Same current examination
Validity
Lifetime
3 years
Maintenance required
No
Yes
PEN-200 alignment
Yes
Yes
Active Directory skills
Included
Included
The important point is that OSCP+ does not replace the lifetime OSCP credential. If your OSCP+ designation later expires, you still retain OSCP. OffSec positions the “+” designation as evidence that the holder has demonstrated recent competency and maintained current professional development.
The OSCP certification exam remains heavily performance-oriented. Candidates receive 23 hours and 45 minutes to work through the examination environment, followed by another 24 hours to submit the required documentation. The exam is remotely proctored.
Exam Area
Machines
Points
Stand-alone targets
3
60
Active Directory set
3
40
Maximum score
—
100
Passing score
—
70
Each stand-alone machine is worth 20 points: 10 points for initial access and 10 for privilege escalation. The Active Directory environment is worth 40 points and contains two client systems plus a domain controller. Candidates begin the AD scenario with credentials for a standard domain user, simulating an assumed-compromise situation.
This makes OSCP pen testing preparation different from simply memorizing tools. Candidates need to understand attack methodology well enough to change direction when the obvious exploit path fails.
Technical ability alone is not enough. OffSec requires candidates to submit a professional report explaining their exploitation process in sufficient detail for another technically competent person to reproduce it.
Missing proof files, incomplete screenshots, inadequate documentation, or use of restricted tools can result in lost points.
That reporting requirement reflects actual penetration-testing work: discovering a vulnerability has limited business value if you cannot explain the evidence, impact, exploitation process, and remediation clearly.
There are no formal certification prerequisites for earning OSCP/OSCP+. OffSec awards the credential to candidates who successfully pass the performance examination.
However, “no formal prerequisites” should not be interpreted as beginner-level difficulty.
Before starting an OSCP training course, candidates benefit from working knowledge of:
TCP/IP and network services
Linux command-line administration
Windows fundamentals
Bash or Python scripting
Web application concepts
Basic vulnerability assessment
Enumeration methodology
Active Directory fundamentals
Privilege escalation concepts
Candidates who are new to cybersecurity may need foundational training before moving directly into ethical hacking offensive penetration testing OSCP prep.
The official Offensive Security OSCP course, PEN-200, builds the skills needed for practical penetration-testing engagements.
Current learning objectives include areas such as:
Candidates learn active and passive reconnaissance, network scanning, DNS enumeration, SMB enumeration, SMTP investigation, SNMP enumeration, and service discovery.
Training covers vulnerability-scanning methodology as well as tools such as Nmap, Nessus, and related techniques for interpreting potential weaknesses.
The curriculum includes areas such as:
Directory traversal
File inclusion
File-upload vulnerabilities
Command injection
SQL injection
Client-side attacks
Candidates learn how to locate and modify public exploits, obtain initial access, attack credentials, and escalate privileges on Windows and Linux systems.
Active Directory is a major exam component, accounting for a 40-point examination set and forming an important part of realistic enterprise penetration testing.
Current OffSec pricing varies depending on whether you want training or only the examination.
Option
Current Listed Price
Included Access
Course + Certification Exam Bundle
$1,749
90 days + 1 exam attempt
Learn One
$2,749/year
1 year + 2 primary exam attempts
OSCP+ Standalone Exam
$1,699
2 exam attempts
Standard exam retake
$249
Additional attempt
OffSec currently lists the Course + Certification Exam Bundle at $1,749 and Learn One at $2,749 per year. Its standalone OSCP+ examination is listed at $1,699. Prices can change, so candidates comparing OSCP certification cost, OSCP training cost, or OSCP certification exam cost should verify pricing before purchasing.
If you encounter searches for “ocsp certificate cost,” that is usually a spelling mix-up; OSCP is the relevant OffSec penetration-testing certification.
The strongest OSCP online training strategy is built around repetition rather than passive video consumption.
OffSec itself provides both a 12-week PEN-200 learning plan and longer study options. Its 12-week plan recommends progressively studying course topics, completing labs, organizing notes, and eventually attempting OSCP-grade practice environments under realistic time constraints.
A practical OSCP preparation course should therefore emphasize four stages:
Build fundamentals: networking, Linux, Windows, scripting, and web technologies.
Develop enumeration discipline: identify services before searching for exploits.
Practice complete attack chains: initial access → privilege escalation → evidence collection.
Simulate exam conditions: solve machines independently while keeping professional notes.
The biggest preparation mistake is learning isolated commands without understanding why they work. An effective OSCP online course should train you to recognize patterns, test hypotheses, troubleshoot failures, and adapt your methodology.
The CEH vs OSCP decision depends on what you want the certification to demonstrate.
Area
OSCP+
CEH
Primary focus
Practical penetration testing
Broad ethical hacking knowledge
Core assessment
Hands-on network exploitation
125-question knowledge exam
Practical component
Central to certification
Separate practical pathway available
Exam style
Performance-based
Multiple choice for standard CEH
Best fit
Pen testers and offensive security roles
Broader ethical-hacking foundations
EC-Council currently lists the standard CEH knowledge examination as 125 multiple-choice questions over four hours. A separate six-hour practical examination with 20 challenges is used as part of its higher practical pathway.
For someone specifically targeting penetration-testing work, OSCP+ certification provides direct evidence of hands-on exploitation ability. CEH can be useful when the goal is broader ethical-hacking knowledge, structured coverage of security topics, or an employer requirement.
The best answer to OSCP vs CEH is therefore not simply “which is harder?” It is which competency does the job require you to prove?
OSCP+ is valid for three years. OffSec now provides continuing professional education and maintenance pathways for keeping the “+” designation active.
One current route requires earning 120 CPE credits over a three-year cycle while maintaining annual certification coverage. OffSec also provides recertification and qualifying-certification pathways.
If OSCP+ expires, the holder does not lose the underlying lifetime OSCP certification.
OSCP+ makes the strongest case for professionals who need to prove that they can perform a penetration test rather than merely describe one.
It is particularly relevant for:
Penetration testers
Ethical hackers
Offensive security consultants
Red-team professionals
Vulnerability assessment specialists
Security engineers moving toward offensive security
The value comes from the preparation process itself: repeated enumeration, exploitation, privilege escalation, Active Directory compromise, troubleshooting, and technical reporting.
If your goal is an offensive security professional role, begin by assessing your Linux, networking, Windows, scripting, and enumeration skills. Then choose an OSCP training online path that gives you enough lab time to solve unfamiliar systems independently. Treat the certification exam as the final validation of that ability—not as the first place you try to develop it.