The OSCP+ exam is OffSec’s hands-on certification assessment for penetration testers. Candidates receive 23 hours and 45 minutes to compromise systems in a private VPN, then another 24 hours to submit a professional penetration-test report. The exam is scored out of 100 points: three standalone machines are worth 60 points and one three-machine Active Directory set is worth 40. A score of 70 is required. Passing awards both OSCP and OSCP+; OSCP+ expires after three years, subject to OffSec renewal.
OSCP+, formally OffSec Certified Professional Plus, is a practical offensive security certification designed to validate real penetration-testing ability. Instead of relying on conventional multiple-choice questions, candidates must identify vulnerabilities, gain access to systems, escalate privileges, work through an Active Directory environment, and document what they accomplished.
For anyone researching what is OSCP+, what is an OSCP, or an OSCP offensive security certification overview, the key point is that this credential focuses on demonstrated technical performance.
Candidates who pass the current exam receive both the OSCP and OSCP+ certification. OSCP remains valid indefinitely, while OSCP+ has a three-year validity period.
That distinction makes the offensive security OSCP+ certification useful for professionals who want a continuously maintained credential while retaining the permanent OSCP certification.
The terms Offensive Security Certified Professional certification, OSCP certification OffSec, OSCP offensive security certification, and Offensive Security Certified Professional OSCP certification all refer to this OffSec penetration-testing certification path.
The current OSCP certification exam is remotely proctored and conducted in a private VPN environment. Candidates receive 23 hours and 45 minutes to complete the technical assessment and another 24 hours after the exam to submit their documentation.
Exam Component
Machines
Points
Primary Objective
Standalone systems
3
60
Initial access and privilege escalation
Active Directory set
3
40
Compromise an AD environment
Total
6
100
Practical penetration testing
Passing requirement
—
70/100
Reach at least 70 points
Each standalone target is worth 20 points: 10 points for initial access and 10 for privilege escalation. The Active Directory set contributes the remaining 40 points. OffSec publishes several possible combinations for reaching the required 70 points.
A critical part of the OSCP+ exam is reporting. Candidates must submit evidence explaining how the objectives were achieved, including appropriate screenshots and technical reproduction details.
This means passing is not simply about getting shells. Evidence collection and documentation are part of the skill being assessed.
There are currently no formal OSCP certification requirements such as another certification, degree, or mandatory work-experience threshold before attempting OSCP+.
OffSec also confirms that completing PEN-200 is not mandatory before purchasing the standalone exam. It is, however, strongly recommended for candidates who do not already have substantial practical penetration-testing experience.
Before beginning an OSCP certification course or serious preparation, candidates should understand:
TCP/IP networking
Linux command-line administration
Windows administration
DNS, HTTP, SMB and common network services
Basic Bash or Python scripting
Enumeration techniques
Vulnerability identification
Basic web exploitation
Linux and Windows privilege escalation
OffSec specifically recommends networking knowledge, reasonable Linux and Windows experience, and familiarity with scripting.
“No formal prerequisite” should therefore not be confused with “beginner-level exam.”
The official Offensive Security OSCP course is PEN-200: Penetration Testing with Kali Linux. OffSec describes PEN-200 as a hands-on, learn-by-doing foundational penetration-testing course.
The current OSCP+ body of knowledge covers areas including information gathering, vulnerability scanning, web application testing, exploitation, privilege escalation, Active Directory techniques and professional penetration-testing documentation.
Effective OSCP training and offensive security training should develop a repeatable methodology:
Enumerate the target — discover ports, services, users, shares, directories and technologies.
Analyze findings — determine which information creates a realistic attack path.
Gain initial access — exploit an appropriate vulnerability within the authorized environment.
Escalate privileges — investigate services, permissions, credentials and configurations.
Attack AD systematically — understand users, systems, authentication and privilege relationships.
Document immediately — record commands, screenshots, credentials and proof while working.
For candidates comparing OSCP training online, OSCP online training, an OSCP online course, or an OSCP preparation course, the amount of independent lab practice is more important than the number of recorded lessons.
Good OSCP ethical hacking preparation should make you solve problems rather than simply copy commands.
OffSec pricing checked on August 19, 2026 lists several ways to pursue the certification.
Option
Listed Price
Includes
OSCP+ Standalone Exam
$1,699
Two exam attempts within 90 days; no PEN-200 course
Course + Cert Bundle
$1,749
90 days of course/lab access and one exam attempt
Learn One
$2,749/year
One year of selected course/lab access plus certification attempts
The standalone route may suit an experienced offensive security professional who already has sufficient lab skills. Candidates who need structured preparation may receive greater value from a package containing PEN-200.
When researching OSCP certification cost, OSCP training cost, OSCP certification exam cost, Offensive Security Certified Professional cost, or broader offensive security certification cost, confirm current pricing directly with OffSec before purchasing because packages and prices may change.
If you searched for “ocsp certificate cost,” the certification acronym you are probably looking for is OSCP, not OCSP.
The OSCP vs CEH comparison is best approached according to your career objective rather than asking which credential is universally better.
Factor
OSCP+
CEH
Primary focus
Practical penetration testing
Broad ethical-hacking knowledge and skills
Main exam style
Extended hands-on assessment
125-question knowledge exam
Additional practical option
Built into OSCP+ assessment
Separate CEH Practical available
Reporting
Required
Not central to CEH knowledge exam
Strong fit
Pen testing and offensive roles
Broad ethical-hacking foundation
OffSec’s exam centers on hands-on compromise and reporting. EC-Council’s current CEH pathway includes a four-hour, 125-question knowledge exam and also offers a separate six-hour practical assessment with 20 challenges.
For CEH vs OSCP, OSCP+ is especially relevant when you want to prove sustained practical ability in enumeration, exploitation, privilege escalation and Active Directory.
CEH can make sense when broader structured ethical-hacking coverage is the immediate priority.
A strong ethical hacking offensive penetration testing OSCP prep strategy should measure your ability to solve unfamiliar problems independently.
Create separate checklists for:
Linux targets
Windows targets
Web applications
SMB and network services
Privilege escalation
Active Directory
Do not let a favorite exploitation tool replace enumeration.
Walkthroughs are useful for learning new techniques but poor at measuring exam readiness. Gradually move toward machines where you must develop the attack path yourself.
After completing a machine, write a concise report containing the vulnerability, exploitation steps, commands, evidence and privilege-escalation path.
This converts reporting into routine rather than an extra task after hours of technical work.
OffSec currently publishes both 12-week and 24-week PEN-200 learning plans, reinforcing the value of systematic preparation.
OffSec also states that PEN-200 course exercises typically require more than 40 hours, separate from the additional time candidates may spend on challenge labs and independent practice.
Whether you use official PEN-200, another OSCP training course, or an OSCP prep course, measure progress through independent execution rather than hours watched.
The OSCP+ cert is valid for three years. The OSCP credential awarded alongside it remains valid indefinitely.
OffSec currently provides several routes for maintaining qualifying certifications. Its CPE framework allows eligible certification holders to earn 120 CPE credits across a three-year certification cycle while maintaining the required annual coverage.
Qualifying OffSec certification exams may also extend OSCP+ validity under OffSec's renewal rules.
Anyone comparing offensive security certs should account for renewal requirements rather than looking only at the initial exam.
OSCP+ makes the most sense when your goal requires genuine offensive-security execution rather than certification knowledge alone. OffSec identifies roles such as penetration tester, security consultant and other security-focused positions as relevant paths for OSCP-certified professionals.
The strongest preparation strategy is straightforward: develop networking and operating-system fundamentals, complete substantial hands-on OSCP pen testing practice, build a consistent enumeration methodology, learn to recover from failed attack paths, and become comfortable producing technical documentation.
Do not schedule the exam simply because you finished an OSCP certification training program. Schedule it when you can take an unfamiliar target from enumeration → initial access → privilege escalation → evidence → report without depending on a walkthrough.
For authoritative Offensive Security OSCP certification official information, verify the latest exam rules, pricing, candidate policies and renewal requirements through OffSec before registration.