OSCP: Offensive Security Certified Professional, Now OffSec Certified Professional
Table of Contents
- What Is OSCP?
- OSCP at a Glance
- Who Awards and Oversees the Credential?
- When and Why Was the Credential Created?
- Who Pursues the Credential, and Where Is It Used?
- What Knowledge and Skills Does It Cover?
- What Are the Eligibility Requirements?
- How Do You Earn the Credential?
- How Long Does It Take, and How Do Candidates Prepare?
- How Much Does the Credential Cost?
- How Do Holders Maintain the Credential?
- What Is Its Professional Value, and What Are Its Limitations?
- What Should Employers and Clients Infer from It?
- How Does It Compare with Related Credentials?
- How Can You Verify the Credential and Use Its Letters Correctly?
- Frequently Asked Questions
- Official Resources and Recent Changes
1. What Is OSCP?
OSCP stands for OffSec Certified Professional, previously named Offensive Security Certified Professional. It is a cybersecurity certification awarded by OffSec that recognizes practical penetration-testing capability: identifying weaknesses, gaining access to vulnerable systems, escalating privileges, and documenting the results. It is not simply a course-completion certificate.
The distinction between OSCP and OSCP+ is important. Since November 1, 2024, passing the updated examination earns both designations. OSCP does not expire; OSCP+ has a three-year validity period and renewal requirements. An older OSCP remains valid without conversion to OSCP+.
For someone evaluating the letters after a professional’s name, the reasonable interpretation is evidence of success in a controlled practical assessment. It is not evidence of a prescribed number of years in employment, nor proof that the holder can independently lead every type of security engagement.
2. OSCP at a Glance
- Full name: OffSec Certified Professional, formerly Offensive Security Certified Professional.
- Abbreviation: OSCP.
- Credential type: Individual, performance-based certification.
- Awarding organization: OffSec.
- Official website: OffSec PEN-200 and OSCP certification page.
- Professional focus: Practical penetration testing.
- Intended career stage: Aspiring penetration testers and practitioners formalizing foundational offensive-security skills.
- First introduced or awarded: Exact original first-award date not confirmed.
- Current status: Active; successful current candidates earn OSCP and OSCP+.
- Geographic scope: Used internationally, including in U.S. and European security recruitment.
- Main eligibility requirement: No formal academic or professional-experience prerequisite.
- Assessment: Remotely proctored practical examination lasting 23 hours 45 minutes, followed by 24 hours for documentation.
- Indicative initial cost: US$1,699 for the standalone examination product, before applicable taxes, as of September 25, 2026.
- Maintenance: None for non-expiring OSCP; separate renewal obligations apply to OSCP+.
- Verification: Official digital credential, certificate QR code, or OffSec verification request.
3. Who Awards and Oversees the Credential?
OffSec owns the credential and controls its examination requirements, assessment framework, certification decisions, and candidate policies. Its employees proctor the examination remotely. PEN-200, Penetration Testing with Kali Linux, is the associated preparation course, but purchasing training and earning certification are separate events. The candidate handbook brings together registration, examination, proctoring, appeal, and maintenance guidance.
OffSec also handles complaints and score disputes. Its published process provides for a disputed examination to be re-evaluated by someone who did not perform the original grading. Academic-policy violations can result in certification revocation and exclusion from future offerings.
Accreditation requires careful wording. As of September 25, 2026, ANAB’s personnel-certification directory lists OffSec Services LLC’s OSCP+ program as an applicant. Applicant status is not accreditation and should not be represented as an accredited ISO/IEC 17024 certification.
4. When and Why Was the Credential Created?
OSCP developed alongside OffSec’s practical penetration-testing training. The underlying approach emphasizes applying techniques in an interconnected laboratory network rather than only recalling terminology. OffSec explicitly described OSCP as an existing credential in 2011, although its precise first-award date is not confirmed.
Three milestones help explain today’s credential:
- January 5, 2014: Penetration Testing with Kali Linux became available online, succeeding Penetration Testing with BackTrack. This was a training-platform and curriculum transition, not the original launch of OSCP.
- January 11, 2022: A revised examination introduced an Active Directory environment and reduced the prominence of a dedicated buffer-overflow target, reflecting enterprise network testing priorities.
- November 1, 2024: The updated examination began awarding both the permanent OSCP and renewable OSCP+ designations.
The hiring implication is that award date matters. An experienced holder of an earlier OSCP passed the requirements applicable at that time, not necessarily the current Active Directory assessment. That is a reason to examine recent work, not to dismiss the earlier credential.
5. Who Pursues the Credential, and Where Is It Used?
OffSec identifies aspiring penetration testers, security professionals, network administrators, and other technology practitioners moving into offensive security as intended candidates.
Documented professional use extends beyond the issuer’s positioning. Security employers include OSCP in recruitment for penetration testing and offensive-security work. For example, EY’s September 2026 Vienna senior penetration-testing posting names OSCP among relevant credentials, while Palantir lists certifications such as OSCP as advantageous rather than mandatory for an offensive-security engineering role.
For staffing purposes, the clearest applications are technical testing of enterprise networks, Windows and Linux systems, authentication arrangements, and common web vulnerabilities. Illustrative settings include corporate IT in financial services, healthcare, retail, and technology businesses. These are applications of the assessed subject matter, not claims that the credential establishes sector-specific expertise.
Within a broader Cyber risk assessment, an OSCP holder may contribute technical evidence about exploitable weaknesses and attack paths. That contribution should be distinguished from enterprise-wide risk quantification, regulatory interpretation, or investment prioritization.
OSCP is an employer- or client-selected qualification, not permission to test arbitrary systems. Authorized testing still needs agreed boundaries and rules of engagement defining permitted activities.
6. What Knowledge and Skills Does It Cover?
The current body of knowledge and associated learning plans can be organized into seven practical areas:
- Information gathering: Discovering hosts, services, and exposed information, then deciding which observations justify further investigation.
- Web application attacks: Understanding weaknesses such as SQL injection, file inclusion, directory traversal, and command injection, and recognizing how they can affect system access.
- Exploit research and adaptation: Evaluating existing exploit code, making necessary modifications, and troubleshooting why an approach does not work.
- Password and authentication weaknesses: Understanding password attacks, credential exposure, and authentication mechanisms.
- Windows and Linux privilege escalation: Identifying permissions, services, configurations, or vulnerabilities that allow movement from limited access to greater control.
- Active Directory and network movement: Examining domain relationships, authentication, lateral movement, and tunneling between network segments.
- Technical reporting: Recording evidence and presenting findings, recommendations, and reproducible technical explanations.
Applied capabilities
Illustrative assignments connected to this knowledge include:
- Testing whether a compromised ordinary account could reach a sensitive server, with the client’s permission and agreed safeguards.
- Investigating whether several individually modest weaknesses combine into a more consequential attack path.
- Producing a technical finding that another authorized tester can reproduce and an administrator can use to validate remediation.
These examples describe possible applications, not guaranteed capabilities of every holder. In a hospital or manufacturer, for example, testing ordinary business IT does not establish competence to test clinical devices or operational technology safely.
Boundaries
The curriculum is broader than any individual examination set. Conversely, passing the assessment is not proof of comprehensive cloud-security expertise, advanced exploit development, mature red-team operations, privacy-law knowledge, or security-program leadership. Treat those as separate capabilities to evaluate. OffSec itself provides additional specialist and advanced learning paths beyond OSCP.
7. What Are the Eligibility Requirements?
There is no formal degree, prior certification, or minimum employment-duration prerequisite for the current examination. Candidates therefore do not need an employer to endorse a prescribed number of penetration-testing years. This accessibility should not be confused with beginner-level technical difficulty.
OffSec recommends a foundation in TCP/IP networking, Windows and Linux administration, and basic Bash or Python scripting. Candidates should distinguish these recommended preparation skills from mandatory eligibility conditions.
Training and examination routes
- Course-supported route: Prepare through PEN-200 purchased in a course-and-examination package or eligible subscription.
- Standalone route: Purchase examination attempts without enrolling in PEN-200. The assessment is the same, not a reduced or alternative qualification. No course-completion exemption is needed because training is not compulsory for this route.
Age: The ordinary minimum enrollment age is 18. Applicants aged 16 or 17 may be accepted through OffSec’s specific approval process, including parental or guardian documentation. Applicants under 16 are not accepted.
Identity and examination setup: Candidates must satisfy remote-proctoring requirements, including an acceptable physical government-issued photo ID in English and the necessary camera, screen-sharing, and technical arrangements. Resolve identification or accommodation needs before the appointment.
Enrollment, payment, and training completion do not authorize someone to claim OSCP. The award depends on passing the practical assessment and submitting the required examination report.
8. How Do You Earn the Credential?
Step 1: Purchase the appropriate route and schedule
Create an OffSec account, select the course-supported or standalone route, and schedule within the attempt’s validity period. OffSec’s examination policy specifies 120 days from purchase for standalone attempts, 120 days after lab access ends for course-bundle attempts, and the active subscription period for subscription attempts. Leave room for any required retake waiting period.
Step 2: Complete identity checks and the practical assessment
The remotely proctored examination uses a private VPN environment. Candidates have 23 hours 45 minutes to perform the practical work. It is a hands-on assessment, not a multiple-choice test.
The current scoring structure is:
- Three standalone machines: 60 points total, with 10 points for initial access and 10 for privilege escalation on each.
- One three-machine Active Directory set: 40 points, allocated 10, 10, and 20. Candidates receive starting credentials for an assumed-breach scenario.
- Passing threshold: 70 out of 100 points, supported by the required evidence. These are objective-based points, not a percentage of multiple-choice answers.
The examination is open-book, allowing permitted notes and online resources. Receiving assistance is prohibited, and AI chatbots are prohibited during both testing and report preparation. There are no course-completion bonus points.
Automated exploitation, mass vulnerability scanners, and commercial tools are prohibited. Metasploit is subject to specific restrictions. Candidates must follow the current tool policy rather than assume that every training tool is allowed.
Step 3: Submit the report
After testing, candidates have another 24 hours to submit documentation. The report must explain the successful attack steps and include the required screenshots and evidence. It is an assessed deliverable, not an optional administrative attachment. OffSec supplies report templates and requires a PDF submission.
Step 4: Receive the decision and credentials
OffSec states that pass/fail results arrive within ten business days after documentation submission. Successful candidates can claim their digital credentials through the learning platform.
Following failure, waiting periods are four weeks after the first failed attempt, eight after the second, and twelve after the third and subsequent failures. Buying another product does not reset the cumulative failure count.
9. How Long Does It Take, and How Do Candidates Prepare?
Prerequisite-building time: There is no required period of employment to complete first. For planning purposes, however, distinguish learning basic networking and operating-system administration from preparing specifically for the assessment.
Preparation time: OffSec publishes 12-week and 24-week PEN-200 learning plans. These are structured preparation options, not universal completion times or guarantees of readiness. They combine course topics, exercises, laboratory work, and examination-style practice.
Preparation choices: A useful readiness test is whether the candidate can investigate unfamiliar authorized lab systems without relying on walkthroughs, recover from unsuccessful approaches, and produce a coherent report. OffSec recommends practicing challenge environments, taking notes, rehearsing reporting, and planning breaks rather than treating the testing window as a requirement to remain awake throughout.
Administrative time: Budget separately for available appointments, the examination and reporting windows, result processing, and possible retake delays. Buying access does not mean an immediate examination or immediate certification decision.
10. How Much Does the Credential Cost?
As of September 25, 2026, advertised individual prices in U.S. dollars are:
- Standalone examination: $1,699. Two attempts, without PEN-200 training materials.
- Course + Cert Bundle: $1,749. Ninety days of PEN-200 course and lab access, with one examination attempt.
- Learn One: $2,749 per year. One year of access to the selected course and associated labs, with two attempts. The subscription automatically renews unless canceled.
These are alternative purchases, not cumulative charges. An illustrative first-attempt course-supported budget is therefore $1,749 before applicable taxes, assuming no extensions, retakes, or additional preparation purchases. Local taxes, currency conversion, and promotions can change the amount payable.
Retakes: OffSec lists a regular examination retake at $249 for eligible candidates who have not yet earned the credential. This is different from the recertification product for existing holders.
Optional preparation: Additional practice platforms, tutoring, equipment, and extra access time are separate budget decisions. Include the opportunity cost of study and assessment time when comparing routes.
Ongoing costs: OSCP itself requires no annual maintenance payment. For OSCP+ maintenance, the current maintenance-only option is $145 annually; the $299 annual membership includes maintenance coverage and additional learning benefits. At unchanged rates, three maintenance-only payments total $435, excluding any separately purchased learning.
11. How Do Holders Maintain the Credential?
OSCP does not expire. It requires neither continuing-education submissions nor annual maintenance fees to remain valid. An expired OSCP+ does not cancel the underlying OSCP.
OSCP+ expires after three years. Its renewal routes include:
- Continuing professional education: Complete 120 qualifying CPE credits over the three-year cycle and maintain annual coverage. Relevant external learning can qualify with supporting documentation.
- Recertification examination: Existing holders may take the designated examination, including to regain expired OSCP+ status. For renewal, the examination becomes available within six months before expiration.
- Another qualifying OffSec certification: Credentials such as OSEP, OSWA, OSWE, OSED, and OSEE can support renewal under the applicable timing and maintenance rules.
Maintaining an existing certification cycle requires annual coverage through the maintenance fee or membership option. Missed years must be covered; purchasing later does not restart the cycle.
OffSec’s handbook distinguishes extending an existing certification from purchasing and passing the $799 recertification examination to obtain a new three-year certification without paying the annual maintenance fee. Holders should select the route that matches their intended continuity of status.
A 90-day post-expiration grace period allows completion of outstanding maintenance and renewal requirements, but the credential remains expired during that period. Afterward, regaining OSCP+ requires the applicable examination route.
Non-expiring does not mean irrevocable. Cheating, prohibited sharing, and unethical use of a credential can trigger revocation under OffSec’s policies.
12. What Is Its Professional Value, and What Are Its Limitations?
OSCP’s most defensible professional value is that it supplies a concrete practical-assessment signal for offensive-security work. Its reporting requirement also distinguishes it from evidence consisting only of attendance or course completion. The reasonable inference is that the holder has demonstrated a bounded set of technical capabilities, not that every relevant professional capability has been assessed.
Employer recognition is observable but not universal. An EY U.S. posting dated September 11, 2026 lists OSCP among acceptable offensive-security certifications while separately requiring a degree, at least five years of relevant experience, leadership, and substantial technical delivery skills. Palantir’s offensive-security posting describes relevant certifications as a plus, not a requirement. These examples illustrate different hiring policies rather than a market-wide mandate.
For candidates, evaluate the credential against the roles they actually want. A professional targeting hands-on infrastructure testing has a different reason to pursue OSCP than someone focused on privacy compliance or security governance. For an employer, the assessment can reduce uncertainty about one part of a candidate’s technical foundation while leaving interview and work-sample evaluation necessary.
Do not interpret job-advertised salaries as an OSCP salary premium: the advertised compensation also reflects experience, location, responsibility, and other requirements. Similarly, avoid treating examination difficulty anecdotes as measurable evidence of business performance.
OffSec does not publish a current certification-holder count or general examination pass rate. Those omissions limit quantitative claims about scarcity or typical candidate success.
13. What Should Employers and Clients Infer from It?
What the credential establishes
A verified holder passed OffSec’s practical assessment and reporting requirements applicable to the award. OSCP does not establish a mandatory employment history. Active OSCP+ additionally indicates compliance with its current validity and renewal conditions, which can involve continuing education rather than another practical examination.
What still needs evaluation
Assess production-testing judgment, engagement scoping, communication, industry familiarity, remediation advice, and project leadership separately. Do not infer that an individual credential constitutes accreditation or authorization of the consulting firm employing the holder.
Useful staffing applications include a technical testing workstream, investigation of identity-related attack paths, or validation of previously identified vulnerabilities. Before assigning overall engagement leadership, request evidence of comparable delivery scale and responsibility.
Evidence to request
Ask for a sanitized client report or an independently created lab report, an explanation of remediation priorities, and references describing authorized project work. Do not request protected examination reports or solutions; OffSec prohibits their sharing.
Three questions to assess applied competence
- An ordinary domain account appears able to reach a sensitive server. How would you investigate the escalation path without exceeding the rules of engagement? A useful answer distinguishes permitted testing, technical hypotheses, operational risks, and stopping or escalation conditions.
- Two individually moderate weaknesses combine to provide administrative access. How would you explain and prioritize the finding? Look for attack-chain reasoning, business consequences, and practical remediation rather than reliance on isolated severity labels.
- What evidence would you retain so another tester could reproduce a finding and confirm remediation? Look for clear prerequisites, reproducible observations, careful handling of secrets, and an explicit retest method.
These are interview prompts about applied judgment, not examination questions or a substitute for a supervised work sample.
14. How Does It Compare with Related Credentials?
- CEH, Certified Ethical Hacker: EC-Council’s alternative covers broader ethical-hacking knowledge through a 125-question, four-hour knowledge examination. CEH Practical is separate; passing both supports CEH Master status. Eligibility generally requires official training or an approved application documenting two years of information-security experience. Do not assume that CEH alone includes the separate practical assessment.
- GPEN, GIAC Penetration Tester: An alternative for professionals assessing networks and systems, covering planning, reconnaissance, exploitation, and related techniques. Its current examination has 82 questions over three hours and includes CyberLive practical assessment. It differs from OSCP’s extended network-testing and report-submission format; compare actual assessment content rather than assuming that all GIAC examinations are purely theoretical.
- OSEP, OffSec Experienced Penetration Tester: A possible next stage for more advanced offensive work, including operating against stronger defenses and developing customized techniques. PEN-300 expects OSCP-level knowledge or equivalent skills, rather than requiring every learner to hold OSCP. Its practical examination is approximately 48 hours.
OSEP can also support OSCP+ renewal under OffSec’s qualifying-certification rules. That is a maintenance relationship, not automatic award of every lower credential. Select among these qualifications according to the knowledge gap, assessment style, and employer requirement, not a presumed prestige ranking.
15. How Can You Verify the Credential and Use Its Letters Correctly?
Ask the holder for the official digital credential or certificate QR code. OffSec states that certificates issued after April 5, 2022 contain a QR code leading to the holder’s digital credential page. For a certificate without a QR code, submit a verification request to OffSec using the person’s full name and OSID, the learner identification number.
Check the holder’s identity, issuing organization, exact designation, award date, and any expiration or status information. In particular, distinguish a non-expiring OSCP from an active OSCP+. A certificate image or résumé statement alone is weaker evidence than the issuer-backed record.
Most OffSec digital credentials are issued through Accredible. OffSec also provides Skills Passport sharing cards, but these are broader achievement summaries rather than substitutes for verifying the individual credential. Older holders can obtain digital credentials through the issuer’s process.
Use the designation actually awarded and currently held. Completing PEN-200 or preparing for the examination is not OSCP status. If OSCP+ expires, describe that status accurately while retaining the separately valid OSCP designation.
A missing public search result should prompt further verification, not an immediate accusation of misrepresentation. Ask the holder to provide the direct credential record or cooperate with an issuer inquiry.
16. Frequently Asked Questions
Can I take the examination without buying PEN-200?
Yes. OffSec offers a standalone OSCP+ examination product without the associated training. Successful candidates receive the same credentials. Buying course access is a preparation choice, not a requirement for that route, and the standalone assessment is not easier.
Is OSCP+ a higher technical grade than OSCP?
Not as a separate award from the current examination: passing it earns both. The principal distinction is that OSCP+ expires and requires renewal, whereas OSCP does not expire. Older OSCP holders may have passed a different historical examination format.
Will I lose OSCP if I stop paying maintenance fees?
No. The underlying OSCP has no annual maintenance-fee requirement. OSCP+ has separate renewal conditions. Letting the plus designation expire does not make the non-expiring OSCP invalid, although disciplinary revocation is a different matter.
Can an older OSCP holder obtain OSCP+ just by collecting CPE credits?
No automatic conversion is provided through CPE alone. OffSec directs existing OSCP holders seeking the plus designation to the recertification examination. CPE is a maintenance route for an eligible expiring credential after it has been earned.
Do laboratory exercises still provide examination bonus points?
No. The current OSCP+ examination has no bonus points for course or laboratory completion. Practice remains useful preparation, but candidates must satisfy the examination’s own scoring and reporting requirements rather than rely on an older bonus-point policy.
17. Official Resources and Recent Changes
Official resources available: OffSec provides a candidate handbook, body of knowledge, examination guide, report templates, preparation plans, proctoring instructions, appeals procedures, verification guidance, and maintenance policies. Candidates should use the examination rules applicable to their appointment, not an older preparation article.
Material changes: The November 1, 2024 transition introduced the paired OSCP and OSCP+ awards. Current maintenance guidance distinguishes the $145 maintenance-only fee from the $299 annual membership, which includes maintenance and learning benefits. These charges concern eligible expiring credentials, not permanent OSCP.
This profile is an independent Umbrex reference and is not issued or endorsed by the credential owner unless an explicit relationship is stated.