Career & Education

OSCP vs CEH: They Clear Different Gates

A practical comparison of cost, difficulty, employer perception, and career outcomes

CEH gets a CV past a filter. OSCP convinces the person running the technical interview. Which one is worth six months of your evenings depends entirely on which gate is actually in front of you.

The argument about these two is usually framed as which one is more respected, which produces a lot of heat and no useful answer. They clear different gates. CEH is a credential that gets a CV past a filter; OSCP is an exam that convinces the person who will actually interview you. Knowing which gate is in front of you is the whole decision.

Here is what each one actually asks of you, what each costs over three years rather than on the day, and the case for doing neither yet.

What the exams are

CEH is 125 multiple-choice questions in four hours. It tests whether you recognise tools, terminology, attack categories and methodology. You can prepare for it by reading, and people routinely pass it without ever having compromised a machine.

EC-Council also sells CEH Practical, a separate six-hour hands-on exam of twenty challenges in a live range. Passing both gives you CEH Master. This distinction matters and is constantly lost: when a job advert says CEH it almost always means the multiple-choice one, and when someone online says CEH proves nothing, they mean the multiple-choice one too. CEH Practical is a genuinely different exam and considerably fewer people hold it.

OSCP is a single hands-on exam — just under twenty-four hours in a live network, followed by a twenty-four hour window to write the report. You get a set of machines to compromise, including an Active Directory chain, and you are scored out of a hundred with seventy to pass. There is no multiple choice and there is no partial credit for knowing how something works. Either you have a shell or you do not.

The reporting half is not an afterthought. People fail OSCP having compromised enough machines, because the documentation was not good enough to prove it. That is deliberate — a penetration test that cannot be written up is not a penetration test — and it is the part candidates under-practise most.

The eligibility difference nobody mentions until they are booking

You cannot simply buy a CEH exam voucher. EC-Council requires either that you take their official training, or that you apply for eligibility on the basis of two years of information security experience, with a non-refundable application fee. The training route is substantially more expensive; the experience route requires a manager to verify your employment.

OffSec has no such gate. You buy the course, you get the exam. That is a genuine difference in accessibility for someone trying to break in without an employer behind them — and it cuts in OSCP's favour, which is not what you would expect from the harder exam.

Cost over three years, not on the day

Compare the ongoing cost, because this is where the two diverge and the sticker price misleads.

CEH requires continuing education: EC-Council's ECE programme asks for 120 credits over a three-year cycle, plus an annual membership fee. Let the credits or the fee lapse and the certification goes inactive. It is a subscription with an exam at the front.

OSCP has historically been a lifetime certification with no renewal. In late 2024 OffSec introduced OSCP+, which carries a three-year validity and is maintained by continued activity; the base OSCP designation remains non-expiring. Check which one your intended employer is asking for, because a job advert written in 2023 and a job advert written last month may mean different things by the same four letters.

The other cost is time, and it is the larger one. OSCP realistically takes three to six months of evenings and weekends for someone with a working knowledge of Linux and networking, and longer without. CEH is a few weeks of study. If you are weighing them against each other, weigh that honestly — six months is a real chunk of a career, and it is only worth spending if the gate in front of you is the technical one.

Which gate is in front of you

This is the part that actually decides it.

CEH clears HR filters. It appears by name in job specifications, in government and defence contracting requirements, and in the procurement rules of large enterprises. In several markets — US federal and defence contracting, much of the Gulf, large parts of the Indian enterprise sector — it is written into the requirement, and no amount of technical ability substitutes for a credential the system is configured to look for. If a recruiter's applicant tracking system is filtering on a string, the string is usually CEH.

Both certifications have appeared on the US Department of Defense's approved qualification lists, which is the main reason CEH retains its position in that market. That list changes, and it is maintained by role category rather than as a single roster — check the current DoD Cyber Workforce qualification matrix for the specific work role you are applying to rather than trusting any article, including this one.

OSCP clears technical panels. Nobody senior asks you to explain what OSCP covers, because they know. It is treated as evidence that you have sat in front of a machine you did not understand and worked until you had a shell — which is the actual job. In a consultancy or a red team, it is the closest thing the industry has to a shared baseline, and its absence on a CV for a testing role is more noticeable than its presence.

A hiring funnel across the top — applicant tracking system, recruiter screen, technical interview — with CEH marked as clearing the first gate and OSCP the last. Below, a six-row comparison: CEH is 125 multiple-choice questions in four hours testing recognition of tools and methodology, needs official training or two years' experience to sit, and requires 120 ECE credits every three years. OSCP is just under 24 hours in a live network plus 24 hours of reporting, tests whether you can get a shell on an unfamiliar machine, has no eligibility gate, and does not expire, though OSCP+ from November 2024 runs three years.
The argument about which is more respected misses the structure. One of them is read by software, the other by the person who will interview you.

The two-gate framing also explains the people who hold both. In defence contracting it is common and rational: CEH to satisfy the contract requirement, OSCP so the team lead takes you seriously. That is not redundancy, it is two different problems.

What neither of them proves

Worth saying plainly, because certification discussions tend to overclaim.

OSCP does not prove you can run a client engagement. It proves you can exploit machines in a lab built to be exploitable, on a network with no monitoring, no EDR and no blue team. Real testing involves scoping, stakeholder management, working around defences that fire, and writing for an audience that includes people who will not read past the executive summary. OSCP touches exactly one of those.

CEH does not prove you can do any of it. What it proves is that you have covered the vocabulary and the methodology systematically, which has genuine value if your role is to manage testers, write requirements, or sit on the defensive side and need to understand what the offensive side is doing. Judged as what it is — a broad knowledge credential — it is a reasonable one. It gets criticised because it is frequently sold as what it is not.

The case for neither, yet

If you are early and choosing between them, consider that the first certification is rarely the constraint.

For a first security job, Security+ is cheaper, faster, sits on the same approved lists for entry-level categories, and is better calibrated to what an entry-level role actually needs. Do that, get the job, and let an employer pay for OSCP later — many will, and a training budget you have not spent is leverage you already hold.

If the goal is specifically offensive security and you want to prove capability rather than clear a filter, there are cheaper ways to demonstrate it that also prepare you properly: a completed Hack The Box or TryHackMe path with public write-ups, a CVE you have reported, a tool you maintain. PNPT and eJPT both cost far less than either of these and are hands-on. None of them replace OSCP on a CV, but they all beat an unfinished OSCP attempt, and they tell you whether you enjoy the work before you commit six months to it.

Deciding, in four questions

  • Is a specific certification named in the job description or contract you are aiming at? Then that is your answer, whatever anyone thinks of it. Check the current requirement, not a list from two years ago.
  • Are you trying to move into hands-on testing from an adjacent role? OSCP. It is the thing that changes how your CV is read by the people who run the technical interview.
  • Do you need breadth for a defensive, managerial or GRC role that touches offensive concepts? CEH is defensible, and CEH Practical is more defensible. Do not let internet opinion talk you out of the right tool for your actual job.
  • Are you unemployed and paying for this yourself? Security+ first, then let an employer fund the rest. The cheapest certification is the one someone else buys.

Prices, formats and what changes

Exam formats, prices, eligibility rules, validity periods and approved-list memberships all change, and several of them have changed within the last two years. Exam structure details above are as published by EC-Council and OffSec at the time of writing; confirm the current exam guide for whichever you choose, particularly the OSCP scoring breakdown, which has been revised more than once.

We hold no affiliation with either organisation, receive nothing if you buy either, and have not been paid to recommend a training provider. The judgements about which gate each certification clears are ours, drawn from how these credentials appear in job requirements rather than from a survey.

oscpcehcertificationspenetration-testingcyber-security-careersoffsecec-council

Arslan ud Din Shafiq

Founder and lead editor of LearnCybers. Full-stack engineer with expertise in Linux systems, cybersecurity, cloud infrastructure and web development. Writing about practical technology since 2019.

Related reading

Newsletter

Get smarter about security

Practical guides, tooling notes and the developments actually worth your attention — delivered when there is something worth saying.

No spam. Unsubscribe in one click.