OSCPOffensive Security Certified Professional
Created per CertMap methodology · About the editorial team →

▾ Jump to …4 sections
Overview
What is OSCP?
The Offensive Security Certified Professional is considered the most prestigious practical certification for penetration testers in the security community and has further solidified its cult status in recent years. The fully practical 24-hour exam format (hacking + report) fundamentally distinguishes OSCP from multiple-choice certifications and serves as a credible proof of performance. Since 2024, OSCP+ replaces the original OSCP for new candidates and extends the credential with an Active Directory scenario. A known limitation is its focused scope: OSCP covers classic network pentesting but no web application depth (OSWE) or advanced exploitation (OSED/OSEE). In job postings for penetration testers, OSCP is the most requested technical certification worldwide.
Quick facts
Key details
Cost, prerequisites, exam & renewal
Prerequisites
No formal prerequisites. PEN-200 course (included in price) is the official preparation. Solid networking and Linux knowledge strongly recommended.
Exam format
Practical: 23 hours 45 min hands-on exam in live network + subsequent report. Proctored. Passing threshold: 70 points/100.
Renewal & maintenance
Valid indefinitely. No renewal required.
Classification
CertMap score and matching roles
Rating
Matching NICE roles
More certifications
More certifications
From OffSec
OSAI+OffSec AI Security ProfessionalOSCC-SECOffSec CyberCore Certified - Security EssentialsOSCC-SJDOffSec CyberCore Certified - Secure Java Development EssentialsOSCP+OffSecOSEPOffensive Security Experienced Penetration TesterOSIROffSec Incident ResponderOSTHOffSec Threat HunterIn Pentesting / Red Team
CEHEC-CouncilGPENGIACOSCP+OffSecOSEPOffSecPECB LEHPECBPECB LPTPPECBPenTest+CompTIAThis page follows CertMap methodology: editorial content is curated by hand. Score, costs and NICE mapping are aggregated from official provider documents. Score methodology → · TCO methodology →
Transparency: CertMap is operated by Daniel Thomas Heessel, who is also managing director of Threat‑Informed, a company specialising in Threat‑Informed Defense. CertMap currently receives no commissions from certification providers, no affiliate links, no sponsored placements. Podcast and interview guests are not paid for appearances and receive no affiliate commissions.
From the knowledge base
View all articles →CISSP or CISM? Two Careers, One Decision
Both require five years of experience, both cost roughly the same at first glance. Yet CISSP and CISM lead to different professions. The comparison with the numbers that course providers don't show.
CISM or CISA? Two ISACA paths, one directional decision
Both come from ISACA, both require five years of experience, and both cost almost the same. The difference is not the price but the role: managing or auditing. The comparison with the numbers and the role mapping.
CC or Security+? The Free Entry Point and the Job-Market Classic
Both are entry-level certifications with no admission barrier, both cover the fundamentals of cybersecurity, and yet they stand for different strategies: one as a low-threshold, temporarily free start, the other as an established credential with weight in the job market. The comparison with the numbers and the opposing cost logic.

1:1 with the CISO
Need the full picture for your case?
Personal strategy instead of weeks of self-research. Vendor-independent, with auditable recommendations and transparent sources.