OSCPOffensive Security Certified Professional
Created per CertMap methodology · About the editorial team → · Official page ↗

▾ Jump to …6 sections
What is OSCP?
OffSec's OSCP certifies practical penetration testing skills. It is assessed in a 24 hour exam, proctored throughout, in which candidates identify, exploit and document vulnerabilities in live lab systems. There are no formal prerequisites; OffSec recommends a solid foundation in TCP/IP networking, basic scripting skills and familiarity with Linux and Windows. The exam can also be booked without course material, as a standalone exam at 1,699 USD. The OSCP has no expiration date; only the additional OSCP+ designation expires three years after issuance. The entry is aimed at anyone who needs proof of hands-on ability for offensive work rather than a knowledge test.
Suitable for
Quick facts
CertMap assessment & background
Demand for the OSCP in offensive roles is broad, evidenced by an industry award from 2024 and by OffSec's own reasoning that expiring variants exist because employers ask for them. The hard part is not admission, there are no formal prerequisites, but preparation: OffSec recommends TCP/IP, scripting, Linux and Windows knowledge, and building that on the side adds considerable time. The limit is quality assurance, there is no documented accreditation and the process is vendor-run. Upkeep is cheap because the OSCP does not expire, entry is not, because pricing is built around course bundles and the lowest price including the exam is 1,699 USD for the standalone exam. Anyone keeping the OSCP+ designation takes on a maintenance obligation the base OSCP does not have.
More on CertMap editorial methodology →Cost, prerequisites, exam & renewal
Prerequisites
There are no formal prerequisites; the credential is awarded on the strength of the performance test alone. OffSec does recommend a solid foundation in TCP/IP networking, basic scripting skills and familiarity with Linux and Windows.
Exam format
The OSCP exam is a 24 hour exam, proctored throughout by an OffSec employee in a private VPN. It is purely hands-on: identify, exploit and report real-world vulnerabilities in live lab systems.
Renewal & maintenance
The OSCP does not expire; OffSec lists it as valid indefinitely. Only the OSCP+ designation expires three years after issuance, and learners who do not maintain it keep the OSCP. There is therefore no annual fee and no CPE requirement for the OSCP.
CertMap score and matching roles
Rating
Schema quality 1/3: documented but vendor-run process without documented accreditation. Practice evidence 3/3: 24 hour proctored hands-on exam on live lab systems. Maintenance: no documented cycle, OffSec publishes no revision rhythm in years, and the base OSCP does not expire. Market recognition 3/3: industry award in 2024 plus employer requirements as the stated reason for expiring variants.
Matching NICE roles
About OffSec
OffSec is the commercial provider of the PEN-200 course and the OSCP family. The exam is sold both bundled with course access and as a separate exam product without course material, the standalone exam at 1,699 USD. OffSec quotes prices in US dollars, without a euro conversion and with a note that US state taxes may apply. The portfolio holds permanent and expiring certificates side by side; OffSec attributes the expiring variants to employer requirements. Price, exam format and recommended prior knowledge are documented publicly and without a login.
More certifications
From OffSec
OSAI+OffSec AI Security ProfessionalOSCC-SECOffSec CyberCore Certified - Security EssentialsOSCC-SJDOffSec CyberCore Certified - Secure Java Development EssentialsOSCE3Offensive Security Certified Expert 3OSCP+OffSecOSDAOffensive Security Defense AnalystIn Pentesting / Red Team
CEHEC Council Certified Ethical HackerCPENTEC Council Certified Penetration Testing ProfessionalECESEC Council Certified Encryption SpecialisteCPPTINE Security Certified Professional Penetration TestereJPTINE Security Junior Penetration TestereMAPTINE Security Mobile Application Penetration TesterFrom the knowledge base
View all articles →CEH or OSCP? Knowledge Exam or 24-Hour Practical Test
Few comparisons come up as often in the security scene: on one side the accredited knowledge exam with decades of presence in tender requirements, on the other the fully hands-on exam format with a strong reputation among pentesters. The comparison with the numbers, the format contrast, and the different renewal models.
OSCP or GPEN? Marathon versus Method
Two technical pentest credentials with a hands-on component, tied in our rating, and yet fundamentally different: on one side the continuous 24-hour practical exam with cult status in the scene, on the other the methodical GIAC exam with CyberLive tasks, accreditation and a maintenance regime. The comparison with the numbers and the surprising cost logic.
CISSP or CISM? Two Careers, One Decision
Both require five years of experience, both cost roughly the same at first glance. Yet CISSP and CISM lead to different professions. The comparison with the numbers that course providers don't show.