OSCP+
Created per CertMap methodology · About the editorial team →

▾ Jump to …4 sections
Overview
What is OSCP+?
OSCP+ is the three-year variant of the OSCP awarded since November 1, 2024, from the PEN-200 course (Penetration Testing with Kali Linux). Passing the updated exam earns both titles: the lifetime OSCP and the expiring OSCP+. The exam is hands-on and proctored over 23 hours 45 minutes across three standalone machines (60 points) plus an Active Directory set (40 points), followed by a professional penetration test report. Strength: the OSCP exam standard is a demanding practical proof of skill with high market recognition. Limitation: unlike the classic OSCP, OSCP+ requires ongoing maintenance via the OffSec CPE program (120 CPE per three-year cycle plus an annual maintenance fee).
Suitable for
Quick facts
Key details
Cost, prerequisites, exam & renewal
Cost over 5 years
Prerequisites
No formal prerequisites. Recommended: solid TCP/IP networking, Windows and Linux administration, basic Bash and Python scripting.
Exam format
23 hours 45 minutes, hands-on, proctored. Three standalone machines (60 points) plus an Active Directory set of three machines (40 points), passing score 70 of 100 points. Followed by a professional penetration test report (insufficient documentation reduces points).
Renewal & maintenance
OSCP+ is valid for three years. Renewal via the OffSec CPE program (120 CPE per cycle plus an annual maintenance fee of 145 USD, one fee covering all expiring OffSec certifications), by retaking the exam, or by passing a higher-level qualifying exam. The classic OSCP awarded in parallel remains valid for life even without renewal.
Classification
CertMap score and matching roles
Rating
Matching NICE roles
More certifications
More certifications
From OffSec
OSAI+OffSec AI Security ProfessionalOSCC-SECOffSec CyberCore Certified - Security EssentialsOSCC-SJDOffSec CyberCore Certified - Secure Java Development EssentialsOSCPOffensive Security Certified ProfessionalOSEPOffensive Security Experienced Penetration TesterOSIROffSec Incident ResponderOSTHOffSec Threat HunterIn Pentesting / Red Team
CEHEC-CouncilGPENGIACOSCPOffSecOSEPOffSecPECB LEHPECBPECB LPTPPECBPenTest+CompTIAThis page follows CertMap methodology: editorial content is curated by hand. Score, costs and NICE mapping are aggregated from official provider documents. Score methodology → · TCO methodology →
Transparency: CertMap is operated by Daniel Thomas Heessel, who is also managing director of Threat‑Informed, a company specialising in Threat‑Informed Defense. CertMap currently receives no commissions from certification providers, no affiliate links, no sponsored placements. Podcast and interview guests are not paid for appearances and receive no affiliate commissions.
From the knowledge base
View all articles →CISSP oder CISM? Zwei Karrieren, eine Entscheidung
Beide verlangen fünf Jahre Erfahrung, beide kosten auf den ersten Blick ähnlich viel. Trotzdem führen CISSP und CISM in verschiedene Berufe. Der Vergleich mit den Zahlen, die Kursanbieter nicht zeigen.
CISM oder CISA? Zwei ISACA-Wege, eine Richtungsentscheidung
Beide kommen von der ISACA, verlangen fünf Jahre Erfahrung und kosten fast dasselbe. Der Unterschied liegt nicht im Preis, sondern in der Rolle: steuern oder prüfen. Der Vergleich mit den Zahlen und der Rollen-Abbildung.
CC oder Security+? Der Gratis-Einstieg und der Arbeitsmarkt-Klassiker
Beide sind Einsteiger-Zertifikate ohne Zulassungshürde, beide decken die Grundlagen der Cybersicherheit ab, und trotzdem stehen sie für verschiedene Strategien: das eine als niedrigschwelliger, zeitweise kostenloser Start, das andere als etablierter Nachweis mit Gewicht im Arbeitsmarkt. Der Vergleich mit den Zahlen und der gegenläufigen Kostenlogik.

1:1 with the CISO
Need the full picture for your case?
Personal strategy instead of weeks of self-research. Vendor-independent, with auditable recommendations and transparent sources.