Skip to content
CertMapCertMap

OSCP+

OffSecSpecialty certificatePentesting / Red Team
Official certification page

Created per CertMap methodology · About the editorial team

Jump to …4 sections

Overview

What is OSCP+?

OSCP+ is the three-year variant of the OSCP awarded since November 1, 2024, from the PEN-200 course (Penetration Testing with Kali Linux). Passing the updated exam earns both titles: the lifetime OSCP and the expiring OSCP+. The exam is hands-on and proctored over 23 hours 45 minutes across three standalone machines (60 points) plus an Active Directory set (40 points), followed by a professional penetration test report. Strength: the OSCP exam standard is a demanding practical proof of skill with high market recognition. Limitation: unlike the classic OSCP, OSCP+ requires ongoing maintenance via the OffSec CPE program (120 CPE per three-year cycle plus an annual maintenance fee).

Suitable for

Penetration Testers
Ethical Hackers
Red Teamers
Security Consultants

Quick facts

Languagesen
RecognitionGlobal
TagsOffensive · Hands-on · Pentest · Active Directory

Key details

Cost, prerequisites, exam & renewal

Cost over 5 years

Exam fee (acquisition)€1,609
AMF (5 years)€667
CPE time value (5 years)€16,000
5-year total€18,276
CPE effort: 40 h per year · 200 h over 5 years · Valued at 80 €/h.
How is TCO calculated?

Classification

CertMap score and matching roles

Rating

Market recognition
3/3
Scheme quality
2/3
Practice evidence
3/3
Maintenance
2/3

Matching NICE roles

Protect and DefendVulnerability Analysis

More certifications

More certifications

This page follows CertMap methodology: editorial content is curated by hand. Score, costs and NICE mapping are aggregated from official provider documents. Score methodology · TCO methodology

Transparency: CertMap is operated by Daniel Thomas Heessel, who is also managing director of Threat‑Informed, a company specialising in Threat‑Informed Defense. CertMap currently receives no commissions from certification providers, no affiliate links, no sponsored placements. Podcast and interview guests are not paid for appearances and receive no affiliate commissions.

Daniel Heessel, CISO of the Year 2026

1:1 with the CISO

Personal strategy instead of weeks of self-research. Vendor-independent, with auditable recommendations and transparent sources.

Open consulting
OSCP+View in quadrant