Skip to content
CertMapCertMap

VERGLEICHE

CEH or OSCP? Knowledge Exam or 24-Hour Practical Test

Few comparisons come up as often in the security scene: on one side the accredited knowledge exam with decades of presence in tender requirements, on the other the fully hands-on exam format with a strong reputation among pentesters. The comparison with the numbers, the format contrast, and the different renewal models.

By Daniel Thomas HeesselLast updated: July 30, 20266 min read

"CEH or OSCP" is the most debated certification question in pentesting, and it is often asked the wrong way. The honest answer: the two compete less than it seems, because they demonstrate different things. One shows that you know the field, the other that you can carry out the attack.


Both address the same domain, the offensive testing of systems, and both appear in the same job postings, often even as alternatives. Yet almost everything that defines a certification separates them: the exam format, the renewal logic, the accreditation, and the language.

What the two stand for

The CEH (Certified Ethical Hacker) from EC-Council has been present in job postings for decades, particularly in government and US contexts. The current version v13 also covers AI-assisted attack techniques and cloud hacking, according to EC-Council. The CEH is accredited under ISO/IEC 17024 and is offered in many exam languages, including German. Those who additionally want to demonstrate hands-on skills can add the optional CEH Practical, a six-hour practical exam.

The OSCP (Offensive Security Certified Professional) from OffSec is regarded in the security community as a particularly respected practical credential for penetration testers. The exam is entirely hands-on: nearly 24 hours of attacking a live practice network, followed by a report. Since late 2024, the OSCP+ with an Active Directory scenario replaces the original format for new candidates; unlike the classic OSCP title, which is valid indefinitely, the Plus runs on a three-year cycle according to OffSec and falls back to the title without the Plus if not renewed. The well-known limitation: the OSCP covers classic network pentesting, not the web app or exploit depth of the more advanced OffSec tiers.

The numbers side by side

CEHOSCP
ProviderEC-CouncilOffSec
Acquisition cost (exam, EUR)€1,103€1,517
Total cost over 5 years (EUR)i€1,471€1,517
Prerequisites2 years IT security experience OR official EC-Council training course.No formal prerequisites. PEN-200 course (included in price) is the official preparation. Solid networking and Linux knowledge strongly recommended.
Exam format125 multiple-choice questions, 4 hours, proctored via Pearson VUE/EC-Council. Passing score: 60–85% (variable).Practical: 23 hours 45 min hands-on exam in live network + subsequent report. Proctored. Passing threshold: 70 points/100.
Validity3 years
CPE effort00
CertMap scoreHow we score6 / 12Market strength
4/6
Substance
2/6
8 / 12Market strength
5/6
Substance
3/6

Values live from the CertMap cost methodology (USD fees converted to EUR, totals include annual fees, recertification and CPE time value). Same data basis as the comparison tool.

Two patterns stand out in the table that shape the decision more than any single price:

  • The exam format is the real difference. The CEH tests knowledge on screen in multiple-choice format (those who want to add hands-on proof can take the optional CEH Practical), the OSCP demands a nearly 24-hour break-in to a live practice network followed by a report. The two formats demonstrate different competencies, and that is exactly why the question "which one is better" misses the point: they answer different questions.
  • The renewal models diverge by vintage. The CEH works on a three-year cycle: continuing education credits plus an annual fee keep the title active. For the OSCP, the classic title is valid indefinitely, with no annual fee and no renewal obligation; anyone starting since late 2024 receives the OSCP+, which according to OffSec falls back to the title without the Plus after three years if not renewed. How CertMap calculates such lifecycle costs is explained in the cost methodology.

Add to that a contrast the table only hints at: the CEH is formally accredited (ISO/IEC 17024) and multilingual, the OSCP is not accredited and is examined in English only; it draws its weight from its reputation in the technical community, not from an accreditation framework.

One asks what you know, the other what you can do. The CEH is the accredited knowledge exam with weight in tenders, the OSCP the practical proof with weight in the technical community.

Prerequisites: experience or course versus an open field

The entry models differ markedly:

  • CEH: Two years of IT security experience OR attendance of the official EC-Council training. The course route makes the CEH attainable even without work experience, but drives up the total cost.
  • OSCP: No formal prerequisites. The PEN-200 course is included in the price and is the official preparation; solid networking and Linux skills are strongly recommended according to OffSec, and in practice they are a prerequisite for passing.

Formally the OSCP is thus more open, in practice its hurdle is the higher one: the exam cannot be passed on study material alone.

The exams

The CEH exam poses 125 multiple-choice questions in four hours, proctored via Pearson VUE or EC-Council, with a variable passing threshold between 60 and 85 percent depending on the question set; it is examined in several languages, including German. The OSCP exam lasts nearly 24 hours straight: an attack on a live practice network under proctoring, passing threshold 70 out of 100 points, followed by a professional report, all in English. There are hardly two exam formats in the security field that are further apart.

Our assessment

What our rating says: In the CertMap rating, the OSCP comes out ahead, carried by two axes at once: it is the most sought-after technical credential among pentesters, and its fully hands-on exam format is the strongest practical proof in this comparison. The CEH counters with its formal accreditation and its decades of presence in tenders, but its exam format primarily demonstrates knowledge. The maintenance side is striking: the CEH demands ongoing continuing education, the classic OSCP title none at all, which in our substance axis is, honestly, a minus for the OSCP; only the newer OSCP+ introduces a renewal cycle. How the rating axes are constructed is explained in the rating methodology.

The decision becomes easier when approached from the target market:

  • If you need the credential for tenders, formal job requirement profiles, and government-adjacent settings, where the CEH has stood as a requirement for years, or if you want an exam in German, the CEH is the right choice.
  • If you want to demonstrate hands-on pentest skills, for example towards technical departments, in technical interviews, or in consulting, the OSCP is the credential with the greater weight in the community.
  • The two are not mutually exclusive: tenders often say "CEH or OSCP", and anyone who has to satisfy a formal requirement and a technical proof at the same time combines them. The annual fee burden is carried by the CEH alone; the renewal question arises for the OSCP only with the newer Plus.

Frequently asked questions

Is the OSCP harder than the CEH?

The two cannot be compared on one scale because they test different things. The CEH demands broad knowledge of attack techniques, the OSCP demands compromising real systems under time pressure and documenting it cleanly. The preparation differs accordingly: study material for the CEH, months of lab practice for the OSCP.

Does the OSCP have to be renewed?

The classic OSCP title does not: valid indefinitely, with no annual fee and no continuing education obligation. Anyone starting since late 2024, however, receives the OSCP+, which according to OffSec runs on a three-year cycle and falls back to the title without the Plus if not renewed. The CEH consistently works on a three-year cycle of continuing education credits and an annual fee.

Are the exams available in German?

The CEH, yes, it is examined in several languages including German. The OSCP is available in English only, including the exam report.

Read next:CC or Security+? The Free Entry Point and the Job-Market ClassicWhat is Personnel Certification under ISO/IEC 17024?