Selkobase certification index

OffSec Certified Professional: Complete Certification, Exam and Preparation Guide

Discover what OSCP / OSCP+ tests, what it takes, and whether it fits your goals

Validates practical penetration testing through network enumeration, exploitation, privilege escalation, Active Directory attacks, and professional reporting. Examine the OSCP / OSCP+ assessment, preparation demands, pricing, prerequisites, renewal expectations, and skills it can demonstrate. Compare the credential with adjacent options from OffSec before deciding whether it belongs in your professional development plan.

View the OSCP / OSCP+ certificationOffSecSearch Certifications by Filters

Credential overview

OffSec Certified Professional: What the certification covers and who it suits

OffSec Certified Professional validates practical penetration testing through network enumeration, exploitation, privilege escalation, Active Directory attacks, and professional reporting.

OffSec Certified Professional validates hands-on penetration testing across network enumeration, exploitation, privilege escalation, Active Directory attacks, and reporting. Candidates build the practical workflow needed to investigate systems, validate weaknesses responsibly, and communicate security findings in a form that supports remediation.

Penetration testingOffensive securityActive DirectoryPrivilege escalationOffSec

Who should take it

Choose OSCP if you already have a technical foundation and want a rigorous hands-on penetration-testing credential. It is a good fit for candidates prepared to practice independently and who want to move beyond broad ethical-hacking theory into structured offensive assessment work.

Best for

OSCP is suited to aspiring penetration testers, security consultants, red-team trainees, vulnerability-assessment professionals, and technically capable defenders who want a deeper offensive-security challenge. It is most appropriate for candidates with solid networking, systems, Linux, Windows, and command-line foundations who are ready for self-directed hands-on work.

Why it matters

OSCP is widely associated with practical offensive-security ability and can be a meaningful signal for candidates pursuing penetration-testing roles. It is most valuable when paired with mature reporting, authorized assessment experience, and the judgment to help organizations remediate risk rather than merely demonstrate access.

Requirements

Candidates should be comfortable with networking, operating systems, command-line tools, web concepts, scripting, and basic security principles. Prior lab or ethical-hacking experience is strongly recommended. Preparation should develop a repeatable process for enumeration, note-taking, evidence capture, troubleshooting, privilege escalation, and clear reporting within an authorized scope.

Best fit

Who OffSec Certified Professional is best suited for

OSCP is suited to aspiring penetration testers, security consultants, red-team trainees, vulnerability-assessment professionals, and technically capable defenders who want a deeper offensive-security challenge. It is most appropriate for candidates with solid networking, systems, Linux, Windows, and command-line foundations who are ready for self-directed hands-on work.

Who should take it

Choose OSCP if you already have a technical foundation and want a rigorous hands-on penetration-testing credential. It is a good fit for candidates prepared to practice independently and who want to move beyond broad ethical-hacking theory into structured offensive assessment work.

Best for

OSCP is suited to aspiring penetration testers, security consultants, red-team trainees, vulnerability-assessment professionals, and technically capable defenders who want a deeper offensive-security challenge. It is most appropriate for candidates with solid networking, systems, Linux, Windows, and command-line foundations who are ready for self-directed hands-on work.

Career value

Career value of OffSec Certified Professional

OSCP supports penetration tester, security consultant, red-team trainee, offensive-security engineer, vulnerability-assessment, and security research pathways. It can be a strong practical differentiator, while real engagement experience, ethical conduct, and high-quality reporting remain essential for career progression.

OSCP is widely associated with practical offensive-security ability and can be a meaningful signal for candidates pursuing penetration-testing roles. It is most valuable when paired with mature reporting, authorized assessment experience, and the judgment to help organizations remediate risk rather than merely demonstrate access.

Learning outcomes

OffSec Certified Professional: Skills and learning outcomes the certification is designed to validate

OffSec Certified Professional is intended to provide evidence of specific knowledge and professional capability. Translate each objective into something you should be able to explain, choose, configure, analyse, or troubleshoot, then verify that your practice demonstrates the skill rather than simple recognition.

  • Enumerate networks and services methodically
  • Validate vulnerabilities through controlled exploitation
  • Apply privilege-escalation and Active Directory attack concepts
  • Document evidence and security impact clearly
  • Produce reports that support remediation and risk decisions

Tags and keywords

Certification tags and search topics

Penetration testingOffensive securityActive DirectoryPrivilege escalationOffSecOffSec OSCPOffSec Certified ProfessionalOSCP certificationhands on penetration testingActive Directory penetration testingoffensive security training

Reference

Quick facts

Provider
OffSec
Code
OSCP
Level
Professional
Credential type
Professional certification
Active exams
1
Known price
$1,749
Study time
250-450h
Last verified
Sep 8, 2026
Official page

Provider

OffSec

Exam details

OffSec Certified Professional: Exam structure and assessed capability

Knowing the subject is only part of preparing for OffSec Certified Professional. Examine how the exam presents scenarios, decisions, tools, and technical concepts, then practise retrieving and applying that knowledge under realistic assessment conditions.

PEN-200

OSCP / OSCP+ certification exam

Proctored hands-on penetration test followed by a separate report-submission window

Official exam
Type
Practical
Delivery
Online
Duration
1425 min

Exam sections

01

OSCP

OSCP / OSCP+ certification exam examines how candidates understand and apply oscp within the wider credential scope. This area connects core concepts to the decisions, dependencies, and consequences practitioners encounter when carrying out the work described by validates practical penetration testing through network enumeration, exploitation, privilege escalation, Active Directory attacks, and professional reporting.

Question notes

Expect this topic to appear through scenario interpretation, objective questions, or practical tasks consistent with the overall OSCP / OSCP+ certification exam format. No separate question count or timing is assigned unless the provider publishes one.

Preparation tips

Build a small practice scenario around oscp and complete it without relying on step-by-step prompts. Afterwards, explain why each decision was appropriate and identify the signal that would have changed your approach.

02

OSCP+

This area concentrates on oscp+ as it appears in realistic tasks and scenarios. Candidates need to recognize the relevant inputs, choose a defensible approach, and understand how the result supports validates practical penetration testing through network enumeration, exploitation, privilege escalation, Active Directory attacks, and professional reporting.

Question notes

Candidates may encounter oscp+ through comparisons, troubleshooting prompts, configuration choices, analysis, or applied exercises. Exact distribution can change with the active exam form.

Preparation tips

Practise explaining oscp+ to a technical peer without reading definitions. Then validate the explanation by completing representative tasks and checking whether your result satisfies the intended objective.

03

PEN

PEN forms a distinct part of the capability assessed in OSCP / OSCP+ certification exam. The section brings together terminology, working methods, common constraints, and the judgment needed to deliver validates practical penetration testing through network enumeration, exploitation, privilege escalation, Active Directory attacks, and professional reporting.

Question notes

Expect this topic to appear through scenario interpretation, objective questions, or practical tasks consistent with the overall OSCP / OSCP+ certification exam format. No separate question count or timing is assigned unless the provider publishes one.

Preparation tips

Review a realistic artifact connected to pen—such as a configuration, report, backlog, model, log set, or design—and identify both correct practice and subtle weaknesses that an assessment could probe.

04

Penetration Testing

Questions or tasks in this area explore penetration testing from both conceptual and operational perspectives. Strong performance depends on connecting the topic to the broader responsibility of validates practical penetration testing through network enumeration, exploitation, privilege escalation, Active Directory attacks, and professional reporting.

Question notes

Candidates may encounter penetration testing through comparisons, troubleshooting prompts, configuration choices, analysis, or applied exercises. Exact distribution can change with the active exam form.

Preparation tips

Use a lab, case study, or worked example to connect penetration testing to observable outcomes. Deliberately introduce one incorrect assumption, diagnose its effect, and document the correction in your own words.

Study effort

OffSec Certified Professional: Preparation strategy and expected study effort

Effective OffSec Certified Professional preparation moves from scope review to active practice. Learn the core concepts, apply them in realistic tasks, test recall and judgment, and reserve enough time to close gaps rather than cramming near the exam date.

Study time

250-450h

Difficulty

Recommended experience

18 months

Practice exam useful
Hands-on lab useful

Exam cost

OffSec Certified Professional: Exam price and the full cost of earning the certification

Use the structured fee rows for the latest known amount and compare region, tax, voucher, or membership notes before registering.

$1,749

United States

Standard priceTax may vary

Prerequisites

What to know before starting OffSec Certified Professional

Candidates should be comfortable with networking, operating systems, command-line tools, web concepts, scripting, and basic security principles. Prior lab or ethical-hacking experience is strongly recommended. Preparation should develop a repeatable process for enumeration, note-taking, evidence capture, troubleshooting, privilege escalation, and clear reporting within an authorized scope.

Career fit

Roles and skills connected to this certification

Explore the roles and skills most directly connected to this certification, then use those paths to compare adjacent credentials.

RoleVulnerability Researcher

A vulnerability researcher analyzes software and systems to discover, understand, and responsibly document weaknesses before they can create avoidable risk.

5 certificationsExplore
RolePenetration Tester

Penetration testers simulate attacks against systems, applications, and networks to identify exploitable vulnerabilities and assess real-world security risks.

9 certificationsExplore
RoleSecurity Engineer

Security engineers design, implement, and maintain technical security controls to protect an organization's systems, data, and infrastructure from threats.

125 certificationsExplore
SkillPenetration Testing

Planning and executing authorized security tests to identify, simulate, and document exploitable vulnerabilities within information systems and network infrastructure.

20 certificationsExplore
SkillInformation Security

Implementing measures to protect digital assets, systems, networks, and sensitive information from unauthorized access, use, disclosure, disruption, modification, or destruction.

104 certificationsExplore
SkillSecurity Engineering

Implementing and validating technical security controls, systems, platforms, and processes to protect information assets.

108 certificationsExplore
SkillVulnerability Research

Vulnerability research is the disciplined discovery, analysis, validation, and responsible communication of software or system weaknesses in authorized contexts.

5 certificationsExplore
SkillReverse Engineering

The practice of analyzing compiled software, binary code, and communication protocols to reconstruct their design, functionality, and security properties without access to original source code.

8 certificationsExplore

Related areas

Related domains and industries

Use these subject and industry paths to understand where this credential fits inside the broader certification index.

Related certifications

Other OffSec certifications to compare

Compare other credentials from OffSec to understand nearby levels, specialties, and alternative certification paths.

OffSec

Professional certification
Featured

OffSec Experienced Penetration Tester

Validates advanced penetration testing and red-team tradecraft for breaching mature defenses, evading controls, moving laterally, and compromising enterprise environments. Explore the exam format, costs, study considerations, prerequisites, renewal expectations, outcomes, and related credentials to judge whether OSEP matches your experience and intended direction.

Study time
280-500h
Difficulty
Level
Expert

OffSec

Professional certification
Featured

OffSec Exploit Developer

Validates Windows user-mode exploit development, reverse engineering, custom shellcode, and bypassing modern exploit mitigations. Explore the exam format, costs, study considerations, prerequisites, renewal expectations, outcomes, and related credentials to judge whether OSED matches your experience and intended direction.

Study time
300-550h
Difficulty
Level
Expert

OffSec

Professional certification
Featured

OffSec Web Expert

Validates advanced white-box web application security through source-code review, complex vulnerability chains, custom exploit development, and rigorous reporting. Explore the exam format, costs, study considerations, prerequisites, renewal expectations, outcomes, and related credentials to judge whether OSWE matches your experience and intended direction.

Study time
280-500h
Difficulty
Level
Expert

OffSec

Professional certification

Kali Linux Certified Professional

Validates practical knowledge of Kali Linux installation, configuration, package management, command-line operation, security tools, troubleshooting, and customization. Explore the exam format, costs, study considerations, prerequisites, renewal expectations, outcomes, and related credentials to judge whether KLCP matches your experience and intended direction.

Study time
50-100h
Difficulty
Level
Foundational

OffSec

Professional certification

OffSec AI Red Teamer

Validates practical red teaming of AI-enabled systems, including generative AI applications, agents, retrieval pipelines, model infrastructure, and cloud-connected attack surfaces. Explore the exam format, costs, study considerations, prerequisites, renewal expectations, outcomes, and related credentials to judge whether OSAI / OSAI+ matches your experience and intended direction.

Study time
120-240h
Difficulty
Level
Expert

OffSec

Professional certification

OffSec CyberCore Certified – Secure Java Development

Validates the ability to identify and repair common vulnerabilities in Java web applications while preserving required application behavior. Explore the exam format, costs, study considerations, prerequisites, renewal expectations, outcomes, and related credentials to judge whether OSCC-SJD matches your experience and intended direction.

Study time
60-120h
Difficulty
Level
Foundational
View all provider certifications

Find the path that fits your goals across the OffSec certification catalog

Continue into individual OffSec certifications to compare what each credential covers, how candidates are assessed, and which professional goals it may support. Check the complete credential details before choosing where to invest your preparation time.