Is the CEH certification worth it?
81 of 8,110 cybersecurity analyst job ads in the United States name the CEH (Adzuna, October 2026)
Whether CEH certification is worth it depends on who pays and which job you want. For most beginners, it is not a good first purchase. The Certified Ethical Hacker (CEH) from EC-Council costs $1,050 or more without training; with official training, the price depends on the training partner. Employers name it in a small minority of ads. In our October 2026 count of 8,110 US security-analyst ads (Adzuna), the CEH appears in 81 of them and Security+ in at least 112. It is worth it in narrower cases: an employer pays, or a US government or defense contract names it. India is a third case if an employer or college pays for the training; there the CEH appears in 7% of the ads for security analysts. How we count ads.
Verdict by situation:
- No security experience yet: start with CompTIA Security+. It costs $439 and needs no experience; EC-Council itself recommends two years of IT security work before the CEH.
- You want to become a penetration tester: the OSCP tests hands-on skill, which the CEH knowledge exam does not.
- Your employer pays, or a job or contract names the CEH: take it. EC-Council lists US Department of Defense 8140 work roles that recognize the CEH, such as cyber defense analyst, cyber defense incident responder and vulnerability assessment analyst.
- You already hold a senior security role: compare it with the CISSP first.
Jump to: cost · renewal · alternatives: Security+, PenTest+ and OSCP
Show the numbers
| Item | Ads | Share of ads |
|---|---|---|
| CompTIA CySA+ | 34 | 15% |
| CEH | 30 | 13% |
| CompTIA Security+ | 17 | 7% |
| SSCP | 9 | 4% |
| ISC2 CC | 0 | 0 of 233 |
| Google Cybersecurity | 0 | 0 of 233 |
Is CEH worth it for you?
Instant answer from October 2026 job ads. No email needed.
Rarely named
81 of 8,110 cybersecurity analyst job ads in the United States name CEH.
- Most-named alternative
- CISSP 4.2%
- Skill asked for most
- SIEM 5.1%
Source: Adzuna job ads, October 2026.
On this page
- Is CEH worth it in 2026? What security-analyst ads show
- CEH cost: exam, eligibility fee and training
- How hard is CEH, and how long does it take to get it?
- Does CEH expire? Renewal with ECE credits
- CEH salary: what the figures measure
- CEH alternatives: Security+, PenTest+ and OSCP
- Who should take the CEH, and who should skip it
- Is CEH worth it? What posters ask on Reddit
- How to get the CEH, step by step
- Sources
Is CEH worth it in 2026? What security-analyst ads show
We count how often employers name a certificate in ads for one role in each country, using the local job title. For the CEH, that role is security analyst. The figures on this page come from those ads. Penetration testing is a different role, which our penetration-tester page covers.
In the US, the CEH appeared in 81 of the 8,110 security-analyst ads in October 2026. In the same ads, Security+ was named in 112, the CISSP in 338 and the CISM in 134. We count Security+ by the phrase comptia security, so ads that write only Security+ are missed and its count is a minimum. Our reading: each of these certificates appears in a small minority of US security-analyst ads, so the choice between the CEH and Security+ comes down to price and prerequisites more than to demand.
The UK sample is smaller. The CEH appeared in 4 of the 235 UK security-analyst ads, while the CISSP was named in 29. In Brazil, the CEH was named in 3 of the 434 ads for analista de segurança. The Mexico sample (12 ads for analista de ciberseguridad) is too small to read.
The ad count cannot show whether an employer that leaves the CEH out of its ad would still value it, or whether a contract requires it in documents that never reach a job board. What the count does show is that a buyer should not expect to see the CEH in many US or UK security-analyst ads.
Is CEH worth it in India?
Partly. Indian employers named the CEH in 7% of the ads for security analysts in October 2026. In the same ads, the CISSP appeared in 18% and Security+ in at least 3%. The sample is small, 250 ads, so a few ads can move a share by several percentage points from month to month. Read the figure as a sign that some Indian employers ask for the CEH, not as a precise rate.
The price is the same problem as elsewhere: EC-Council lists the exam in US dollars ($950 online, $1,199 at a test center), and training partners set their own prices. For an Indian candidate, the CEH makes most sense when an employer or a college program pays for the official training, which also removes the $100 eligibility fee. If you pay for it yourself and have no security experience, Security+ is still the cheaper start: $439, with no prerequisite.
What security-analyst ads name besides certificates
Three posts asked whether to learn Python, Terraform or a SIEM before buying another certificate. Our count tracks two skills for this role. In US security-analyst ads, SIEM (security information and event management) appeared in 5.1% and Splunk in 1.2%. In UK ads, SIEM appeared in 25%; in India, in 20%. Our reading: for an analyst job, hands-on SIEM experience belongs on the resume next to any certificate. Our security-analyst page lists every skill we track for the role by country.
CEH cost: exam, eligibility fee and training
EC-Council offers two ways to become eligible for the exam, and they change the bill.
| Item | Price | Who pays it |
|---|---|---|
| Eligibility application | $100, not refunded | Self-study route only |
| Knowledge exam voucher, online with proctor | $950 | All candidates (often bundled with training) |
| Knowledge exam voucher, Pearson VUE test center | $1,199 | If you choose a test center |
| Practical exam voucher (for CEH Master) | $550 | Optional |
| Retake voucher | discounted, price not published | If you fail |
| Continuing education fee | $80 a year | Every certified member |
| Official training (boot camp, live online or self-paced) | set by each training partner | Training route |
Source: EC-Council eligibility page, exam retake policy and continuing education fee page, read October 4, 2026. Analysis: CertWorthIt.
Self-study route. You apply with proof of two years in an information security role, pay $100 and, once approved, buy a voucher. With the online exam, the minimum is $1,050; at a test center, $1,299. Approval usually takes 5 to 10 business days, the approval is valid for 90 days, and a voucher must be used within 12 months.
Training route. Official training from EC-Council's iClass, an Authorized Training Center or a partner university makes you eligible without the application, the fee or the reference checks. Most training packages include the exam voucher. EC-Council does not set training prices; its partners do, and its own course page asks you to contact an advisor for a price. So we cannot give a training figure. Compare at least two quotes and check what each one includes: EC-Council's course kits list courseware, an exam voucher and six months of lab access, with retakes in some packages.
Show the numbers
| Item | |
|---|---|
| CEH, self-study route (online exam + eligibility fee) | $1,050 |
| CompTIA Security+ (SY0-701) | $439 |
| CompTIA PenTest+ (PT0-003) | $439 |
| OSCP+ standalone exam (OffSec) | $1,699 |
Over three years, the self-study route with the online exam comes to $1,290: $1,050 to get certified plus $240 in continuing education fees. The same three years of Security+ cost $589 ($439 for the exam plus $150 for one renewal). Adding the practical exam for CEH Master raises the CEH figure to $1,840.
How hard is CEH, and how long does it take to get it?
The knowledge exam has 125 multiple-choice questions in four hours. The passing score depends on the exam form you get and ranges from 60% to 85%; your cut score and your result appear on the transcript when you finish. EC-Council does not publish a pass rate. It does say that members with limited experience rate the exam as difficult, while experienced IT and security staff find it moderately hard.
How long it takes depends on the route. Official training is a five-day boot camp, and training centers often hold the exam at the end of the fifth day. Self-paced courses and self-study take longer, and we cannot say how much longer: the Reddit posts we collected about the CEH contain no first-person study-time reports we could count, so we give no range.
The bigger question is what you know before you start. EC-Council recommends at least two years of IT security experience and says its course will not teach you what a port is. Becoming an ethical hacker without that background is harder, because the course assumes networking basics. If they are new to you, budget time for them before you start. That is one reason to look at Security+ first.
For study materials, two posters asked which resources and labs to use. The official course has 20 modules and 221 hands-on labs in EC-Council's cyber range, and course kits include six months of lab access. Self-study materials are sold in the EC-Council store. EC-Council says self-published YouTube videos are not a substitute for official training and do not count as study when you apply for eligibility. We have no sourced comparison of third-party practice platforms, so we do not rank them.
Both CEH exams are accredited by ANAB under ISO/IEC 17024, EC-Council says. If you fail, there is no wait before the first retake and a 14-day wait before each later one, up to five attempts in 12 months.
Show the numbers
| Item | CEH |
|---|---|
| Questions | 125 questions |
| Exam time | 240 minutes (4 h) |
| Passing score | 60–85% |
| Format | Multiple choice, hands-on practical |
| Where you take it | test center · online, proctored |
Is CEH v13 worth it, or should you wait for the next version?
The current exam is version 13, which EC-Council markets as "CEH AI" and which adds AI tools to the course. New versions come every 12 to 18 months, EC-Council says. Waiting gains little: under the ECE policy, taking a newer-version exam later counts toward renewal. If you need the CEH for a job now, take the current version.
Does CEH expire? Renewal with ECE credits
Yes. A CEH is valid for three years. To keep it, you earn 120 EC-Council Continuing Education (ECE) credits within each three-year cycle and pay the continuing education fee of $80 every year (ECE policy and fee page, read October 4, 2026). Credits for a calendar year must be registered by February 1 of the next year.
Activities that count include conferences, webinars, courses, writing articles and passing another exam. Two entries in EC-Council's credit table matter most for a typical holder: another IT security certification exam earns 40 credits, and an EC-Council ECE exam earns all 120. Your normal job duties earn none.
If you miss the 120 credits, your certification is suspended. You then have 12 months to make up the credits and pay the fee. After that, it is revoked, and you must pass the current exam again to get it back.
Compared with CompTIA, the CEH costs more to keep: $240 per three-year cycle against $150 for Security+ or PenTest+. If you hold both, passing a CompTIA exam during the cycle counts for 40 of your 120 CEH credits.
Show the numbers
| Item | |
|---|---|
| 1. Experience | 2 years of work experience |
| 2. Exam | 125 questions, 240 minutes |
| 3. Certified | valid for 3 years |
| 4. Renewal | 120 ECE credits every 3 years |
CEH salary: what the figures measure
EC-Council's salary page puts US entry-level roles at about $60,382 a year for a security analyst, $65,946 for a SOC analyst and $66,802 for a junior ethical hacker, figures it takes from ZipRecruiter, Salary.com and Indeed. For US ethical hackers overall, it gives $99,000 to $170,000 (Glassdoor, May 2026) and an average of $130,000. None of these figures measures what the CEH itself adds: they describe pay for job titles, not for people who hold the certificate.
EC-Council's CEH course page cites Glassdoor at about $174,000 a year as of July 2026, with top earners at $298,000. The salary page also breaks pay down by role for 2026:
| Role (US) | Pay a year, as quoted by EC-Council | Data from |
|---|---|---|
| Junior ethical hacker | $66,802 | ZipRecruiter |
| SOC analyst | $71,449 to $85,113 | Salary.com |
| Penetration tester | $80,445 to $94,881 | Salary.com |
| Application security engineer | $88,190 to $106,071 | Salary.com |
| Security architect | $124,688 to $141,986 | Salary.com |
| Manager, penetration testing and red team | $133,290 to $156,603 | Salary.com |
| Chief information security officer (CISO) | $347,395 to $429,727 | Salary.com |
Source: EC-Council, ethical hacker salary page, read October 4, 2026; figures as EC-Council quotes them from ZipRecruiter and Salary.com.
The highest-paid role in the table, the CISO, is a management job, not a hacking job. Our reading: the job you land sets your pay far more than the CEH does. For certified ethical hacker salary questions, the useful figure is the pay for the role you can realistically get. For a first security job, those are the junior ethical hacker and SOC-analyst rows, not the $174,000 headline. Our security-analyst page covers demand for that role by country.
Show the numbers
| Country | CEH | Ads | Share of ads |
|---|---|---|---|
| India | 11 | 54 | 20% |
| United States | 30 | 233 | 13% |
| United Kingdom | 3 | 69 | 4% |
CEH salary in India
We have no CEH salary figure for India from EC-Council or from any source we could verify, so we give none. What we can give is demand: the CEH appeared in 7% of the ads for Indian security analysts in October 2026. We found no India figure that separates the effect of the CEH from experience and job title, which is why we leave salary sites out.
CEH alternatives: Security+, PenTest+ and OSCP
The four credentials test different things, and the format matters more than the name. Each pairing has its own comparison page; here is the short version.
| CEH | Security+ | PenTest+ | OSCP | |
|---|---|---|---|---|
| Vendor | EC-Council | CompTIA | CompTIA | OffSec |
| Exam | 125 multiple-choice questions, 4 hours | Up to 90 questions, 90 minutes, multiple-choice and performance-based questions | Up to 90 questions, 165 minutes, multiple-choice and performance-based questions | Hands-on: three standalone machines and an Active Directory set, then a written report |
| Experience required | 2 years in information security, or official training | None (2 years recommended) | None (3 to 4 years recommended) | None listed by OffSec in our sources |
| Exam price | $950 to $1,199, plus $100 without training | $439 | $439 | $1,699 exam only; $1,749 with the course |
| Valid for | 3 years | 3 years | 3 years | OSCP+: 3 years; traditional OSCP does not expire |
| Renewal | 120 ECE credits + $80 a year | 50 CEUs + $150 per 3 years | 60 CEUs + $150 per 3 years | Exam, advanced OffSec certification or CPE program |
Source: EC-Council, CompTIA and OffSec certification pages, checked October 3 and 4, 2026. Analysis: CertWorthIt.
Security+ is the cheaper entry-level option and needs no experience; a new version (SY0-801) is planned for November 17, 2026. Studying its material without taking the exam gives you the basics but not the credential. See our CEH vs Security+ comparison.
PenTest+ costs $439, mixes multiple-choice and performance-based questions, and CompTIA recommends three to four years of penetration-testing work first. See CEH vs PenTest+ and the PenTest+ page.
The OSCP is a long practical: OffSec's exam guide gives about 23 hours and 45 minutes of hands-on time, followed by a written report. Skills from practice platforms such as Hack The Box map onto that format, not onto 125 multiple-choice questions. Our CEH vs OSCP page compares the two in full.
For readers on the road to the OSCP, our answer, based on these facts, is Security+ first at $439, then the OSCP if penetration testing is the goal. The CEH fits in between only if a job or contract asks for it.
More comparisons: CEH vs CISSP, CEH vs CySA+ with the CySA+ page, and CEH vs eJPT with the eJPT page. The cybersecurity field page groups every security credential we track.
Show the numbers
| Country | CEH | CompTIA CySA+ |
|---|---|---|
| India | 20% | 15% |
| United Kingdom | 4% | 25% |
| United States | 13% | 15% |
Who should take the CEH, and who should skip it
Take it if:
- Your employer pays for official training, which also removes the $100 eligibility fee and the reference checks.
- A job ad, a client contract or a US Department of Defense role names it. EC-Council lists six 8140 work roles that recognize the CEH: all-source analyst, warning analyst, cyber defense analyst, cyber defense incident responder, vulnerability assessment analyst, and research and development specialist. It also says the CEH meets the baseline for four of five Cybersecurity Service Provider roles.
- You target India and an employer pays: the CEH appears in 7% of the ads for Indian security analysts, from a small sample, with the CISSP at 18%.
Skip it, or take it later, if:
- You are new to IT security. Start with Security+ and the networking basics the CEH course assumes.
- You want to prove you can run a penetration test. The OSCP exam tests that directly; the CEH knowledge exam does not.
- You would pay $1,050 or more yourself for a line on your resume. In the US, the same money covers Security+ with $611 left over for practice labs or a second exam.
Show the numbers
| Item | |
|---|---|
| Do you have 2 years of the work experience it requires? | No: Not yet. Look at CISSP (Certified Information Systems Security Professional) first, then the CEH once you qualify. |
| Yes | Apply for the CEH exam. |
Is CEH worth it? What posters ask on Reddit
We grouped the CEH questions in the Reddit posts we collected (r/SecurityCareerAdvice, r/cybersecurity and r/oscp) by theme. Reddit is a self-selected sample, so these show what people ask, not how many people hold an opinion.
- Value for a first job. One poster asked whether the CEH would improve their chances at an entry-level job, or whether Security+, PNPT, eJPT or the CCNA would be a better use of money (r/SecurityCareerAdvice). Our answer: Security+ first if you pay for it yourself, as the alternatives section explains; we have no facts on PNPT or the CCNA.
- What to learn next. Three posts asked whether Python, Terraform, a SIEM, the CEH or the CISSP would close a skills gap (r/SecurityCareerAdvice). The skills section gives the ad counts.
- Resources and labs. Posters asked which materials and lab platforms to use alongside the CEH (r/SecurityCareerAdvice; r/cybersecurity). The difficulty section covers the official labs; we do not rank third-party platforms.
- Order on the road to the OSCP. CEH or Security+ first (r/oscp), and whether to study only the key Security+ modules before the CEH (r/oscp). Our answer: Security+ first; studying its material without the exam gives you the basics but not the credential (see the alternatives section).
- OSCP or CEH next to Hack The Box practice (r/SecurityCareerAdvice). Our answer: the OSCP, because practice-platform skills match its hands-on format.
None of these posters asked how to renew, but renewal is where the CEH's cost adds up, so check the renewal section before you buy.
How to get the CEH, step by step
- Choose a route. Official training (iClass, an Authorized Training Center or a partner university) makes you eligible directly. Otherwise, apply for eligibility with proof of two years in an information security role.
- For the self-study route, pay the $100 eligibility fee and tell your references that EC-Council will contact them. Approval usually takes 5 to 10 business days and stays valid for 90 days.
- Buy the voucher: $950 for the online proctored exam or $1,199 at a Pearson VUE center. Use it within 12 months.
- Take the four-hour exam of 125 multiple-choice questions.
- Optional: take the six-hour practical exam ($550) for CEH Master.
- After you pass, pay the $80 fee each year and log 120 ECE credits within three years.
Show the numbers
| Level | Certification | Experience | Named first |
|---|---|---|---|
| Entry | ISC2 CC | no work experience required | – |
| Entry | Google Cybersecurity | no work experience required | – |
| Entry | IBM Cybersecurity Analyst | beginner course (vendor) | – |
| Associate | SSCP | required: 1 year of work experience | – |
| Professional | CompTIA Security+ | recommended: 2 years of work experience | – |
| Professional | CEH | required: 2 years of work experience | – |
| Professional | CRISC | required: 3 years of work experience | – |
| Professional | CompTIA PenTest+ | recommended: 3 years of work experience | – |
| Expert | CISSP | required: 4 years of work experience on the shortest route (4–5 years, depending on the route) | – |
| Expert | CompTIA CySA+ | recommended: 4 years of work experience | – |
| Expert | CISM | required: 5 years of work experience | – |
| Expert | CISA | required: 5 years of work experience | – |
| Expert | ISO 27001 Lead Implementer / Auditor | required: 5 years of work experience | – |
| Expert | CompTIA SecurityX (CASP+) | recommended: 10 years of work experience | – |
Sources
- Adzuna job-ad counts, security-analyst ads in the US, UK, India, Brazil and Mexico, October 2026; analysis: CertWorthIt. How we count.
- EC-Council, Certified Ethical Hacker course page (exam format, passing score, version, training, recognition, salary citation), read October 4, 2026.
- EC-Council, CEH application process and eligibility, read October 4, 2026.
- EC-Council, exam retake policy, ECE policy and continuing education fees, read October 4, 2026.
- EC-Council iClass, CEH course page, read October 4, 2026.
- EC-Council, ethical hacker salary page, read October 4, 2026.
- CompTIA, Security+ and PenTest+ pages and continuing education pages, checked October 3, 2026.
- OffSec, PEN-200 and OSCP page, checked October 3, 2026.
- Reddit questions about the CEH from the posts we collected, linked in the Reddit section, read October 4, 2026.
Edited by Elena Marsh · Data checked October 4, 2026
Questions people ask
Is CEH worth it for a first cybersecurity job?
Usually not as the first certificate you pay for yourself. EC-Council recommends two years of IT security experience before the CEH, and its course does not teach basics such as what a port is. Of the 8,110 US security-analyst ads we counted in October 2026 (Adzuna), 81 named the CEH and at least 112 named CompTIA Security+. Both appear in a small minority of ads, so the bigger difference is price: Security+ costs $439 and has no prerequisite. Take the CEH first only if an employer pays for it or a specific job ad asks for it.
Is CEH still worth it when the OSCP is the hands-on standard?
For a different purpose, yes. The CEH knowledge exam is 125 multiple-choice questions, so it shows that you know the terms and methods. The OSCP is a hands-on exam with a written report, so it shows that you can break into machines. If your goal is penetration testing, the OSCP tests that skill directly. If your goal is a job where an ad or a contract names the CEH, for example roles under the US Department of Defense 8140 rules, the CEH is the credential that counts there.
Should you take Security+ before the CEH?
In most cases, yes. Security+ needs no experience and costs $439, while the CEH asks for two years in information security or official training. Once you hold the CEH, passing a CompTIA exam during your three-year cycle earns 40 of the 120 ECE credits you need. A Security+ you passed before the CEH does not count, because credits must be earned inside the cycle.
Is CEH easy to pass?
Not for beginners. EC-Council does not publish a pass rate. It says members with limited experience rate the exam as difficult, while experienced IT and security staff find it moderately hard. The passing score is 60% to 85%, depending on the exam form, and you can take the exam up to five times in 12 months.
Do ethical hackers make a lot of money?
The job pays well in the US, by the figures EC-Council quotes: $99,000 to $170,000 a year on its salary page (May 2026) and about $174,000 on its CEH page (Glassdoor, July 2026). These describe people already working as ethical hackers, not what the CEH adds. For entry-level roles, the same salary page quotes about $60,382 for a security analyst, $65,946 for a SOC analyst and $66,802 for a junior ethical hacker (ZipRecruiter, Salary.com and Indeed), which is closer to what a new holder can expect.
Which hacker has the highest salary?
In the role table on EC-Council's salary page, the highest-paid role is the chief information security officer (CISO), at $347,395 to $429,727 a year in the US (Salary.com). That is a senior management job, not a hacking job. The best-paid hands-on role in the same table is manager of penetration testing and red team, at $133,290 to $156,603.
Can you make $500,000 a year in cybersecurity?
Not as an ethical hacker, by the figures we have. EC-Council's CEH page cites $298,000 a year for top-earning US ethical hackers (Glassdoor, July 2026). The only figures near $500,000 in our sources are for chief information security officers, $347,395 to $429,727 a year (Salary.com, as EC-Council quotes it), and no certificate leads to that role on its own.
Are ethical hackers still in demand?
We count ads for security analysts, not for ethical hackers as a job title. In October 2026, that came to 8,110 US security-analyst ads (Adzuna), and 81 of them named the CEH. This page reports one month of counts, so it says nothing about whether demand is rising or falling.
What is CEH Master?
It is the level you reach by passing both CEH exams: the four-hour knowledge exam and the optional six-hour practical exam, which has 20 challenges in a live cyber range. The practical voucher costs $550 on top of the knowledge exam. The practical exam is the only part of the CEH that tests hands-on skill.