Is OSCP worth it for a penetration-testing job in 2026?
73% of penetration tester job ads in the United States name the OSCP (158 of 217, Adzuna, October 2026)
The answer to "is OSCP worth it?" is yes if you know networking, Windows, Linux and basic scripting, want penetration-testing work and can pay at least $1,699. The OSCP (OffSec Certified Professional, a 24-hour hands-on hacking exam from the training company OffSec) appeared in 73% of the ads for US penetration testers on Adzuna, a job-ad search site, in October 2026.
A penetration tester is paid to break into an organization's systems with permission and report the weak points. Verdict by situation:
- New to IT: skip it for now. First learn the three areas OffSec strongly recommends: networking, Windows and Linux administration, and basic scripting.
- Some hacking practice, but no hands-on exam yet: the eJPT (INE's Junior Penetration Tester exam) is one hands-on exam you could try first.
- You want to be hired as a penetration tester and have the background: plan for the OSCP. It appears in more US penetration-tester ads we counted than the eJPT.
You earn the OSCP by passing the exam that follows OffSec's PEN-200 course.
Show the numbers
| Item | Ads | Share of ads |
|---|---|---|
| OSCP | 158 | 73% |
| CEH | 66 | 30% |
| eJPT | 3 | 1% |
Is OSCP worth it for you?
Instant answer from October 2026 job ads. No email needed.
Employers ask for it
73% of penetration tester job ads in the United States name OSCP (158 of 217 ads).
- Most-named alternative
- CEH 30%
- Official exam fee
- $1,699 source
Source: Adzuna job ads, October 2026. Small sample: 217 ads. Treat this as a rough guide.
Get your full report
Two optional questions shape your first step. No email needed.
On this page
- Is the OSCP certification worth it in 2026? What penetration-tester ads show
- What is the OSCP, and who is it for?
- OSCP vs OSCP+: what changed?
- How much does the OSCP cost? Exam, course and subscription
- How hard is the OSCP exam?
- How long does it take to get the OSCP?
- Does the OSCP expire? OSCP renewal and OSCP+
- What is the OSCP salary?
- OSCP vs CPTS and PNPT: which fits you?
- Is OSCP worth it? What Reddit posters say
- What should you do first?
- What we did not check
- Sources
Is the OSCP certification worth it in 2026? What penetration-tester ads show
For US penetration-tester jobs, ads name the OSCP: in October 2026, it appeared in 158 of the 217 US penetration-tester ads we counted on Adzuna.
In the same October 2026 count of US penetration-tester ads on Adzuna, the CEH (Certified Ethical Hacker, from EC-Council) appeared in 66 ads and the eJPT in 3.
The count shows whether an ad mentions the OSCP, not whether the ad requires it or whether holders get interviews.
The UK and India samples are small, so read them with care. In October 2026, the OSCP appeared in 28 of the 58 UK penetration-tester ads on Adzuna; India is not counted yet.
What does the OSCP prove to an employer?
It proves you broke into live test machines and documented the attacks under exam rules. OffSec grades the hacking and the written report.
OffSec lists roles the OSCP "can open the door to," from penetration tester to SOC analyst (someone who watches security alerts). That list is OffSec's marketing, not job-ad data; we count the OSCP only in penetration-tester ads.
What is the OSCP, and who is it for?
OffSec built PEN-200 for people who want to become penetration testers, and it does not describe the OSCP as a beginner certification. The course page calls PEN-200 "OffSec's essential training program for aspiring penetration testers."
On prerequisites, OffSec's PEN-200 FAQ says, word for word: "While there are no formal prerequisites, it is strongly recommended that you have:"
- "A solid understanding of TCP/IP networking"
- "Reasonable Windows and Linux administration experience"
- "Familiarity with basic Bash and/or Python scripting"
TCP/IP is the set of rules computers use to address and talk to each other. Bash and Python are languages for small scripts that automate tasks.
The course page lists the audience as infosec (information security) professionals moving into penetration testing, ethical hackers, penetration testers, network administrators and other technology staff. For OffSec's exam-only product, its Standalone exam FAQ recommends "at least some experience in the field of penetration testing."
OSCP vs OSCP+: what changed?
Passing the exam now earns two titles that differ only in whether they expire. OffSec's PEN-200 page says: "Upon passing the exam, learners earn both the OSCP and OSCP+ certification." The OSCP+ expires after three years; the OSCP does not (renewal details).
How much does the OSCP cost? Exam, course and subscription
The OSCP costs $1,699 for the exam alone, $1,749 with 90 days of OffSec's course, or $2,749 a year for the Learn One subscription. For PEN-200, all three lead to the same exam; the Standalone FAQ says "The exam content is identical."
OSCP cost from OffSec, in US dollars on the PEN-200 page:
| Option | Price | What it includes |
|---|---|---|
| OSCP+ Standalone Exam | $1,699 once | Exam only, no course or labs; two attempts valid 120 days (Standalone FAQ) |
| Course + Cert Bundle | $1,749 once | 90 days of PEN-200 (or another course), hands-on labs (practice networks you may attack), one exam attempt |
| Learn One | $2,749 a year | One year of one course such as PEN-200, its labs and two exam attempts; auto-renews unless canceled |
| Exam retake | $249 | One more attempt, to be taken within 120 days of purchase (Standalone FAQ) |
Source: OffSec PEN-200 page; attempts and retake from the Standalone FAQ.
Exam only. The standalone exam is the cheapest route if you have prepared elsewhere. If you pass on the first try, you lose the second attempt and get no refund.
The 90-day bundle. For $50 more than the exam alone, you get the course and labs, but one attempt instead of two.
Show the numbers
| Item | Fee |
|---|---|
| Fees to get certified: Exam | $1,699 |
| Fees to get certified: Official prep course (optional) | $1,749 |
| Fees to get certified: One retake (optional) | $249 |
How hard is the OSCP exam?
The OSCP exam is hard by design: 23 hours and 45 minutes of hands-on hacking under a proctor (an OffSec employee who watches you). Then you get 24 more hours to upload your report, and you need 70 of 100 points. The course page says: "Not everyone passes on the first try."
A single machine is one target computer you attack on its own. Initial access is your first access to a machine; privilege escalation means raising that access to administrator control. Active Directory is Microsoft's system for managing users and computers on a company network; the exam gives you one login, and you move through three connected machines.
The points, from OffSec's exam guide:
| Part of the exam | Points |
|---|---|
| Three single machines: 10 for initial access and 10 for privilege escalation on each | 60 |
| One Active Directory set of three machines, starting from a given username and password | 40 |
| Needed to pass | 70 |
Source: OffSec OSCP exam guide.
Several point combinations reach 70, so you can pass without solving every machine; OffSec's guide lists them.
The exam runs over a VPN, a private encrypted link into OffSec's exam network. The report records every attack step, the commands you ran and their output. The guide calls the documentation rules "very strict"; incomplete documentation means reduced or zero points.
Show the numbers
| Item | OSCP |
|---|---|
| Exam time | 1,425 minutes (23 h 45 min) |
| Passing score | 70 of 100 |
| Format | Hands-on practical |
| Where you take it | online, proctored |
Which tools can you use on the OSCP exam?
You may use some tools, such as Nmap (a free network scanner), on every target, but not commercial tools, automatic exploitation tools or AI chatbots. OffSec's exam guide is the only rulebook, and OffSec says it "will not comment on allowed or restricted tools" beyond it. The guide bans:
- spoofing (faking network addresses or names)
- paid commercial tools
- tools that exploit a machine automatically, such as SQLmap
- mass vulnerability scanners such as Nessus
- AI chatbots such as ChatGPT
Metasploit, a free attack framework, may be used against one target machine of your choice; two of its helper tools are allowed on every machine.
What happens if you fail the OSCP?
With the Standalone product, you wait, then take another attempt. The Standalone FAQ lists a $249 retake, to be taken within 120 days of purchase. Its waiting periods are 4 weeks after a first attempt, 8 weeks after a second and 12 weeks after the third attempt or any later one.
How long does it take to get the OSCP?
Expect months, not weeks. In the r/oscp posts we collected (the OSCP community on Reddit), ten people stated how long their preparation took (self-reported): a median of 4.5 months (the middle value), from 2 to 10 months.
OffSec counts 321 hours of PEN-200 content. At 20 hours a week, 321 hours take about 16 weeks, close to four months, before any extra practice. At that pace, the 90-day bundle is tight.
When should you buy the OSCP course?
Buy it when you can study steadily, because the bundle lasts only 90 days. Learn One gives a full year for $1,000 more than the bundle.
What should you study for the OSCP?
Study what the exam grades: getting into single machines, escalating privileges and attacking an Active Directory set, then documenting each step. One poster who had worked as a penetration tester for three years failed the first attempt and wrote: "I wasted so much time studying things that were not on the exam" (r/oscp). They passed the second time.
Another poster on a second attempt said they had worked through about 50 to 60 practice machines and still found them hard (r/oscp).
Does the OSCP expire? OSCP renewal and OSCP+
The OSCP does not expire; the OSCP+ expires three years after it is issued. The PEN-200 course page lists three ways to keep the "+":
- Pass a recertification exam (an exam taken to renew the title) within six months of the OSCP+ expiration date.
- Pass another qualifying OffSec certification exam before the OSCP+ expires.
- Complete OffSec's CPE program (continuing professional education, credits earned for further training).
If you do none of these, you lose the "+" and keep the OSCP.
Show the numbers
| Country | OSCP | Ads | Share of ads |
|---|---|---|---|
| United States | 158 | 217 | 73% |
| United Kingdom | 28 | 58 | 48% |
What is the OSCP salary?
We did not collect an OSCP salary source we could verify, so this page gives no figure. To judge pay, write down the salary range in each penetration-tester ad you would apply to, where the ad gives one.
OSCP vs CPTS and PNPT: which fits you?
Pick the OSCP if you want the certification named in our US penetration-tester count and can work under a proctor and strict tool rules. The CPTS (Certified Penetration Testing Specialist, from the hacking-practice site Hack The Box) and PNPT (TCM Security's Practical Network Penetration Tester) are also hands-on, report-based exams; we do not count either in job ads.
OSCP vs CPTS and PNPT, from each vendor's page:
| OSCP (OffSec) | CPTS (Hack The Box) | PNPT (TCM Security) | |
|---|---|---|---|
| Price we read | $1,699 exam only; $1,749 with 90 days of course | Not checked | $499 (as shown on TCM's page) with 12 months of training, one attempt and one free retake |
| Exam | 23 hours 45 minutes of proctored hacking, then 24 hours for the report | Web, external and internal testing of an Active Directory network over a VPN, with a commercial-grade report | 5 days of unproctored testing, all tools allowed (AI if disclosed in the report), 2 days for the report, then a live 15-minute spoken debrief of your findings |
| Before the exam | No formal prerequisites | Finish all 28 modules of the Penetration Tester path | TCM suggests its PJPT first without professional hacking experience |
Source: vendor pages listed under Sources.
For an alternative, our eJPT page compares INE's exam with these. If an employer asks for the CEH or the CISSP (ISC2's certification that asks for years of security work), see our CEH page or CISSP page.
Is OSCP worth it? What Reddit posters say
In the question groups we built from posts we collected, Reddit posters asked about study plans, exam rules and jobs more than about value. Each point links the posts it rests on, so read them as examples, not a poll.
- Value: in our group of worth-it questions, four posts asked outright, one titled "Is oscp worth it or it is just a paper weight?" (r/oscp). A SOC analyst paying out of pocket asked whether a blue-team (defensive) path would serve them better (r/oscp).
- Jobs after passing: one poster planned an internship after the exam and asked how fast offers came (r/oscp). Another, with seven years in IT, the OSCP and a cybersecurity degree, was not getting many interviews and asked what else would make them stand out (r/oscp).
- Exam timing: posters asked when to book the exam after the labs (r/oscp). Leave room for a retake and its waiting period (see the failure section).
What should you do first?
Rate yourself this week on the three areas OffSec's PEN-200 page recommends: TCP/IP networking, Windows and Linux administration, and Bash or Python scripting. Write one line on what you could explain to a friend in each. Then:
- New to IT or no target job yet: the OSCP can wait. Work on your lowest-rated area with our cybersecurity roadmap; the CompTIA Security+ page covers an exam on security basics.
- Some practice, no hands-on exam yet: you could take the eJPT first.
- Ready: pick the OffSec option from the cost table whose access window you can fill with study.
What we did not check
- OffSec's pass rate: we found none on OffSec's pages.
- The price of the OSCP+ recertification exam, the CPE program, a Learn One renewal and an extension of PEN-200 access.
- Whether the retake waiting periods and the $249 retake, both from the Standalone FAQ, also apply to the bundle and Learn One.
- Salaries for OSCP holders, from any source.
Sources
All vendor pages below were read October 8, 2026. An archived copy is a saved copy of a page from the date given.
- Adzuna job-ad counts, penetration-tester ads in the US, UK and India, October 2026; analysis: CertWorthIt. How we count.
- OffSec, PEN-200 and OSCP page (prices, OSCP and OSCP+, prerequisites, audience, renewal).
- OffSec, OSCP exam guide (time limits, points, report, tool rules), archived copy of September 21, 2026.
- OffSec, Standalone certification exam FAQ (attempts, retake, waiting periods, refunds), archived copy of September 27, 2025.
- Hack The Box, CPTS page, archived copy of August 31, 2026.
- TCM Security, PNPT page, archived copy of October 2, 2026.
- Preparation times: r/oscp posts and comments we collected that state a finished preparation time (10 statements).
- Reddit questions about the OSCP from the posts we collected, linked in the Reddit section.
Edited by Jere Salmisto · Data checked October 8, 2026
Questions people ask
Is the OSCP certification worth it?
Yes, if you already know networking, Windows and Linux administration and basic scripting, want penetration-testing work and can pay at least $1,699. The OSCP (OffSec Certified Professional) is a 24-hour hands-on hacking exam with a written report. In October 2026, it appeared in 158 of the 217 US penetration-tester ads we counted on Adzuna, a job-ad search site. A penetration tester is paid to break into an organization's systems with permission and report the weak points. If you are new to IT, learn those three areas first.
Is the OSCP still worth it in 2026?
For US penetration-tester jobs, ads name it: in October 2026, the OSCP, OffSec's hands-on hacking certification, appeared in 73% of the ads for US penetration testers on Adzuna, a job-ad search site. We have one month of data, so we cannot say whether that share is rising or falling.
How much does it cost to take the OSCP exam?
OffSec, the company behind the OSCP, sells the OSCP+ Standalone Exam for $1,699. Standalone means exam only. OffSec's Standalone exam FAQ says this product includes two attempts valid for 120 days and lists a $249 retake if you fail both. Passing earns the OSCP and the OSCP+, a version that expires.
How much does the OSCP course cost?
OffSec's course for the OSCP is PEN-200. Its Course + Cert Bundle (a package of course access plus the exam) costs $1,749 for 90 days of the course and labs (practice networks you may attack) and one exam attempt. Learn One costs $2,749 a year for one course, its labs and two exam attempts, and renews unless you cancel. These are OffSec's prices in US dollars on its PEN-200 page.
Is the OSCP exam difficult?
Yes, by its format. OffSec's exam guide gives you 23 hours and 45 minutes of hands-on hacking, watched by an OffSec proctor (an exam supervisor) over a VPN, a private encrypted link to the exam network. You need 70 of 100 points from three single machines and an Active Directory set (Microsoft's system for managing users and computers on a company network). You then get 24 more hours to submit a penetration test report, the document that records every attack step. OffSec's own page says not everyone passes on the first try.
Can a beginner take the OSCP?
OffSec lists no formal prerequisites for the course or the exam. OffSec does not call the OSCP a beginner certification, though. Its PEN-200 page strongly recommends a solid understanding of TCP/IP networking (how computers address and talk to each other), Windows and Linux administration experience, and basic Bash or Python scripting. Learn those first.
Does the OSCP expire?
The OSCP itself does not expire, according to OffSec's PEN-200 page. Passing the exam also gives you the OSCP+, which expires three years after it is issued. To keep the OSCP+, OffSec lists three paths. You can pass a recertification exam (an exam to renew the title) within six months of the expiration date, pass another qualifying OffSec exam before it expires, or complete OffSec's CPE program (continuing professional education credits for further training).
Is OSCP worth it, according to Reddit?
In the question groups we built from Reddit posts about the OSCP, people asked about study plans, exam rules and jobs more than about value. One poster with seven years in IT, the OSCP and a degree said interviews were still slow to come.
What is the OSCP certification salary?
We did not collect a salary source we could verify, so we give no figure. To judge pay, note the salary ranges in the penetration-tester ads you would apply to.
Can you make $500,000 a year in cybersecurity?
We found no reliable source for that figure, so check the pay data for the role you want in your country.