CEH vs CISSP: which should you take, and when?

Job-ad data: October 2026 · Editor: · Updated

Get this as a monthly report

The CEH vs CISSP choice has a clear order: take the CEH (Certified Ethical Hacker, a multiple-choice exam on attacking systems with permission to find weak spots) first if you want both. Its exam needs two years in security or official training. The CISSP (Certified Information Systems Security Professional, for running security programs) needs five years to hold.

On Adzuna, a job-ad search site, 81 of the 8,110 US security-analyst ads in October 2026 contained the phrase ceh, and 338 of the 8,110 contained cissp; both were counted in the same ads. With no security job yet, read what to do first.

CEH CISSP
Awarded by EC-Council, which also accredits training centers ISC2, a membership body for security professionals
Focus Attack methods, tested by multiple choice Designing and managing security across eight domains (topic areas)
Experience needed To take the exam: two years of information-security work, or official training To hold it: five years of security work in two or more domains; one year can be replaced
Main exam 312-50: 125 questions, 4 hours 100 to 150 items, 3 hours, adaptive (questions set by your earlier answers)
Exam fee $950 online or $1,199 at Pearson VUE (a test-center chain) $749, Americas price
Renewal 120 ECE credits (logged learning) every 3 years, plus $80 a year 120 CPE credits (logged learning) every 3 years, plus $135 a year

Source: EC-Council and ISC2 pages listed under Sources.

CEH vs CISSP: share of cybersecurity analyst job ads naming each
CISSP is named more often than CEH in all 4 countries with enough ads.
Show the numbers
CEH vs CISSP: share of cybersecurity analyst job ads naming each. Share of job ads that name each item. Source: Adzuna job ads, October 2026.
CountryCEHCISSP
India7%18%
United Kingdom2%12%
United States81 of 8,1104.2%
Brazil3 of 4344 of 434

CEH or CISSP: which do employers name more?

Instant answer from October 2026 job ads. No email needed.

Country

CEH is named in more job ads in the United States.

  1. CEH66 of 217 ads30%
  2. CISSP338 of 8,110 ads4.2%

Source: Adzuna job ads, October 2026. Small sample: 217 ads. Treat this as a rough guide.

Get your full report

Two optional questions shape your first step. No email needed.

Your experience
Your goal

Keep these numbers up to date

Inside: CEH and CISSP side by side, by share of job ads naming each.

Email me my CEH vs CISSP report for the United States, plus a monthly update when these numbers change. Unsubscribe anytime.

What’s in it?
  • The certifications that rose or fell most in job ads this month
  • One new study from our data, with its sources
  • New certifications, jobs and countries we added

One email a month. Unsubscribe in one click.

We use AI to analyse the job-ad data and write your report. The counts come from Adzuna job ads; figures and sources are checked automatically.

How we use your email: privacy policy

On this page
  1. Which one fits you?
  2. What experience does each one require?
  3. How do the two exams work?
  4. What do the CEH and CISSP cost over three years?
  5. How do you keep each one active?
  6. Which job ads name the CEH and the CISSP?
  7. What should you do first with no security job yet?
  8. What do Reddit posters ask about the CEH and the CISSP?
  9. What we did not check
  10. Sources

Which one fits you?

The CEH fits someone early in hands-on security work, and the CISSP fits an experienced practitioner who designs or runs a security program.

EC-Council awards the CEH when you pass its knowledge exam. The current version is v13, sold as CEH AI, and the official course covers 20 modules. Pass the optional CEH Practical too and EC-Council names you a CEH Master.

The CISSP covers eight domains, from Security and Risk Management (16% of the exam) to Software Development Security (10%). Holding it means you passed the exam and ISC2 accepted your record of security work.

Both vendors list approval under DoD 8140, the US Defense Department rule that matches certifications to defense cybersecurity jobs. Approval is given per work role, not per certificate, and we checked roles only for EC-Council. EC-Council says CEH AI meets the baseline for 4 of the 5 Cybersecurity Service Provider (CSSP) roles, the department's defensive-security job group. Both are ANAB-accredited (ANAB audits certification programs in the US).

What experience does each one require?

The CEH exam needs two years of information-security work or official EC-Council training. The CISSP needs five years in the field to hold, though you can take its exam earlier.

CEH: experience or official training

EC-Council's eligibility page offers two routes. Completing official training at an accredited training center, through EC-Council's online learning or at an approved academic institution makes you eligible for the exam. Without training, you send an eligibility application with proof of at least two years in an IT-security domain and a non-refundable $100 application fee. The fee is waived for holders of an active CEH from versions 1 to 7.

EC-Council contacts your listed verifiers and expects approval within 5 to 10 business days; an approval is valid for 90 days. Once you buy the exam voucher (a prepaid code for booking the exam), you have 12 months to take it. The CEH Practical has the same two-year-or-training rule.

Where do EC-Council's own pages disagree?

Point One EC-Council text Another EC-Council text
Two years of experience CEH product page: candidates "should have" 2 years in IT security or complete official training Eligibility page: the program "requires" two years in an information-security role unless you attend official training
Passing score CEH product page, exam-details table: 60% to 85% Same page, FAQ: typical cut scores from 65% to 85%

Source: EC-Council CEH product and eligibility pages.

EC-Council explains the range: questions rotate, so each exam form has its own passing score. Our reading: you apply through the eligibility page, so plan by its "requires" wording.

CISSP: five years, or the exam first as an Associate

ISC2 asks for at least five years of cumulative full-time work in two or more of the eight domains. One year can be replaced by a bachelor's or master's degree in computer science, IT or a related field, or by a credential on ISC2's waiver list, but only one waiver counts.

If you pass without the experience, you become an Associate of ISC2, a status for people who passed the exam but still need the work history. You then have six years to earn the five years. Every candidate who passes must complete endorsement, the application in which ISC2 confirms the experience, within nine months of the exam date.

Does the CEH shorten the CISSP experience rule?

Not in the copy we read: the CEH was missing from ISC2's approved-credential list (date in Sources). Check the live list. That copy names CompTIA Security+ (an entry-level exam) and the CISM (Certified Information Security Manager), so a CEH holder needs a degree or a listed credential for the waiver.

How do the two exams work?

The CEH is a four-hour multiple-choice exam with a fixed 125 questions. The CISSP is a three-hour adaptive exam: it picks each question from your earlier answers and stops somewhere between 100 and 150 items.

CEH (312-50) CISSP
Questions 125, multiple choice 100 to 150 items, adaptive
Time 4 hours 3 hours
Passing score Varies by exam form, about 60% to 85% (EC-Council gives two ranges) 700 out of 1,000
Where Online with remote proctoring (a supervisor watches over the internet), at a training center or at a Pearson VUE center Pearson test centers authorized by ISC2
Retakes Up to five attempts in 12 months; no wait before the second, 14 days before each later one -
Practical exam Optional CEH Practical: 6 hours, 20 challenges, $550 voucher None on the pages we read

Source: EC-Council CEH product, eligibility and retake pages; ISC2 CISSP exam outline.

EC-Council describes its official course as a five-day boot camp that can end with the four-hour exam on the fifth day.

CEH vs CISSP exams side by side: questions, time, format
CEH, 125 questions in 240 minutes.
Show the numbers
CEH vs CISSP exams side by side: questions, time, format. Source: eccouncil.org, cert.eccouncil.org, isc2.org, checked October 4, 2026.
ItemCEHCISSP
Questions125 questions100–150 questions
Exam time240 minutes (4 h)180 minutes (3 h)
Passing score60–85%700 of 1,000
FormatMultiple choice, hands-on practicalMultiple choice, adaptive testing
Where you take ittest center · online, proctoredtest center

What do the CEH and CISSP cost over three years?

If you pass each on the first attempt and take the CEH through the self-study route, the CEH comes to $1,290 over three years with the online exam, or $1,539 at a Pearson VUE center. The CISSP comes to $1,154 at ISC2's Americas price.

Item CEH, self-study route CISSP, Americas price
Entry $100 application fee None listed on the ISC2 pricing and endorsement pages we read
Exam $950 (online) or $1,199 (Pearson VUE) $749
Staying certified $80 a year, 3 years (continuing-education fee) $135 a year, 3 years (maintenance fee)
Three-year total $1,290 online, $1,539 at Pearson VUE $1,154

Source: EC-Council eligibility and continuing-education fee pages; ISC2 exam pricing and AMF pages. Both totals assume one yearly fee for each of the three years.

On the official-training route, EC-Council lists the same $950 and $1,199 voucher prices and no application fee. The training itself costs extra. Its price is set by EC-Council's training partners, not by EC-Council, so we do not price it; see the EC-Council CEH page for providers.

Neither total includes books, failed attempts or the $550 CEH Practical. An Associate of ISC2 pays a $50 yearly fee instead of $135 until their experience is approved, then an $85 upgrade fee.

What the CISSP certification costs to get and keep (USD)
The required CISSP fees add up to $749. Keeping CISSP costs $135 a year ($405 over the 3-year cycle).
Show the numbers
What the CISSP certification costs to get and keep (USD). Source: isc2.org, checked October 5, 2026.
ItemFee
Fees to get certified: Exam$749
Fees to get certified: Annual fee, $135 a year × 3 years$405

How do you keep each one active?

Both run on three-year cycles of 120 credits, with a yearly fee that EC-Council's fee page sets at $80 for the CEH and ISC2's maintenance-fee page at $135 for the CISSP.

CEH. EC-Council certifications are valid for three years. You log 120 ECE (EC-Council Continuing Education) credits within those three years and pay the annual fee, which is $80 for certifications whose exam code starts with 312, as the CEH's does. If the credits are missing, the certification is suspended; you are reinstated if you earn the 120 credits within 12 months after the three years end.

CISSP. ISC2 asks for 120 CPE (continuing professional education) credits per three-year cycle, which you log with ISC2. The $135 annual maintenance fee (AMF) is due every year. Associates pay $50 a year and earn 15 CPE credits a year.

Holding both means $215 in yearly fees.

Which job ads name the CEH and the CISSP?

Both credentials appear in security-analyst and SOC-analyst ads (SOC: security operations center, the team that watches for attacks). We searched Adzuna by job title, security analyst and soc analyst, and counted an ad when its text contained the phrase ceh or cissp, whether as required, preferred or one option among several.

Ads searched All ads Containing ceh Containing cissp
US, security analyst 8,110 81 338
UK, security analyst 235 4 29
India, security analyst 250 17 45
Brazil, analista de segurança 434 3 4
US, SOC analyst 233 30 32

Source: Adzuna API, job ads collected in October 2026. Analysis: CertWorthIt. Brazilian searches use the Portuguese job title with the English credential phrase.

UK, Indian and Brazilian SOC-analyst samples fell below our reporting threshold, so they are left out. A phrase count misses ads that write only "Certified Ethical Hacker" or the CISSP's full name, so each count is a minimum. For what else these jobs ask for, see our pages on cybersecurity analysts and SOC analysts.

What cybersecurity analyst job ads name in the United States: certifications and skills
CEH is named in 81 of these 8,110 ads; SIEM leads with 5.1%.
Show the numbers
What cybersecurity analyst job ads name in the United States: certifications and skills. Share of job ads that name each item. Source: Adzuna job ads, October 2026.
ItemAdsShare of ads
SIEM4155.1%
CISSP3384.2%
CompTIA1622.0%
CISM1341.7%
CompTIA CySA+1191.5%
CompTIA Security+1121.4%
Splunk1001.2%
CEH8181 of 8,110

What should you do first with no security job yet?

Start with the basics and a first job in IT or security; both credentials come later. Without two years in a security role, the CEH means paying for official training, and a passed CISSP exam leaves you an Associate with work still to log.

  1. Pick a target job. Security analyst and SOC analyst are the two jobs we counted; our role pages describe what each does.
  2. Read 20 local ads this week. Search a job site for that title in your city and note every credential named, including ceh, cissp and Security+.
  3. Choose an entry exam. Our cybersecurity roadmap lays out the route from a first exam to a first job, and our Security+ page covers CompTIA's general security exam. For hands-on practice, our eJPT page covers an entry-level hacking exam.
  4. Log your security work from day one. Keep dates, duties and a contact for each job, because EC-Council and ISC2 both ask you to prove your experience.

In what order should you take both?

Take the CEH first and the CISSP later. That order follows the vendors' entry rules, not our job-ad counts: the CEH needs two years or official training, the CISSP five years, or four with a degree or listed credential.

Our CEH page covers its exam and renewal, and our CISSP page covers study time. For the management route, see our CISM vs CISSP comparison; if you come from networking, our CCNA vs CISSP comparison shows how a network credential can count toward the CISSP waiver.

What do Reddit posters ask about the CEH and the CISSP?

Posters ask whether the CEH helps with a first job and how young a full CISSP can be, in posts we collected on r/SecurityCareerAdvice, r/oscp and r/cissp. Posters are a self-selected group, so read these as questions, not statistics.

  • The CEH for a first security job. One poster asked whether the CEH would help them land an entry-level job, or whether Security+ or another entry-level exam was the better use of money (r/SecurityCareerAdvice). Our job-ad counts cannot show hiring odds; with no job yet, start with step 3 above.
  • The CEH or Security+ on the way to the OSCP. One post asked which comes first on the road to the OSCP, OffSec's hands-on penetration-testing exam (r/oscp). A beginner lacks the two years the CEH self-study route asks for, so start with step 3 above; our OSCP page covers that exam.
  • Hack The Box practice plus one certification. A poster training on Hack The Box Academy, a hacking-practice site, asked whether to add the OSCP or the CEH (r/SecurityCareerAdvice). The CEH knowledge exam is multiple choice; only the optional CEH Practical tests hands-on work. Our CISSP vs OSCP comparison covers the OSCP route.
  • Both names in a list of skills to learn. A network engineer moving into security listed the CEH and the CISSP next to Python, Terraform (cloud-setup software) and SIEM tools (software that collects security alerts) as skills to learn (r/SecurityCareerAdvice). Under the vendors' rules, the two are years apart.
  • How young a full CISSP can be. A poster who became a fully endorsed CISSP at 23 asked whether anyone younger had reached full status (r/cissp). The ISC2 pages we read set no age rule; only the five years of work count.

What we did not check

  • CEH training prices. Training partners set them, so we did not price the official-training route.
  • Retake fees for either exam, and the CISSP retake rules.
  • Pass rates and salaries. We found no official, dated figures on the pages we read.
  • CEH exam languages, and whether the CISSP can be taken online.
  • Prices outside the US and the Americas, and local taxes.
  • When the yearly fees fall due. Our totals assume one EC-Council fee and one ISC2 fee in each of the three years.
  • The CISSP in pentester ads (jobs that hack systems with permission). We counted only the CEH there, so no side-by-side figure exists.

Sources

All pages below were read October 8, 2026.

Keep these numbers up to date

Inside: CEH and CISSP side by side, by share of job ads naming each.

Email me my CEH vs CISSP report for the United States, plus a monthly update when these numbers change. Unsubscribe anytime.

What’s in it?
  • The certifications that rose or fell most in job ads this month
  • One new study from our data, with its sources
  • New certifications, jobs and countries we added

One email a month. Unsubscribe in one click.

We use AI to analyse the job-ad data and write your report. The counts come from Adzuna job ads; figures and sources are checked automatically.

How we use your email: privacy policy

Questions people ask

CISSP vs CEH: which should I take first?

If you want both, take the CEH (Certified Ethical Hacker) first, because its entry rule is lighter. EC-Council, which awards it, asks for two years of information-security work or its official training. The CISSP (Certified Information Systems Security Professional) needs five years of security work in at least two of its eight domains, the topic areas of ISC2's exam outline. With no security job yet, start with a first job and an entry-level exam instead of either one.

Can I take the CEH exam without experience?

Yes, through official training. EC-Council says a candidate who completes its official training at an accredited training center, through its own online learning or at an approved academic institution is eligible for the CEH (Certified Ethical Hacker) exam. Without training, you must prove at least two years of information-security work and pay a non-refundable $100 application fee. EC-Council does not set the training price; its training partners do.

Does the CEH count toward the CISSP experience waiver?

Not in the copy we read. The CISSP (Certified Information Systems Security Professional) needs five years of security work, and ISC2 lets one listed credential or a computer science or IT degree replace one of those years; this is called a waiver. The CEH (Certified Ethical Hacker) was not on ISC2's approved-credential list in the copy we read, while CompTIA Security+ (an entry-level exam) was. ISC2 can change the list, so check the live version before you plan around it.

How much do the CEH and CISSP cost over three years?

On EC-Council's self-study route, the CEH (Certified Ethical Hacker) costs $1,290 over three years with the online exam: a $100 application fee, the $950 exam voucher (a prepaid code to book the exam) and three $80 annual fees. At a Pearson VUE test center, the voucher is $1,199 and the total $1,539. The CISSP (Certified Information Systems Security Professional) costs $1,154 at ISC2's Americas price: the $749 exam plus three $135 annual maintenance fees. Training, books and retakes are not included.

Which job ads name the CEH and the CISSP?

We counted both in the same ads on Adzuna, a job-ad search site. Of the 8,110 US security-analyst ads we counted in October 2026, 81 contained the phrase ceh (for the Certified Ethical Hacker) and 338 contained cissp (for the Certified Information Systems Security Professional). Of the 233 US SOC-analyst ads, for jobs in a security operations center that watches for attacks, 30 contained ceh and 32 contained cissp.

Is the CEH exam hands-on?

No. The CEH (Certified Ethical Hacker) knowledge exam, code 312-50, has 125 multiple-choice questions in four hours, and EC-Council awards the certification when you pass it. Hands-on skill is tested in the optional CEH Practical, a six-hour exam with 20 challenges and a $550 exam voucher (a prepaid code to book it). EC-Council gives the title CEH Master to people who pass both; it is not a separate certification and cannot be bought.