CEH vs CISSP: which should you take, and when?
The CEH vs CISSP choice has a clear order: take the CEH (Certified Ethical Hacker, a multiple-choice exam on attacking systems with permission to find weak spots) first if you want both. Its exam needs two years in security or official training. The CISSP (Certified Information Systems Security Professional, for running security programs) needs five years to hold.
On Adzuna, a job-ad search site, 81 of the 8,110 US security-analyst ads in October 2026 contained the phrase ceh, and 338 of the 8,110 contained cissp; both were counted in the same ads. With no security job yet, read what to do first.
| CEH | CISSP | |
|---|---|---|
| Awarded by | EC-Council, which also accredits training centers | ISC2, a membership body for security professionals |
| Focus | Attack methods, tested by multiple choice | Designing and managing security across eight domains (topic areas) |
| Experience needed | To take the exam: two years of information-security work, or official training | To hold it: five years of security work in two or more domains; one year can be replaced |
| Main exam | 312-50: 125 questions, 4 hours | 100 to 150 items, 3 hours, adaptive (questions set by your earlier answers) |
| Exam fee | $950 online or $1,199 at Pearson VUE (a test-center chain) | $749, Americas price |
| Renewal | 120 ECE credits (logged learning) every 3 years, plus $80 a year | 120 CPE credits (logged learning) every 3 years, plus $135 a year |
Source: EC-Council and ISC2 pages listed under Sources.
Show the numbers
| Country | CEH | CISSP |
|---|---|---|
| India | 7% | 18% |
| United Kingdom | 2% | 12% |
| United States | 81 of 8,110 | 4.2% |
| Brazil | 3 of 434 | 4 of 434 |
CEH or CISSP: which do employers name more?
Instant answer from October 2026 job ads. No email needed.
CEH is named in more job ads in the United States.
Source: Adzuna job ads, October 2026. Small sample: 217 ads. Treat this as a rough guide.
Get your full report
Two optional questions shape your first step. No email needed.
On this page
- Which one fits you?
- What experience does each one require?
- How do the two exams work?
- What do the CEH and CISSP cost over three years?
- How do you keep each one active?
- Which job ads name the CEH and the CISSP?
- What should you do first with no security job yet?
- What do Reddit posters ask about the CEH and the CISSP?
- What we did not check
- Sources
Which one fits you?
The CEH fits someone early in hands-on security work, and the CISSP fits an experienced practitioner who designs or runs a security program.
EC-Council awards the CEH when you pass its knowledge exam. The current version is v13, sold as CEH AI, and the official course covers 20 modules. Pass the optional CEH Practical too and EC-Council names you a CEH Master.
The CISSP covers eight domains, from Security and Risk Management (16% of the exam) to Software Development Security (10%). Holding it means you passed the exam and ISC2 accepted your record of security work.
Both vendors list approval under DoD 8140, the US Defense Department rule that matches certifications to defense cybersecurity jobs. Approval is given per work role, not per certificate, and we checked roles only for EC-Council. EC-Council says CEH AI meets the baseline for 4 of the 5 Cybersecurity Service Provider (CSSP) roles, the department's defensive-security job group. Both are ANAB-accredited (ANAB audits certification programs in the US).
What experience does each one require?
The CEH exam needs two years of information-security work or official EC-Council training. The CISSP needs five years in the field to hold, though you can take its exam earlier.
CEH: experience or official training
EC-Council's eligibility page offers two routes. Completing official training at an accredited training center, through EC-Council's online learning or at an approved academic institution makes you eligible for the exam. Without training, you send an eligibility application with proof of at least two years in an IT-security domain and a non-refundable $100 application fee. The fee is waived for holders of an active CEH from versions 1 to 7.
EC-Council contacts your listed verifiers and expects approval within 5 to 10 business days; an approval is valid for 90 days. Once you buy the exam voucher (a prepaid code for booking the exam), you have 12 months to take it. The CEH Practical has the same two-year-or-training rule.
Where do EC-Council's own pages disagree?
| Point | One EC-Council text | Another EC-Council text |
|---|---|---|
| Two years of experience | CEH product page: candidates "should have" 2 years in IT security or complete official training | Eligibility page: the program "requires" two years in an information-security role unless you attend official training |
| Passing score | CEH product page, exam-details table: 60% to 85% | Same page, FAQ: typical cut scores from 65% to 85% |
Source: EC-Council CEH product and eligibility pages.
EC-Council explains the range: questions rotate, so each exam form has its own passing score. Our reading: you apply through the eligibility page, so plan by its "requires" wording.
CISSP: five years, or the exam first as an Associate
ISC2 asks for at least five years of cumulative full-time work in two or more of the eight domains. One year can be replaced by a bachelor's or master's degree in computer science, IT or a related field, or by a credential on ISC2's waiver list, but only one waiver counts.
If you pass without the experience, you become an Associate of ISC2, a status for people who passed the exam but still need the work history. You then have six years to earn the five years. Every candidate who passes must complete endorsement, the application in which ISC2 confirms the experience, within nine months of the exam date.
Does the CEH shorten the CISSP experience rule?
Not in the copy we read: the CEH was missing from ISC2's approved-credential list (date in Sources). Check the live list. That copy names CompTIA Security+ (an entry-level exam) and the CISM (Certified Information Security Manager), so a CEH holder needs a degree or a listed credential for the waiver.
How do the two exams work?
The CEH is a four-hour multiple-choice exam with a fixed 125 questions. The CISSP is a three-hour adaptive exam: it picks each question from your earlier answers and stops somewhere between 100 and 150 items.
| CEH (312-50) | CISSP | |
|---|---|---|
| Questions | 125, multiple choice | 100 to 150 items, adaptive |
| Time | 4 hours | 3 hours |
| Passing score | Varies by exam form, about 60% to 85% (EC-Council gives two ranges) | 700 out of 1,000 |
| Where | Online with remote proctoring (a supervisor watches over the internet), at a training center or at a Pearson VUE center | Pearson test centers authorized by ISC2 |
| Retakes | Up to five attempts in 12 months; no wait before the second, 14 days before each later one | - |
| Practical exam | Optional CEH Practical: 6 hours, 20 challenges, $550 voucher | None on the pages we read |
Source: EC-Council CEH product, eligibility and retake pages; ISC2 CISSP exam outline.
EC-Council describes its official course as a five-day boot camp that can end with the four-hour exam on the fifth day.
Show the numbers
| Item | CEH | CISSP |
|---|---|---|
| Questions | 125 questions | 100–150 questions |
| Exam time | 240 minutes (4 h) | 180 minutes (3 h) |
| Passing score | 60–85% | 700 of 1,000 |
| Format | Multiple choice, hands-on practical | Multiple choice, adaptive testing |
| Where you take it | test center · online, proctored | test center |
What do the CEH and CISSP cost over three years?
If you pass each on the first attempt and take the CEH through the self-study route, the CEH comes to $1,290 over three years with the online exam, or $1,539 at a Pearson VUE center. The CISSP comes to $1,154 at ISC2's Americas price.
| Item | CEH, self-study route | CISSP, Americas price |
|---|---|---|
| Entry | $100 application fee | None listed on the ISC2 pricing and endorsement pages we read |
| Exam | $950 (online) or $1,199 (Pearson VUE) | $749 |
| Staying certified | $80 a year, 3 years (continuing-education fee) | $135 a year, 3 years (maintenance fee) |
| Three-year total | $1,290 online, $1,539 at Pearson VUE | $1,154 |
Source: EC-Council eligibility and continuing-education fee pages; ISC2 exam pricing and AMF pages. Both totals assume one yearly fee for each of the three years.
On the official-training route, EC-Council lists the same $950 and $1,199 voucher prices and no application fee. The training itself costs extra. Its price is set by EC-Council's training partners, not by EC-Council, so we do not price it; see the EC-Council CEH page for providers.
Neither total includes books, failed attempts or the $550 CEH Practical. An Associate of ISC2 pays a $50 yearly fee instead of $135 until their experience is approved, then an $85 upgrade fee.
Show the numbers
| Item | Fee |
|---|---|
| Fees to get certified: Exam | $749 |
| Fees to get certified: Annual fee, $135 a year × 3 years | $405 |
How do you keep each one active?
Both run on three-year cycles of 120 credits, with a yearly fee that EC-Council's fee page sets at $80 for the CEH and ISC2's maintenance-fee page at $135 for the CISSP.
CEH. EC-Council certifications are valid for three years. You log 120 ECE (EC-Council Continuing Education) credits within those three years and pay the annual fee, which is $80 for certifications whose exam code starts with 312, as the CEH's does. If the credits are missing, the certification is suspended; you are reinstated if you earn the 120 credits within 12 months after the three years end.
CISSP. ISC2 asks for 120 CPE (continuing professional education) credits per three-year cycle, which you log with ISC2. The $135 annual maintenance fee (AMF) is due every year. Associates pay $50 a year and earn 15 CPE credits a year.
Holding both means $215 in yearly fees.
Which job ads name the CEH and the CISSP?
Both credentials appear in security-analyst and SOC-analyst ads (SOC: security operations center, the team that watches for attacks). We searched Adzuna by job title, security analyst and soc analyst, and counted an ad when its text contained the phrase ceh or cissp, whether as required, preferred or one option among several.
| Ads searched | All ads | Containing ceh |
Containing cissp |
|---|---|---|---|
| US, security analyst | 8,110 | 81 | 338 |
| UK, security analyst | 235 | 4 | 29 |
| India, security analyst | 250 | 17 | 45 |
| Brazil, analista de segurança | 434 | 3 | 4 |
| US, SOC analyst | 233 | 30 | 32 |
Source: Adzuna API, job ads collected in October 2026. Analysis: CertWorthIt. Brazilian searches use the Portuguese job title with the English credential phrase.
UK, Indian and Brazilian SOC-analyst samples fell below our reporting threshold, so they are left out. A phrase count misses ads that write only "Certified Ethical Hacker" or the CISSP's full name, so each count is a minimum. For what else these jobs ask for, see our pages on cybersecurity analysts and SOC analysts.
Show the numbers
| Item | Ads | Share of ads |
|---|---|---|
| SIEM | 415 | 5.1% |
| CISSP | 338 | 4.2% |
| CompTIA | 162 | 2.0% |
| CISM | 134 | 1.7% |
| CompTIA CySA+ | 119 | 1.5% |
| CompTIA Security+ | 112 | 1.4% |
| Splunk | 100 | 1.2% |
| CEH | 81 | 81 of 8,110 |
What should you do first with no security job yet?
Start with the basics and a first job in IT or security; both credentials come later. Without two years in a security role, the CEH means paying for official training, and a passed CISSP exam leaves you an Associate with work still to log.
- Pick a target job. Security analyst and SOC analyst are the two jobs we counted; our role pages describe what each does.
- Read 20 local ads this week. Search a job site for that title in your city and note every credential named, including
ceh,cisspand Security+. - Choose an entry exam. Our cybersecurity roadmap lays out the route from a first exam to a first job, and our Security+ page covers CompTIA's general security exam. For hands-on practice, our eJPT page covers an entry-level hacking exam.
- Log your security work from day one. Keep dates, duties and a contact for each job, because EC-Council and ISC2 both ask you to prove your experience.
In what order should you take both?
Take the CEH first and the CISSP later. That order follows the vendors' entry rules, not our job-ad counts: the CEH needs two years or official training, the CISSP five years, or four with a degree or listed credential.
Our CEH page covers its exam and renewal, and our CISSP page covers study time. For the management route, see our CISM vs CISSP comparison; if you come from networking, our CCNA vs CISSP comparison shows how a network credential can count toward the CISSP waiver.
What do Reddit posters ask about the CEH and the CISSP?
Posters ask whether the CEH helps with a first job and how young a full CISSP can be, in posts we collected on r/SecurityCareerAdvice, r/oscp and r/cissp. Posters are a self-selected group, so read these as questions, not statistics.
- The CEH for a first security job. One poster asked whether the CEH would help them land an entry-level job, or whether Security+ or another entry-level exam was the better use of money (r/SecurityCareerAdvice). Our job-ad counts cannot show hiring odds; with no job yet, start with step 3 above.
- The CEH or Security+ on the way to the OSCP. One post asked which comes first on the road to the OSCP, OffSec's hands-on penetration-testing exam (r/oscp). A beginner lacks the two years the CEH self-study route asks for, so start with step 3 above; our OSCP page covers that exam.
- Hack The Box practice plus one certification. A poster training on Hack The Box Academy, a hacking-practice site, asked whether to add the OSCP or the CEH (r/SecurityCareerAdvice). The CEH knowledge exam is multiple choice; only the optional CEH Practical tests hands-on work. Our CISSP vs OSCP comparison covers the OSCP route.
- Both names in a list of skills to learn. A network engineer moving into security listed the CEH and the CISSP next to Python, Terraform (cloud-setup software) and SIEM tools (software that collects security alerts) as skills to learn (r/SecurityCareerAdvice). Under the vendors' rules, the two are years apart.
- How young a full CISSP can be. A poster who became a fully endorsed CISSP at 23 asked whether anyone younger had reached full status (r/cissp). The ISC2 pages we read set no age rule; only the five years of work count.
What we did not check
- CEH training prices. Training partners set them, so we did not price the official-training route.
- Retake fees for either exam, and the CISSP retake rules.
- Pass rates and salaries. We found no official, dated figures on the pages we read.
- CEH exam languages, and whether the CISSP can be taken online.
- Prices outside the US and the Americas, and local taxes.
- When the yearly fees fall due. Our totals assume one EC-Council fee and one ISC2 fee in each of the three years.
- The CISSP in pentester ads (jobs that hack systems with permission). We counted only the CEH there, so no side-by-side figure exists.
Sources
All pages below were read October 8, 2026.
- EC-Council: CEH product page, CEH certification page, application process and eligibility, exam retake policy, ECE policy, continuing education fees.
- ISC2: CISSP, CISSP experience requirements, CISSP experience waiver, CISSP exam outline, exam pricing, AMF overview, member policies, Associate of ISC2, endorsement.
- Job ads: Adzuna API, October 2026, security-analyst and SOC-analyst ads; phrases
cehandcissp. Analysis: CertWorthIt. Method. - Reddit: posts collected from r/SecurityCareerAdvice, r/oscp and r/cissp, linked where cited.
Questions people ask
CISSP vs CEH: which should I take first?
If you want both, take the CEH (Certified Ethical Hacker) first, because its entry rule is lighter. EC-Council, which awards it, asks for two years of information-security work or its official training. The CISSP (Certified Information Systems Security Professional) needs five years of security work in at least two of its eight domains, the topic areas of ISC2's exam outline. With no security job yet, start with a first job and an entry-level exam instead of either one.
Can I take the CEH exam without experience?
Yes, through official training. EC-Council says a candidate who completes its official training at an accredited training center, through its own online learning or at an approved academic institution is eligible for the CEH (Certified Ethical Hacker) exam. Without training, you must prove at least two years of information-security work and pay a non-refundable $100 application fee. EC-Council does not set the training price; its training partners do.
Does the CEH count toward the CISSP experience waiver?
Not in the copy we read. The CISSP (Certified Information Systems Security Professional) needs five years of security work, and ISC2 lets one listed credential or a computer science or IT degree replace one of those years; this is called a waiver. The CEH (Certified Ethical Hacker) was not on ISC2's approved-credential list in the copy we read, while CompTIA Security+ (an entry-level exam) was. ISC2 can change the list, so check the live version before you plan around it.
How much do the CEH and CISSP cost over three years?
On EC-Council's self-study route, the CEH (Certified Ethical Hacker) costs $1,290 over three years with the online exam: a $100 application fee, the $950 exam voucher (a prepaid code to book the exam) and three $80 annual fees. At a Pearson VUE test center, the voucher is $1,199 and the total $1,539. The CISSP (Certified Information Systems Security Professional) costs $1,154 at ISC2's Americas price: the $749 exam plus three $135 annual maintenance fees. Training, books and retakes are not included.
Which job ads name the CEH and the CISSP?
We counted both in the same ads on Adzuna, a job-ad search site. Of the 8,110 US security-analyst ads we counted in October 2026, 81 contained the phrase ceh (for the Certified Ethical Hacker) and 338 contained cissp (for the Certified Information Systems Security Professional). Of the 233 US SOC-analyst ads, for jobs in a security operations center that watches for attacks, 30 contained ceh and 32 contained cissp.
Is the CEH exam hands-on?
No. The CEH (Certified Ethical Hacker) knowledge exam, code 312-50, has 125 multiple-choice questions in four hours, and EC-Council awards the certification when you pass it. Hands-on skill is tested in the optional CEH Practical, a six-hour exam with 20 challenges and a $550 exam voucher (a prepaid code to book it). EC-Council gives the title CEH Master to people who pass both; it is not a separate certification and cannot be bought.