CISSP vs OSCP: which fits your goal, and which comes first?

Job-ad data: October 2026 · Editor: · Updated

Get this as a monthly report

CISSP vs OSCP: take the OSCP (OffSec Certified Professional) for penetration testing, attacking systems with permission to find weak spots. Take the CISSP (Certified Information Systems Security Professional) for designing and running security programs. The OSCP has no experience requirement, so you can take it first, but it assumes hands-on Linux, networking and scripting (writing small programs) skills.

The CISSP has a work-experience rule (details). New to IT? Start with the quick answer.

CISSP OSCP
Issuer ISC2, a membership body for security professionals OffSec, a company that sells penetration-testing courses and exams
Written for Designing, building and managing a security program Penetration testing: breaking into test machines and reporting how
Experience to hold it 5 years of full-time security work in 2 or more of 8 domains (topic areas); a waiver (degree or approved credential) can replace 1 year None
Exam 100 to 150 questions, 3 hours, adaptive (each question picked by your earlier answers) 23 hours 45 minutes of hands-on attacks on lab (practice) machines, then 24 hours to upload a report
Validity Renewed every 3 years with 120 CPE (continuing professional education) credits OSCP does not expire; the OSCP+, a version earned with it, expires after 3 years

OSCP vs CISSP at a glance. Source: ISC2 and OffSec pages listed under Sources; prices under cost.

CISSP vs OSCP exams side by side: questions, time, format
CISSP: 180 minutes (3 h); OSCP: 1,425 minutes (23 h 45 min).
Show the numbers
CISSP vs OSCP exams side by side: questions, time, format. Source: isc2.org, help.offsec.com, offsec.com, checked October 3, 2026.
ItemCISSPOSCP
Exam time180 minutes (3 h)1,425 minutes (23 h 45 min)
Passing score700 of 1,00070 of 100
FormatMultiple choice, adaptive testingHands-on practical
Where you take ittest centeronline, proctored

CISSP or OSCP: which do employers name more?

Instant answer from October 2026 job ads. No email needed.

Country

OSCP is named in more job ads in the United States.

  1. CISSP338 of 8,110 ads4.2%
  2. OSCP158 of 217 ads73%

Source: Adzuna job ads, October 2026. Small sample: 217 ads. Treat this as a rough guide.

Get your full report

Two optional questions shape your first step. No email needed.

Your experience
Your goal

Keep these numbers up to date

Inside: CISSP and OSCP side by side, by share of job ads naming each, with the official fees.

Email me my CISSP vs OSCP report for the United States, plus a monthly update when these numbers change. Unsubscribe anytime.

What’s in it?
  • The certifications that rose or fell most in job ads this month
  • One new study from our data, with its sources
  • New certifications, jobs and countries we added

One email a month. Unsubscribe in one click.

We use AI to analyse the job-ad data and write your report. The counts come from Adzuna job ads; figures and sources are checked automatically.

How we use your email: privacy policy

On this page
  1. Quick answer by situation
  2. OSCP vs CISSP: which do job ads name?
  3. What experience does each one require?
  4. How do the two exams work?
  5. What do the CISSP and OSCP cost over three years?
  6. How do you keep each credential?
  7. CISSP vs OSCP difficulty: which exam is harder?
  8. Which should you take first, the CISSP or the OSCP?
  9. What we did not check
  10. Sources

Quick answer by situation

  • No IT or security job yet: neither is the right first exam. Your first step: read our cybersecurity roadmap, then search any job site for penetration tester and security analyst and list the credentials named in ten ads of each.
  • No IT work yet, and you want an entry exam: take CompTIA Security+, an entry-level security exam that ISC2 accepts as one year of CISSP experience; once you have the three skills below, take the eJPT, a junior penetration-testing exam.
  • Help desk, IT support or system administration, and you want to attack systems: the OSCP can be your target. First step: rate yourself on the three skills OffSec strongly recommends (networking, Windows and Linux administration, basic Bash or Python scripting); if one is weak, take the eJPT first; if none is, start PEN-200, OffSec's OSCP course.
  • SOC (security operations center, the team that watches for attacks) or security analyst with one to three years: start by listing which of the eight domains in ISC2's exam outline your daily work covers, because ISC2 counts experience by domain. You can pass the CISSP exam early and become an Associate of ISC2, a lower membership level for people who passed without the experience. To attack systems instead, use the skills check above.
  • Five years of security work in two or more domains (or four with a waiver): take the CISSP.
  • Penetration tester who wants to lead teams or design security: add the CISSP.
  • Security manager or architect: the CISSP fits your work. Take the OSCP only if you want to do hands-on testing yourself.

OSCP vs CISSP: which do job ads name?

Each is counted in a different job's ads on Adzuna, a job-ad search site, so the figures are not a ranking. We counted an ad when it contained oscp (which also matches OSCP+, the three-year version earned with it) or cissp, whether as a requirement or a plus.

Credential Job we counted Country Ads for that job Ads naming it
OSCP Penetration tester United States 217 158
OSCP Penetration tester United Kingdom (small sample, read with care) 58 28
CISSP Security analyst United States 8,110 338
CISSP Security analyst United Kingdom 235 29
CISSP Security analyst India 250 45
CISSP SOC analyst United States 233 32

Source: Adzuna API, ads collected in October 2026. Method.

For the analyst jobs, our cybersecurity-analyst page and SOC-analyst page list what those ads name by country.

What experience does each one require?

The CISSP needs five years of security work before you can hold it, and the OSCP needs none. You can take either exam without experience.

CISSP: five years, one of them waivable

ISC2 asks for a minimum of five years cumulative, full-time experience in two or more of the eight domains. A bachelor's or master's degree in computer science, IT or a related field can cover one year, and so can a credential from ISC2's approved list, such as CompTIA Security+. Only one waiver counts: a degree and a credential cannot be combined. Part-time work of 20 to 34 hours a week and internships can also count.

After you pass, you apply for certification through endorsement, the step where your experience is confirmed, within nine months of the exam date. If you pass without the experience, you can become an Associate of ISC2, which you keep by paying $50 a year and earning 15 CPE credits a year. You then have six years to earn the five years of experience.

OffSec awards the OSCP without prerequisites to anyone who passes the exam. For its course, PEN-200, OffSec strongly recommends, though does not require, a solid understanding of TCP/IP networking (how computers talk over the internet), Windows and Linux administration experience, and basic Bash or Python scripting. For the exam-only option, it recommends at least some experience in the field of penetration testing.

Does the OSCP count toward the CISSP experience rule?

The OSCP is not on ISC2's approved list for the one-year waiver, as we read it, so it does not shorten the five years. Penetration-testing work itself can count: ISC2's exam outline lists penetration testing under the Security Assessment and Testing domain. ISC2 decides at endorsement whether your work fits two domains.

How do the two exams work?

The CISSP is a three-hour multiple-choice exam, and ISC2's outline lists select testing centers; the OSCP is a hands-on attack exam of nearly 24 hours plus a written report.

CISSP (ISC2) OSCP (OffSec)
Format Multiple choice and advanced item types, adaptive Hands-on attacks on lab machines, then a written report
Time 3 hours 23 hours 45 minutes, plus 24 hours to upload the report
Content 100 to 150 questions across 8 domains 3 single machines and 1 Active Directory (Microsoft's system for managing a network's users) set of 3
Passing score 700 out of 1,000 70 of 100 points
Where Select testing centers Proctored (watched) by OffSec, lab reached over a VPN (encrypted connection)

Source: ISC2 CISSP exam outline; OffSec PEN-200 page and OSCP exam guide, archived September 21, 2025.

What do the CISSP and OSCP cost over three years?

The CISSP costs $1,154 over three years at ISC2's Americas price, and the OSCP $1,699 (two exam attempts) or $1,749 (one attempt) at OffSec's US prices, depending on the package. The totals are not directly comparable: the CISSP total includes its yearly fee for staying certified but no study material, and the bundle includes a course.

Item CISSP, Americas OSCP+ Standalone Exam OSCP Course + Cert Bundle
Exam or package $749 x 1 attempt $1,699 x 1 (two exam attempts, no course) $1,749 x 1 (90 days of course and labs, one exam attempt)
Yearly fee $135 x 3 years OSCP+ upkeep not priced OSCP+ upkeep not priced
Three-year total $1,154 $1,699 $1,749

Source: ISC2 exam pricing and annual-fee pages; OffSec PEN-200 page and standalone exam FAQ.

ISC2 calls its yearly fee the annual maintenance fee (AMF); an Associate of ISC2 pays $50 a year instead until certified. Other regions, including Europe and the UK, have their own CISSP exam prices on ISC2's pricing page.

CISSP vs OSCP: what each certification costs
Cheapest route: CISSP $749, OSCP $1,699.
Show the numbers
CISSP vs OSCP: what each certification costs. Source: isc2.org, offsec.com, help.offsec.com, checked October 3, 2026.
ItemFee
CISSP: Fees to get certified: Exam$749
OSCP: Fees to get certified: Exam$1,699
OSCP: Fees to get certified: Official prep course (optional)$1,749
OSCP: Fees to get certified: One retake (optional)$249

How do you keep each credential?

The CISSP needs ongoing study and a yearly fee; the OSCP itself needs nothing, and only the OSCP+ expires.

  • CISSP: 120 CPE credits per three-year cycle plus $135 a year. CPE (continuing professional education) means courses, conferences and similar learning you log with ISC2. ISC2 suggests 40 credits a year.
  • OSCP: no expiration date. The OSCP+, earned with it, expires three years after it is issued. To keep the OSCP+, pass a recertification exam within six months of the expiration date, pass another qualifying OffSec exam, or use OffSec's CPE program.

CISSP vs OSCP difficulty: which exam is harder?

The CISSP tests breadth across eight domains in three hours, and the OSCP tests whether you can break into lab machines and document every step in nearly 24 hours.

Which should you take first, the CISSP or the OSCP?

Your target job sets the order: the OSCP for hands-on testing, the CISSP once your work meets its experience rule. If you are not working in either job yet, start with the quick answer.

Is the OSCP a beginner certification?

No, it is not a first certification. OffSec lists 321 hours of content for PEN-200. A beginner can build the three recommended skills through IT work, then try the eJPT.

Should a penetration tester add the CISSP?

Yes, if you want to move toward leading teams, security architecture or management, and your work covers two CISSP domains. Our CISM vs CISSP comparison covers the management route, and our CISSP vs Security+ comparison covers the entry route.

What we did not check

  • Salary. We found no dated source that compares pay for CISSP and OSCP holders.
  • Pass rates. Neither ISC2 nor OffSec publishes one on the pages we read.
  • CISSP retake price. ISC2's pricing page lists no separate retake fee, and we did not confirm one.
  • Exam delivery and languages. The pages we read do not say whether the CISSP can be taken online or which languages the OSCP exam offers.
  • OSCP costs and rules. We did not check the price of the OSCP+ recertification exam or OffSec's CPE program (see the PEN-200 page). OffSec's help pages blocked our reader, so the exam facts come from archived copies (see Sources) and may have changed. Its standalone-exam FAQ, archived September 2025, lists a $249 retake and waits of 4 weeks after a first attempt and 8 after a second; it does not say whether the waits apply to the bundle.

Sources

All pages below were read October 8, 2026. An archived copy is a saved copy of a page from the date given.

Keep these numbers up to date

Inside: CISSP and OSCP side by side, by share of job ads naming each, with the official fees.

Email me my CISSP vs OSCP report for the United States, plus a monthly update when these numbers change. Unsubscribe anytime.

What’s in it?
  • The certifications that rose or fell most in job ads this month
  • One new study from our data, with its sources
  • New certifications, jobs and countries we added

One email a month. Unsubscribe in one click.

We use AI to analyse the job-ad data and write your report. The counts come from Adzuna job ads; figures and sources are checked automatically.

How we use your email: privacy policy

Questions people ask

Is the CISSP or the OSCP harder?

They are hard in different ways. The CISSP (Certified Information Systems Security Professional, from ISC2) is an adaptive multiple-choice exam, meaning each question is picked based on your earlier answers. It has 100 to 150 questions over eight domains (topic areas), takes three hours and needs 700 out of 1,000 to pass. The OSCP (OffSec Certified Professional) is hands-on. OffSec's exam guide, archived September 2025, gives 23 hours and 45 minutes to break into lab machines (practice computers built for the exam), then 24 hours to upload a report; you need 70 of 100 points.

Can a beginner take the OSCP or the CISSP?

You can take either exam, but they suit beginners differently. The OSCP (OffSec Certified Professional) has no experience requirement, so you can take it first, but OffSec strongly recommends networking knowledge, Windows and Linux administration, and basic Bash or Python scripting. The CISSP (Certified Information Systems Security Professional) needs five years of security work before you can hold it. If you pass the exam first, you can become an Associate of ISC2, a lower membership level that gives you six years to earn that experience. With no IT experience yet, look at CompTIA Security+, an entry-level security exam.

OSCP vs CISSP: which should I take first?

Your target job sets the order. Take the OSCP (OffSec Certified Professional) first for penetration testing, attacking an organization's systems with permission to find weak spots: it has no experience requirement, but it assumes hands-on Linux, networking and scripting skills. Take the CISSP (Certified Information Systems Security Professional) first if you want to design or manage security and already have the experience it requires. That is five years of security work, or four with a waiver (a degree or approved credential that replaces one year).

How much do the CISSP and OSCP cost over three years?

With one exam attempt, the CISSP (Certified Information Systems Security Professional) costs $1,154 over three years at ISC2's Americas price: the $749 exam plus three yearly fees of $135, ISC2's charge to keep the credential. The OSCP (OffSec Certified Professional) costs $1,749 with OffSec's Course + Cert Bundle (90 days of course and labs plus one attempt) or $1,699 for the exam alone with two attempts, at OffSec's US prices read in October 2026.

Does the OSCP expire?

The OSCP (OffSec Certified Professional) does not expire. Passing OffSec's exam earns both the OSCP and the OSCP+, a version that expires three years after it is issued. OffSec lists three ways to keep the OSCP+: pass a recertification exam within six months of the expiration date, pass another qualifying OffSec exam, or use OffSec's continuing professional education (CPE) program, where you log learning activities. The CISSP (Certified Information Systems Security Professional), by contrast, stays valid only while you earn 120 CPE credits every three years and pay ISC2's $135 yearly fee.

Which do job ads name, the CISSP or the OSCP?

We count each in a different job's ads on Adzuna, a job-ad search site, in October 2026. The OSCP (OffSec Certified Professional) is counted in US penetration-tester ads, the CISSP (Certified Information Systems Security Professional) in US security-analyst and SOC-analyst (security operations center) ads.