What Is the OSCP PEN-200 Exam?
The Offensive Security Certified Professional (OSCP) is a hands-on penetration testing certification administered by OffSec, the team behind Kali Linux. In 2026, passing the PEN-200 course and its 24-hour practical exam grants you both the lifetime OSCP credential and the renewable OSCP+ designation. Candidates must compromise a network of target machines within roughly 23 hours and 45 minutes, then submit a professional report within 24 more hours, scoring at least 70 out of 100 points. It targets aspiring penetration testers, red teamers, and security engineers, and costs $1,749 for the standard 90-day bundle. Unlike theory-heavy credentials such as CEH, the OSCP refuses to be gamed: there is no multiple-choice section, and every point must be earned by actually exploiting a live system and documenting the path you took.
Key Points at a Glance
Before diving into the details, here are the essential facts every candidate should understand about the OSCP PEN-200 exam in 2026, from who it serves to how it is scored and what it costs. These points map directly to the decisions you will make when registering and building your study plan.
- Who it is for: Aspiring pentesters, red teamers, and security professionals moving into offensive roles.
- What it tests: Practical exploitation across stand-alone machines and an Active Directory set — no multiple choice.
- When you take it: A scheduled 23h 45m hacking window plus a 24h reporting window.
- Where: Remote, over a proctored VPN connection provided by OffSec.
- Why it matters: OSCP is widely regarded as the gold standard for practical pentesting skills and a strong resume differentiator.
What OSCP Means in 2026
The OSCP has held near-mythical status in cybersecurity for over a decade because it refuses to be gamed. There are no multiple-choice questions and no shortcuts: you must actually break into live systems and document how you did it. As OffSec itself frames it, the philosophy is “Try Harder,” meaning the certification rewards persistence and methodology over memorization. According to OffSec’s PEN-200 course page, the course teaches core pentesting skills including enumeration, exploitation, and evidence gathering for proof of work, and it is designed specifically to prepare candidates for the OSCP+ exam.
What makes OSCP distinct in a crowded certification market is its transfer to real work. The report you produce during the exam is the closest thing to a junior penetration tester’s deliverable that most candidates will ever have on file. That is also why hiring managers treat the three letters after your name as proof that you can execute, not merely study. The structured CEH ethical hacking methodology framework covers a similar five-phase approach to engagements, but OSCP demands you actually execute each phase against live targets. For IT professionals weighing whether offensive security is a viable career path, OSCP remains the most respected single credential to anchor that transition, even as cloud and AI security topics expand around it.
The OSCP+ Split Explained
The November 2024 change is the single most important fact to internalize before you register. Passing PEN-200 now awards two separate designations at once. You receive OSCP, which is lifetime and remains the brand recruiters still explicitly ask for, and you also receive OSCP+, which carries a three-year validity period. As Unihackers’ OSCP certification guide documents, OSCP+ is renewable through the OffSec CPE program, a recertification exam, or by passing another qualifying OffSec exam. The exam itself is unchanged in 2026 by this split — only the credentialing outcome on your transcript differs.
Practically, this means your lifetime OSCP title is safe even as OffSec modernizes its maintenance model. The OSCP+ layer simply formalizes ongoing skill validation in line with how most vendor programs now operate. If you already hold a legacy OSCP, you can take the OSCP+ standalone exam to add the renewable designation without repeating the full PEN-200 journey. For planning purposes, budget for either continuing education units or a future recertification attempt roughly three years out, and factor that recurring cost into your total investment.
Exam Format and Scoring
The OSCP exam is structured to mirror a real engagement under time pressure. According to OffSec’s official OSCP+ Exam Guide, the practical portion gives you 23 hours and 45 minutes of hands-on hacking followed by an additional 24 hours to write and submit a professional penetration testing report. You connect to a dedicated VPN containing a set of target machines and must compromise them, collecting proof files (local.txt and proof.txt) from each.
The point distribution is fixed and worth memorizing, because it dictates your exam-day strategy:
| Component | Points | Notes |
|---|---|---|
| Stand-alone machines (3) | 20 each (60 total) | Independent boxes, including a buffer overflow |
| Active Directory set | 40 | Mandatory chain, no bonus points available |
| Passing score | 70 of 100 | Report quality can affect final scoring |
Because the Active Directory set is worth 40 points and cannot be softened by any bonus, most successful candidates prioritize it early. A common failure pattern is spending eight hours on a single stand-alone box and never completing the AD chain, which mathematically caps your achievable score below the pass threshold.
PEN-200 Course Content Breakdown
The PEN-200 course is the official learning path tied to the OSCP exam. It bundles an 850-plus page PDF coursebook, over 17 hours of video content, and access to a structured lab environment. The curriculum is organized into modules that map directly to what you will face on exam day, as outlined in Programs.com’s 2026 OSCP guide. Each module pairs theory with hands-on exercises, and OffSec expects you to complete every lab rather than skim.
The major content areas include Linux and Windows privilege escalation (sudo misconfigurations, SUID exploitation, token impersonation), web exploitation (SQL injection, LFI/RFI, command injection), buffer overflow exploitation written in C and Python, Active Directory attacks (Kerberoasting, AS-REP roasting, lateral movement), password attacks with Hydra, John, and Hashcat, tunneling and port forwarding through SSH and chisel, client-side exploitation, and professional reporting with an emphasis on ethics. A critical caveat: PEN-200 does not cover cloud exploitation, EDR bypass, or phishing. To close those gaps before a real job, most candidates supplement with HackTheBox Pro Labs or PortSwigger Academy.
Realistic Study Timeline by Background
OffSec does not publish an official pass rate, and most candidates fail their first attempt — a fact confirmed by CertEmpire’s OSCP cost breakdown, which notes that OffSec deliberately keeps pass-rate statistics private. What is well documented is the time investment required. Expect anywhere from 250 to 600 hours of focused, hands-on practice depending on your starting point.
| Background | Typical Prep Time | Weekly Hours |
|---|---|---|
| Active pentester | 3–4 months | 25–30+ |
| Security professional | 4–6 months | 20 |
| Developer / sysadmin | 6–9 months | 15–20 |
| Beginner (little IT experience) | 9+ months, often after one failed attempt | 10–15 |
Beginners are explicitly not the target audience. OffSec recommends solid Linux and Windows administration skills, networking knowledge, and basic scripting ability as prerequisites. If you lack those foundations, a credential like CompTIA Security+ or Network+ should come first. A practical sample 16-week plan for a working security professional: weeks 1–4 cover PEN-200 modules and exercises; weeks 5–8 focus on privilege escalation drills across 30 lab machines; weeks 9–12 tackle the AD sets and pivoting; weeks 13–15 run two to three full 24-hour mock exams; week 16 is rest and final report-writing practice.
Cost Breakdown and Hidden Expenses
OSCP is one of the more expensive professional certifications, and the sticker price understates the true investment. The standard PEN-200 bundle costs $1,749, which includes 90 days of lab access and a single exam attempt. The annual Learn One subscription runs $2,749 and includes two exam attempts, while Learn Unlimited is $6,099 per year. Exam retakes cost roughly $249 each. These figures are documented across Coursera’s OSCP guide and corroborated by the sources above.
Hidden costs add up quickly and should be planned for upfront. A virtual private server for hosting additional labs runs $10–$20 per month. Supplemental platforms like HackTheBox Pro or TryHackMe add $20–$50 per month. Books and references such as privilege escalation handbooks cost $50–$100, and premium learning paths from INE or PortSwigger Pro can run $200–$500 if you choose to use them. One legitimate way to reduce the burden: many cybersecurity consultancies and government contractors offer full or partial tuition reimbursement for OSCP, so always ask your employer before self-funding.
Building Your Lab Practice Plan
Passing OSCP is fundamentally a methodology problem, not a knowledge-recall problem. The candidates who succeed build a repeatable loop: enumerate thoroughly, exploit the first foothold, escalate privileges, pivot, and document every step as they go. To train that loop, your practice environment should mix the official PEN-200 labs with external platforms graded to OSCP difficulty.
A concrete weekly routine that experienced holders recommend: dedicate two weekday evenings (2–3 hours each) to working PEN-200 modules and completing exercises, then block one full weekend day for a longer HackTheBox session focused on retired OSCP-style machines and an Active Directory Pro Lab. Keep a structured note-taking system — Obsidian or CherryTree are popular — and write a mini-report for every machine you root, including the command sequence, screenshots, and remediation advice. Track three metrics weekly: machines rooted, new privilege escalation techniques mastered, and reports completed. If any metric stalls for two weeks, change your platform or join a study group on Discord or the r/oscp subreddit for accountability.
Common Reasons Candidates Fail
Understanding why people fail is more valuable than memorizing another technique. The most frequent failure mode is poor time management — burning eight or more hours on a single stand-alone box instead of pivoting when progress stalls. The second is weak Active Directory skills: because the AD set is worth 40 points and offers no partial bonus, an incomplete chain often makes the 70-point threshold mathematically unreachable. The third, and most overlooked, is documentation. Candidates regularly compromise machines correctly but lose points because they forgot to screenshot proof files or their report omitted exploitation steps.
Other recurring mistakes include neglecting stamina and logistics. A 24-hour exam is physically demanding, and candidates who do not rehearse hydration, sleep breaks, and meal timing during mock exams often crash in the final hours. Relying too heavily on automated tools (Metasploit is restricted to a single target on the exam) trips up those who never practiced manual exploitation. Finally, under-preparing on privilege escalation — the single most heavily weighted practical skill — leaves candidates with a foothold they cannot elevate. The antidote to all of these is disciplined mock exams: schedule at least two full 24-hour simulations under real conditions before your attempt.
OSCP Salary and Career Impact
The financial return on OSCP is strong, though the credential is narrower in job-posting volume than management-focused certs. According to ZipRecruiter data referenced in Unihackers’ analysis, the average US salary tagged to OSCP holders was $119,895 per year as of April 2026, with a typical range from $90,000 to $168,000. By role, junior pentesters land around $82,000–$100,000, security consultants earn $110,000–$130,000, and red team leads can command $140,000–$168,000. Regions matter: San Francisco and New York skew toward $140,000–$160,000, while Midwest hubs like Chicago and Dallas cluster around $110,000–$120,000.
It is worth being realistic about volume. While OSCP appears in roughly 600-plus US job postings, CISSP surfaces in over 80,000 and Security+ in around 70,000, per CyberSeek data cited by Programs.com. For a broader view of where OSCP ranks against the highest paying IT certifications in 2026, the data shows management credentials lead on raw posting volume. OSCP’s value is differentiation, not breadth: it filters you into specialized pentest, red team, and offensive security roles where it is frequently listed as “strongly preferred” or required. For career changers, the credential plus the exam report you retain is often what converts a help desk or sysadmin background into a first penetration testing offer, and building portfolio projects for junior candidates alongside it strengthens that transition.
References
- OffSec — PEN-200 Course and OSCP+ Certification
- OffSec Support Portal — OSCP+ Exam Guide
- OffSec — OSCP+ Standalone Exam
- Programs.com — OSCP Certification 2026 Guide
- Unihackers — OSCP Certification 2026: Cost and Exam
- CertEmpire — OSCP Certification Cost 2026 Breakdown
- Coursera — What Is OSCP Certification and Is It Worth It?