OSCP: OffSec Certified Professional
The OSCP (OffSec Certified Professional, course code PEN-200) is a hands-on penetration-testing certification from OffSec. The current course-and-exam bundle costs $1,749; the Learn One subscription is $2,749 a year. The exam is a proctored 23-hour-45-minute practical, followed by 24 hours to write the report, and you need 70 of 100 points to pass. It is genuinely demanding, but sits at the entry level of OffSec's ladder.
- Price from
- $1,749
- Exam
- 23h 45m + 24h report
- Level
- Advanced
- Report
- Yes
What OSCP is and who runs it
OSCP stands for OffSec Certified Professional. It is issued by OffSec (formerly Offensive Security), the company behind Kali Linux, and it is earned by passing a single hands-on exam tied to the PEN-200 course, “Penetration Testing with Kali Linux.” There is no multiple-choice paper. You are dropped into a private VPN with vulnerable machines and have to actually break into them, escalate privileges, and then write a professional report proving how you did it. Since late 2024 the current credential is technically branded “OSCP+,” which adds an assumed-breach Active Directory scenario and expires after three years unless renewed; the classic OSCP name is what everyone still uses.
Cost and what’s included
OffSec sells this as bundles and subscriptions, not a flat exam fee. The Course + Cert Bundle is $1,749 and gives you 90 days of access to the PEN-200 course materials, the hands-on labs, and one exam attempt. The Learn One subscription is $2,749 per year and includes a full year of one 200- or 300-level course, its labs, and two exam attempts. If you already have the skills and only want to sit the exam, the standalone OSCP+ exam is $1,699. Retake vouchers are bought separately when your included attempts run out.
Time: the exam and the report
The exam gives you 23 hours and 45 minutes of hands-on hacking time, and it is proctored the whole way through via webcam and screen share. When that clock stops, a second clock starts: you get another 24 hours to write and upload your penetration-test report as a PDF. The report is not a formality. Missing screenshots, missing proof files, or thin documentation can zero out points you technically earned, and once submitted the report is final.
How hard it is, honestly
OSCP is hard for most people, but its difficulty is more about stamina and time management than exotic technical tricks. The machines lean on solid enumeration, known vulnerabilities, and privilege escalation rather than cutting-edge exploits. You need 70 of the 100 points, and the layout — three standalone boxes worth 60 and a three-machine Active Directory set worth 40 — means the AD set is nearly unavoidable if you want a comfortable pass. Metasploit is limited to one target, and automated tools like SQLMap and vulnerability scanners are banned, so you have to understand what you are doing. Most people who fail run out of time or fall into rabbit holes, not talent.
Is it worth it — and for whom
OSCP remains the most widely recognized practical pentest cert, and for many junior and mid-level roles it functions as an HR filter you clear once and benefit from for years. It is worth it if you want a penetration-testing or red-team job and need a credential recruiters recognize. It is less compelling if your work is web- or cloud-focused, or if you already hold hands-on certs like CPTS or PNPT — some reviewers openly argue those teach more per dollar. The price and the grind are the real costs.
How to prepare
Budget two to three months of consistent practice. Work through the PEN-200 material and its lab machines, then do volume on external practice ranges — OffSec’s own Proving Grounds Practice and the community “OSCP-like” machine lists (Lainkusanagi, TJ Null) are the standard recommendations. Practice Active Directory attacks and pivoting specifically, since that set is worth 40 points. Build a note-taking and screenshot habit early, and write at least one practice report before exam day so the documentation half does not surprise you.
SourcesOffSec PEN-200 course & pricingOSCP Exam GuideOffSec Exam Retake Policy

Common questions
How much does the OSCP exam cost?
$1,749 course + exam bundle (or $2,749/yr Learn One). Set by OffSec and subject to change — confirm the current price on their page.
How long is the OSCP exam?
The OSCP exam runs 23h 45m + 24h report.
Does OSCP require a written report?
Yes. OffSec grades a written report alongside the practical, and it counts toward whether you pass — see how the report is graded on the reports page.
Who runs the OSCP certification?
OSCP (OffSec Certified Professional) is run by OffSec. It is an advanced exam that assumes solid prior experience in the network penetration testing track.
Can you retake the OSCP exam?
1 attempt in the bundle, 2 on Learn One; cooling-off 4/8/12 weeks.
What people who sat OSCP say
I actually enjoyed the overall experience, and learned a lot from the material and the actual exam.
As much as I disliked preparing for the exam, I dislike the price point of the OSCP more.