OSCP vs OSEP
Two pentest exams that come up together — how they actually differ, and who each one is for.
OSEP is the sequel, not the rival. OSCP proves broad penetration-testing fundamentals and is the recognised entry to OffSec; OSEP (PEN-300) assumes that foundation and adds custom evasion, breaching defenses and deeper Active Directory. Both cost $1,749. Do OSCP first — OSEP expects those foothold and privilege-escalation skills as prerequisites.
- OSCP
- advanced, $1,749 course + exam bundle (or $2,749/yr Learn One)
- OSEP
- expert, $1,749 course + exam bundle (or $2,749/yr Learn One)
- Harder
- OSEP
| OSCP | OSEP | |
|---|---|---|
| Vendor | OffSec | OffSec |
| Level | advanced | expert |
| Duration | 23h 45m + 24h report | 47h 45m + 24h report |
| Format | fully practical, proctored; 70/100 to pass | practical evasion + report; reach the objective or 100 pts |
| Cost | $1,749 course + exam bundle (or $2,749/yr Learn One) | $1,749 course + exam bundle (or $2,749/yr Learn One) |
What each one is
OSCP — Offensive Security Certified Professional, the PEN-200 course — is OffSec’s foundational penetration-testing certification and the recognised entry to the whole path. It covers broad, hands-on offensive fundamentals: enumeration, exploitation, privilege escalation, and introductory Active Directory across a network of machines.
OSEP — OffSec Experienced Penetration Tester, the PEN-300 course — is the advanced follow-on. It focuses on evasion and breaching defenses: custom payloads, antivirus and application-control bypass thinking, phishing for initial access, and deeper Active Directory lateral movement once inside.
The real difference
These are not rivals; they are rungs on the same ladder. OSCP teaches you to get a foothold and escalate. OSEP assumes you already can, and spends its time on what happens when the defenses are switched on and fighting back.
Reviewers who have done both are blunt about the relationship. One who holds OSCP and OSEP says PEN-300 assumes all those initial foothold and privilege-escalation skills as a prerequisite; another puts it plainly that the PEN-300 course builds on the material covered in the OSCP. The jump in difficulty is real — OSEP expects OSCP-level skill on day one and moves quickly from there.
Cost and time
Both cost $1,749 for the course-and-exam package, so price is not the deciding factor here — capability is.
The exams show the gap. OSCP is a 23-hour-45-minute hands-on exam plus a 24-hour report window, passing at 70 of 100 points. OSEP roughly doubles the hands-on time to 47 hours 45 minutes, again with a 24-hour report, and you pass by reaching the objective or scoring 100 points. OSEP is longer, less forgiving, and assumes far more going in.
Which one to choose
For anyone starting out, OSCP is the answer. It is the credential most pentest roles list, and it is the prerequisite — in spirit, and often in skill — for everything above it.
Move to OSEP once you hold OSCP, or have equivalent real-world experience, and you want to push into red-team and evasion work. Going straight to OSEP is only sensible if you already have strong Active Directory and evasion fundamentals from the field; otherwise the step up is punishing.
In short: OSCP proves you can break in; OSEP proves you can do it against defenses designed to stop you. Do them in that order.
What people who sat these say
it assumes all those initial foothold and privileges escalation skills are a pre-requisite
The PEN-300 course builds on the material covered in the OSCP
Full detail on each: OSCP · OSEP. For where both sit in a longer plan, see the roadmap.