OSCP vs OSWP
Two exams that come up together — how they actually differ, and who each one is for.
These are not really rivals. OSCP is the flagship practical pentest cert — advanced, broad, and the name employers look for. OSWP is a narrow, entry-level add-on covering Wi-Fi attacks only, included with an OffSec subscription. Nobody should pick OSWP instead of OSCP; take OSCP for your career, and add OSWP later if wireless work is part of your job.
- OSCP
- advanced, $1,749 course + exam bundle (or $2,749/yr Learn One)
- OSWP
- entry, Included with OffSec Learn ($799/yr Fundamentals, $2,749/yr Learn One)
- Harder
- OSCP
| OSCP | OSWP | |
|---|---|---|
| Vendor | OffSec | OffSec |
| Level | advanced | entry |
| Duration | 23h 45m + 24h report | 3h 45m + 24h report |
| Format | fully practical, proctored; 70/100 to pass | recover the wireless key across 3 scenarios, then a PDF report |
| Cost | $1,749 course + exam bundle (or $2,749/yr Learn One) | Included with OffSec Learn ($799/yr Fundamentals, $2,749/yr Learn One) |
What each one is
OSCP, from OffSec, is the advanced, fully hands-on penetration testing certification most employers recognise. You work through the PEN-200 course and labs, then sit an exam where you compromise live machines and write a professional report. It covers the general pentest kill chain — enumeration, exploitation, privilege escalation, Active Directory — across Windows and Linux.
OSWP, also from OffSec, is a single-topic wireless certification built on the PEN-210 course. It is entry-level and narrow by design: it teaches attacks against Wi-Fi networks and little beyond that. The exam gives you a short window to recover wireless keys across a few scenarios, followed by a report.
The real difference
The honest framing is that these are complementary, not competing. OSCP is a career cornerstone; OSWP is a focused add-on that proves one specific skill — wireless attacks. They sit at different levels (OSCP is advanced, OSWP entry-level) and share almost no common ground. Reviewers who hold both are candid that OSWP is the lighter of the two: within the pentesting community it is not known as a difficult exam, and experienced practitioners often find the material straightforward. That is not a knock — it is simply a much smaller scope. Treat OSWP as one skill added to a toolkit, not as a step that stands in for OSCP.
Cost and time
OSCP is the bigger commitment in every sense. The bundle is $1,749 for the course plus one exam attempt, or $2,749 a year for Learn One; the exam is 23h 45m plus a 24-hour report, and passing needs 70/100. OSWP is not sold the same standalone way — it comes included with an OffSec Learn subscription ($799 a year for Learn Fundamentals, or the $2,749 Learn One that also covers OSCP). Its exam is short: 3h 45m of hands-on work plus a 24-hour reporting window. In both time and difficulty, OSWP is a fraction of OSCP.
Which one to choose
For almost everyone, the answer is OSCP first — it is the credential that changes how your résumé reads, and it is the one job listings ask for. OSWP is not an alternative to that; it is something you add when wireless assessment is genuinely part of your role, or when you already hold a Learn subscription and want to pick up the skill cheaply. If you are on Learn One, OSWP is effectively bundled, so there is little reason not to take it eventually. Just do not treat it as a substitute for OSCP; it was never meant to be one.
What people who sat these say
Although Offensive Security holds great reputation in the industry, among the pentesting community this particular certification isn't exactly known for being particularly challenging.
As a standalone product, I don't think it really holds up.
Full detail on each: OSCP · OSWP. For where both sit in a longer plan, see the roadmap.