Short answer: The CEH (Certified Ethical Hacker) is EC-Council's globally recognised entry-to-mid-level ethical hacking certification. In India it typically costs around ₹85,000–₹1,10,000 for the exam voucher plus training, uses a 125-question, 4-hour exam, and is worth it when paired with genuine hands-on skills.
What is the CEH certification?
CEH stands for Certified Ethical Hacker, a certification created and awarded by the EC-Council (International Council of E-Commerce Consultants). It validates that you understand how attackers think and operate — reconnaissance, scanning, exploitation, privilege escalation and covering tracks — so you can legally test and defend systems. CEH is one of the most widely requested credentials in Indian job listings for roles such as SOC analyst, security analyst and junior penetration tester, and it is often listed as a preferred qualification in government and defence-sector tenders.
The current version is CEH v13, which adds AI-driven attack and defence techniques on top of the classic ethical hacking methodology. EC-Council periodically updates the version, so always confirm the latest revision before booking.
CEH exam format at a glance
There are two separate exams under the CEH programme. The knowledge exam (multiple-choice) earns you the CEH credential; the optional CEH Practical is a hands-on lab exam that earns the CEH (Practical) title. Passing both gives you "CEH Master" status.
| Item | CEH (Knowledge) | CEH (Practical) |
|---|---|---|
| Format | Multiple choice | Hands-on lab challenges |
| Questions / tasks | ~125 MCQs | 20 practical challenges |
| Duration | 4 hours | 6 hours |
| Passing score | ~60–85% (cut score varies by exam form; roughly 70%) | Score-based (typically ~70%) |
| Delivery | ECC Exam / VUE testing centre or online proctored | Online proctored cyber range |
| Result | CEH credential | CEH (Practical) credential |
Note: EC-Council uses multiple exam forms with different cut scores, so the exact pass mark you need can vary between roughly 60% and 85%. Treat ~70% as a safe target when preparing.
CEH eligibility: who can apply?
There are two accepted paths to sit the CEH exam:
- Official training route: Attend official or authorised CEH training. This waives the experience requirement and is the most common path for students and career-changers.
- Experience route: If you self-study without official training, you must show at least 2 years of verifiable information-security work experience and pay an eligibility application fee to EC-Council, who review your application before granting exam access.
For most freshers and college students in India, the training route is simpler because it removes the two-year experience hurdle. If you are new to the field, start with fundamentals first — see our primer on what is ethical hacking before committing to CEH.
CEH syllabus: the 20 modules
The CEH body of knowledge is organised into 20 modules that follow the full attack lifecycle. At a high level they cover:
- Introduction to ethical hacking and the cyber kill chain
- Footprinting and reconnaissance
- Scanning networks
- Enumeration
- Vulnerability analysis
- System hacking
- Malware threats (trojans, viruses, worms)
- Sniffing
- Social engineering
- Denial-of-Service (DoS/DDoS)
- Session hijacking
- Evading IDS, firewalls and honeypots
- Hacking web servers
- Hacking web applications
- SQL injection
- Hacking wireless networks
- Hacking mobile platforms
- IoT and OT hacking
- Cloud computing security
- Cryptography
CEH v13 threads AI-assisted techniques through these modules — for example using AI to speed up reconnaissance or to help triage vulnerabilities. Knowing the theory is only half the job; you must practise each of these in a lab to actually pass and, more importantly, to be employable.
How much does CEH cost in India?
CEH pricing has several parts, and EC-Council changes voucher prices periodically, so always confirm current rates on the official EC-Council site. As an approximate 2026 guide:
- Exam voucher: roughly US$950–US$1,199 (approximately ₹80,000–₹1,00,000 depending on the exchange rate and whether it includes exam-prep material).
- Eligibility application fee (experience route only): around US$100.
- Official / authorised training: varies widely by provider, from tens of thousands of rupees to over a lakh.
- CEH Practical voucher: priced separately if you want the Master title.
Because the rupee-dollar rate moves and EC-Council revises pricing, treat every figure here as approximate. The realistic all-in budget for training plus a voucher in India is commonly in the ₹85,000–₹1,50,000 range.
CEH validity and renewal (ECE credits)
CEH is valid for 3 years. To keep it active you enrol in EC-Council's Continuing Education (ECE) scheme and earn 120 ECE credits over the three-year cycle, plus pay an annual membership fee. Credits come from activities such as attending webinars, writing articles, completing additional training, or mentoring. If you let it lapse without credits, you may have to re-take the exam.
How to prepare for the CEH exam
Passing CEH is very achievable with a structured plan. Most candidates need roughly 8–12 weeks of consistent study, assuming a few hours per day. A realistic study path looks like this:
- Weeks 1–2 — Fundamentals: Networking (TCP/IP, ports, protocols), Linux basics, and how the web works. Skipping these is the single biggest reason beginners fail.
- Weeks 3–8 — Module-by-module practice: For each of the 20 modules, read the theory, then immediately reproduce it in a lab. Use tools such as Nmap, Wireshark, Burp Suite, Metasploit and sqlmap on intentionally vulnerable targets you own or that are legally provided for practice.
- Weeks 9–10 — Tool fluency and reporting: Get fast with the core toolset and practise writing short findings so you can explain, not just memorise.
- Weeks 11–12 — Mock exams: Take timed practice tests, review every wrong answer, and revise weak modules until you consistently score above 75%.
Cryptography, wireless attacks and cloud modules are commonly under-prepared, so give them extra attention. Never practise on systems you do not own or have written permission to test — that is illegal and it is the exact opposite of ethical hacking.
CEH vs other cyber security certifications
CEH is not the only path into security. Here is how it compares to other popular options so you can pick the right one for your stage:
| Certification | Level | Focus | Best for |
|---|---|---|---|
| CEH | Entry–Mid | Broad ethical hacking, theory + optional practical | Recognition, first security job, tenders |
| CompTIA Security+ | Entry | Security fundamentals, defensive | Absolute beginners, IT support crossover |
| OSCP | Advanced | Fully hands-on penetration testing | Serious pentesters and red teamers |
| CompTIA PenTest+ | Mid | Practical pentesting and reporting | Pentesters wanting a mid-tier proof |
A common Indian career path is Security+ or CEH to break in, then OSCP once you specialise in offensive work. There is no single "best" certificate — it depends on your goal and current skill level.
Career paths after CEH
CEH opens doors to a range of roles depending on where your interest lies:
- Defensive / blue team: SOC analyst, incident responder, threat hunter.
- Offensive / red team: penetration tester, VAPT engineer, red teamer.
- Advisory: security consultant, GRC and compliance analyst.
- Specialist tracks: cloud security, application security, or forensics as you gain experience.
Whichever route you take, hands-on ability and clear reporting decide how far and fast you progress — and how much you earn.
Is CEH worth it in India?
CEH carries strong brand recognition with Indian HR teams and is frequently named in job descriptions, government tenders and defence-sector requirements. That name recognition is its biggest strength. However, be honest with yourself about two things:
- A certificate is not a skill. Recruiters increasingly test candidates on live labs and practical tasks. If you memorise theory to clear the MCQ but cannot actually run an Nmap scan, exploit a vulnerable box, or write a clean report, you will struggle in interviews.
- Pair it with hands-on practice. CEH is most valuable when you also build a home lab, practise on legal platforms, and can demonstrate real work. This is exactly why our training emphasises labs over slideware.
Once certified, your earning potential improves — see our detailed breakdown of CEH salary in India for realistic fresher-to-senior numbers.
How Cyber Defence prepares you for CEH
Cyber Defence is an ISO-certified, GeM-registered cyber security and ethical hacking training institute based in Hisar, Haryana, founded by Amit Kumar (CEH, CRTA). We do not claim CERT-In empanelment, and we never advertise fake pass-rates or reviews — what we offer is honest, hands-on training.
- CEH-aligned Ethical Hacking course: ₹60,000 for 6 months, EMI available. This covers the full CEH syllabus with practical labs, live online classes plus classroom sessions in Hisar. Please note the EC-Council exam voucher is separate and is not included in the course fee.
- Entry-level Cyber Security course: ₹15,000 for 3–4 months — ideal if you are a complete beginner and want fundamentals before committing to CEH.
Explore all our programmes on the courses page, learn about our flexible best cyber security online course, or join our classroom ethical hacking course in Hisar.
FAQ
Is CEH worth it in India?
Yes, if you combine it with genuine hands-on skill. CEH is widely recognised by Indian employers and appears in many job listings and government tenders, but recruiters increasingly test practical ability, so treat the certificate as a door-opener rather than a guarantee.
How much does CEH cost?
The exam voucher is approximately US$950–US$1,199 (roughly ₹80,000–₹1,00,000), and training is charged separately. Prices change often, so confirm current rates directly with EC-Council before booking.
Can a fresher do CEH?
Yes. Freshers usually take the official-training route, which waives the two-year experience requirement. Beginners should first build fundamentals — our ₹15,000 entry cyber security course is designed for exactly that.
CEH vs OSCP — which is better?
They serve different goals. CEH is broad, theory-plus-practical and great for recognition and early-career roles. OSCP is a tougher, fully hands-on penetration-testing certification valued by red teams. Many professionals do CEH first, then pursue OSCP as they specialise.
How long is CEH valid?
CEH is valid for 3 years. You keep it active by earning 120 ECE (continuing education) credits over the cycle and paying the annual membership fee, otherwise you may need to re-take the exam.
Does Cyber Defence include the CEH exam voucher in its course fee?
No. Our ₹60,000 CEH-aligned ethical hacking course covers training and hands-on labs, but the EC-Council exam voucher is purchased separately from EC-Council.
Ready to start? Talk to our team about the CEH-aligned ethical hacking course, EMI options and the entry-level cyber security course. Call or WhatsApp +91-75175-72000 to get a free counselling session and a study plan built around your goals.

