OSCP — Offensive Security Certified Professional (PEN-200)
OSCP is OffSec’s hands-on penetration testing certification, taken after the PEN-200 course. You compromise a private network under exam conditions and then document it as a client-ready report. It is the credential that penetration testing teams themselves treat as a baseline, because there is no way to pass it without genuinely exploiting machines.
Last updated: 6 August 2026
The facts
| Vendor | OffSec |
|---|---|
| Level | Advanced |
| Format | Roughly 24 hours of hands-on exploitation (23 hours 45 minutes) against five isolated target machines including a linked Active Directory set worth 40 of the 100 points, followed by 24 hours to write a professional penetration test report. You need 70 points. Bonus points from lab submissions were withdrawn for exams taken on or after 1 November 2024. |
| Cost | High band, the most expensive item most Indian learners here will consider apart from SANS. OffSec sells course-plus-exam bundles and annual subscriptions rather than a cheap standalone voucher, and the realistic total for course access, lab time and one attempt runs well into six figures in rupees. Retakes cost extra. Check OffSec’s pricing page for current bundles and any regional pricing. |
| Validity / renewal | The classic OSCP does not expire. OSCP+, the variant awarded alongside it, is time-bound and lapses after three years unless renewed, which is OffSec’s way of signalling current skills. Confirm which designation your attempt awards under the current rules. |
| Prerequisites | No formal eligibility requirements — anyone can buy PEN-200. In practice you need solid Linux command line, TCP/IP and networking, at least basic Bash or Python scripting, and comfort with Windows and Active Directory concepts. People who skip that groundwork usually burn a very expensive attempt learning it. |
Vendors revise prices, formats and eligibility. Always confirm on the vendor's own site before you pay — including against this page.
Is it worth it?
OSCP proves you can enumerate, exploit, pivot and report under a hard deadline without help. In India it is the credential that moves you into real penetration testing and red team roles at consultancies, product security teams and the better MSSPs, and it is often the single line on a CV that gets a technical interview. It also proves report writing, which employers value more than candidates expect.
The downside
It is expensive, brutal on time, and the failure rate is high — many people pass on a second or third attempt, each with its own fee. It is not a fit for defensive, GRC, audit or SOC careers, where the money is better spent elsewhere. And it certifies exploitation skill, not client handling, scoping or business judgement.
Compared to
| Versus | Verdict |
|---|---|
| CEH | OSCP is harder, costlier and technically respected; CEH is cheaper, theory-based and better recognised by Indian HR filters and government tenders. They solve different problems and a lot of working pentesters end up holding both for exactly that reason. |
| PNPT | PNPT is significantly cheaper, gives five days instead of 24 hours, and adds a live debrief that mimics client reality. OSCP still wins on employer recognition, especially with recruiters and HR software. PNPT is arguably the better learning experience; OSCP is the better market signal. |
| OSEP | OSEP is the natural sequel, not an alternative — it assumes OSCP-level ability and focuses on evasion and lateral movement in defended networks. Do not attempt OSEP first. |
| CompTIA PenTest+ | PenTest+ is a multiple-choice and simulation exam covering the pentest process including scoping and compliance. It is easier and cheaper, and it renews Security+, but it does not demonstrate exploitation ability the way OSCP does. |
Where we fit
We provide foundation and preparation only: Linux, networking, scripting, web attacks, privilege escalation and report writing habits that make PEN-200 survivable instead of overwhelming. We are explicit that Amit Kumar holds CEH and CRTA, not OSCP — this is groundwork from someone who teaches the fundamentals, not OSCP mentoring from an OSCP holder. We are not an OffSec partner, we do not issue OSCP, and we do not sell PEN-200 or exam vouchers. You buy those from OffSec.
We issue no vendor certification and resell no exam vouchers. Buy from the vendor.
OSCP — FAQs
Is OSCP worth it for someone in India?
▾
How many machines are in the OSCP exam and what is the pass mark?
▾
Can I pass OSCP as a fresher with no job experience?
▾
Kya aap OSCP certificate dete ho?
▾
Not sure if OSCP is the right next step?
Free call. If the honest answer is a cheaper certification, or six more months of lab work before you pay anyone, that is what you will hear.
Call +91 75175 72000