Skip to main content
← Back to certifications
OffSecCybersecurityAdvancedVendor-neutralActive

Offensive Security Certified Professional

A hands-on offensive-security credential emphasizing practical penetration-testing methodology, enumeration, exploitation, privilege escalation, and clear technical reporting.

Last verified: 2026-09-01

Overview

Offensive Security Certified Professional (OSCP) is a hands-on penetration testing credential earned by passing OffSec’s OSCP+ exam. The assessment emphasizes vulnerability identification, exploitation, privilege escalation, Active Directory, and professional reporting in a controlled exam network. Candidates who pass receive the lifetime OSCP credential and the time-limited OSCP+ designation, which demonstrates more recent validation of the same practical skill set.

Recommended experience
OffSec does not require a prior certification to attempt the OSCP+ exam. Candidates are expected to have substantial hands-on preparation in penetration testing methodology, Linux and Windows administration, networking, Active Directory, enumeration, exploitation, privilege escalation, and technical reporting.
Estimated study time
200–350 hours
Target job roles
Penetration TesterOffensive Security ConsultantRed Team OperatorSecurity ConsultantVulnerability Researcher

Exam Details

OffSec Certified Professional Plus Exam

Exam code
OSCP+
Number of exams
1
Duration
1425 minutes
Question count
3 standalone machines plus 1 Active Directory set containing 3 machines
Delivery method
Online proctored hands-on exam in a private VPN
Price
$1,699 USD standalone exam; course and subscription bundles are also available

Skills and Domains

Identifying Vulnerabilities

12%

Identify weaknesses and attack paths within the controlled exam environment.

Exploiting Systems

11%

Gain initial access to vulnerable systems using appropriate exploitation techniques.

Escalating Privileges

18%

Escalate privileges on compromised systems and demonstrate administrative control.

Active Directory

26%

Operate through an assumed-compromise Active Directory scenario and progress toward domain compromise.

Documenting Findings

33%

Produce clear professional documentation showing the assessment process, evidence, and results.

Study Resources

OSCP+ Exam Guide

Official resource

Official Guide · Free

Official OffSec exam structure, scoring, timing, and reporting requirements.

View resource

PEN-200 / OSCP Certification

Official resource

Documentation · Free

Official OffSec course and certification overview.

View resource

OSCP+ Candidate Handbook

Official resource

Documentation · Free

Official OffSec candidate handbook covering registration, exam process, retakes, expiration, and recertification.

View resource

Renewal

Validity period
OSCP: lifetime; OSCP+: 3 years
Renewal method
The OSCP credential does not expire. To maintain OSCP+, keep required maintenance coverage active and complete an eligible renewal path such as the OffSec CPE program, a qualifying certification exam, or the recertification exam.
Notes
Passing the current exam awards both OSCP and OSCP+. OSCP remains valid indefinitely. OSCP+ expires after three years unless maintained under OffSec’s current renewal requirements.

Recommended Before

Verify with official provider.

Recommended After

Verify with official provider.

Alternatives

Verify with official provider.

Specializations

Verify with official provider.

Explore certification categories

Browse focused certification guides by technology and career domain.