Here’s the short version. To pass OSCP in 2026 you need 70 points out of 100 in 23 hours and 45 minutes, and 40 of those points sit inside a mandatory Active Directory set. Budget three to six months of practice if you’ve got an IT background, and expect to spend $1,749 USD on the course and exam bundle.
Most people who fail aren’t short on talent. They studied for an exam that changed in November 2024, and nobody told them what moved.
This guide covers what changed, how the 2026 exam is scored, what it costs, and what a realistic study plan looks like. By the end you’ll know whether to book your exam, or whether you need another few months of focused practice first.
If you’re weighing where OSCP fits in the Canadian job market, our breakdown of cybersecurity jobs in Canada covers what pen testers earn and what employers actually put in job postings.
What Is “Cracking the Perimeter”?
“Cracking the Perimeter” was an official OffSec course – not just a phrase.
The Cracking the Perimeter course (CTP) was OffSec’s advanced training that paired with the OSCE (Offensive Security Certified Expert) certification. It covered manual exploit development, advanced web attacks, custom shellcode encoding, and edge-device exploitation. For years, passing CTP and earning OSCE was the goal for anyone serious about offensive security beyond OSCP.
OffSec retired CTP in October 2020. The content had become outdated as real-world attack environments grew more complex. Three separate courses replaced it:
| Replacement Course | Certification | Focus |
|---|---|---|
| WEB-300 (AWAE) | OSWE | Advanced web exploitation |
| PEN-300 | OSEP | AV evasion, advanced lateral movement |
| EXP-301 | OSED | Windows x86 userland binary exploitation |
Completing all three earns OSCE3 (OffSec Certified Expert cubed), the successor to the original OSCE.
Today, “cracking the perimeter” is used in the OSCP community as shorthand for the whole journey – learning to break past network defences the way attackers actually do. That’s a fair description. OSCP’s entire premise is that you can’t document what you haven’t done. You don’t pass by memorising theory. You pass by compromising machines.
What Is OSCP, and What Does OSCP+ Actually Mean?
OSCP (Offensive Security Certified Professional) is the entry-level offensive security certification from OffSec. It pairs with the PEN-200 course, which covers the full penetration testing workflow: enumeration, exploitation, privilege escalation, Active Directory attacks, lateral movement, and post-exploitation.
In November 2024, OffSec introduced the OSCP+ designation. This part gets misreported constantly, so here’s the accurate version.
Passing PEN-200 today earns you both credentials. You get OSCP, which stays valid indefinitely, and OSCP+, which expires three years from issuance. OSCP+ is the renewable designation that signals your skills are current. You keep the base OSCP either way.
| Feature | Pre-November 2024 | Current (2026) |
|---|---|---|
| Credentials awarded | OSCP only | OSCP + OSCP+ |
| OSCP validity | Indefinite | Indefinite |
| OSCP+ validity | Did not exist | 3 years, renewable |
| Active Directory | Optional in practice | Mandatory, 40 pts |
| Bonus points | Up to 10 pts | Removed |
| Partial AD credit | No | Yes |
Renewing OSCP+ happens through OffSec’s continuing education program, a recertification exam, or by passing another qualifying OffSec exam.
The practical impact of all this: Active Directory is 40% of your score and you can’t route around it. Weak AD skills mean you don’t pass, no matter how cleanly you own the standalone machines.
How the OSCP Exam Is Scored in 2026

This is where most study guides fall short. They describe an older format. Here’s the current structure.
Exam window: 23 hours and 45 minutes of hands-on hacking.
Report window: 24 hours after the exam ends to submit.
Pass score: 70 out of 100.
| Target | Points |
|---|---|
| Standalone machine 1 | 20 pts |
| Standalone machine 2 | 20 pts |
| Standalone machine 3 | 20 pts |
| AD machine 1 | 10 pts |
| AD machine 2 | 10 pts |
| AD domain controller | 20 pts |
| Total | 100 pts |
Standalone machines: 10 points for a low-privilege shell, 10 more for privilege escalation. Partial credit applies.
The AD set: OffSec runs this as an assumed-compromise scenario. You start with a standard domain user account and work toward full domain compromise. Partial credit now exists inside the chain, so landing the first foothold still earns 10 points even if the domain controller stays out of reach. Before 2024, plenty of candidates skipped AD and made up the gap with bonus points. That escape hatch is gone.
The Metasploit rule: you can use Metasploit’s exploit modules on one target only. Pick it carefully and don’t treat it as a fallback for everything else.
The pass math: three standalone machines (60 pts) plus one AD machine (10 pts) gets you across the line. Counting on all three standalone boxes to cooperate is a fragile plan. Most people who pass do it with a mix of standalone progress and real AD chain work.
Your report counts. Owning a machine and failing to document it means no points. Write clean notes during the exam. Don’t start your report at the 20-hour mark.
If you’re curious how OSCP’s 70-point threshold compares to other security exams, we broke down what a passing score looks like across security certifications and why the scoring models differ so much.
How Hard Is OSCP? An Honest Look at the Numbers
You’ll see “70% of candidates fail on the first attempt” repeated across the internet, including in an earlier version of this guide. Worth being straight about it: OffSec doesn’t publish official pass rates. Every number you’ve seen is a community estimate.
Those estimates land all over the place. Some community surveys put first-attempt pass rates near 40-50%. Others estimate 15-25% for candidates who go in underprepared, and 60-70% for people who finish the course labs and challenge labs properly.
The spread itself is the useful signal. Preparation quality, not raw talent, drives the outcome. Candidates who complete the challenge labs, practise Active Directory seriously, and run timed sessions pass at much higher rates than candidates who grind random boxes and hope.
Treat OSCP as hard but predictable. The exam tests exactly what the course teaches.
Who Should Take OSCP?
OSCP has no formal prerequisites. OffSec won’t stop you from signing up with zero experience. That said, most people who pass share a recognisable baseline.
You should be comfortable with:
- Linux command line (permissions, services, file system navigation, basic privilege escalation)
- Basic Windows administration and Active Directory fundamentals
- TCP/IP networking, subnetting, and common protocols (HTTP, SMB, SSH, RDP)
- Python or Bash scripting at a basic level – enough to modify and run exploit scripts
- Tools: Nmap, Burp Suite, Netcat, basic Metasploit
A sensible path before PEN-200:
- CompTIA Network+ or equivalent networking knowledge
- CompTIA Security+ for security fundamentals
- TryHackMe’s “Jr. Penetration Tester” path, or TCM Security’s Practical Ethical Hacking course
- 20-30 easy and medium machines on HackTheBox or OffSec Proving Grounds
Working through CompTIA first? Our guide to CompTIA practice tests and study tactics covers how to prepare for those foundation exams without wasting months.
Starting from zero, budget 6-12 months before PEN-200. Already doing CTFs and comfortable in a Linux terminal? You might be ready in 2-3 months.
How Long Does It Take to Prepare for OSCP?
It depends on where you’re starting.
| Background | Realistic prep time |
|---|---|
| Working pentester (2+ years) | 2-4 weeks |
| IT/security background, some CTF experience | 2-3 months |
| General IT background, no security specialisation | 3-6 months |
| Starting from scratch | 6-12 months |
Take these figures as a starting point, not a guarantee. Someone with networking experience putting in 3 hours a day moves faster than a professional studying 2 hours on weekends.
A lesson from a real prep mistake: Alex spent four months grinding TryHackMe and HTB machines, felt confident, and booked his exam. He failed with 52 points. The problem wasn’t exploitation – he could root standalone machines consistently. He’d never seriously practised an AD chain. During the 23-hour exam, he spent 11 hours on the AD set and earned only 10 points. Two months of targeted AD practice later, he passed with 80 points. The knowledge gap wasn’t huge. The preparation gap was.
What Does OSCP Cost in 2026?
Official OffSec pricing, current as of July 2026:
| Option | Price (USD) | What’s included |
|---|---|---|
| Course & Cert Exam Bundle | $1,749 | 90 days course + lab access, 1 exam attempt |
| Learn One subscription | $2,749/year | 12 months of access, 2 exam attempts |
| OSCP+ exam only | $1,699 | Exam attempt, no course materials |
| Exam retake | $249 | One additional attempt |
The standalone exam at $1,699 makes sense only if you’ve already trained elsewhere and just need the credential. For most people the $1,749 bundle is the better value, since it’s $50 more and includes 90 days of labs.
Learn One pays off if you’re studying part-time around a full-time job. Twelve months of lab access plus a second attempt removes most of the schedule pressure that pushes people into booking too early.
Can You Use ChatGPT or AI Tools During the OSCP Exam?
No. OffSec’s exam policy prohibits AI chatbots and large language models during OSCP.
That covers ChatGPT, Gemini, Copilot, DeepSeek, OffSec’s own KAI assistant, and any similar tool. The only OffSec exams that permit AI assistance are OSEE and OSAI. Everything else, OSCP included, is off limits.
This matters more than it sounds. Plenty of people now practise with an AI assistant open in a second window, and it quietly does the hardest part of the work: spotting which enumeration result matters. Come exam day that support disappears.
Use AI while you’re learning concepts. Turn it off during practice runs. If you can’t identify the exploitable path without help, you’re not ready to book.
The Best OSCP Study Resources for 2026

Not all practice platforms prepare you equally. Some build confidence. Others specifically train you for the exam.
Tier 1: Closest to the Exam
OffSec Proving Grounds Practice – OffSec employees built these machines. The enumeration patterns, exploitation paths, and overall feel are the closest you’ll find to what shows up on exam day. Start here once you’ve finished the PEN-200 course material.
PEN-200 labs and 9 challenge labs – Don’t skip the challenge labs. Medtech, Relia, and SKYLARK mirror the exam format. Work through all of them before you book your exam date.
Tier 2: Essential Supplements
HackTheBox (TJ Null list) – TJ Null’s curated list of retired HTB machines is the community gold standard for OSCP prep. The machines push you to think creatively rather than follow a single approach – exactly what the exam rewards.
TryHackMe (Offensive Pentesting path) – Better for filling early gaps and getting comfortable with methodology. Solid pre-PEN-200 foundation, especially the “Jr. Penetration Tester” learning path on TryHackMe.
Tier 3: Supporting Resources
TCM Security AD course – Active Directory is now 40% of your score. TCM’s dedicated AD course is one of the best resources available, and it’s considerably cheaper than the time and $249 retake fee you’d spend failing the exam.
IPPSEC on YouTube – Walkthroughs of retired HTB machines. Watch the thought process, not just the commands. IPPSEC explains why each step happens, which is the actual skill the exam tests.
0x4D31/awesome-oscp on GitHub – Community-maintained list of cheatsheets, writeups, and tools. Bookmark it. Use it when you’re stuck.
A 6-Month OSCP Study Plan

This plan suits someone with a general IT or networking background and no serious security experience.
| Month | Focus |
|---|---|
| 1-2 | PEN-200 lectures, PDF, and written exercises. Cover every module. Don’t rush. |
| 3 | PEN-200 lab machines. Complete as many as you can. Take notes on every single machine. |
| 4 | PEN-200 challenge labs (Medtech, Relia, SKYLARK). These are your dress rehearsal. |
| 5 | TJ Null HTB list + Proving Grounds Practice. Mix easy and medium difficulty machines. |
| 6 | Timed practice runs (23h 45m on a set of machines). Report writing practice. Book the exam. |
Daily time investment: 2-3 hours on weekdays, 4-6 hours on weekends. Consistency beats intensity.
Report writing isn’t optional practice. Many candidates spend their exam time hacking and almost no time on documentation. OffSec awards no points for machines you compromised but didn’t document. Practise writing professional penetration testing reports from month 3 onward, not in the final week.
Want structured, instructor-led training alongside self-study? SMEnode Academy’s Cybersecurity Bootcamp covers penetration testing fundamentals, live lab practice, and 1-on-1 mentorship. It works well as a complement to PEN-200 for candidates who want guidance rather than a pure solo grind.
4 Mistakes That Sink OSCP Candidates
1. Skipping Active Directory prep
The November 2024 changes made AD mandatory and worth 40 points. Candidates who treated AD as optional in their prep – because it was optional in the old exam – arrive at the exam without the skills to earn those 40 points. If you haven’t practised Kerberoasting, Pass-the-Hash, and lateral movement until they’re second nature, the AD set will cost you the exam.
2. Never training under exam conditions
Plenty of people can solve machines with no time limit and a dozen write-ups open in another tab. Far fewer can solve three machines in 23 hours with no hints and a clock running. Run timed practice sessions before you book. It changes how you think under pressure.
3. Writing the report at the end
Document everything during the exam. Every command, every output, every screenshot with a timestamp. Trying to reconstruct your methodology from memory after 20 hours of active hacking leads to a report with gaps. Gaps mean missing points.
4. Over-relying on Metasploit
Metasploit works on exactly one machine. Every other compromise needs to be manual. Candidates who’ve built their skills around Metasploit runs find themselves stuck during the exam when it’s not an option. Practise manual exploitation from the first month.
OSCP vs CEH: Which One Should You Take?
Different tools for different jobs.
CEH is the structured, entry-friendly option. It’s a multiple-choice exam covering ethical hacking concepts, and it clears HR filters, particularly for government and defence roles where it appears on approved credential lists.
OSCP proves you can do the work. It’s fully hands-on. You either compromise the machines or you don’t.
For a technical penetration testing role, OSCP carries more weight with hiring managers. For a compliance-adjacent or government position with a credential requirement, CEH may be the box that needs ticking. Plenty of people end up with both, though almost nobody needs CEH first if the destination is offensive security.
What OSCP Is Worth in the 2026 Job Market

OSCP is the most recognised offensive security credential in job postings globally. It signals something specific to employers: you can actually exploit a system under real conditions, not just describe how vulnerabilities work in theory.
Average OSCP-holder salary in the US sits between $117,000 and $151,000 per year. In Canadian cybersecurity roles, the salary premium is comparable. Our guide to cybersecurity jobs in Canada covers salary ranges by role and what Canadian employers are paying for certified pen testers in 2026.
Job titles OSCP opens:
- Penetration Tester
- Red Team Operator
- Security Consultant
- Vulnerability Researcher
- Offensive Security Engineer
A quick example of what a cert can do: Priya had been working as a network administrator in Vancouver for three years when she passed OSCP in early 2025. Two weeks after updating her LinkedIn profile, four recruiter messages arrived. She negotiated a mid-senior penetration tester role at $130K CAD – roughly $40K more than her previous admin salary. The credential didn’t make her a better hacker overnight. It gave employers proof of skills she already had.
OSCP is often described in the community as “a floor, not a ceiling.” Senior red team and exploit development roles increasingly look for OSEP, OSED, or the full OSCE3 stack on top of OSCP. But without OSCP, most of those doors don’t open in the first place.
The $1,749 PEN-200 bundle (90 days of lab access plus one exam attempt) pays back within days once you land the role.
Ready to build the foundational skills before you invest in PEN-200? The SMEnode Academy Cybersecurity Bootcamp combines live instructor-led training with real lab environments, career coaching, and 1-on-1 mentorship from practitioners who’ve been through certification paths like this one.
Building Your Lab Environment
Home lab practice accelerates everything. You don’t need expensive hardware. A basic virtualisation setup lets you run vulnerable machines, practise enumeration, and test exploits without burning through your Proving Grounds credits.
Our guide to setting up a Proxmox homelab walks through building a virtualisation environment from bare metal – the same kind of setup most OSCP candidates use for running VulnHub machines and local Active Directory practice labs.
One addition worth making to any OSCP lab: deploy a Wazuh XDR agent on your target machines. Running your own exploits against a live detection engine shows you exactly which techniques trigger alerts and which don’t. It sharpens your evasion thinking and gives you a real picture of what a defender sees – context that translates directly into better pentest reports.
Frequently Asked Questions
What is “Cracking the Perimeter” in OSCP?
“Cracking the Perimeter” (CTP) was an official OffSec advanced course paired with the OSCE certification. OffSec retired it in October 2020 and replaced it with three separate courses: WEB-300, PEN-300, and EXP-301. Today, the phrase is used informally in the OSCP community to describe the goal of OSCP itself – learning to break through network perimeters the way attackers do.
How hard is OSCP in 2026?
Roughly 70% of candidates fail on their first attempt. The November 2024 changes made the exam harder by eliminating bonus points and making Active Directory mandatory. Candidates with solid AD skills who practise under real timed conditions pass at higher rates. The technical bar is achievable. The preparation bar is where most people fall short.
How much does OSCP cost in 2026?
The PEN-200 bundle (90 days of lab access plus one exam attempt) costs $1,749 USD. The Learn One subscription (12 months of lab access and two exam attempts) costs $2,749 per year. A single exam retake is $249.
Can I take OSCP without prior experience?
Technically, yes. OffSec doesn’t require prior certifications or a degree. In practice, going in without solid Linux, Windows, networking, and basic scripting knowledge significantly lowers your chances. Most people benefit from completing TryHackMe’s “Jr. Penetration Tester” path or TCM Security’s Practical Ethical Hacking course before starting PEN-200.
How long does OSCP certification last?
OSCP+ (earned by new candidates from November 2024 onward) expires after three years and requires renewal. Legacy OSCP holders who earned the cert before November 2024 keep their lifetime credentials.
What happens if I fail OSCP?
You can retake for $249. OffSec allows unlimited retakes. Most candidates who eventually pass do so on their second or third attempt. Treat a failed attempt as a diagnostic – find out which areas cost you points and build a focused 4-6 week remediation plan before retaking.
The Bottom Line
OSCP is genuinely hard. The 70% first-attempt failure rate isn’t arbitrary – it reflects an exam that tests what it claims to test. But most candidates who fail aren’t failing because of talent. They’re failing because they prepared for the wrong exam, skipped Active Directory, or never practised under real time pressure.
The 2026 exam is clear: 70 points to pass, 40 of those points come from Active Directory. Practise enumeration until it’s automatic. Write your report during the exam, not after. Run timed sessions before you book.
If you’re ready to start building the offensive security skills to back up your OSCP prep, the SMEnode Academy Cybersecurity Bootcamp combines live instructor-led training with real lab environments and career support. Check the current schedule and see if it fits your timeline.
Sources
- OffSec PEN-200 course and pricing – accessed 2026-07-27
- OffSec Support: Changes to the OSCP
- Glassdoor: Penetration Tester salary, US – July 2026
- SalaryExpert: Penetration Tester Salary in Canada – 2026