OSCP Course Guide 2026: OSCP+ Exam, Cost, Syllabus and Career Scope
Explore the OSCP course in 2026—syllabus, cost in India, hands-on lab training, exam structure, and global job prospects. Learn how to become a certified penetration tester.
Quick answer: The OSCP course is OffSec's PEN-200, Penetration Testing with Kali Linux. Passing its exam now earns OSCP+ alongside OSCP. The exam is a proctored, hands-on test made up of standalone machines and an Active Directory set, plus a written report. Check OffSec's current exam guide for the duration, points and pass mark, and its pricing page for current PEN-200 plans.
Key takeaways
- Since late 2024, passing earns OSCP and OSCP+; the original OSCP title does not expire but OSCP+ must be maintained.
- Under the current exam the Active Directory set is assumed breach, there are no bonus points and no dedicated buffer overflow machine.
- Check OffSec's official OSCP+ Exam Guide before booking, because rules change without much notice, and weigh the cost carefully.
OSCP is one of the best-known hands-on penetration testing certifications, and it changed in important ways in the last two years. This guide covers what the course teaches, how the exam works today, what it costs, who should take it, and how to prepare from India.
What is the OSCP course?
The OSCP course is PEN-200, Penetration Testing with Kali Linux, from OffSec (formerly Offensive Security). It teaches you to find and exploit weaknesses in networks, web applications and Active Directory environments, then document them in a professional report. You study online through the OffSec Learning Platform, with course material, videos and hands-on lab machines.
The certification you earn by passing the exam is the Offensive Security Certified Professional. Since late 2024, passing also gives you OSCP+, a version of the credential that has to be kept current. The original OSCP title does not expire.
What changed with OSCP+?
If you read older OSCP guides, three things are now different:
| Area | Older guides say | Current exam |
|---|---|---|
| Active Directory | Attack the AD set from scratch | Assumed breach: you are given a username and password for the AD set |
| Bonus points | Up to 10 points for lab and exercise work | No bonus points; your score comes only from the exam |
| Buffer overflow | A guaranteed buffer overflow machine | No dedicated buffer overflow machine; three standalone machines plus the AD set |
| Credential | OSCP only, lifetime | OSCP plus OSCP+, where OSCP+ has an expiry and must be maintained |
Always check the official OSCP+ Exam Guide before you book, because OffSec updates rules without much notice.
What does the OSCP syllabus cover?
PEN-200 follows the stages of a real penetration test. You can expect these areas:
| Area | What you learn |
|---|---|
| Information gathering | Passive research, port and service enumeration with tools such as Nmap, service-specific enumeration |
| Vulnerability scanning | Using scanners well and verifying results by hand |
| Web application attacks | Common flaws such as SQL injection, cross-site scripting, directory traversal, file inclusion, file upload and command injection |
| Client-side attacks and public exploits | Finding, reading and safely adapting existing exploit code |
| Password attacks | Weak and reused credentials, hash types and cracking in a lab |
| Privilege escalation | Windows and Linux misconfigurations, services, permissions and scheduled tasks |
| Tunnelling and pivoting | Port forwarding and moving between network segments |
| Active Directory | Enumeration, attacking authentication, lateral movement |
| Metasploit | Using the framework, and working without it |
| Reporting | Writing findings so a client can reproduce and fix them |
Everything in the course is practised against OffSec's own lab machines. Using the same techniques on systems you don't own or don't have written permission to test is illegal in India under the IT Act, 2000, and in most other countries.
How does the OSCP exam work?
The exam is a proctored, remote practical test. You connect to an exam network over VPN, attack the machines, and then write a report.
| Item | Detail |
|---|---|
| Hands-on time | 23 hours 45 minutes |
| Report deadline | A further 24 hours to submit your documentation |
| Standalone machines | 3 machines, 20 points each (10 for initial access, 10 for privilege escalation) |
| Active Directory set | 3 machines worth 40 points (10, 10 and 20), starting from supplied credentials |
| Pass mark | 70 out of 100 |
| Results | Pass or fail by email within ten business days of submitting the report |
There are several ways to reach 70. For example, the full AD set (40) plus initial access on all three standalone machines (30) passes. Two rules catch people out:
- Metasploit is limited. You may use Metasploit modules or Meterpreter against only one target machine of your choice.
- AI tools are banned. OffSec's guide states that LLMs and AI chatbots are strictly prohibited during the exam.
Points also depend on your report. If a step is missing from your documentation, the flag may not count, so take screenshots and notes as you go.
How much does the OSCP course cost?
OffSec prices its plans in US dollars. As listed on the OffSec pricing page in October 2026:
| Plan | Price | What you get |
|---|---|---|
| Course + Cert Bundle | US$1,749 one-time | 90 days of PEN-200 access and labs, one exam attempt |
| Learn One | US$2,749 per year | One year of PEN-200 (or another 200 or 300-level course), labs, two exam attempts |
The rupee cost depends on the exchange rate and any taxes applied at checkout, so check the final amount when you pay. OffSec also runs occasional discounts. Training from a local institute is a separate cost on top of, or instead of, extra lab time.
Which plan should you pick? If you already work in security and can study full time, 90 days can be enough. Most working professionals and freshers do better with a year of access and a second exam attempt, because the course and labs take longer than people expect.
Who should take the OSCP course?
OSCP suits people who want hands-on offensive security roles: aspiring penetration testers, security analysts moving into testing, system or network administrators who want to think like an attacker, and bug bounty hunters who want a structured method.
It is not a beginner certification. You will struggle if you are new to networking or the command line. Before PEN-200 you should be comfortable with:
- TCP/IP, common ports and protocols, and subnets
- Linux and Windows command lines, file permissions and services
- Reading and lightly editing Python, Bash and PowerShell scripts
- How common web applications work (HTTP, forms, cookies)
If these are shaky, start with a foundation course such as OffSec's 100-level CyberCore material or a structured ethical hacking course, then move to PEN-200.
OSCP vs CEH and other certifications
OSCP is fully practical and focuses on exploitation and reporting. CEH (EC-Council) covers a wider set of concepts with a knowledge exam, plus a separate practical exam. Many learners do CEH or a similar foundation first and OSCP later. The right order depends on your job target; our comparison of CEH vs OSCP goes through it in detail.
How should you prepare for OSCP?
- Build the fundamentals first. Networking, Linux, Windows and basic scripting.
- Work through the PEN-200 modules in order and complete the exercises; they build the habits the exam tests.
- Practise on the PEN-200 labs, including the challenge labs that resemble the exam, and keep structured notes for every machine.
- Drill Active Directory. It is 40 points, and the assumed-breach start means enumeration and lateral movement matter most.
- Practise without Metasploit, since you can only use it on one machine.
- Write practice reports. A clear template saves hours during the real report window.
- Do a timed mock day to test your stamina, breaks and note-taking before the real attempt.
Set up your own practice lab for extra repetition; our guide to building a penetration testing lab shows a safe setup. For exam-day tactics, read how to pass PEN-200 OSCP on the first attempt.
What jobs can you get after OSCP?
OSCP is commonly listed in job adverts for penetration tester, security consultant, vulnerability assessment and penetration testing (VAPT) analyst, and red team roles. It is also useful for application security and SOC staff who want to understand attacks from the other side.
The certification alone rarely gets you hired. Employers in India also look for practical evidence: write-ups of legal lab work, a portfolio of reports, CTF results or bug bounty findings on programmes that permit testing. Salaries vary widely with city, company and experience, so check current listings on job portals for your target role. For a step-by-step path, see the penetration tester career roadmap for India.
Next step
Check yourself against the prerequisite list above. If you are ready, choose a plan on OffSec's site and set a study schedule of at least a few months. If you want trainer support, a structured lab routine and doubt-clearing while you go through PEN-200, WebAsha runs an OSCP training programme online and in Pune.
Related reading
Frequently Asked Questions
What's Your Reaction?
Like
0
Dislike
0
Love
0
Funny
0
Wow
0
Sad
0
Angry
0