OSCP Course Guide 2026: OSCP+ Exam, Cost, Syllabus and Career Scope

Explore the OSCP course in 2026—syllabus, cost in India, hands-on lab training, exam structure, and global job prospects. Learn how to become a certified penetration tester.

May 02, 2025 - 11:06
Updated: 8 days ago
130.2k
OSCP Course Guide 2026: OSCP+ Exam, Cost, Syllabus and Career Scope

Quick answer: The OSCP course is OffSec's PEN-200, Penetration Testing with Kali Linux. Passing its exam now earns OSCP+ alongside OSCP. The exam is a proctored, hands-on test made up of standalone machines and an Active Directory set, plus a written report. Check OffSec's current exam guide for the duration, points and pass mark, and its pricing page for current PEN-200 plans.

Key takeaways

  • Since late 2024, passing earns OSCP and OSCP+; the original OSCP title does not expire but OSCP+ must be maintained.
  • Under the current exam the Active Directory set is assumed breach, there are no bonus points and no dedicated buffer overflow machine.
  • Check OffSec's official OSCP+ Exam Guide before booking, because rules change without much notice, and weigh the cost carefully.

OSCP is one of the best-known hands-on penetration testing certifications, and it changed in important ways in the last two years. This guide covers what the course teaches, how the exam works today, what it costs, who should take it, and how to prepare from India.

What is the OSCP course?

The OSCP course is PEN-200, Penetration Testing with Kali Linux, from OffSec (formerly Offensive Security). It teaches you to find and exploit weaknesses in networks, web applications and Active Directory environments, then document them in a professional report. You study online through the OffSec Learning Platform, with course material, videos and hands-on lab machines.

The certification you earn by passing the exam is the Offensive Security Certified Professional. Since late 2024, passing also gives you OSCP+, a version of the credential that has to be kept current. The original OSCP title does not expire.

What changed with OSCP+?

If you read older OSCP guides, three things are now different:

AreaOlder guides sayCurrent exam
Active DirectoryAttack the AD set from scratchAssumed breach: you are given a username and password for the AD set
Bonus pointsUp to 10 points for lab and exercise workNo bonus points; your score comes only from the exam
Buffer overflowA guaranteed buffer overflow machineNo dedicated buffer overflow machine; three standalone machines plus the AD set
CredentialOSCP only, lifetimeOSCP plus OSCP+, where OSCP+ has an expiry and must be maintained

Always check the official OSCP+ Exam Guide before you book, because OffSec updates rules without much notice.

What does the OSCP syllabus cover?

PEN-200 follows the stages of a real penetration test. You can expect these areas:

AreaWhat you learn
Information gatheringPassive research, port and service enumeration with tools such as Nmap, service-specific enumeration
Vulnerability scanningUsing scanners well and verifying results by hand
Web application attacksCommon flaws such as SQL injection, cross-site scripting, directory traversal, file inclusion, file upload and command injection
Client-side attacks and public exploitsFinding, reading and safely adapting existing exploit code
Password attacksWeak and reused credentials, hash types and cracking in a lab
Privilege escalationWindows and Linux misconfigurations, services, permissions and scheduled tasks
Tunnelling and pivotingPort forwarding and moving between network segments
Active DirectoryEnumeration, attacking authentication, lateral movement
MetasploitUsing the framework, and working without it
ReportingWriting findings so a client can reproduce and fix them

Everything in the course is practised against OffSec's own lab machines. Using the same techniques on systems you don't own or don't have written permission to test is illegal in India under the IT Act, 2000, and in most other countries.

How does the OSCP exam work?

The exam is a proctored, remote practical test. You connect to an exam network over VPN, attack the machines, and then write a report.

ItemDetail
Hands-on time23 hours 45 minutes
Report deadlineA further 24 hours to submit your documentation
Standalone machines3 machines, 20 points each (10 for initial access, 10 for privilege escalation)
Active Directory set3 machines worth 40 points (10, 10 and 20), starting from supplied credentials
Pass mark70 out of 100
ResultsPass or fail by email within ten business days of submitting the report

There are several ways to reach 70. For example, the full AD set (40) plus initial access on all three standalone machines (30) passes. Two rules catch people out:

  • Metasploit is limited. You may use Metasploit modules or Meterpreter against only one target machine of your choice.
  • AI tools are banned. OffSec's guide states that LLMs and AI chatbots are strictly prohibited during the exam.

Points also depend on your report. If a step is missing from your documentation, the flag may not count, so take screenshots and notes as you go.

How much does the OSCP course cost?

OffSec prices its plans in US dollars. As listed on the OffSec pricing page in October 2026:

PlanPriceWhat you get
Course + Cert BundleUS$1,749 one-time90 days of PEN-200 access and labs, one exam attempt
Learn OneUS$2,749 per yearOne year of PEN-200 (or another 200 or 300-level course), labs, two exam attempts

The rupee cost depends on the exchange rate and any taxes applied at checkout, so check the final amount when you pay. OffSec also runs occasional discounts. Training from a local institute is a separate cost on top of, or instead of, extra lab time.

Which plan should you pick? If you already work in security and can study full time, 90 days can be enough. Most working professionals and freshers do better with a year of access and a second exam attempt, because the course and labs take longer than people expect.

Who should take the OSCP course?

OSCP suits people who want hands-on offensive security roles: aspiring penetration testers, security analysts moving into testing, system or network administrators who want to think like an attacker, and bug bounty hunters who want a structured method.

It is not a beginner certification. You will struggle if you are new to networking or the command line. Before PEN-200 you should be comfortable with:

  • TCP/IP, common ports and protocols, and subnets
  • Linux and Windows command lines, file permissions and services
  • Reading and lightly editing Python, Bash and PowerShell scripts
  • How common web applications work (HTTP, forms, cookies)

If these are shaky, start with a foundation course such as OffSec's 100-level CyberCore material or a structured ethical hacking course, then move to PEN-200.

OSCP vs CEH and other certifications

OSCP is fully practical and focuses on exploitation and reporting. CEH (EC-Council) covers a wider set of concepts with a knowledge exam, plus a separate practical exam. Many learners do CEH or a similar foundation first and OSCP later. The right order depends on your job target; our comparison of CEH vs OSCP goes through it in detail.

How should you prepare for OSCP?

  1. Build the fundamentals first. Networking, Linux, Windows and basic scripting.
  2. Work through the PEN-200 modules in order and complete the exercises; they build the habits the exam tests.
  3. Practise on the PEN-200 labs, including the challenge labs that resemble the exam, and keep structured notes for every machine.
  4. Drill Active Directory. It is 40 points, and the assumed-breach start means enumeration and lateral movement matter most.
  5. Practise without Metasploit, since you can only use it on one machine.
  6. Write practice reports. A clear template saves hours during the real report window.
  7. Do a timed mock day to test your stamina, breaks and note-taking before the real attempt.

Set up your own practice lab for extra repetition; our guide to building a penetration testing lab shows a safe setup. For exam-day tactics, read how to pass PEN-200 OSCP on the first attempt.

What jobs can you get after OSCP?

OSCP is commonly listed in job adverts for penetration tester, security consultant, vulnerability assessment and penetration testing (VAPT) analyst, and red team roles. It is also useful for application security and SOC staff who want to understand attacks from the other side.

The certification alone rarely gets you hired. Employers in India also look for practical evidence: write-ups of legal lab work, a portfolio of reports, CTF results or bug bounty findings on programmes that permit testing. Salaries vary widely with city, company and experience, so check current listings on job portals for your target role. For a step-by-step path, see the penetration tester career roadmap for India.

Next step

Check yourself against the prerequisite list above. If you are ready, choose a plan on OffSec's site and set a study schedule of at least a few months. If you want trainer support, a structured lab routine and doubt-clearing while you go through PEN-200, WebAsha runs an OSCP training programme online and in Pune.

Related reading

Frequently Asked Questions

OSCP (Offensive Security Certified Professional) is OffSec's hands-on penetration testing certification. You earn it by passing a proctored practical exam after the PEN-200 course, where you compromise machines in a lab network and submit a professional report of your findings.

Both are awarded for passing the same PEN-200 exam. OSCP is the long-standing title and does not expire. OSCP+ is the newer version with an expiry date that must be maintained, intended for employers and frameworks that require current, renewable credentials.

The exam has 100 points: three standalone machines worth 20 each and an Active Directory set worth 40. You need 70 to pass. Bonus points are no longer available, and points only count if your report documents how you obtained them.

You get 23 hours and 45 minutes of hands-on time in the exam network, followed by a further 24 hours to write and submit your report. Results arrive by email within ten business days of submitting the documentation.

OffSec prices in US dollars: US$1,749 for the Course + Cert Bundle with 90 days of access and one attempt, or US$2,749 a year for Learn One with two attempts. The final rupee amount depends on exchange rates and taxes at checkout.

Not for complete beginners. You should already know networking, Linux and Windows command lines and basic scripting. Newcomers usually do better after a foundation course in ethical hacking or OffSec's 100-level material, then move on to PEN-200.

Metasploit modules and Meterpreter are allowed against only one target machine of your choice. OffSec's exam guide states that LLMs and AI chatbots are strictly prohibited during the exam, so practise working without them.

There is no longer a dedicated buffer overflow machine. The current exam consists of three standalone machines and an Active Directory set. Understanding memory corruption still helps, but your preparation time is better spent on enumeration, web attacks, privilege escalation and AD.

It depends on your starting skills. People with a solid networking and Linux background often need a few months of steady practice; beginners usually need longer, including time for fundamentals. A year of lab access gives most working professionals enough room.

OSCP is commonly requested for penetration tester, VAPT analyst, security consultant and red team roles. Employers also expect practical evidence such as lab write-ups, reports or legal bug bounty findings, so build a portfolio alongside the certification.

What's Your Reaction?

Like Like 0
Dislike Dislike 0
Love Love 0
Funny Funny 0
Wow Wow 0
Sad Sad 0
Angry Angry 0
Vaishnavi

Vaishnavi is a skilled tech professional at the Ethical Hacking Training Institute in Pune, responsible for managing and optimizing the technical infrastructure that supports advanced cybersecurity education. With deep expertise in network security, backend operations, and system performance, she ensures that practical labs, online modules, and assessments run smoothly and securely. Her behind-the-scenes contributions play a vital role in delivering a seamless and secure learning experience for aspiring ethical hackers.