OSCP Exam Update: What Is the OSCP Certification and What Changed in 2024?

Stay informed about the OSCP exam updates effective November 1, 2024. Learn about the new OSCP+ certification, pricing, recertification paths, exam changes, and frequently asked questions. Find out how OSCP holders can upgrade, the promotional offer, and how to maintain OSCP+ in the evolving cybersecurity landscape.

Jan 24, 2025 - 19:03
Updated: 8 days ago
122.3k
OSCP Exam Update: What Is the OSCP Certification and What Changed in 2024?

Quick answer: OSCP is OffSec's hands-on penetration testing certification, taken after the PEN-200 course. Since 1 November 2024 the exam has an assumed-breach Active Directory set, no bonus points, and a passing candidate earns both OSCP, which does not expire, and OSCP+, which lapses after three years unless renewed.

Key takeaways

  • OSCP is a practical exam. You attack lab machines and write a report. There are no multiple-choice questions.
  • From 1 November 2024 the Active Directory section starts from a normal domain user account, the way many real internal tests begin.
  • Bonus points from lab exercises were removed, so the exam score stands on the exam machines alone.
  • Passing now awards OSCP (no expiry) and OSCP+ (valid for three years).
  • Exam fees, vouchers and renewal terms change. Always read them on OffSec's site before you pay.

What is the OSCP certification?

OSCP stands for OffSec Certified Professional. It is the certification attached to the PEN-200 course, "Penetration Testing with Kali Linux", from OffSec (formerly Offensive Security). You study the course, practise in the lab, then sit a proctored practical exam in which you must compromise machines in an isolated network and submit a professional report. OffSec's own page for the course is at offsec.com/courses/pen-200.

It matters for hiring because it proves you can do the work under time pressure. A recruiter cannot tell from a multiple-choice score whether you can chain a web bug into a shell. They can tell from OSCP.

What changed in the OSCP exam on 1 November 2024?

Three things changed: the Active Directory section, the removal of bonus points, and the new OSCP+ designation. OffSec made the changes so the exam looks more like a real engagement and matches its other certifications.

AreaBeforeFrom 1 November 2024
Active Directory setAttack the domain from outsideAssumed breach: you start with a standard domain user account and work towards full domain compromise
Bonus pointsEarned from lab exercises and challenge labsRemoved
Credential awardedOSCP, no expiryOSCP and OSCP+ on passing. OSCP does not expire. OSCP+ lasts three years

The exam is built from a set of independent machines plus the Active Directory set. As I understand the current format, the Active Directory set is worth 40 points, three standalone machines are worth 20 points each, and 70 points pass. Check the current exam guide on OffSec's site before you plan around those numbers.

What does "assumed breach" mean in the Active Directory section?

Assumed breach means the test begins after the attacker already has a foothold. You get one low-privilege domain account, as if a user had been phished or had reused a password. From there you enumerate the domain, move between machines, escalate privilege and reach the domain controller.

This is closer to many internal engagements, where the client's question is "if one laptop falls, how far can an attacker go?" It also means you need to understand Active Directory as a system: users, groups, service accounts, trusts, Kerberos, and how misconfiguration links them. Memorising one tool command is not enough.

OSCP vs OSCP+: what is the difference?

OSCP is the lasting credential. OSCP+ is the same exam result with an expiry, so an employer can see you have kept your skills current.

  • OSCP: stays valid for life and needs no renewal.
  • OSCP+: valid for three years from issue.

OffSec's renewal options for OSCP+ have included retaking the exam, earning another advanced OffSec certification such as OSEP, OSWA, OSED or OSEE before expiry, and a continuing professional education route. The details of each path, including the time window for retaking, are OffSec's to set. Read the current policy rather than relying on a blog post, including this one.

I already hold an older OSCP. What should I do?

You do not have to do anything to keep your OSCP. It stays valid. Retaking the exam is only needed if you want the OSCP+ designation. Any discounted retake price you see quoted from an old offer may have ended, so ask OffSec or an authorised partner for current pricing.

What about the new AWS module in PEN-200?

Check the current syllabus to see whether PEN-200 includes an AWS module and whether it is part of the OSCP+ exam, because course content and exam scope can move apart. Never assume a course module is examined.

How should you prepare for the current exam?

  1. Finish the PEN-200 material and exercises. Even without bonus points, the exercises build the habits the exam tests.
  2. Spend real time on Active Directory. Build a small home lab with a domain controller and two or three joined machines, or use a legal training lab. Practise enumeration from a low-privilege user until it is routine.
  3. Practise on legal targets only. Use the OffSec lab, your own virtual machines, or platforms built for training such as Hack The Box. Testing any system without written permission is an offence under India's Information Technology Act, 2000.
  4. Take notes as if for a report. Write the command, the output and what it proved, as you go. Reports are marked, and a good machine with a poor report can still cost you.
  5. Rehearse the clock. Do one full timed mock. Plan breaks, food and sleep. Decide beforehand when you will stop chasing one machine and move on.

Common mistakes

  • Counting on bonus points that no longer exist.
  • Treating Active Directory as one chapter. On the format described above it carries 40 of the 100 points.
  • Relying on automated exploitation tools without knowing what they do. Some are restricted in the exam, so read the rules.
  • Skipping the report practice until the last week.

Is OSCP worth it for a career in India?

For penetration testing and red-team roles it is widely recognised, and it signals practical skill. It is hard, and it will not replace experience. A sensible path for a beginner is networking and Linux basics, then a foundation certification, then OSCP. If you are earlier in your journey, start with our guide to passing PEN-200, compare it with CPENT in OSCP vs CPENT, and check the voucher guide for how to buy.

Next steps

If you want guided preparation with lab practice, see WebAsha's OSCP | PEN-200 course. Read the current exam guide on OffSec's site first, so you know exactly what you are signing up for.

Related reading

Frequently Asked Questions

OSCP is OffSec's practical penetration testing certification, taken after the PEN-200 course. You compromise machines in an isolated exam network within a time limit and submit a report. It is hands-on, with no multiple-choice questions.

Passing the current exam awards both. OSCP never expires. OSCP+ is valid for three years and must be renewed by retaking the exam, earning another qualifying OffSec certification, or an approved continuing education route. Check OffSec for current terms.

No. Bonus points were removed from 1 November 2024. Your result now depends on the exam machines and a valid report alone, so lab exercises help you learn but no longer add marks.

Assumed breach means you start with a standard domain user account, as if an attacker already had a foothold. You then enumerate the domain, move laterally and escalate until you control the domain, like many real internal tests.

No. An existing OSCP stays valid for life. You only need the new exam if you want the OSCP+ designation. The discounted retake offer that ran until 31 March 2025 has ended.

Yes on systems you own or have written permission to test, such as your own virtual machines or training labs. Testing anyone else's system without authorisation is an offence under India's Information Technology Act, 2000.

What's Your Reaction?

Like Like 0
Dislike Dislike 0
Love Love 0
Funny Funny 0
Wow Wow 0
Sad Sad 0
Angry Angry 0
Aayushi Sinha

With a passion for staying on the cutting edge of technology trends, I am dedicated to delivering content that not only informs but also inspires. Whether you need in-depth analysis pieces, informative guides, or thought-provoking opinion pieces, I craft content that resonates with tech enthusiasts and professionals alike.