How to choose between Security+, CEH and OSCP

Wed Aug 26 2026

How to choose between Security+, CEH and OSCP

Maya is a fictional junior systems administrator with networking fundamentals and roughly $2,000 for training. She is considering penetration testing or a cleared government contractor role.

So the penetration-testing path points toward OSCP. The cleared role may require CEH.

There is no universal winner here. Security+, CEH, and OSCP fit different hiring systems. Ranking them on one difficulty ladder is lazy advice. As InfoSec Job Board puts it: “Ask an offensive security practitioner which certification to get and you will hear ‘OSCP’ before you finish the question. Search entry-level pentest postings on big job boards and you will keep seeing ‘CEH’ in the requirements anyway. Both observations are true.”

Most newcomers should start with Security+. Buy CEH when a contract, recruiter, or HR filter names it. Then pursue OSCP for offensive security once you’ve built enough skill for a sensible attempt.

Read the job posting first. Compare its requested signal with the skill the certification tests. Then choose a sequence your budget can survive.

In this article

At a glance, these certifications prove different things

CertificationBest forExam formatApproximate costPractical intensityExperience or eligibilityRenewal or expirationTypical hiring signal
Security+Entry-level cybersecurity and security operationsExam covering five security domainsCurrent price varies by purchase routeFoundational knowledgeNo prior experience requiredCurrent maintenance terms not supplied in the research notesFamiliar baseline for junior security roles
CEHRoles whose contract, recruiter, or HR filter names CEH125-question multiple-choice knowledge exam; CEH Practical is separateAbout $1,000–$1,300Primarily knowledge-based for the commonly referenced examOfficial training or an eligibility application backed by two years of security workEC-Council continuing education and annual feesCompliance, contractor, HR-filter, and some regional-market signal
OSCP / OSCP+Penetration testing and offensive securityApproximately 24-hour proctored exam with live machines and a professional reportAbout $1,699 exam-only, $1,749 reported course-plus-exam bundle, or $2,749 Learn One packageHigh hands-on intensityNo formal prerequisite; substantial preparation expectedOSCP remains valid indefinitely; OSCP+ expires after three yearsTechnical signal for offensive-security employers

The prices are approximate. Check the provider, region, tax, and included attempts before paying.

Security+ is the baseline for a broad start

Security+ is the most sensible first credential when your destination is still broad. CompTIA’s official certification page lists SY0-701 as the current exam and divides it across five domains:

  • General Security Concepts: 12%
  • Threats, Vulnerabilities, and Mitigations: 22%
  • Security Architecture: 18%
  • Security Operations: 28%
  • Security Program Management and Oversight: 20%

Security Operations carries the largest share at 28%. Program Management and Oversight accounts for another 20%. So the exam covers governance and risk alongside technical subjects.

CompTIA says no prior experience is required. Its CertMaster product estimates list 30–60 hours for Learn+Labs, 25–40 for Learn, 10–20 for Practice, and 15–25 for Labs. Those are training-product estimates, not a promise that you’ll pass in that time.

That breadth makes Security+ a plausible baseline for security operations, junior IT security, vulnerability management, and compliance-adjacent roles. If you’re new to the field, our guide to starting in cybersecurity covers the first steps. It can also help translate a systems-administration background into security language.

The boundary matters. Security+ tests foundational knowledge. It doesn’t demonstrate that you can enumerate a target, exploit it, escalate privileges or write a penetration-test report.

A possible SY0-701 refresh appears in PlanetCert’s 2026 certification map, but the discussion is speculative. CompTIA has announced no retirement date in the supplied material. Don’t let a rumor turn into a rushed purchase.

CEH earns its keep when a hiring system asks for it

Why do employers request CEH if it isn’t a hands-on pentesting credential? Certification hiring has two audiences: the system deciding whether your application advances and the person assessing your technical ability.

The commonly referenced CEH knowledge exam contains 125 multiple-choice questions, according to ProExamPrep. CEH Practical exists as a separate assessment. Most job postings that say “CEH” mean the knowledge certification, so read the wording carefully.

Eligibility has a catch: InfoSec Job Board reports two routes through EC-Council — official training, or an eligibility application backed by two years of security work. Confirm the current rule with EC-Council before buying a voucher.

CEH’s strongest value is procedural:

  • Contract and cleared work. Secondary reporting places CEH on DoD 8140/8570-related approved lists for particular work roles and contracts. Eligibility depends on the specific role and contract; CEH is not blanket approval for every government cybersecurity job.
  • HR requirements. CEH appears in template job descriptions often enough that recruiters and applicant-tracking systems recognize it.
  • Some regional markets. InfoSec Job Board reports stronger recruiter recognition in parts of South Asia and the Gulf. Check current local postings before spending the money.

CEH is a targeted checkbox. Calling it equivalent to OSCP-level ability misleads beginners. Its value is real when a named filter controls access to the interview; the multiple-choice pass itself supplies limited evidence about your ability to conduct an engagement.

OSCP tests the offensive workflow from foothold to report

As of August 26, 2026, the OSCP exam is a proctored, hands-on assessment involving live machines and a professional penetration-test report, as described by InfoSec Job Board. There is no multiple-choice section to carry you past a weak showing on the machines.

What does the work involve? It follows a rough sequence:

  1. Enumerate the environment. Identify exposed services, versions and attack paths. Note credentials and other useful clues.
  2. Gain access. Turn a vulnerability or misconfiguration into an initial foothold.
  3. Escalate privileges. Move from limited access toward administrator or root-level control.
  4. Work through Active Directory. The updated exam includes an assumed-compromise scenario: begin with a standard user account and pursue domain compromise.
  5. Write the report. Document evidence, attack paths and impact. Explain remediation in a form another professional can use.

OffSec’s support documentation confirms the assumed-compromise Active Directory scenario and the removal of bonus points worth up to 10, effective November 1, 2024. Those changes have been in force since November 1, 2024.

OSCP has no formal experience prerequisite. The practical bar is high. HackerDNA describes months of preparation as normal and points readers toward TJ Null’s community machine list; neither is an OffSec requirement.

The credential gives a pentest interviewer something practical to probe. You still need to explain your enumeration, exploitation, escalation, and reporting decisions. If those skills are still unfamiliar, OSCP is an expensive first cybersecurity purchase.

OSCP+ changes renewal, not the buying decision

Myth: OSCP expires after three years.
Fact: OSCP+ expires after three years; the underlying OSCP remains valid indefinitely.

Since November 1, 2024, passing the updated exam awards both OSCP and OSCP+. Keeping the “+” active requires maintenance coverage and one of three routes:

  1. Pass the recertification exam within six months before expiry.
  2. Earn another qualifying OffSec certification before expiry.
  3. Complete OffSec’s CPE program.

If OSCP+ lapses, you keep OSCP for life. The continuing decision concerns the extra designation and its maintenance burden.

For a first-time buyer, OSCP+ should rarely decide the purchase — readiness and target role do. The “+” matters later, when comparing maintenance value.

The $199 promotional price for existing OSCP holders ended March 31, 2025. OffSec’s support article lists $799 after that promotion; verify the current price before budgeting.

Cost only helps when it changes your decision

Maya has $2,000. A reported $1,699 standalone OSCP exam consumes 84.95% of that budget:

$1,699 ÷ $2,000 × 100 = 84.95%

That leaves $301. A failed attempt, taxes, or lab access could consume it quickly. The calculation doesn’t prove OSCP is poor value; it shows why buying before you’re ready is a gamble.

Credential or purchaseApproximate figureSource confidence
Security+Current figure not suppliedCheck CompTIA before purchase
CEHAbout $1,000–$1,300Secondary planning range; verify
OSCP standalone examAbout $1,699Newer secondary-market report; verify
OSCP course plus examAbout $1,749Secondary report; bundle contents vary
OSCP Learn OneAbout $2,749, including two attemptsSecondary report; verify current terms
OSCP retake$249OffSec support documentation
OSCP+ exam for existing holders$799 after promotionOffSec support documentation

CEH figures vary; an older, narrower estimate of $935–$1,199 appears elsewhere. Use the broader range for planning.

OSCP bundle descriptions also differ, so verify exactly what the $1,749 package includes. The figures above are approximate secondary-market reports; verify the current terms before paying.

A salary graphic and a single job-board snapshot can’t support a precise return-on-investment claim, so don’t spend a four-figure budget on either.

Hiring follows the target role and the evidence you bring

Maya’s contractor posting may name CEH because a contract or compliance framework expects it. A pentest team may prefer OSCP because it wants evidence of enumeration, escalation, and reporting. Both hiring behaviors can exist in the same market.

For this reader, Security+ is the broadest first signal. CEH’s value is contractual and procedural; OSCP’s value is technical.

“Offensive security hiring is proof-of-work hiring.” A portfolio with legal lab write-ups, CTF work, and methodology notes lets you discuss decisions instead of reciting a credential title.

A sensible sequence depends on your target postings; the hiring weight of each credential varies by employer and role, so read the postings and ask the hiring team.

For Maya, CEH may be the correct purchase for a cleared role that requires it. OSCP may be the better target for a pentest team. An attempt before she can solve comparable labs would burn most of her budget for little evidence.

PNPT and CPTS are cheaper practical checkpoints

OSCP isn’t the only route into hands-on offensive security.

PNPT covers a practical external-to-internal engagement with Active Directory work, a written report, and a live debrief, at a lower reported cost than OSCP.

CPTS is a fully practical certification with a much lower reported price than OSCP. Technical interviewers increasingly recognize it, while automated hiring systems have less awareness.

Treat either as a skill-building checkpoint rather than a guaranteed substitute. A credential named in a contract still has a different job to do.

For Maya, labs plus PNPT or CPTS would preserve money for study time and a later OSCP attempt. Before spending heavily, she should ask: does she want the daily work of penetration testing, or only the reputation attached to it?

Match the credential to the door

Career goalFirst choiceWhy
New to cybersecurity or broad entry-level securitySecurity+Generalist foundation and no experience requirement
Cleared or contractor role whose posting requires CEHCEHContract and HR-filter value
Penetration testing or red teamingOSCP, after preparationHands-on signal respected by offensive-security employers
Budget-constrained aspiring pentesterLabs plus PNPT or CPTS, then OSCPBuilds skill before the larger purchase
Employer funds one credentialThe credential explicitly required by the target roleEmployer demand beats generic prestige

This is Blackhawk’s recommendation, not a law of hiring. A small consultancy may favor a portfolio over a named certification. A government contract may have less flexibility because its requirements are contractual.

Choose a sequence your budget can survive

Use this decision tree:

  1. Look at three target postings. If all three require CEH, choose it. A named contractual filter beats generic prestige.
  2. Check the pentesting path. If the postings point toward pentesting but you can’t yet complete comparable legal labs, start with labs (PNPT or CPTS) before OSCP.
  3. Choose Security+ when the destination is broad. If the postings span security operations, junior security, vulnerability management, or compliance, Security+ is the sensible first signal.
  4. Build evidence alongside study. Keep legal lab notes and CTF write-ups. Add methodology documents or a practical assessment project.
  5. Use employer funding literally. If an employer pays for one certification, take the credential required by the target role or contract.

The usual broad-security sequence is:

Security+ first, followed by an entry-level role or labs and then a job-specific certification.

The offensive-security sequence is:

Build networking and Linux fundamentals. Then do labs and write-ups. Pursue PNPT, CPTS or equivalent practice before moving on to OSCP.

The cleared-contract sequence is:

Take Security+ when foundations are missing. Add CEH when a target role requires it, and build hands-on skills alongside both.

If you can’t name three target roles, or you have no legal lab environment in which to practice, postpone the purchase. Spend the budget on fundamentals and hands-on work.

Return to Maya’s two choices and the path is clear. Security+ first keeps broad and cleared options open. She can practice offensive skills in parallel, buy CEH for a specific contractor requirement, and pursue OSCP after her lab work shows that the attempt is defensible. If pentesting becomes the clear priority, PNPT or CPTS can precede OSCP.

Buy the signal your next job requires

For most readers like you, buy Security+ first. Choose CEH only for a named filter. Choose OSCP after hands-on work proves you’re ready; choose PNPT or CPTS first when the OSCP attempt would consume your budget.

OffSec’s support documentation makes the renewal distinction clear: OSCP+ can expire after three years while OSCP itself remains valid indefinitely.

Before you buy, fill in three blanks:

  • Three target postings.
  • One required credential.
  • One legal lab artifact you can show.

If you can’t fill those blanks, wait.