Zum Hauptinhalt springen

OSCP vs CEH vs PNPT: which certification is actually worth it?

· 8 Minuten Lesezeit
Haythem Rehouma
Formateur en cybersécurité offensive

Short answer: if you want to do the work, take a practical exam — PNPT or CPTS to start, OSCP when you can afford it and have the hours. CEH gets you past HR filters in government and large corporate settings but teaches little. No certification gets you hired alone; a practical one plus a real report does.

Certification advice in this field is usually written by people selling one. Here is the comparison as a hiring manager would make it, with the cases where each is genuinely the right buy.

The comparison

OSCPCEHPNPTCPTS
Format24-hour hands-on exam plus a reportMultiple choice (plus an optional practical)5-day hands-on engagement plus a report and a debrief10-day hands-on exam plus a report
CostRoughly 1,600 US dollars with course accessAround 1,200 US dollars, more with trainingAround 400 US dollarsAround 500 US dollars with training
Realistic preparation4 to 8 months4 to 8 weeks2 to 4 months3 to 6 months
Tests whatEnumeration, exploitation, persistence under time pressureVocabulary and recognitionA full internal engagement, Active Directory includedA full engagement, broad and deep
Known by recruitersUniversallyUniversally, especially in governmentGrowingGrowing, strong in technical circles
Teaches you the jobSubstantiallyBarelyYes, it is modelled on real consultingYes, and it is the broadest syllabus

OSCP: still the reference, for one specific reason

OSCP's value is not the syllabus, which is not the most modern. It is what passing it proves about you: that you can enumerate methodically under time pressure, keep notes while exhausted, and write a report at the end of a very long day. That is close enough to consulting work that hiring managers treat it as a proxy for stamina and method.

Take it if you are targeting consultancies, if job postings in your market name it directly, or if you need an external deadline to force structure on your study.

Do not take it first if money is tight or your foundations are shaky. It punishes gaps in networking and enumeration mercilessly, and failing costs a retake fee plus months of morale. Get comfortable with methodology and Active Directory first — the free penetration testing course and Nmap in depth cover exactly the ground people fail on.

CEH: what it is actually for

CEH is a knowledge exam. It will not teach you to compromise anything, and the technical community's opinion of it is not subtle.

That said, dismissing it entirely is bad advice for some people. It appears by name in government job requirements, in defence contracting, and in some large corporate and non-Western markets, where a candidate without it is filtered out before a human reads the CV. It also satisfies compliance frameworks that name it explicitly.

So the honest rule: buy CEH if a job you actually want lists it. Otherwise the same money buys PNPT and CPTS together, and those teach you something.

PNPT: the best first practical certification

Five days to compromise an internal network, then a professional report and a live debrief with an assessor. The debrief is the part nobody else does, and it is the closest thing in the certification market to the moment that decides whether a client renews the contract.

It is also cheap, it covers Active Directory and OSINT-driven external access, and it looks like a real engagement rather than an obstacle course. For most people entering the field, this is the highest return per dollar.

CPTS: the broadest syllabus

Ten days, a full engagement, and a preparation path that is genuinely large — arguably the most complete offensive syllabus available at this price. It is more demanding in total hours than PNPT and less time-pressured than OSCP.

If you have the months and want depth rather than a name, this is the strongest technical choice. Its recognition is still narrower than OSCP's outside technical teams, which matters only if your CV has to survive a non-technical filter.

Which order, depending on where you are

No security experience, limited budget. Foundations first — networking, Linux, Windows, Active Directory — then PNPT. Do not buy anything until you can enumerate a subnet and explain what you found.

Already in IT, targeting a consultancy. PNPT or CPTS, then OSCP when you can commit four to eight months. The first gives you the job-shaped skills, the second gives you the name.

Government, defence, or a market where CEH is named. CEH first, purely as a key, then a practical certification immediately after so you can actually do the work.

Already testing professionally. Skip the entry tier. Specialise: cloud, Active Directory depth, red team tradecraft, or exploit development. Specialisation pays more than another general certificate — that is the reasoning behind courses like Red Team Operations and AWS Penetration Testing.

What none of them do

No certification gets you hired on its own. Every one of these has thousands of holders, and hiring managers have interviewed the version of the candidate who passed the exam and could not explain what they did.

What differentiates, in order:

  1. A report a stranger can read. Executive summary, findings with business impact, reproduction steps, remediation. Almost nobody produces one before their first job. Produce one.
  2. A home lab you attacked and then defended. Detection knowledge makes an attacker better and interviews easier.
  3. Being able to explain a chain out loud — from initial access to domain admin — without notes and without jargon inflation.

The certificate opens the door. Those three decide what happens in the room.

A note on cost

Between them, the exams above cost between 400 and 1,600 US dollars, and the training packages can double that. Before spending, exhaust what is free: the complete pentest course, Nmap, Wireshark and Infrastructure Defense are free with an account here, and public practice platforms cover most of the hands-on hours. Buy the exam when the only thing missing is the credential, not the skill.

Frequently asked questions

Is the OSCP still worth it in 2026?
Yes, if you are targeting consulting work or a market where postings name it. Its value is proving you can enumerate methodically under time pressure and write a report afterwards. It is not the best first certification when budget is limited — PNPT or CPTS teach the same job for a third of the price.
Is CEH respected?
Not by technical practitioners, because it is a knowledge exam rather than a practical one. It remains useful where it is named explicitly — government, defence contracting, some large corporate and non-Western markets — where its absence filters out a CV before a human reads it. Buy it if a job you want lists it, not otherwise.
Which certification should a complete beginner take first?
None, for the first six to twelve months. Build networking, Linux, Windows and Active Directory foundations first, because every practical exam assumes them. When you are ready to certify, PNPT is the best value entry point at around 400 dollars. The free pentest course covers the methodology first.
How hard is the OSCP exam?
Hard for reasons of endurance more than difficulty: twenty-four hours of hands-on compromise followed by a professional report, with a pass mark that leaves little room for a stalled machine. Most people who fail do so on enumeration gaps and time management, not on exotic exploitation.
Can I get a pentest job without any certification?
Yes, and people do it every year with a home lab, documented practice on legal targets and one well-written report. Certifications mostly solve the filtering problem — getting a human to look at you — which matters more in large organisations than in small consultancies.
PNPT or CPTS?
PNPT if you want the fastest realistic engagement experience and a live debrief, which nothing else offers. CPTS if you want the broadest syllabus and have several months. Both are practical, both are cheap next to OSCP, and either one plus a portfolio makes you employable.

Where to go next

Before buying an exam, close the gaps it will test. The free pentest course covers the methodology and reporting, Windows Fundamentals and Active Directory Attacks cover the domain work every practical exam now includes, and the roadmap puts them in order.