OffSec · Offensive Security

Offensive Security Certified Professional

OSCP / OSCP+ · PEN-200

The OSCP is OffSec's flagship hands-on penetration testing certification and one of the most respected — and most feared — credentials in offensive security. This is not a multiple-choice test: you spend nearly 24 hours actually breaking into live machines, then a further 24 hours writing a professional report. A pass opens doors to red-team, pentest, and security-engineering roles; a fail costs a four-figure retake and weeks of lost momentum. This page breaks down exactly how the exam is built, scored, and proctored — and how to get it done right.

23h 45m + report
Hands-on / practical
70 / 100 to pass
Online, OffSec-proctored

Pay Only After You Pass

No upfront fee — you settle only after your verified passing result. We advertise guaranteed results — 100% pass guaranteed or money back.

Exam Spec Sheet

Provider OffSec (Offensive Security)
Course PEN-200 (PWK)
Format Hands-on lab + written report
Exam window 23h 45m hacking + 24h report
Scoring 70 of 100 points to pass
Fee ~$1,749 bundle / ~$1,699 exam-only
Proctoring OffSec live proctor over VPN
Validity OSCP+ 3 yrs · legacy OSCP lifetime
Language English
See OSCP Help Options

EXAM FORMAT

How the OSCP exam is built — at a glance

3 + 3

Six target machines

Three independent standalone hosts plus a three-machine Active Directory set. You enumerate, exploit, and escalate to capture a proof file from each.

23h 45m

Hacking window

A near-24-hour, continuously proctored block to compromise as many targets as possible and collect the local.txt and proof.txt files that prove access.

+24h

Report window

After the lab closes you get 24 hours to submit a professional penetration-test report. A perfect compromise with a missing or sloppy report still fails.

How scoring works

The exam is scored out of 100 points and you need 70 to pass. Each of the three standalone machines is worth 20 points (60 total), and the Active Directory set is worth 40 points as a chain. Under the current OSCP+ format there are no course-based bonus points — every point must be earned on the exam itself.

Proof files & documentation

For every machine you compromise you must capture screenshots, commands, and the proof file from the target, then write them up clearly enough for a reviewer to reproduce. The report is graded for completeness and reproducibility — missing steps or unverifiable claims can cost you the points you earned in the lab.

WHAT'S TESTED

The point split across the exam targets — bars show each target's share of the 100 points

1

Standalone Machines (×3)

60 pts

Three independent hosts, 20 points each. Each requires service enumeration, finding and exploiting a foothold vulnerability, then a privilege-escalation path to root or SYSTEM. Linux and Windows targets both appear.

2

Active Directory Set

40 pts

A three-machine domain, scored as a chain. You start from a provided low-privilege credential (an "assumed breach"), then pivot host-to-host — 10 points for the first machine, 10 for the second, and 20 for compromising the Domain Controller.

The skills under test span the full kill chain: enumeration, web and service exploitation, buffer-overflow-style memory corruption, password attacks, lateral movement, and privilege escalation on both Linux and Windows. Because the AD set is worth 40 points as a unit, many candidates who clear the standalone boxes still fall short — domain compromise is where most attempts are won or lost.

DELIVERY & PROCTORING

How you sit the exam — and what OffSec watches on test day

Online, on your own machine

There is no test center. You schedule a slot, then connect over a VPN from your own computer into OffSec's exam environment, where the target machines live. You use your own Kali setup and tools, which makes the exam realistic — but also means your environment, connection, and stamina are entirely on you.

Live OffSec proctoring

A live OffSec proctor monitors you continuously for the full 23h45m through your webcam and a shared screen. Before the exam unlocks you complete an identity check, a webcam room scan, and a system check. The proctor can see everything you do, so the exam tests genuine skill under sustained observation.

ID & identity check

A valid, unexpired government photo ID whose name matches your OffSec account. The proctor verifies it on camera before connecting you to the VPN.

Environment & screen share

A webcam room scan, a clear workspace, and continuous screen sharing. Only approved tools are allowed — no automated exploitation frameworks beyond the documented limits.

Breaks & endurance

You may take breaks, but you must notify the proctor and stay within view of the camera when you return. Managing fatigue across a near-24-hour window is part of the challenge.

WHO SHOULD TAKE THIS

The OSCP is built for working and aspiring offensive-security pros

  • Aspiring and junior penetration testers proving hands-on skill
  • Red teamers and ethical hackers building a recognized credential
  • SOC analysts and defenders moving toward offensive roles
  • Sysadmins and developers pivoting into security engineering
  • Candidates meeting employer or contract OSCP requirements

PREREQUISITES & DIFFICULTY

No formal gatekeeping — but one of the hardest exams in IT

  • No formal certification prerequisite — open to anyone who enrolls
  • Solid Linux command-line, networking (TCP/IP), and Bash/Python comfort
  • Familiarity with web app attacks, AD basics, and privilege escalation
  • Stamina for a near-24-hour exam and clear technical writing

Difficulty: The OSCP is widely considered one of the toughest entry-to-mid-level security certifications. The "try harder" philosophy means there are no hints and no partial credit for getting close — you either capture the proof file or you don't. Most candidates invest several months of lab practice, and first-attempt fails are common. That sustained pressure is exactly what our help is designed to manage.

HOW EXAM ASSIST HELPS YOU PASS THE OSCP

The OSCP is a brutal, near-24-hour practical with a four-figure retake cost on the line. Exam Assist pairs you with a vetted offensive-security specialist and works on a pay-after-you-pass model — so the risk sits with us, not you. No upfront fee, guaranteed results: just an honest feasibility answer and a verified result before you settle.

1

Share your exam details

Tell us your scheduled exam date, your OffSec plan (PEN-200 bundle or standalone), and your current skill level. Takes a couple of minutes over WhatsApp, Telegram, or Discord.

2

Get an honest feasibility answer

We review your timeline and the exam's proctoring constraints and tell you plainly whether it's realistic — before any money is discussed. If it isn't a fit, we say so.

3

The sitting is handled

Exam Assist handles the sitting end to end. You're matched with an OSCP specialist who maps the work around the standalone boxes, the Active Directory chain, and the report deliverable — discreetly and confidentially.

4

Settle after the verified result

You only pay once your passing result is confirmed by OffSec. No verified result, nothing owed.

Ready to lock in your OSCP?

Tell us your exam date and target, and get an honest, no-obligation feasibility answer first.

Book OSCP Help

FREQUENTLY ASKED

Straight answers about the OSCP exam

What score do you need to pass the OSCP exam? +
You need 70 of 100 points to pass. Points come from three standalone machines worth 20 points each (60 total) plus an Active Directory set worth 40 points. Under the current OSCP+ format there are no longer any course-based bonus points, so your score is determined entirely by the targets you compromise during the exam.
How long is the OSCP exam? +
The hands-on portion runs for 23 hours and 45 minutes of continuous, proctored hacking. After the exam window closes you have a further 24 hours to write and submit a professional penetration test report documenting every step and proof file. Both parts must be completed for a passing result.
Is the OSCP exam proctored? +
Yes. The OSCP is a remotely proctored exam delivered over a VPN connection into OffSec's lab. A live OffSec proctor monitors you continuously through your webcam and shared screen for the full 23h45m, verifies your government photo ID beforehand, and checks your environment. You take it on your own machine, but every action is observed.
What is the difference between OSCP and OSCP+? +
OSCP+ is the current credential, introduced in November 2024. The exam itself is the same hands-on PEN-200 challenge, but OSCP+ removes bonus points and is valid for three years, after which you renew through a recertification exam, another qualifying OffSec certification, or OffSec's continuing-education program. An OSCP earned before November 2024 remains valid for life.
How much does the OSCP cost? +
The PEN-200 course bundle is about $1,749 and includes 90 days of lab access plus one exam attempt. A standalone OSCP exam (no course) is about $1,699 and includes two attempts within 90 days. Additional retake attempts cost roughly $249 each. Subscription options like Learn One and Learn Unlimited bundle multiple attempts. Prices are set by OffSec and can change.
Do I pay Exam Assist before or after I see my OSCP result? +
You settle only after your verified passing result is confirmed. There is no upfront fee — you share your exam details, receive an honest feasibility answer, and decide before any money changes hands. We advertise a guaranteed pass with money back if you do not pass; we offer a transparent, results-first arrangement.

KEEP EXPLORING

Book your help and compare sibling security exams

YOUR OSCP, HANDLED

Get expert OSCP help with no upfront fee — you settle only after your verified passing result. Honest feasibility answer first, results-first arrangement always.

OR CHAT WITH US