Skip to main content
Offensive security benchmark
Offensive Security

OSCP

Offensive Security Certified Professional. A 24-hour practical exam that remains the industry's most respected entry-to-mid penetration testing credential.

DifficultyAdvanced
Study6–12 months
Exam£1,400+
Valid3 years
Format24-hour practical exam + 24-hour report
Practical weight95% practical / 5% theory
Compare
POST verdict
StrongMarket-level call. Not personal advice.

Still the practitioner benchmark for offensive security in UK consultancy and red-team hiring. Earned the hard way, respected for that reason.

Confidence: High Signal strength: High
UK pentest consultancies and red-team functions continue to treat OSCP as the working-class senior signal. CREST CRT carries regulatory weight, but OSCP carries practitioner weight, and the two reinforce rather than replace each other.
Pentest consultancy and red-team JDs name OSCP as required or strongly preferred. CHECK and CREST CRT sit alongside it for regulated UK work, but recruiter shortlist behaviour treats OSCP as the default filter.
Who this pays off for
  • Sysadmins and SOC analysts with active homelab time targeting a first pentest consultancy seat
  • Internal movers in security teams formalising existing offensive reps for a consultancy hire
  • AppSec and red-team candidates pairing OSCP with OSEP, OSWE or CRTO to widen senior shortlist coverage
Who walks away with nothing
  • Career changers with no Linux, networking or scripting fundamentals. The exam will end at hour eight rather than hour twenty-four.
  • Compliance-track or GRC-leaning candidates. CISSP, CISM or CRISC carry more weight on those shortlists.
  • Defenders looking to broaden into offensive thinking. BTL1, GCIH or PEH do more for the actual day job.
The named failure mode

Booking the exam attempt before the lab work is real. Candidates rely on writeups and methodology mnemonics, run out of attack surface on the second box, and never recover the time. The walkthrough-prepared-OSCP-attempt pattern is the most common reason capable candidates fail two attempts in a row before passing on the third.

Recruiter signal, not marketing

Shortlist position on UK pentest consultancy, red-team and offensive security engineer roles. It does not unlock CREST-regulated test lead positions without CRT, and it does not substitute for shipped engagement reports at senior consultant level.

Falsifiability
  • OffSec restructures the OSCP exam toward a multi-day engagement-report format and the practitioner signal sharpens further
  • CREST CRT becomes the dominant UK pentest hiring filter for non-regulated commercial work as well as regulated
  • Hands-on platforms like Hack The Box Pro Labs or TCM PNPT reach recruiter recognition parity with OSCP in mainstream UK consultancy hiring

This tells you whether the cert is worth pursuing. It does not tell you whether it is worth pursuing for you.

See if it's right for you

This cert in isolation tells you very little. Here is where it actually sits. The pathways that use it, and the roles it realistically supports.

  • Junior Penetration Tester
  • Red Team Operator
  • Application Security Engineer
  • Offensive Security Consultant
Practitioner take

OSCP is still the cert that opens doors at consultancies, and it's the only popular offensive cert where the exam genuinely punishes shortcut-takers. The catch nobody admits: the exam isn't the hard part. The six to nine months of HTB and PG lab boxes that precede it are. People who try to brute-force OSCP in eight weeks of paid lab time mostly fail, then quietly don't tell anyone. If you've got six months of consistent lab evidence already, it's worth every penny. If you don't, start with eJPT or PNPT and earn the right to attempt this one.

Authored opinion. Updated against current hiring conditions, not vendor marketing.

Recommended prior knowledge

  • Solid Linux command line
  • Networking + TCP/IP fundamentals
  • Comfort with Python or Bash scripting
  • Exposure to Active Directory

Common misconceptions

  • OSCP makes you a senior pentester, it's a competent-junior benchmark.
  • Try Harder solves everything, methodology and notes matter more.

What this cert does NOT guarantee

  • Six-figure salary day one
  • Red team operator roles
  • Bug bounty income

Practical skills that matter

  • Enumeration
  • Privilege escalation (Win/Linux)
  • Active Directory attacks
  • Web app exploitation
  • Buffer overflows (legacy)
  • Report writing

The next step

A cert is a signal. A Career Verdict tells you whether the signal is worth sending.

A Career Verdict tells you whether this cert earns its place on your specific route, what it won't fix, and what to sit before or after it.

A route shows what people usually do. A Career Verdict judges whether it's realistic for you.

Get a judgement on your situation£39, one-off. Built for your inputs, yours to keep.

Built on POST's practitioner-authored assessment framework, calibrated by James from twenty years across helpdesk, infrastructure and security. Framework is human-authored; the verdict applies it to your inputs.