The CEH versus OSCP argument has been settled online for years, and the settlement goes like this: CEH is a multiple-choice paper certificate, OSCP is the real thing, and OSCP holders earn a lot more. Two of those three claims hold up. The third one we checked on 19 September 2026, and it does not.
We teach the VAPT & Ethical Hacking programme at our KPHB 5th Phase campus in Kukatpally, so this question reaches us roughly every second batch, usually from someone about to spend a meaningful amount of money on the wrong exam at the wrong time. So rather than repeat the standard verdict, we pulled pay data for both certifications from a single source on a single day, read the live Hyderabad hiring picture the same morning, and checked the current exam specifications against what EC-Council and OffSec publish themselves. Every number below carries its source and the date we read it.
Should You Choose CEH or OSCP in 2026?
Choose CEH when you need a widely recognised credential early in an Indian security career, and OSCP when you already have hands-on experience and need proof you can exploit a live network. On 19 September 2026, PayScale India put average pay for holders of the two certifications within three thousand rupees of each other.
That last sentence is the part most comparisons get wrong, so it is worth being precise about what it does and does not mean. It does not mean OSCP is not worth doing. It means the certificate on its own is not the salary lever it is sold as — the role you hold and the years behind you are. People who pass OSCP tend to earn well because of what they could already do before they sat it, not because a PDF landed in their inbox afterwards.
The practical decision, then, is rarely "which is better". It is "which one can I actually justify right now, and what do I need in place first". The rest of this article answers that with numbers rather than opinion.
What Is the Certified Ethical Hacker (CEH) Certification?
CEH is EC-Council's vendor-neutral ethical hacking certification, currently at version 13, tested by 125 multiple-choice questions over four hours. EC-Council's course runs 20 learning modules with 221 hands-on labs covering 550 attack techniques, and the passing score moves between 60 and 85 percent depending on which question bank you are served.
There is a second, separate exam most people skip in the comparison. The CEH Practical is six hours and 20 real-world challenges in a cyber range, and passing both the knowledge exam and the practical earns the CEH Master designation. If you are going to do CEH at all, this is the version worth doing — it is the only part of the CEH track that asks you to produce a result rather than recognise one.
CEH v13 was released on 23 September 2024 and is the version currently in market. It leans heavily on AI-assisted testing content, which is genuinely current but also the sort of thing that dates quickly. Recertification runs on a three-year cycle with 120 continuing-education credits, so CEH is not a one-time purchase in the way OSCP historically was.
What Is the OSCP Certification?
OSCP is OffSec's hands-on penetration testing certification, earned by hacking a live lab network for 23 hours and 45 minutes and then writing a professional report within a further 24 hours. You need 70 of 100 points: three standalone machines carry 60, and an Active Directory set carries 40.
The exam sits on top of the PEN-200 course. There is no multiple choice anywhere in it. You are dropped into a network, and either you get a shell and escalate to root or administrator, or you do not. The report is not a formality either — a machine you compromised but cannot document reproducibly does not score.
That structure is why OSCP carries the reputation it does. It is also why it is a poor first certification. Nothing about the format is forgiving to someone who has never had a real target in front of them.
How Do the CEH and OSCP Exams Actually Differ?
CEH asks you to recognise the right answer; OSCP asks you to produce a working one. A CEH candidate picks from four options, 125 times, in four hours. An OSCP candidate has to gain access and escalate privileges on six machines, then document every step well enough for someone else to reproduce it.
| CEH v13 (EC-Council) | OSCP (OffSec PEN-200) | |
|---|---|---|
| Exam format | 125 multiple-choice questions | Live lab network, 6 machines |
| Duration | 4 hours | 23 hours 45 minutes |
| Report required | No | Yes — 24-hour window after the lab |
| Pass mark | 60–85% (varies by question bank) | 70 of 100 points |
| Optional practical | CEH Practical — 20 challenges, 6 hours | Not applicable, the exam is the practical |
| Recertification | Every 3 years, 120 ECE credits | No continuing-education requirement |
| What it proves | Breadth of attack knowledge | You can compromise a network unaided |
CEH figures from EC-Council's official CEH page; OSCP figures from the OffSec OSCP Exam Guide. Both read 19 September 2026.
The scoring detail is where OSCP candidates most often misjudge their preparation, so it is worth putting on the page in full. The 100 points are not evenly spread, and the Active Directory set is close to decisive.
| Exam component | Points | How they break down |
|---|---|---|
| 3 standalone machines | 60 | 20 each — 10 for initial access, 10 for privilege escalation |
| Active Directory set (3 machines) | 40 | 10 for machine 1, 10 for machine 2, 20 for machine 3 |
| Needed to pass | 70 | Full AD set plus three initial accesses is one of the four routes |
Point breakdown taken from the OffSec OSCP Exam Guide, read 19 September 2026.
Read that table once more and the implication is hard to miss. Drop the Active Directory set entirely and you are left chasing 70 points out of a possible 60. It is arithmetically impossible. Every OSCP study plan that treats Active Directory as an optional extra is a failed attempt waiting to happen, and it is the single most common gap we see in people who arrive having already failed once.
The report is half the exam nobody practises
OSCP gives you a second 24-hour window purely for documentation, and machines you cannot evidence do not count. Writing a professional penetration testing report is a trainable skill, and it is the one most self-study candidates never rehearse before exam day. If you want the structure, our guide to what VAPT actually involves covers where reporting sits in a real engagement.
What Do CEH and OSCP Cost in 2026?
OffSec publishes OSCP pricing openly — 1,649 US dollars for the 90-day bundle with one exam attempt on 19 September 2026 — while EC-Council's CEH price reaches Indian buyers through resellers and varies widely. EC-Council charges a separate 100 US dollar eligibility application fee for self-study candidates.
The OffSec tiers as listed on the PEN-200 course page on 19 September 2026 were 1,649 dollars for the 90-day bundle with one exam attempt, 2,599 dollars a year for 365 days of lab access and two attempts, and 5,799 dollars a year for unlimited library access and unlimited attempts. Worth noting: several widely-shared comparison articles still quote 1,749 and 2,749 dollars, which were last year's numbers. Check the vendor page yourself before you budget.
CEH is harder to price honestly because EC-Council sells in India largely through Accredited Training Centres and voucher resellers, and the spread between them is wide enough that quoting a single figure would be misleading. Get the voucher price, the practical exam price and the training price in writing, separately, before you pay anyone. A bundle quoted as one number is where the surprises live.
Not sure which exam your current level actually justifies? Ask an instructor first.
Sit in on a live class online or at our KPHB, Kukatpally campus, bring your CV, and get a straight answer before you spend anything on a voucher. 60 minutes, no payment required.
Does CEH or OSCP Pay More in India?
On PayScale India, read on 19 September 2026, the two are effectively level: CEH holders averaged ₹8,76,000 a year and OSCP holders ₹8,79,000 — a gap of about three thousand rupees. These are market estimates, not guarantees, and they depend on experience, employer and interview performance.
| Certification (PayScale India) | Average annual pay | Reported range | Sample size | Last updated |
|---|---|---|---|---|
| Certified Ethical Hacker (CEH) | ₹8,76,000 | ₹3,00,000 – ₹30,00,000 | 566 profiles | 25 April 2026 |
| Offensive Security Certified Professional (OSCP) | ₹8,79,000 | ₹3,03,000 – ₹30,00,000 | 87 profiles | 5 March 2026 |
| Penetration Tester (job role, not certification) | ₹5,07,223 | ₹1,95,000 – ₹20,00,000 | 127 profiles | 11 June 2026 |
All three figures read from PayScale India on 19 September 2026. Self-reported data. Market estimates, not guarantees — actual pay depends on experience, employer, city and interview performance.
Three things in that table are worth reading slowly. First, the certification averages sit almost on top of each other, which is the opposite of what the ranking articles claim. Second, both are well above the average for the penetration tester job title itself, which tells you these averages are being pulled up by senior people who hold the certification alongside eight or ten years of work — the certificate is a marker of that seniority, not the cause of it. Third, look at the sample sizes: 566 CEH holders against 87 OSCP holders. That ratio is itself a finding about the Indian market.
We would rather publish the honest version of this than the flattering one, including where it is weak. PayScale data is self-reported, the OSCP sample of 87 is small enough that the average will move, and neither figure controls for years of experience. What it is good enough to conclude is the negative claim: there is no evidence in this data of the large OSCP pay premium that gets asserted without a source. If someone quotes you one, ask which dataset it came from and on what date.
Which Certification Do Indian Employers Actually Ask For?
Most Indian job descriptions name several certifications together as desirable rather than ranking one above another. A HCLTech penetration testing advert for Hyderabad on 19 September 2026 listed Certified Red Team Operator, Certified Ethical Hacker, Offensive Security Certified Professional and GIAC Penetration Tester in a single line as highly desirable.
That single line is worth more than most of the internet's opinion on this question. The employer is not saying OSCP beats CEH. It is saying: show us any credible evidence you have done offensive work, and we will look at your CV. The certification is a filter, and several different keys open the same door.
We read the first page of Naukri's Hyderabad penetration testing results the same morning — 22 listings including promoted ones — and the pattern held. Certification names appeared in the skill tags of individual adverts in both directions: CEH on listings from Jaggaer and Experian, OSCP on listings from Metmox and JAGGAER. No listing on that page asked for OSCP and excluded CEH, or the reverse.
CEH clears more HR filters
It is the more widely recognised name among Indian recruiters and HR screening tools, which matters most at the point where a human has not yet read your CV.
OSCP clears more technical rounds
A hiring manager who has done the exam knows exactly what it took. It buys you credibility in the interview, which is a later and different gate from the CV screen.
Neither replaces a portfolio
Two or three written engagement reports you can walk an interviewer through is the evidence that converts. Certifications get you into the room to show them.
Is CEH or OSCP Better for a Fresher?
Neither certification solves a fresher's real problem, which is that penetration testing is not a fresher market in India. Naukri listed 503 penetration testing vacancies in Hyderabad on 19 September 2026 and only 13 of them accepted zero years of experience — against 120 at three years.
That is a 9.2-fold widening between zero and three countable years, and it is the number we would want a 22-year-old to see before they spend on either exam. Across the first page of those 503 listings, the median minimum experience asked for was four years. Exactly one advert opened at zero.
| Hyderabad penetration testing vacancies, Naukri, 19 Sep 2026 | Count | Share of the 503 |
|---|---|---|
| All experience levels | 503 | 100% |
| Open at 0 years | 13 | 2.6% |
| Open at 3 years | 120 | 23.9% |
Counts read live from Naukri's Hyderabad penetration testing search with its experience filter applied, 19 September 2026. Job-board counts move daily and include some duplicate postings.
So the useful advice for a fresher is not CEH or OSCP. It is: get the first two years somewhere the door is wider, and do offensive work on the side while you are there. A SOC floor is the usual answer in Hyderabad, and the route is well documented — our piece on whether a fresher can become a SOC analyst has the vacancy maths for that side, and the IT support to SOC analyst transition covers the version where you already have a helpdesk job.
If you want a certification during those two years, CEH is the defensible choice, because it clears screens while you accumulate the experience that OSCP will later assume you have. Attempting OSCP as a fresher is not impossible. It is just an expensive way to discover a gap that a year of real work would have closed for free.
Which Certification Should You Do First?
For most people in India the honest order is skills first, CEH second and OSCP third, because the market pays for demonstrated experience rather than for the certificate itself. Answer the four questions below and the planner will show which step you are actually on, and what to do next.
CEH, OSCP, or neither yet?
Four questions. Nothing is stored and nothing is sent anywhere.
1. Where are you starting from?
2. What are you aiming at?
3. Given a deliberately vulnerable Linux machine, can you get root?
4. Hours a week you can genuinely give to labs?
Pick one option in each group to see which certification fits your current level.
A thinking aid, not a verdict. It weighs the four factors that decide an OSCP result in practice, against the live Hyderabad hiring data we read on 19 September 2026 — it cannot see your aptitude, your budget or how a particular employer screens.
What Do You Need to Know Before Attempting OSCP?
Three things decide an OSCP result: Linux and Windows privilege escalation, Active Directory attack chains, and the ability to write a reproducible report under time pressure. The Active Directory set alone carries 40 of the 100 exam points, so a candidate weak there is fighting for a pass from the start.
Web application skills matter too, but they are rarely what breaks people. What breaks people is the middle of the chain: you have a shell on a low-privilege user, the obvious escalation paths are patched, and you have six hours left. That is a pattern-recognition skill built by repetition on many machines, not by reading about it.
Honest pre-OSCP checklist
If you cannot tick four of those six, an OSCP attempt is premature rather than ambitious. The exam does not teach you those things; it checks whether you already have them. Our overview of how to become a penetration tester sets out the longer route, and the different types of penetration testing explains which specialism each of these skills belongs to.
How Does the AimNxt VAPT Curriculum Map to Each Exam?
The AimNxt VAPT & Ethical Hacking programme runs 15 modules across four months, and 11 of them feed both certifications while four feed OSCP far more than CEH. The four are Linux for Hackers, Windows Internals & Active Directory, Active Directory Attacks, and Report Writing & Professional Skills.
Here is the actual module order, so you can see for yourself where each exam's demands sit rather than take our word for it.
| # | AimNxt VAPT & Ethical Hacking module | Weighted toward |
|---|---|---|
| 01 | Networking Fundamentals & Lab Setup | Both |
| 02 | Linux for Hackers | OSCP |
| 03 | Windows Internals & Active Directory | OSCP |
| 04 | Web Technologies & OWASP Top 10 | Both |
| 05 | Information Gathering & Reconnaissance | Both |
| 06 | Vulnerability Assessment & Scanning | Both |
| 07 | Web Security – Injection Attacks | Both |
| 08 | Web Security – Authentication & Authorization | Both |
| 09 | Client-Side Attacks & Logic Flaws | Both |
| 10 | Network Exploitation & Post-Exploitation | Both |
| 11 | Active Directory Attacks | OSCP |
| 12 | Wireless Security & IoT | Both |
| 13 | Mobile Application Security | Both |
| 14 | Cloud Security & API Testing | Both |
| 15 | Report Writing & Professional Skills | OSCP |
Module names and order taken verbatim from the AimNxt VAPT & Ethical Hacking course curriculum. Tools named in the programme include Kali Linux, Nmap, Wireshark, Burp Suite, Metasploit, Nessus, OpenVAS, Hashcat, John The Ripper, SQLMap, Gobuster and Amass. Programme duration is four months, and it closes with a capstone penetration testing engagement and report.
Module 11, Active Directory Attacks, covers Active Directory enumeration, Kerberoasting, NTLM relay attacks, domain privilege escalation and domain persistence. That is, almost item for item, the 40-point half of the OSCP exam. Module 15 covers professional penetration testing reports, vulnerability documentation, executive summary writing and remediation recommendations — the part of the exam that runs after the lab closes.
Modules 04 through 09 are where the CEH knowledge exam lives. Breadth across web technologies, reconnaissance, scanning, injection, authentication attacks and client-side flaws is exactly what 125 multiple-choice questions sample from. The overlap is genuine, which is the reason we teach one programme rather than two: the divergence is in depth and in the last mile, not in the subject list.
What Does This Choice Look Like in Hyderabad?
Hyderabad has real penetration testing demand — 503 open roles on Naukri on 19 September 2026 — but it is a mid-career market, with a median minimum of four years experience across the first page of listings. That makes the entry route, not the certificate, the thing to plan first.
The employers are recognisable: Accenture, HCLTech, NTT DATA Business Solutions, Experian, Controlcase, Astra Security and a set of consultancies hiring for client engagements. Most of that work sits in the HITEC City, Madhapur and Gachibowli corridor. Several adverts on the day we looked were for consulting delivery rather than in-house security, which matters because consulting work is report-heavy — the OSCP-style documentation skill has a direct commercial value here, not just an exam value.
For the study half, our KPHB 5th Phase campus in Kukatpally runs weekday, weekend and fast-track batches for the VAPT & Ethical Hacking programme, in classroom, online and hybrid formats. The weekend batch exists mostly because the people who benefit most from this programme are already working somewhere in IT and cannot commit to weekday evenings for four months.
What AimNxt Will and Will Not Promise About Either Exam
AimNxt prepares you for the CEH and OSCP exams but does not award either — EC-Council and OffSec own their certifications, and AimNxt is an independent training provider issuing its own certificate of completion. The AimNxt Job Interview Guarantee program guarantees interview opportunities, not a job offer or a salary.
We are saying that plainly because this corner of the training market is not always plain about it. Nobody can sell you a CEH or an OSCP; those are EC-Council's and OffSec's exams, booked and paid for with them. What a training provider can genuinely do is get you to the point where sitting one is a reasonable use of your money, and then help you convert it into interviews.
On outcomes: the Job Interview Guarantee program commits us to interview opportunities through our hiring-partner network until you are placement-ready. It does not commit anyone to hiring you, and it says nothing about salary — what happens inside an interview depends on your skills and your performance on the day. And we do not publish fees in blog posts. Come to a Free Live Demo Session, sit in on a live class, and ask the instructor directly whether your current level justifies an exam attempt this year. If the honest answer is no, you will get that answer.
The full module list, tools and batch formats are on the Ethical Hacking & VAPT training page. If you are earlier in the journey than this article assumes, the cyber security course is usually the better starting point.
Frequently Asked Questions
Before You Buy a Voucher, Sit In on a Live Class
Fifteen sequenced modules across four months, from networking fundamentals and Linux to Active Directory attacks and professional report writing, finishing with a full capstone engagement.
Ethical Hacking & VAPT
or
Cyber Security Course
Classroom | Online | Hybrid · KPHB, Kukatpally · Kali Linux, Nmap, Burp Suite, Metasploit · Capstone report
60 minutes with the instructor, online or at our KPHB, Kukatpally campus. No payment required. Bring your CV.
