If you are searching for an OSCP study plan for 2026, you already know the hard part is not learning the tools. It is surviving 23 hours and 45 minutes at a keyboard, under proctoring, needing 70 points with no safety net. The OSCP has always been a stamina exam as much as a skills exam, and the current format has quietly made it harsher than the one most online write-ups describe.
This is a 12-week plan built around the exam as it actually runs today. It assumes you can commit roughly 12 to 15 hours a week, which is realistic for someone working full time. If you have less time than that, stretch the same phases across 16 to 18 weeks rather than compressing them. Rushing the Active Directory phase is the single most common reason people book the exam and then fail it.
What the OSCP Exam Actually Looks Like in 2026
Before you plan anything, you need the format exactly right, because a surprising number of study guides still describe the pre-2024 exam.
The practical runs for 23 hours and 45 minutes. After the machine time ends, you get a further 24 hours to write and submit your penetration testing report. You are proctored throughout via webcam and screen share.
The point structure breaks down like this:
| Component | Machines | Points available | How points are awarded |
|---|---|---|---|
| Standalone targets | 3 | 60 (20 each) | 10 for initial low-privilege access, 10 for privilege escalation |
| Active Directory set | 3 | 40 | 10 for the first host, 10 for the second, 20 for the Domain Controller |
| Total | 6 | 100 | 70 required to pass |
Two facts change how you should study, and both are commonly missed.
Bonus points are gone. Since 1 November 2024, OffSec no longer awards the 10 bonus points that used to come from completing course exercises and lab machines. You must clear 70 points live, on the day. Anyone who used to plan on scraping 60 plus a 10-point cushion is now planning to fail.
The AD set is effectively mandatory. With 40 points in the domain chain and only 60 across the standalone boxes, clearing all three standalone machines still leaves you 10 points short of a pass. In practice, almost every passing route goes through the AD set. If you fully own the domain and take one standalone machine to root, you are at 60, and a single low-privilege foothold on a second standalone puts you over the line.
Exam Tip: You cannot pass the OSCP by rooting every standalone machine and skipping Active Directory. Three standalone boxes at full marks is 60 points, and the pass mark is 70. Treat the AD set as the exam, not the bonus round.
OSCP vs OSCP+
When you pass the current exam you are awarded both credentials. OSCP is a lifetime, non-expiring certification. OSCP+ carries the same exam but expires after three years, and you renew it with CPE credits, a recertification exam, or a higher OffSec certification. There is no separate exam to sit and no extra fee. We have covered the differences in detail in OSCP vs OSCP+: What Changed in 2026.
What it costs
The Course and Cert Bundle sits at around $1,749 and includes 90 days of PEN-200 lab access plus one exam attempt. Learn One runs at roughly $2,749 for a full year of lab access, the wider OffSec catalogue, and two exam attempts. Standalone retakes are about $249 each.
If you are on the 90-day bundle, the 12-week plan below maps almost exactly onto your lab window. Start the clock on the plan and the lab subscription on the same day.
Before Week One: The Prerequisites That Save You Money
The OSCP is not an entry-level certification, and the fastest way to waste $1,749 is to start PEN-200 without the groundwork. Be honest about the following before you buy.
- Linux command line. You should be comfortable navigating, editing files in the terminal, managing permissions, and reading logs without looking things up.
- Networking fundamentals. Subnetting, routing, common ports and what services run on them. If this is shaky, CompTIA Network+ is the cheapest fix.
- Bash and Python scripting. You do not need to be a developer. You do need to modify a public exploit, fix a hard-coded IP and port, and write a loop that tries fifty things for you.
- Web application basics. HTTP requests and responses, how a proxy works, what SQL injection and file upload flaws look like in the wild.
If you have already worked through the HTB CPTS or the PNPT, you are in a strong position. Both build the enumeration discipline OSCP rewards.
The 12-Week OSCP Study Plan
The plan runs in four phases: foundations, offensive fundamentals, Active Directory, and exam simulation. Each phase ends with a checkpoint you must actually pass before moving on.
Weeks 1 to 3: Foundations and Enumeration Discipline
PEN-200 ships as 23 learning modules. In the first three weeks you are not trying to finish them. You are building the habit that carries the whole exam: methodical enumeration.
- Work through the information gathering, vulnerability scanning and introductory web attack modules.
- Build your note-taking system now, not in week ten. Obsidian, CherryTree or plain Markdown all work. What matters is a per-host template you fill in every single time: open ports, service versions, credentials found, things tried, things that failed.
- Write your own enumeration checklist. Not someone else's. The act of writing it is what embeds it.
- Start a personal command reference. Every time you look up syntax twice, it goes in the file.
Checkpoint: you can go from a bare IP address to a full service inventory with version numbers and a prioritised list of attack paths, without consulting a walkthrough.
Weeks 4 to 6: Exploitation and Privilege Escalation
This is where most of the standalone machine points live.
- Cover the web application attacks, client-side attacks, file transfer and antivirus evasion modules.
- Spend serious time on privilege escalation on both platforms. Half the points on every standalone box come from escalation, and it is where people stall. Learn the enumeration scripts, then learn what their output actually means.
- Practise modifying public exploits. Download something from Exploit-DB that does not quite fit, and make it work. This is an examinable skill.
- Do not skip file transfer. Getting a file onto a restricted host under exam conditions, with no internet access to look it up, catches people out constantly.
Checkpoint: you can take a standalone practice box from foothold to root in under 90 minutes without hints, and your notes from that box would be enough to write a report a week later.
Weeks 7 to 9: Active Directory, the 40 Points That Decide It
Give this phase everything. The AD set is a single chained scenario, so a mistake early in the chain costs you all 40 points, not a proportion of them.
Core techniques you must be able to execute cold:
- Domain enumeration with BloodHound and manual methods, so you can still work when a tool breaks.
- Kerberoasting and AS-REP roasting, including cracking the resulting tickets offline.
- Pass-the-Hash and Pass-the-Ticket for lateral movement between the first and second host.
- Credential harvesting from memory, from disk, and from misconfigured shares.
- Domain privilege escalation paths to Domain Controller, including delegation abuse and ACL misconfigurations.
Work the PEN-200 AD modules first, then drill the OffSec Proving Grounds AD chains and the retired HTB Pro Labs style environments until the chain feels routine.
Exam Tip: Practise the AD chain end to end in one sitting, not technique by technique. The exam does not hand you a Kerberoasting exercise, it hands you a domain and 40 points, and the difficulty is knowing which technique applies at each hop.
Checkpoint: you can compromise a three-host domain from initial foothold to Domain Controller in under four hours, twice, on two different chains.
Weeks 10 to 12: Exam Simulation and Report Practice
The final three weeks are not for new material. They are for rehearsing the day.
- Run at least two full mock exams. Six machines, no walkthroughs, and a hard 23 hour 45 minute clock. Start at the same time of day you have booked the real exam. This is the only way to learn what your brain does at hour 16.
- Write the report both times. A full, professional report with reproduction steps and screenshots. Candidates have failed with 70+ points on the machines because the report did not prove they earned them.
- Build your report template now. Executive summary, methodology, per-host findings with steps to reproduce, screenshots showing the proof and local flags with the IP visible.
- Practise taking proof screenshots as you go. Not at the end. If you lose a shell at hour 20 and have no screenshot, those points are gone.
- Week 12 should be light. Review your notes, re-read your AD chain, sleep properly. Do not learn a new tool in the final ten days. Spaced review of what you already know beats cramming something unfamiliar.
Exam Day Tactics That Are Worth Points
A study plan gets you to the door. These decisions get you through it.
Start with the Active Directory set. It carries the most points and demands the most mental clarity. Attacking it at hour 18 when you are exhausted is a choice that fails people.
Set hard time boxes. Ninety minutes per standalone machine on the first pass. If you have not found a foothold, move on and come back. The exam punishes stubbornness more than it punishes gaps in knowledge.
Take breaks on a schedule, not on feel. Ten minutes every two hours, away from the screen. You will feel like you cannot afford it. The alternative is tunnel vision at hour 14, which is far more expensive.
Enumerate again when you are stuck. The overwhelming majority of failed attempts trace back to incomplete enumeration rather than missing knowledge. If you cannot find the entry point, you have not looked hard enough at what is already in front of you.
Do not use AI assistants. ChatGPT and equivalent tools are explicitly prohibited and detection means an automatic fail. The proctoring is watching your screen.
Screenshot everything, immediately. Local flag, proof flag, IP address visible in the same frame. Shells die. Screenshots do not.
How Long Should You Really Give It?
Twelve weeks at 12 to 15 hours a week is roughly 150 to 180 hours of focused study, and it works for candidates who arrive with the prerequisites in place. Here is how the timeline should flex.
| Your starting point | Realistic timeline | Where to add time |
|---|---|---|
| Working pentester or CPTS/PNPT holder | 8 to 10 weeks | Straight to AD and mock exams |
| Sysadmin or SOC analyst with solid Linux | 12 weeks | Follow the plan as written |
| IT generalist, some scripting | 16 to 20 weeks | Double the foundations phase |
| New to security, no Linux comfort | 6 to 9 months | Build prerequisites before buying PEN-200 |
The plan is not the variable that matters most. Consistency is. Ninety minutes a day, six days a week, beats a ten-hour Sunday every time, because enumeration instinct is built by repetition rather than by volume.
Common Mistakes That Cost People the Pass
- Treating the AD set as optional. It is 40 of the 100 points and there is no route to 70 that comfortably avoids it.
- Planning around bonus points. They no longer exist. Any guide that mentions them is describing an exam that has not run since October 2024.
- Collecting tools instead of building method. The exam rewards a repeatable process, not a large toolkit.
- Neglecting the report. It is a graded deliverable, not paperwork. Practise it.
- Booking the exam by date rather than by readiness. Book it after you have passed two mock exams, not before.
- Skipping manual techniques. When an automated tool fails under exam conditions, and one will, you need the manual equivalent.
Where the OSCP Fits in Your Certification Path
The OSCP remains the most widely recognised hands-on penetration testing credential, and it still opens doors that multiple-choice certifications do not. It is also expensive and demanding, so it should sit at the right point in your path rather than at the start of it.
If you are earlier in the journey, CompTIA PenTest+ or the eJPT give you the theory and the vocabulary at a fraction of the cost. If you want a practical exam that builds directly towards OSCP, the HTB CPTS is the closest thing to a rehearsal. And if you are weighing offensive against defensive, our comparison of PenTest+ and CEH is a useful starting point.
Ready to Start Practising?
The OSCP practical is won in the lab, but the underlying knowledge, enumeration logic, privilege escalation paths, Active Directory attack theory and reporting standards, is exactly what CertCrush drills.
Work through the offensive security material on CertCrush alongside your PEN-200 labs, use the practice questions to find the gaps in your theory before they cost you points at hour 14, and go into the exam knowing your weak areas are already closed.
Create your free CertCrush account and start today, or browse the full course catalogue to see everything covered.
