Study Timeline

How Long to Study for OSCP (Offensive Security Certified Professional)

A complete week-by-week study plan for the OSCP (Offensive Security Certified Professional) (Very Hard difficulty, ~25% pass rate).

12

Weeks

14

Hrs/Week

169

Total Hours

~25%

Pass Rate

Baseline, tooling, and rules
Week 1

10-12 hours this week

  • Read the OSCP+ Exam Guide on help.offsec.com end to end, including the Metasploit restriction and the point disqualification list
  • Build and snapshot a Kali Linux virtual machine, and confirm OpenVPN works from it
  • Set up a note-taking system with a template per host covering ports, services, credentials, and screenshots
  • Practice the proof screenshot format now: file contents plus ipconfig, ifconfig, or ip addr in the same frame
  • Write your enumeration checklist as a document you will follow rather than improvise from
Enumeration depth
Week 2

12-15 hours this week

  • Work the PEN-200 information gathering and vulnerability scanning modules
  • Practice Nmap and the Nmap Scripting Engine until you can justify every flag you use
  • Enumerate SMB, SNMP, and NFS on practice targets without relying on an all-in-one script
  • Run your checklist against five machines and time how long a full pass takes
  • Revise the checklist based on anything you missed and had to go back for
Web application attacks by hand
Week 3

12-15 hours this week

  • Work the PEN-200 web application modules covering SQL injection, XSS, command injection, directory traversal, and file uploads
  • Exploit a SQL injection manually end to end without sqlmap, since sqlmap is banned in the exam
  • Turn a file upload into an interactive reverse shell, not a web shell
  • Practice with Burp Suite Free only, since Burp Pro is a prohibited commercial tool
  • Document one web exploitation chain as though it were an exam report section
Linux privilege escalation
Week 4

12-15 hours this week

  • Work the PEN-200 Linux privilege escalation module
  • Escalate to root on ten practice machines using ten different mechanisms
  • Practice SUID, sudo misconfiguration, cron, and writable path escalations separately until each is automatic
  • Read proof.txt from /root/ with cat in an interactive shell and capture the screenshot correctly each time
  • Write down which enumeration script output you trust and which you always verify by hand
Windows privilege escalation
Week 5

12-15 hours this week

  • Work the PEN-200 Windows privilege escalation module
  • Escalate to SYSTEM or Administrator on ten practice machines using different mechanisms
  • Practice service misconfiguration, unquoted service path, and privilege abuse routes
  • Confirm on each box that your shell runs as SYSTEM, Administrator, or an administrator-privileged user, since anything less caps the machine at partial points
  • Practice reading proof.txt from the Administrator Desktop with type from an interactive shell
Password attacks and credential discipline
Week 6

10-12 hours this week

  • Work the PEN-200 password attacks module
  • Practice online attacks with Hydra and offline cracking with your chosen wordlists
  • Build a credential log format and use it on every practice box so reuse is obvious
  • Practice extracting credentials from config files, databases, and backups
  • Chain a credential found on one host into access on another
Active Directory from assumed breach
Week 7

15-18 hours this week

  • Work the PEN-200 Active Directory modules on enumeration, attacking AD authentication, and lateral movement
  • Practice a full three-machine domain compromise starting from a supplied standard user account
  • Drill Kerberos-based attacks and lateral movement without using Metasploit, since Metasploit cannot be used for pivoting
  • Time yourself: the AD set is 40 points and should be attempted early in the exam
  • Document the whole chain as a report section with every command and its output
Pivoting and tunneling
Week 8

10-12 hours this week

  • Practice SSH local, remote, and dynamic port forwarding until you can build each from memory
  • Route scanning and exploitation traffic through proxychains to a second subnet
  • Set up a Windows port forward without touching Metasploit
  • Practice recovering when a tunnel drops mid-attack rather than starting the chain over
  • Run a two-hop scenario end to end and document it
PEN-200 challenge labs
Week 9

15-18 hours this week

  • Work the PEN-200 challenge labs, prioritizing the three built to replicate the OSCP+ exam environment
  • Treat one challenge lab as a scored run and record which machines you would have earned points on
  • Log every point at which you got stuck and what unblocked you
  • Practice using reverts sparingly, since the exam gives 24 reverts resettable once
  • Write a full report for one challenge lab in the exact submission format
Full-length exam simulation
Week 10

24 hours this week

  • Run a 23 hour 45 minute simulation against six unfamiliar machines, sleeping and eating on the schedule you plan to use
  • Enforce the real restrictions: no sqlmap, no Nessus, no AI chatbots, Metasploit against one target only
  • Capture every proof screenshot in the required format as you go rather than at the end
  • Track your point total against the published 70-point combinations to see which path you were closest to
  • Note the hour at which your judgment degraded and plan a rest break just before it
Report writing under time
Week 11

12-15 hours this week

  • Write the full report for your week 10 simulation inside a 24-hour window
  • Use an OffSec suggested template or your own, as long as it is structured and professional
  • Include modified exploit code with the original URL, highlighted changes, and an explanation of why
  • Export to PDF, archive to .7z without a password, name it in the exact required format, and confirm it is under 200MB
  • Generate the MD5 of the archive and practice the verification step you will do at upload.offsec.com
Gap closing and exam logistics
Week 12

10-12 hours this week

  • Redo practice machines in the category where you lost the most simulation points
  • Test your webcam against the exact physical ID you will present, confirming the text and photo are legible
  • Verify your machine meets the proctoring requirements: 64-bit dual core, 8GB RAM, 20mbps down and 10mbps up
  • Confirm the name on your OffSec learner profile matches your government ID
  • Book the slot, remembering the rescheduling window closes 48 hours before the start time
Working Full-Time Schedule

Duration: 18 weeks

Hours/week: 10 hours

Daily: ~2 hours on weeknights

Weekends: 3-4 hours Saturday + Sunday

Study during lunch breaks and commute time. Use weekends for deeper study sessions and practice tests.

Weekend-Only Schedule

Duration: 24 weeks

Hours/week: 7 hours

Saturday: 4-5 hours of focused study

Sunday: 3-4 hours of practice tests

Longer timeline but sustainable. Review flashcards on weeknights for 15-20 minutes to maintain retention.

Frequently Asked Questions

How long does it take to study for the OSCP (Offensive Security Certified Professional)?

Plan for 12 weeks of dedicated study at 14 hours per week (169 total hours). If studying while working full-time, extend to 18 weeks.

Can I pass the OSCP (Offensive Security Certified Professional) in 2 weeks?

It's unlikely for most candidates. The OSCP (Offensive Security Certified Professional) is rated "Very Hard" difficulty and typically requires 12 weeks of preparation. Rushing increases your risk of failing and paying the exam fee again.

How many hours a day should I study for OSCP (Offensive Security Certified Professional)?

Aim for 3-4 hours per day on weekdays. Quality matters more than quantity, use active recall and practice tests rather than passive reading.

Is OSCP (Offensive Security Certified Professional) hard to pass?

The OSCP (Offensive Security Certified Professional) is rated "Very Hard" difficulty with a pass rate of ~25%. Significant preparation is essential.

Ready to start your OSCP (Offensive Security Certified Professional) journey?

Get the complete exam guide with tips, resources, and practice questions.

View OSCP (Offensive Security Certified Professional) Guide