How Long to Study for OSCP (Offensive Security Certified Professional)
A complete week-by-week study plan for the OSCP (Offensive Security Certified Professional) (Very Hard difficulty, ~25% pass rate).
12
Weeks
14
Hrs/Week
169
Total Hours
~25%
Pass Rate
10-12 hours this week
- Read the OSCP+ Exam Guide on help.offsec.com end to end, including the Metasploit restriction and the point disqualification list
- Build and snapshot a Kali Linux virtual machine, and confirm OpenVPN works from it
- Set up a note-taking system with a template per host covering ports, services, credentials, and screenshots
- Practice the proof screenshot format now: file contents plus ipconfig, ifconfig, or ip addr in the same frame
- Write your enumeration checklist as a document you will follow rather than improvise from
12-15 hours this week
- Work the PEN-200 information gathering and vulnerability scanning modules
- Practice Nmap and the Nmap Scripting Engine until you can justify every flag you use
- Enumerate SMB, SNMP, and NFS on practice targets without relying on an all-in-one script
- Run your checklist against five machines and time how long a full pass takes
- Revise the checklist based on anything you missed and had to go back for
12-15 hours this week
- Work the PEN-200 web application modules covering SQL injection, XSS, command injection, directory traversal, and file uploads
- Exploit a SQL injection manually end to end without sqlmap, since sqlmap is banned in the exam
- Turn a file upload into an interactive reverse shell, not a web shell
- Practice with Burp Suite Free only, since Burp Pro is a prohibited commercial tool
- Document one web exploitation chain as though it were an exam report section
12-15 hours this week
- Work the PEN-200 Linux privilege escalation module
- Escalate to root on ten practice machines using ten different mechanisms
- Practice SUID, sudo misconfiguration, cron, and writable path escalations separately until each is automatic
- Read proof.txt from /root/ with cat in an interactive shell and capture the screenshot correctly each time
- Write down which enumeration script output you trust and which you always verify by hand
12-15 hours this week
- Work the PEN-200 Windows privilege escalation module
- Escalate to SYSTEM or Administrator on ten practice machines using different mechanisms
- Practice service misconfiguration, unquoted service path, and privilege abuse routes
- Confirm on each box that your shell runs as SYSTEM, Administrator, or an administrator-privileged user, since anything less caps the machine at partial points
- Practice reading proof.txt from the Administrator Desktop with type from an interactive shell
10-12 hours this week
- Work the PEN-200 password attacks module
- Practice online attacks with Hydra and offline cracking with your chosen wordlists
- Build a credential log format and use it on every practice box so reuse is obvious
- Practice extracting credentials from config files, databases, and backups
- Chain a credential found on one host into access on another
15-18 hours this week
- Work the PEN-200 Active Directory modules on enumeration, attacking AD authentication, and lateral movement
- Practice a full three-machine domain compromise starting from a supplied standard user account
- Drill Kerberos-based attacks and lateral movement without using Metasploit, since Metasploit cannot be used for pivoting
- Time yourself: the AD set is 40 points and should be attempted early in the exam
- Document the whole chain as a report section with every command and its output
10-12 hours this week
- Practice SSH local, remote, and dynamic port forwarding until you can build each from memory
- Route scanning and exploitation traffic through proxychains to a second subnet
- Set up a Windows port forward without touching Metasploit
- Practice recovering when a tunnel drops mid-attack rather than starting the chain over
- Run a two-hop scenario end to end and document it
15-18 hours this week
- Work the PEN-200 challenge labs, prioritizing the three built to replicate the OSCP+ exam environment
- Treat one challenge lab as a scored run and record which machines you would have earned points on
- Log every point at which you got stuck and what unblocked you
- Practice using reverts sparingly, since the exam gives 24 reverts resettable once
- Write a full report for one challenge lab in the exact submission format
24 hours this week
- Run a 23 hour 45 minute simulation against six unfamiliar machines, sleeping and eating on the schedule you plan to use
- Enforce the real restrictions: no sqlmap, no Nessus, no AI chatbots, Metasploit against one target only
- Capture every proof screenshot in the required format as you go rather than at the end
- Track your point total against the published 70-point combinations to see which path you were closest to
- Note the hour at which your judgment degraded and plan a rest break just before it
12-15 hours this week
- Write the full report for your week 10 simulation inside a 24-hour window
- Use an OffSec suggested template or your own, as long as it is structured and professional
- Include modified exploit code with the original URL, highlighted changes, and an explanation of why
- Export to PDF, archive to .7z without a password, name it in the exact required format, and confirm it is under 200MB
- Generate the MD5 of the archive and practice the verification step you will do at upload.offsec.com
10-12 hours this week
- Redo practice machines in the category where you lost the most simulation points
- Test your webcam against the exact physical ID you will present, confirming the text and photo are legible
- Verify your machine meets the proctoring requirements: 64-bit dual core, 8GB RAM, 20mbps down and 10mbps up
- Confirm the name on your OffSec learner profile matches your government ID
- Book the slot, remembering the rescheduling window closes 48 hours before the start time
Duration: 18 weeks
Hours/week: 10 hours
Daily: ~2 hours on weeknights
Weekends: 3-4 hours Saturday + Sunday
Study during lunch breaks and commute time. Use weekends for deeper study sessions and practice tests.
Duration: 24 weeks
Hours/week: 7 hours
Saturday: 4-5 hours of focused study
Sunday: 3-4 hours of practice tests
Longer timeline but sustainable. Review flashcards on weeknights for 15-20 minutes to maintain retention.
How long does it take to study for the OSCP (Offensive Security Certified Professional)?
Plan for 12 weeks of dedicated study at 14 hours per week (169 total hours). If studying while working full-time, extend to 18 weeks.
Can I pass the OSCP (Offensive Security Certified Professional) in 2 weeks?
It's unlikely for most candidates. The OSCP (Offensive Security Certified Professional) is rated "Very Hard" difficulty and typically requires 12 weeks of preparation. Rushing increases your risk of failing and paying the exam fee again.
How many hours a day should I study for OSCP (Offensive Security Certified Professional)?
Aim for 3-4 hours per day on weekdays. Quality matters more than quantity, use active recall and practice tests rather than passive reading.
Is OSCP (Offensive Security Certified Professional) hard to pass?
The OSCP (Offensive Security Certified Professional) is rated "Very Hard" difficulty with a pass rate of ~25%. Significant preparation is essential.
Ready to start your OSCP (Offensive Security Certified Professional) journey?
Get the complete exam guide with tips, resources, and practice questions.
View OSCP (Offensive Security Certified Professional) Guide