CEH Certification Guide 2026: Exam, Cost & Practical
Updated August 2, 202625+ min read

CEH and CEH Practical Certification Guide: Everything You Need to Know

Complete decision guide covering eligibility, exam format, costs, CEH Practical, study strategies, and career value for every experience level.

What you’ll learn in this article…

  • CEH exam voucher costs $1,199 with total spend reaching over $4,700.
  • CEH Practical adds a six-hour, hands-on lab to earn CEH Master status.
  • Information security analyst roles are projected to grow 31 to 32 percent by 2032.

Your Complete Guide to CEH and CEH Practical Certification

EC-Council's Certified Ethical Hacker remains the most widely recognized offensive security certification worldwide, appearing in more federal job postings and corporate requisitions than any competing credential. Yet prospective candidates face a tangle of confusing version numbers, multiple exam paths, and pricing that can swing from $1,199 for a standalone voucher to over $4,500 for bundled training.

This guide delivers the decision framework for choosing a cybersecurity certification before you spend that money: complete cost breakdowns across self-study, bootcamp, and official training routes; tiered certification study plans matched to your experience level; a deep dive into CEH Practical and CEH Master requirements; version comparisons from v11 through v15; and career ROI data grounded in current labor market figures.

CEH Credential Snapshot

What exactly do you get when you earn a certification in cyber security like the Certified Ethical Hacker, and how does it fit into the larger landscape of Cybersecurity Certification Roadmaps? Here is the fast reference before we go deep in later sections.

Quick Reference Facts

  • Credential name: Certified Ethical Hacker (CEH)
  • Issuing body: EC-Council1
  • Current version: CEH v13, with v15 on the roadmap2
  • Knowledge exam code: 312-501
  • Practical exam code: 312-50 (Practical)1
  • Exam fee: roughly $950 to $1,199 depending on delivery channel and region4
  • Application fee: $100 (waived if you complete official EC-Council training)4
  • Format: 125 multiple-choice questions5
  • Duration: 240 minutes (4 hours)6
  • Passing score: variable, ranging from 60% to 85% depending on the specific exam form you receive6
  • Recertification cycle: every 3 years, requiring 120 ECE credits7

How the Pieces Fit Together

CEH is actually three related products under one brand. The knowledge exam (312-50) is the multiple-choice test that grants the base CEH title.1 The CEH Practical is a separate 6-hour hands-on exam in a live cyber range where you attack real target machines.1 Passing both earns you the CEH Master designation at no extra fee beyond the two exam vouchers.1

The variable passing score often surprises candidates. EC-Council uses multiple exam forms of differing difficulty, and each form is psychometrically calibrated to its own cut score. You will not know your target percentage in advance, so aim comfortably above 85% in practice tests rather than treating 70% as a safe zone.8

What the Certified Ethical Hacker Validates and Who Should Pursue It

The Five Phases of Ethical Hacking

The CEH curriculum builds on a methodology EC-Council calls the five phases of ethical hacking. Every tool, technique, and domain in the exam connects to one of these phases.

  • Reconnaissance: Gathering information about the target before launching an attack. This includes passive techniques like OSINT, DNS queries, and social media scraping, as well as active probes.
  • Scanning: Using tools to identify live hosts, open ports, services, and vulnerabilities. Nmap, Nessus, and various enumeration scripts fall here.
  • Gaining Access: Exploiting a discovered vulnerability to enter the system. This phase covers password cracking, Metasploit modules, SQL injection, and other common exploitation vectors.
  • Maintaining Access: Establishing persistence on a compromised machine through backdoors, rootkits, or trojans, while also escalating privileges.
  • Clearing Tracks: Hiding evidence of the intrusion by deleting logs, modifying timestamps, or using steganography to obscure data exfiltration.

Understanding this attack chain is what the CEH primarily validates. The certification is not about building exploits from scratch but about systematically applying an attacker’s mindset to real-world scenarios.

What CEH Actually Validates

The CEH knowledge exam tests your familiarity with over 500 hacking tools and your ability to choose the right one for a given scenario. You need to recognize Nmap scan types, Metasploit commands, Wireshark filters, Burp Suite modules, and dozens of other utilities. But you won’t be asked to perform a live intrusion during the multiple-choice test.

This is the biggest difference between CEH and the Offensive Security Certified Professional (OSCP). OSCP’s 24-hour hands-on exam demands you compromise machines, pivot networks, and write a report. CEH’s theoretical exam instead measures breadth of awareness: can you name the tool, explain the command, or spot the indicator of a specific attack phase? Even the six-hour CEH Practical is a guided, scenario-based lab where you answer questions about pre-configured environments rather than hunting for flags on unknown targets.

In short, CEH validates offensive-security methodology and tool awareness. It signals that you know how attackers think, which tools they use, and how to walk through the phases of a pen test. It does not, by itself, prove you can execute a penetration test from start to finish on a hardened network.

How CEH Differs from Defensive Certifications

CompTIA Security+ and CySA+ are excellent starting points for IT professionals, but their lenses are defensive. The CompTIA Security+ Certification Guide details network security, access controls, and risk management. CySA+ focuses on threat detection and data analysis from a blue-team perspective. Neither requires you to think like an adversary.

CEH flips the script. It treats the network the way a criminal would, making you methodically map, probe, and exploit. That perspective is valuable for roles in vulnerability management, threat intelligence, or red teaming. It also gives blue-teamers a deeper appreciation of what they’re defending against. However, if your day-to-day involves configuring firewalls, managing SIEM alerts, or patching systems, CEH is a complement, not a replacement, for defensive credentials.

Who Should Pursue the CEH: Learner Profiles and Verdicts

Not every cybersecurity hopeful needs a CEH, and for some, it is the wrong credential to pursue first. Here is how it fits four distinct learner profiles.

  • Career changer with no IT background: Verdict: skip CEH for now. The exam assumes a baseline understanding of networking, operating systems, and security fundamentals. Without that, you will struggle to connect tool usage with the underlying protocols. Start with foundational credentials like CompTIA Network+ and Security+ (see our comptia certification order guidance) to build the vocabulary and context CEH expects.
  • IT professional pivoting to security: Verdict: good fit if you need structured offensive thinking. You already understand networks, firewalls, and system administration. CEH will give you a framework for thinking about attacks and help you shift from “keep things running” to “break things ethically.” The tool exposure is especially useful for vulnerability analyst or junior pen test positions.
  • DoD or government employee seeking IAT/IAM compliance: Verdict: strong fit due to regulatory recognition. CEH is listed under DoD 8570/8140 directives for several cybersecurity roles. If your employer or target agency requires that baseline, the certification directly unlocks eligibility. Just confirm whether the CEH Master (knowledge + practical) or the standalone CEH is the accepted version.
  • Experienced how to become a penetration tester with OSCP or GPEN: Verdict: limited value unless an employer or contract demands it. You already demonstrate hands-on exploitation skill. CEH adds stackable recognition under EC-Council’s pathway and may satisfy checkbox requirements for government bids, but it won’t teach you new offensive techniques. If the goal is deeper red-team skills, consider advanced credentials like OSEP or the Hack The Box Certified Penetration Testing Specialist instead.

In every case, the CEH’s strength is its methodology-first, tool-awareness approach. Whether that aligns with your career stage depends on what you already bring to the exam room.

EC-Council maintains two distinct eligibility pathways for the CEH exam: completing official training, which requires no prior experience, or submitting an experience waiver application backed by at least two years of information security work. Knowing which path fits your background helps you avoid unnecessary costs and delays.

Official Eligibility Pathways

  • Training pathway: Enroll in an EC-Council approved training program (at an accredited training center, through an authorized academic partner, or via the official iLearn online course). Once you finish training, you receive an exam voucher and are automatically eligible to sit for the exam. There is no background check or application fee in this route.
  • Experience waiver pathway: If you already have professional information security experience, you can skip formal training. You must complete the CEH Exam Eligibility Application, document at least two years of relevant work, and pay a non-refundable $100 application fee. EC-Council reviews your submission; typical processing takes 5 to 10 business days. Approval is not guaranteed and requires verifiable job responsibilities aligned with the CEH domains.

Neither pathway requires holding another certification, but reviewing prerequisites for cybersecurity certifications can clarify the baseline knowledge many newcomers lack before attempting the CEH exam. EC-Council recommends foundational knowledge equivalent to CompTIA Network+ and Security+.

Recommended Background Regardless of Pathway

Even if you take the training route, the CEH is not a beginner-level exam. Successful candidates generally bring:

  • Networking fundamentals: Comfort with TCP/IP, subnetting, common protocols, and firewall concepts.
  • Operating system familiarity: Proficiency in both Windows and Linux command-line environments, as many exam tools and scenarios involve terminal usage.
  • Basic scripting and automation: Reading and writing simple scripts (Python, Bash, or PowerShell) helps with understanding exploits and tool output.
  • Core security concepts: Understanding of threats, vulnerabilities, risk management, and common attack vectors, material often covered in CompTIA Security+.

Walking in cold without these skills makes the 125-question, four-hour exam significantly harder. While official training covers many topics, it moves quickly and assumes you can absorb technical concepts without handholding.

The Experience Waiver Application Process

If you choose the waiver path, plan for verification. You will need:

  • A detailed resume or curriculum vitae listing your information security roles and dates.
  • Employer contact information for supervisors who can confirm your responsibilities.
  • A signed verification letter on company letterhead, or EC-Council’s standard verification form completed by your supervisor.
  • Payment of the $100 non-refundable application fee.

EC-Council may reach out to references. Any discrepancy or insufficient documentation leads to denial. Once approved, you receive an eligibility ID that lets you purchase an exam voucher and schedule your test at a Pearson VUE center or via online proctoring. The entire process, from submission to eligibility, typically wraps up within two weeks, so plan ahead if you have a target exam date.

Exam Format, Domains, Scoring, and CEH Practical Vs. CEH Master

The cybersecurity credential landscape is shifting decisively toward practical validation, and EC-Council’s pairing of a broad knowledge exam with an optional hands-on practical reflects that trend. Understanding how the two assessments work, and how they combine, lets you choose the path that best proves your skills.

Inside the 312-50 Knowledge Exam

The core CEH exam (312-50) is a four-hour, 125-question multiple-choice test delivered through Pearson VUE. It does not use a fixed pass mark; instead, EC-Council applies a dynamic cut score that fluctuates based on exam form difficulty, typically landing between 60% and 85%. That design means you cannot target a single percentage, you need to demonstrate competence across a wide surface area.

The blueprint organizes content into nine domains, with the following approximate weight distributions:

  • Network & Perimeter Hacking: 25%
  • Reconnaissance Techniques: 15%
  • System Hacking Phases & Attack Techniques: 15%
  • Web Application Hacking: 15%
  • Mobile, IoT & OT Hacking: 10%
  • Cloud Computing, IDS/Firewalls, and Honeypots: 10%
  • Cryptography: 5%
  • Social Engineering: 5%
  • Evading Security Mechanisms, Malware Threats, and Session Hijacking: remaining percentage

Because the test covers more than 300 tools and the five phases of ethical hacking, its difficulty springs from breadth, not depth. Candidates who memorize tool names and definitions often hit a ceiling; those who can map tools to attack phases and interpret command output tend to fare better.

CEH Practical: Hands-On in a Live Cyber Range

The CEH Practical is a separate, six-hour exam that takes place inside a live remote-proctored cyber range (Aspen / iLabs / CyberQ). It contains 20 scenario-based challenges, each requiring you to execute a specific task, such as packet analysis, vulnerability scanning, web application exploitation, system hacking, or cryptography, and submit the correct flag, evidence, or answer. No written report is required. You pass by completing at least 14 out of the 20 tasks, corresponding to a 70% score.

This exam tests your ability to navigate a real environment under time pressure, not your recall of theory. The tasks mirror the same nine domains as the knowledge exam, but with a heavier practical emphasis on network and perimeter attacks (the network/perimeter domain alone accounts for five challenges). The platform records your keystrokes and screens, so proctors can verify that tasks were genuinely performed. Because the voucher cost is $550 and the exam demands hands-on comfort with tools like Nmap, Metasploit, Wireshark, and Burp Suite, candidates should schedule the practical only after consistent lab practice.

Earning the CEH Master Designation

You earn the CEH Master title by passing both the 312-50 knowledge exam and the CEH Practical. There is no extra fee beyond the two exam vouchers. While the base CEH credential requires only the knowledge exam, the Master designation signals to employers that you have validated both theoretical and applied hacking skills. The practical exam is optional, but its value is climbing: more hiring managers now filter for candidates who can show hands-on capability rather than just a multiple-choice pass.

How This Exam Differs from Practical-Centric Credentials

A frequent point of comparison is the OSCP, which focuses narrowly on exploitation proficiency under time pressure. CEH’s knowledge exam stands apart because it demands wide familiarity across many domains and phases, and the practical test adds a structured drill in a range of techniques. If you are weighing CEH against an advanced practical certification, consider your current depth: CEH Master proves broad applied knowledge, while OSCP proves specialized penetration testing depth. Many professionals eventually earn both, but the CEH Master often serves as a strong launch point for transitioning into hands-on roles.

Total Cost of CEH Certification Across Every Path

The total cost of earning your Certified Ethical Hacker credential varies significantly depending on how you train. EC-Council publishes current voucher and training bundle pricing on its official store, and authorized training centers list their own rates. Before committing, check eccouncil.org for the latest exam voucher price, training bundle options (iLearn, iClass, and partner bootcamps), application fees for the experience-based eligibility route, retake fees, and the three-year recertification cost including annual membership and ECE credit requirements. Prices change periodically, so always verify directly before budgeting.

Side-by-side cost comparison of three CEH certification paths: self-study, official EC-Council training bundle, and bootcamp, across six expense categories

Full Cost Breakdown: Training, Vouchers, Retakes, and Renewal Fees

A standard CEH exam voucher costs $1,199, covering the non-refundable application fee. However, the total cybersecurity certification cost can vary by more than $3,500 depending on whether you choose self-study vs. instructor-led training and whether you factor in the first three-year renewal cycle.

Total Cost by Learning Path

  • Self-study (~$1,500, $2,200): You pay the voucher fee, add third-party study materials ($30, $80), optional iLabs access ($199 for six months), and practice exams ($20, $50). Over three years, add the $240 EC-Council annual membership for recertification. Self-study candidates who purchase labs and practice exams still spend roughly $1,800, $2,200.
  • Official iLearn or iClass (~$2,500, $3,500): These packages bundle the exam voucher, iLabs access, official courseware, and a practice exam. The higher upfront cost narrows the gap with self-study once you factor in the extras a self-study candidate would have to buy separately. After three years of annual membership, the total lands around $2,800, $3,700.
  • Bootcamp (~$3,000, $5,000+): Instructor-led training includes the voucher, labs, and exam prep, but travel and lodging can push the top end beyond $5,000. Adding the three-year membership cycle brings the all-in range to roughly $3,300, $5,300.

What Official Training Includes

iLearn and iClass packages come with six months of iLabs, an official practice exam, and the exam voucher. A self-study student who purchases iLabs and a practice exam independently will spend about $250 on those items alone, which significantly reduces the real price difference between official training and the do-it-yourself route.

Recertification and Annual Maintenance

The CEH certification expires after three years. To renew, you must accumulate 120 ECE credits and maintain an active EC-Council membership, which costs $80 per year. Over a three-year cycle, that is $240. Many ECE-earning activities are free, webinars, self-study, publishing, but some professionals choose paid options such as conferences or advanced courses, which can add $500, $2,000 to the recertification cycle. Plan on at least the $240 membership cost for each renewal.

Retake Fees and Waiting Periods

If you fail the CEH exam, you must wait 14 days before attempting it again. EC-Council sells a retake voucher for $499, substantially less than the full exam price. There is no limit on attempts, but each retake requires the waiting period and a new voucher purchase, as outlined in the Online Cybersecurity Exams Retakes policy.

How to Prepare: Study Plans by Experience Level

Your ideal study plan depends on how much hands-on IT and security experience you bring to the table. The plans below cover the CEH knowledge exam; if you are also targeting CEH Practical, add two to four weeks of dedicated lab time on top of these timelines. Adjust daily hours up or down based on your schedule, but keep the theory, lab, and practice test ratio close to these targets for balanced preparation.

PlanTimelineDaily Study HoursTheory / Lab / Practice Test RatioRecommended Resources
Career Changer (No IT Background)16 to 20 weeks1.5 to 2 hours40% / 40% / 20%Official EC-Council courseware (iClass or self-paced), a networking and OS fundamentals primer, iLabs virtual environment, at least two full-length practice exams, and a supplemental ethical hacking textbook
Early IT Professional (1 to 2 years in help desk, networking, or sysadmin)10 to 14 weeks1 to 1.5 hours30% / 45% / 25%Official CEH study guide, iLabs or comparable home lab (Kali Linux, Metasploitable), video course from an independent platform, Exam Readiness practice tests, and domain-specific flashcards for weaker areas
Working Cybersecurity Practitioner (2 or more years in a security role)6 to 8 weeks1 hour20% / 50% / 30%Official exam objectives checklist for gap analysis, iLabs or personal pen-testing lab, one focused practice exam set, and targeted review of CEH-specific tools and methodology terminology
Experienced Specialist or Manager (5 or more years, holds other security certs)4 to 6 weeks45 minutes to 1 hour15% / 45% / 40%Exam objectives mapped against existing knowledge, rapid lab refresher using iLabs or CTF platforms, two to three timed practice exams to calibrate pacing, and a review of any newly added domains in the current exam version

Jobs, Salary, and Employer Demand for CEH Holders

The CEH credential maps to roles across penetration testing, security operations, and vulnerability management. The U.S. Bureau of Labor Statistics projects 31 to 32 percent job growth for information security analysts (SOC 15-1212) from 2022 to 2032, well above the national average. Job board snapshots from 2025 and 2026 show roughly 1,000 U.S. postings on both Indeed and LinkedIn mentioning CEH by name, with worldwide LinkedIn listings ranging from approximately 5,000 to 15,000 depending on search filters. CEH also satisfies specific work-role requirements under the DoD 8140 (formerly 8570) directive, making it a common prerequisite for defense and government contractor positions. The salary figures below reflect BLS national data for roles commonly pursued by CEH holders; individual earnings will vary by experience, clearance status, and employer.

RoleBLS SOC CodeU.S. Employment25th Percentile SalaryMedian Salary75th Percentile SalaryMean Salary
Information Security Analysts15-1212179,430$92,160$124,910$159,600$127,730
Computer and Information Systems Managers11-3021645,970$134,350$171,200$216,220$187,990
Computer Network Architects15-1241177,010$102,120$130,390$164,440$135,890
Computer Network Support Specialists15-1231146,450$56,720$73,340$95,710$79,610

CEH Salary by Metro Area

Compensation for information security analysts, the role most closely aligned with the CEH credential, varies significantly by metro area. The table below shows annual wages for this occupation across the top ten metro areas ranked by total employment. All figures are drawn from the Occupational Employment and Wage Statistics program (2024 data) published by the U.S. Bureau of Labor Statistics. Keep in mind that these figures reflect the broader information security analyst occupation; individual salaries will vary based on experience, employer, clearance level, and additional certifications held alongside the CEH.

Metro AreaTotal Employment25th PercentileMedian SalaryMean Salary75th Percentile
San Francisco, Oakland, Fremont (CA)4,010$129,350$168,160$166,090$188,060
Seattle, Tacoma, Bellevue (WA)4,490$121,370$152,660$156,000$174,530
Washington, Arlington, Alexandria (DC, VA, MD, WV)15,870$111,130$138,410$146,720$172,670
New York, Newark, Jersey City (NY, NJ)10,160$106,760$138,360$146,810$172,050
Baltimore, Columbia, Towson (MD)4,370$103,780$136,050$144,460$175,420
Boston, Cambridge, Newton (MA, NH)4,870$101,760$132,170$132,120$164,370
Denver, Aurora, Centennial (CO)3,620$103,780$131,670$137,180$165,430
Dallas, Fort Worth, Arlington (TX)6,570$101,550$131,280$128,470$154,150
Los Angeles, Long Beach, Anaheim (CA)4,420$97,800$131,280$133,230$164,130
Atlanta, Sandy Springs, Roswell (GA)4,940$96,970$126,880$127,490$160,670

Renewal, Continuing Education, and Expiration Rules

Your CEH certification will expire if you do not actively maintain it, so understanding the renewal cycle before you earn the credential saves you from an unpleasant surprise three years later.

The 120-ECE, Three-Year Cycle

EC-Council requires every CEH holder to earn 120 EC-Council Continuing Education (ECE) credits within each three-year recertification period.1 Credits come from a broad menu of professional activities, and each category carries a defined cap per cycle:4

  • IT security courses: Up to 40 credits per qualifying course, whether it is an EC-Council offering or a third-party training program.
  • Authoring an article or white paper: Up to 20 credits per published piece.
  • Authoring a security tool: Up to 40 credits, useful for developers who contribute to open-source projects.
  • Identifying a new vulnerability: 10 credits per verified disclosure.
  • Conference presentation: 3 credits per talk.
  • Security book or article review: 5 credits per review.
  • Association membership: 2 credits (for example, ISSA or ISACA membership).
  • Chapter meeting attendance: 1 credit per meeting.
  • Higher education coursework: 10 credits per academic quarter.
  • EC-Council item writing: 3 credits for contributing exam questions.
  • Passing another EC-Council designated exam: A single qualifying exam can satisfy the full 120-credit requirement in one shot, though this is obviously the most expensive route.

Capture-the-flag competitions and teaching security topics also count in practice, as long as they fit EC-Council's documented activity categories.

Annual Maintenance Fee and Deadlines

Beyond earning credits, you owe an annual maintenance fee of $80 per year2, totaling $240 across the full three-year cycle.5 Credits and documentation are due by February 1 of each renewal year.1 Missing a payment or failing to submit credits by the deadline causes your certification status to move to "suspended."1

What Happens If You Lapse

After suspension, EC-Council grants a 12-month grace period3, during which you can still catch up on fees and credits. If you let that grace period expire without resolving the shortfall, your certification is revoked entirely3, and you will need to sit for the exam again from scratch. There is no reinstatement path once revocation is final, so even a modest lapse is worth avoiding.

The Cheapest Way to Accumulate Credits

If budget is a concern, you can realistically hit 120 credits over three years without spending much beyond the maintenance fee. Free vendor webinars and community conference talks each earn a handful of credits. Writing blog posts or short articles on security topics can yield up to 20 credits per piece, and several per cycle can stack quickly. If your employer already provides access to EC-Council's online learning platform or bundled membership resources, those courses often count directly. Combining two or three published articles with regular webinar attendance and a single short training course can close the gap without requiring an expensive bootcamp or additional exam voucher. The key is logging activities as you go rather than scrambling at the end of the cycle.

Best Alternatives and Next Credentials After CEH

Choosing between credentials often comes down to a single question: do you want a foundational, knowledge-based certification that checks a box, or a hands-on, practical validation that proves you can actively find vulnerabilities? The CEH is widely recognized, but several alternatives can better match specific career goals or test styles. Here's how four top contenders compare.

CompTIA PenTest+ (PT0-003)

This vendor-neutral CompTIA PenTest+ certification blends multiple-choice questions with performance-based tasks, making it a natural step up from CEH’s knowledge focus. CompTIA designed PenTest+ for professionals with 3 to 4 years of security experience3, and it carries strong recognition in corporate and government hiring, including DoD 8570 compliance4.

  • Exam format: Multiple-choice and performance-based.3
  • Fee: $404 to $4391, with total program costs around $1,100 including study materials2.
  • Best for: Roles in enterprise SOCs, compliance-focused environments, and federal contracting.

PenTest+ covers planning, scoping, and reporting in addition to technical exploitation, so it proves you can manage a full engagement lifecycle, not just run tools.

OSCP (Offensive Security Certified Professional)

If you want to move from theoretical knowledge to proven hands-on ability, the OSCP is the industry’s gold standard for practical offensive skills. The exam is 100 percent practical, requiring you to compromise a series of machines in a timed lab environment. Offensive Security expects candidates to have 1 to 3 years of prior IT or security experience5, but the PEN-200 course can also serve as a rigorous bootcamp.

  • Exam format: Fully hands-on, no multiple-choice.5
  • Fee: $1,7495, which includes course access and one exam attempt.
  • Best for: Red team members, penetration testers, and consultants who need to demonstrate exploitation proficiency.

Employers at boutique consultancies and security firms often value the OSCP more highly than any knowledge exam because it reflects real-world capability under pressure.

PNPT (Practical Network Penetration Tester)

The PNPT certification from TCM Security takes a different approach by requiring candidates to complete a full pentest engagement, including reporting and a live debrief. The exam simulates a realistic internal and external network assessment, and the price point is significantly lower than many other practical certifications.

  • Exam format: Practical assessment with a debrief.5
  • Fee: $499.5
  • Best for: Professionals at smaller firms or independent consultants who want a credential that mirrors client delivery.

PNPT is newer on the scene, but its growth among hiring managers who value demonstrated methodology over trivia makes it a compelling next step after CEH.

GPEN (GIAC Penetration Tester)

For enterprise and government environments that demand a formal, proctored exam backed by deep training, the GIAC GPEN certification fits the bill. The exam itself is multiple-choice5, but it is paired with SANS’s SEC560 course, which is hands-on and intensive. You will need that training or equivalent real-world background before sitting the test.

  • Exam format: Multiple-choice.5
  • Fee: $2,000 to $2,499 for the exam alone5, plus SANS course costs.
  • Best for: Military, intelligence, and large corporate security teams that have training budgets.

GPEN’s high cost is justified by SANS’s industry-leading courseware and the credential’s enduring brand recognition in regulated sectors.

No single certification fits every career stage. Use CEH to anchor your foundational vocabulary, then pick a follow-up that matches the kind of role you want: PenTest+ for compliance breadth, OSCP for practical skill signaling, PNPT for affordable, engagement-style proof, or GPEN if you have access to formal SANS training.

CEH Version History: V11 Vs. V12 Vs. V13 Vs. V15

CEH versions track how the exam and official courseware evolve to keep pace with threats. Each major release reshuffles tool coverage, attack vectors, and lab environments, so knowing the differences helps you choose training and study materials that match the current 312-50 exam.

What changed in each version

  • CEH v11 (2020-2021): Introduced 20 modules, 420 attack techniques, and 92 new lab exercises. It covered classic ethical hacking tools and methodologies without AI-specific content.1
  • CEH v12 (2022-2023): Expanded to 519 attack techniques and 220 total labs, with 33 new hands-on challenges. Slides grew to 1,676, and AI received minimal mention. Lab manual pages reached 1,900.
  • CEH v13 (2024-2025): Bumped attack techniques to 550 and integrated AI/ML into every domain. Labs totaled 221 (91 core, 130 self-study). MITRE ATT&CK alignment became explicit, and the exam code remained 312-50.3
  • CEH v15 (2026): Deepens AI-driven attack and defense scenarios while keeping the same 20-module structure. Official materials emphasize adversarial AI, automated threat detection, and LLM-based attack chains. Slide and lab counts are updated, but EC-Council has not yet released a detailed comparison for all metrics.5

AI and automation: the biggest leap (v13 and v15)

Starting with v13, AI is no longer a sidebar topic. Courseware now walks you through attacks such as AI-powered password cracking, adversarial inputs, and automated reconnaissance. v15 extends this with expanded real-world labs that simulate AI-driven phishing, deepfake social engineering, and defensive analysis using machine learning. If you last certified before 2024, this shift means your earlier study guides will miss significant exam content.4

Why EC-Council skipped v14

EC-Council does not officially confirm the reason, but version numbering jumps are common when updates coincide with major technology shifts. The leap to v15 likely reflects the depth of AI and automation additions, signalling a transformative update rather than an incremental refresh.

Do older study materials still work?

v11 and v12 books and videos are now outdated for the current exam. v13 resources cover most v15 topics, but the latest labs and AI extensions mean that v15-specific official courseware or updated third-party courses offer the safest preparation path. If you hold a v13 voucher, verify with EC-Council whether it remains valid for the v15 exam.5

CEH Certification Path at a Glance

The journey from first eligibility check to CEH Master designation typically spans four to eight months, depending on your experience level and chosen training path. Here is the end-to-end roadmap with approximate costs and timelines at each stage.

Six-step CEH certification timeline from prerequisites through renewal, with costs ranging from $100 to $2,999 per stage

Frequently Asked Questions

These are the questions career changers (especially those making a cybersecurity career change without it experience) and early cybersecurity learners ask most often about the Certified Ethical Hacker credential. Each answer is kept concise so you can scan quickly and dig deeper in the sections above.

The CEH Practical is a six-hour, fully hands-on exam delivered in a proctored lab environment. You face 20 scenario-based challenges that require you to demonstrate real skills such as vulnerability scanning, system exploitation, and packet analysis. There are no multiple-choice questions. You must reach a minimum score of 70 percent to pass. Completing both the knowledge exam and the Practical earns the CEH Master designation.

If you have zero IT experience, CEH is a steep entry point. EC-Council recommends at least two years of information security experience or equivalent training. Career changers typically benefit from building a foundation first, such as the Google Cybersecurity Professional Certificate Guide or a networking credential, before pursuing CEH. That said, the credential carries strong name recognition with employers and can accelerate your transition once you have baseline technical skills.

Total cost depends on your path. Official EC-Council training bundles (including the exam voucher) range from roughly $2,200 to $3,500. A standalone exam voucher purchased through EC-Council costs around $1,199, plus a $100 non-refundable application fee if you qualify through experience rather than official training. Renewal runs $80 per year in ECE (EC-Council Continuing Education) membership fees. Over a three-year cycle, expect to spend $3,000 to $4,000 or more.

CEH v13, released in 2024, introduced AI-driven ethical hacking modules and refreshed lab content. CEH v15, which began rolling out in late 2025, expanded coverage of cloud-native attack surfaces, advanced AI/ML exploitation techniques, and updated its toolset to reflect current threat landscapes. The exam blueprint domains remain similar in structure, but v15 added new objectives around generative AI risks. If you are registering now, you will sit for v15.

CEH and OSCP test fundamentally different skills. The CEH knowledge exam is a 125-question, multiple-choice test that emphasizes breadth of ethical hacking concepts, tools, and methodology. OSCP is a 24-hour practical penetration testing exam requiring you to compromise multiple machines. Most practitioners consider OSCP significantly more difficult and more technically demanding. CEH Practical bridges part of that gap but remains narrower in scope than OSCP.

CEH holders commonly pursue roles such as penetration tester, SOC analyst, vulnerability analyst, security analyst (see the how to become a security analyst roadmap), and cybersecurity consultant. The credential is also approved under DoD Directive 8570/8140 for certain government and defense contractor positions. Many mid-level security engineering and incident response roles list CEH as a preferred or required qualification, particularly in regulated industries.

Yes. CEH certification is valid for three years from the date you pass the exam. To maintain active status, you must earn 120 EC-Council Continuing Education (ECE) credits during each three-year cycle and pay the annual membership fee of $80. If you let it lapse, EC-Council may require you to retake the current version of the exam to reinstate your certification.

Recent Articles

In this article

Follow us