Skip to content
Macksofy Technologies
OffSec rebrand explained

OSCP+ vs OSCP in 2026 — What Changed, What It Means for Indian Candidates

OffSec rebranded OSCP to OSCP+ in late 2024. Here's everything that actually changed in the 2026 exam — Active Directory expansion, buffer-overflow removal, CPE recertification — and how Indian candidates should adjust their prep.

OSCP OSCP+ OffSec PEN-200
Macksofy Editorial· Cybersecurity Training Editorial6 May 2026 9 min read
OSCP+ vs OSCP in 2026 — What Changed, What It Means for Indian Candidates — Certification Guides · Macksofy
In short

What is the difference between OSCP and OSCP+?

OSCP+ is the same exam with a currency requirement: OffSec rebranded the credential in late 2024 so OSCP+ lapses after three years unless renewed through continuing education, while plain OSCP stays lifetime but undated. The exam itself expanded Active Directory and dropped buffer overflow. Macksofy runs OSCP exam-prep bootcamps in India.

In late 2024 OffSec rebranded the OSCP exam to OSCP+ and changed enough of the underlying mechanics that 2024-syllabus content is now obsolete. If you're starting in 2026, you're studying for OSCP+ — not the legacy exam. Here's what's different and what it means for Indian candidates.

At a glance
OSCP (legacy, pre-Nov 2024)
  • Buffer-overflow box (25 points)
  • Standalone Linux + Windows + 3-host AD chain
  • Bonus 10 lab points for completing exercises + lab boxes
  • Lifetime certification — no recertification
  • PEN-200 v2.0 / v3.0 syllabus
OSCP+ (current, Nov 2024 onwards)
  • Buffer-overflow REMOVED
  • Full Active Directory chain expanded — single connected AD set worth ~40 points
  • Bonus lab points REMOVED
  • Cert valid 3 years — CPE-based recertification required
  • PEN-200 v4.0 syllabus + AWS cloud module

What was removed

  • Buffer-overflow standalone target — no more bespoke BoF practice for the exam
  • Bonus lab points — you can no longer 'bank' 10 points before exam day
  • Self-paced 'lifetime' certification — every OSCP+ now expires after 3 years

What was added

  • Expanded Active Directory chain — full 5+ host AD set worth ~40 of 100 exam points
  • AWS cloud module (PEN-200 modules 20–21) — IAM enumeration, S3 / EC2 / Lambda discovery, Pacu modules
  • Modern post-exploitation — RBCD, Shadow Credentials, ADCS abuse (ESC1-ESC8) covered explicitly
  • CPE-based 3-year recertification — the cert lapses without 90 CPEs

Why OffSec made these changes

Real-world penetration testing in 2024–26 is dominated by Active Directory and cloud — not by hand-rolled buffer overflows. OffSec aligned the exam with what hiring teams actually pay for. The recertification requirement also brings OSCP into line with industry standards (CISSP, GIAC) and makes the cert a continuing-education signal, not a one-time stamp.

How prep changes for OSCP+ in 2026

TopicPre-2024 weight2026 weight
Buffer overflowsSignificant — bespoke practiceZero
Active DirectoryModerate (3 hosts)Heavy (5+ hosts, ~40 pts)
Web exploitationModerateModerate
Privilege escalation (Linux + Windows)HeavyHeavy
Cloud (AWS) enumerationNoneModerate (PEN-200 mod 20–21)
ReportingRequired (basic)Required (stricter rubric)
Lab grinding for bonusWorth 10 pointsNo bonus — pure exam scoring

What hasn't changed

  • 24-hour exam window + 24-hour reporting window
  • 70 / 100 passing score
  • Hands-on practical format with required professional report
  • Mentor-until-pass support on the Macksofy bootcamp track
  • Recognition with hiring managers — OSCP+ is treated as 'OSCP' on every JD we've reviewed in 2026

Should I worry about the recertification clock?

Practically: no. 90 CPEs in 3 years is one OffSec annual subscription course (40 CPEs), one industry conference (8 CPEs/day) and a handful of webinars or blog posts. If you're working in security, you'll accumulate them by accident. The risk is for OSCP+ holders who leave security for unrelated roles and never log activities back into OffSec's CPE portal.

Cost in India in 2026

  • OffSec direct: PEN-200 + 90-day lab + exam ≈ ₹1,70,000 (USD 1,749)
  • Through Macksofy: the same official course + 90-day lab + exam voucher = ₹1,45,000 (15% off, 3/6/12-month EMI)
  • Macksofy 60h instructor-led bootcamp with mentor-until-pass support: quoted separately, on top of the bundle above
  • Self-study without a mentor: cheapest route, but you absorb every retake (~$249 per attempt) and get no structured AD lab time
Train with Macksofy

Macksofy's OSCP+ bootcamp is one of several hands-on tracks Macksofy delivers across India and the UAE. CERT-In empanelled, EC-Council accredited, with weekend cohorts and corporate batches.

View training catalog
FAQ

Quick answers.

Check your OffSec dashboard — anyone who paid for the legacy exam was given a grace window to attempt under the old format. As of 2026, all new exam vouchers are OSCP+ only.
Marginally. The AD chain is genuinely deeper, but the BoF removal compensates for it. Pass rates are roughly equivalent — Macksofy's 2024–25 OSCP+ cohort passed at 78% first-try, comparable to legacy OSCP cohorts.
Most JDs still say 'OSCP' as shorthand. Hiring managers understand they're the same credential. List it on your CV as 'OSCP+ (PEN-200)'.
Unlikely. The '+' positions OffSec for future tier expansion (OSCP++ etc.) and OffSec has invested heavily in the rebrand across marketing, partner materials and Discord.
Talk to us

Get a fixed-price proposal in 48 hours.

Tell us about your security need — pentest, audit, training or a wider engagement. A senior consultant will reply within a few business hours.

CERT-In Empanelled
Information Security Auditor · India
  • CERT-In Empanelled
  • EC-Council ATC · CompTIA Authorized
  • Thousands of professionals trained
  • India + UAE engagements