Certification Decision Tool
Is this certification relevant to your route?
Five answers, one call. Everything below is composed from records TechWaymark already holds: the vendor page someone read, TechWaymark's certification intelligence, the public market verdict and the recorded ruling for your target role. There is no score and no ranking.
Free, no account, and nothing you choose here leaves your browser.
Your position
OSCP+ for SOC Analyst
Limited value for this route
On this route, OSCP+ buys less than the time and money it costs.
- Offensive cred won't help you tune a SIEM.
- By study effort this is a professional level exam and you are earlier than the stage it is usually sat at. That is a sequencing observation, not an entry requirement: effort bands say how much ground the syllabus covers, not who is allowed to book.
- On recruiter recognition this one does the job it is being asked to do.
This is a read on relevance, not a prediction. Nothing here is a guarantee of an interview, an offer or a salary.
UK hiring signal
Pentest consultancy and red-team JDs name OSCP as required or strongly preferred. CHECK and CREST CRT sit alongside it for regulated UK work, but recruiter shortlist behaviour treats OSCP as the default filter.
- Signal strength: High
- TechWaymark's market call: Strong
Practical depth
Still the most-recognised offensive cert, but it gates on lab time, not on the exam itself. Hands-on depth is recorded as very high.
- Lab persistence and stamina
- Offensive practicality, not theory
- Credibility with consultancies
Career-stage fit
By study effort this is a professional level exam and you are earlier than the stage it is usually sat at. That is a sequencing observation, not an entry requirement: effort bands say how much ground the syllabus covers, not who is allowed to book.
- Sysadmins and SOC analysts with active homelab time targeting a first pentest consultancy seat
- Internal movers in security teams formalising existing offensive reps for a consultancy hire
- AppSec and red-team candidates pairing OSCP with OSEP, OSWE or CRTO to widen senior shortlist coverage
Eligibility and prerequisites
Nothing here is a hard gate unless the vendor page says so. Recommended experience is the vendor's guidance about comfort with the syllabus, not permission to sit the exam.
- Recorded prerequisite: TryHackMe / HTB consistency
- Recorded prerequisite: eJPT or PNPT first
- Vendor recommended experience, not a bar to booking: OffSec expects TCP/IP networking, working Windows and Linux administration, some Active Directory, and Bash or Python scripting before starting.
Route relevance
Offensive cred won't help you tune a SIEM. Easiest cyber entry. Saturated by bootcamps, but real shifts thin the field fast.
- Recorded ruling for SOC Analyst: skip
- Basis: explicit TechWaymark ruling
What it cannot compensate for
A certification changes what a filter does with your name. It does not change what you can show a panel.
- Red team engagements alone
- AppSec engineering
- Senior architecture work
- Career changers with no Linux, networking or scripting fundamentals. The exam will end at hour eight rather than hour twenty-four.
- Compliance-track or GRC-leaning candidates. CISSP, CISM or CRISC carry more weight on those shortlists.
- No paid experience yet. The exam will not stand in for the first role.
Opportunity cost
Roughly 200 hours of part-time study for a professional level exam. That is the same block of time as a small piece of work you could show instead, so the comparison is worth making honestly.
- TechWaymark holds more than one figure for this exam (£1,298 (PEN-200 bundle) and £1,400+), so no single amount is shown. Take the vendor's published price as the current one.
- Typical study window: 3–6 months
- Validity: lifetime
Better or adjacent, on the record
Only certifications TechWaymark has already ruled useful for this target appear here.
Closer to the actual job than Sec+, alerts, triage, mindset.
Free, vendor-relevant, lands well in the interview.
Microsoft Certified: Security Operations Analyst Associate
Direct fit for Microsoft Sentinel / Defender shops.
Hands-on defensive lab work. Reads as 'has done shifts before'.
Where this comes from
Most recent vendor review recorded: 2026-09.
OSCP+ (PEN-200). The PEN-200 exam now awards OSCP+, which carries a three-year validity, alongside the lifetime OSCP designation. Existing OSCP holders keep their credential.
Signal, hands-on depth, prerequisites and what the exam does not unlock.
Market-level call "Strong", confidence High. UK pentest consultancies and red-team functions continue to treat OSCP as the working-class senior signal. CREST CRT carries regulatory weight, but OSCP carries practitioner weight, and the two reinforce rather than replace each other.
Recorded ruling for SOC Analyst.
Vendor pricing moves by region and promotion. Figures are indicative, not quotes.
Keep this with your route
No Route Brief is saved in this browser yet. A brief puts this certification in sequence with everything else the move needs.
Plot a routeRead the full page on OSCP+, or compare two exams side by side at cert compare.