Skip to content
Getting Digital
All certifications

EC-Council certifications

EC-Council sells the most argued-about credential we document. Nothing else in this section is simultaneously named in job adverts, accepted by public-sector hiring frameworks and dismissed by much of the profession it claims to certify. A hub page that tiptoes around that is useless to you, so this one takes a side.

Exam delivery: Pearson VUE or the EC-Council Exam Centre (remote proctored); an exam voucher from EC-Council or bundled with accredited training

Ask a recruiter about the CEH and the answer is warm. The letters are known, they survive the keyword filter that reads your application before a person does, and in government and defence contracting, where approved-credential lists decide who may even be proposed for a role, this one appears on them. Ask somebody who breaks into networks for a living and the answer flips, often sharply. Their objection is not snobbery about entry-level qualifications. Offensive security is judged by what you achieve under time pressure against a system that resists you, and 312-50 instead asks you to recognise tools, attack phases and countermeasures in a multiple-choice paper spanning twenty modules. Somebody can pass it without ever having gained a foothold on anything. Both camps describe the same certificate correctly, because they are answering separate questions. The recruiter is asking whether a hiring process will let you through. The tester is asking whether the work will get done once it has. We are not going to average those two into something diplomatic. The CEH buys you access to a process, not evidence of skill, and the only thing that matters when you are deciding is which of the two you are short of.

Who should pay for this, and who should keep their money

Pay for it where a specific employer, contract clause or public-sector role list demands it, because at that point the debate about rigour is irrelevant and no substitute exists. Pay for it if your seat is defensive or advisory. Analysts in a security operations centre, auditors, risk and compliance people all benefit from knowing an attacker's vocabulary and sequence, and nobody in those roles is expected to run the attack. Pay for it when your employer covers the training and the days that come with it. Keep your money if your goal is penetration testing and this is the first credential you buy yourself. The people who will interview you for that work weigh evidence of another kind entirely: an examination that sets real machines against you across a full working day or longer, then asks for a professional write-up of what you found and how far you reached. We do not yet document an exam of that shape, so we will not pretend to know any particular one's current rules; the format is the point. PenTest+ sits in between, mixing performance tasks into a booked paper and examining the planning and reporting that clients actually pay for. EC-Council's own reply to the criticism is CEH Practical: six hours, twenty challenges staged in its range, with both halves together yielding the Master designation. That practical half is the part that speaks to ability, and it is the part most candidates quietly skip.

A lapse here is not a pause

Plan the three years after your pass, not just the sitting. Maintaining the credential means logging continuing-education credits with EC-Council across that period and paying a membership charge every year rather than once, and the annual line is the one people forget because it arrives long after the exam is behind them. Miss either obligation and the certificate is not merely shown as out of date. It is withdrawn, and the way back is another exam rather than a catch-up on paperwork. Several bodies we cover let an expired pass sit harmlessly on a CV as a dated fact; this is not one of them. Exam fee, eligibility application and yearly charge, each dated to the day we checked it, sit on the CEH page.

Professional

Frequently asked

Will the CEH get me a penetration testing job?
On its own, rarely. It can get your application read, which is not nothing, and in public-sector or contractor hiring it is sometimes the box that has to be ticked before anything else is considered. What follows is a technical interview in which you are asked how you would approach a target and what you did last time, and a multiple-choice pass supplies no answer to that. Treat it as the entry to the process rather than the thing that wins it.
Must I take EC-Council's training to sit the exam?
No. There are two routes to eligibility: EC-Council's own course, which grants it automatically, or an application documenting two years spent working in information security, which carries a non-refundable charge of its own. The self-study route is far cheaper overall because official training bundles carry most of the cost of this credential. Our CEH page lists both routes with the fees as we read them.
Is the knowledge exam worth taking without the Practical?
If the requirement in front of you names the CEH, yes, since that requirement is usually satisfied by the multiple-choice credential alone. If you are buying it to prove capability, no. Budget for both parts from the start or reconsider the whole purchase, because the hands-on half is what a technical reader looks for and holding the pair also earns the Master designation.

Official certification portal: cert.eccouncil.org

Other vendors

Last reviewed 12 September 2026 · Getting Digital