OSCP exam scoring and a 24 hour time budget
The OSCP exam is 100 points across one Active Directory set and three standalone machines, and until 30 November 2026 you need 70 to pass. From 1 December 2026 OffSec switches to scaled scoring, so the pass threshold will depend on your exam set; this page covers both, plus a 24 hour plan you can rehearse.
How OSCP points work
The exam has four parts: one Active Directory set worth 40 points and three standalone machines worth 20 points each, for 100 in total. Each standalone is usually split into 10 points for a local (low privilege) flag and 10 for the proof (root or SYSTEM) flag. That is the structure described in OffSec's OSCP+ exam guide; confirm it on the live page, because OffSec edits it.
The 2026 scoring change
On 6 October 2026 OffSec published its OSCP+ scoring update. Starting 1 December 2026, the points you earn are converted to a scaled score using a conversion specific to your exam set, and the passing threshold varies by set. Through 30 November 2026 the fixed 70 out of 100 rule still applies.
OffSec says the exam still has three standalone machines and one Active Directory chain, with the same 24-hour duration, grading requirements and proctoring. It also says results issued before the change will not be recalculated, and that no change to your study approach is needed. The post publishes no new numeric cut score, so the safest plan is to aim well above 70 raw points rather than for the old line exactly.
Which combinations reach 70 (old fixed rule)
This table uses the fixed 70 point line that applies through 30 November 2026. After that date treat it as an effort guide, since the equivalent threshold depends on your set.
| Combination | Points | Reaches 70? |
|---|---|---|
| Complete AD set, one full standalone, and one more standalone local flag | 70 | Yes |
| Complete AD set and three standalone local flags | 70 | Yes |
| Complete AD set and two full standalones | 80 | Yes |
| Complete AD set and one full standalone | 60 | No, 10 short |
| Three full standalones, no AD points | 60 | No, 10 short |
| Three full standalones plus 10 partial AD points (only if your set awards partial credit) | 70 | Yes |
The Active Directory set is the swing: with all 40 points you need only 30 more. Without it, three perfect standalones stop at 60.
An hour-by-hour 24h plan
| Hours | Focus | Checkpoint |
|---|---|---|
| 0:00 to 0:45 | Setup and recon | VPN up, notes open, full port scans running against every target in the background. |
| 0:45 to 5:00 | Active Directory set | The biggest block of points, so it gets the freshest hours. Stop at 90 minutes without a new lead. |
| 5:00 to 5:30 | Break | Eat, walk, reread your notes. |
| 5:30 to 8:30 | Standalone one | Local flag first, then escalation. Take proof screenshots the moment you get a flag. |
| 8:30 to 11:30 | Standalone two | Same loop. Log the time of every flag. |
| 11:30 to 14:30 | Standalone three | If it is not moving, rotate to a box with an open lead. |
| 14:30 to 15:30 | Rest | A real break, or a short sleep if you function better with one. |
| 15:30 to 19:30 | Second pass | Return to the stuck boxes with fresh eyes. Re-run enumeration you rushed. |
| 19:30 to 21:30 | Evidence sweep | Stop hunting new points. Retake any missing proof screenshots and reproduce key steps. |
| 21:30 to 24:00 | Buffer | Finish notes, shut down cleanly, and write the report skeleton while it is fresh. |
The plan front-loads the biggest block of points and keeps the last hours free. Adjust the order if recon shows a quick win, but keep the breaks.
The 90 minute rabbit hole cap
Set a hard rule before you start: 90 minutes on one box with no new flag and no new lead means you move. Write down where you stopped and the next idea, then switch. When you come back, re-enumerate from the top before trying anything exotic.
The report deadline
Per OffSec's reporting requirements, the report is due 24 hours after the exam ends, delivered as a PDF inside a .7z archive. Confirm the file naming and size rules on the live page. Do not plan to write from scratch: keep a running log during the exam and finish the report skeleton in the buffer hours. See the OSCP report template for a structure you can paste.
Practise the pacing in ZeroBox
The ZeroBox exam simulator runs a timed OSCP session with the same four-part layout. It shows live pacing against the 24-hour clock, a burndown chart of points remaining against time, break countdowns, and a rabbit-hole warning when one box has had 90 minutes without a flag. Rehearse on boxes from the TJ Null list or the OSCP-like machine catalogue, then read what the burndown chart says about where your time went.
Rehearse the clock before the real one.
Run a timed mock exam with pacing, a burndown chart and a rabbit-hole warning, all offline in your browser.
Frequently asked questions
Do I still need 70 points to pass the OSCP?
Through 30 November 2026 the pass mark is 70 out of 100. From 1 December 2026 OffSec converts raw points to a scaled score specific to your exam set, so the threshold varies by set. OffSec states that the competency required to pass does not change.
How long should I stay on one machine?
A common rule is 90 minutes with no new flag and no new lead. Past that point, switch targets and come back later. The ZeroBox exam simulator warns you at that mark and lets you snooze the warning for 30 minutes.
How long do I have to submit the report?
Per OffSec's exam guide, you get 24 hours after the exam ends to upload the report. Confirm the current rule on the live OffSec help center page before your attempt.
Does the ZeroBox simulator use the new scaled scoring?
No. The simulator uses a fixed 70 point threshold, because OffSec has not published per-set conversions. Use it to practise pacing and evidence handling, not to predict your result.
Related
- Exam simulator
- TJ Null OSCP list
- OSCP-like machines by difficulty
- OSCP report template with CVSS findings
- Pentest methodology checklist
Sources
- OffSec: OSCP+ Scoring Update (published 2026-10-06)
- OffSec Help Center: OSCP+ Exam Guide
- OffSec Help Center: OSCP+ Reporting Requirements
Last reviewed: 2026-10-08. ZeroBox is an independent project and is not affiliated with OffSec or Hack The Box.