Certified Ethical Hacker: What It Really Measures

‘Certified Ethical Hacker’ is the badge everyone has heard of — which is exactly why it ends up over-weighted in tenders and job specs. Here’s what the CEH honestly proves, what it doesn’t, and what actually tells you someone can hack.

What it is
EC-Council knowledge cert (v13)
Format
125 multiple-choice questions
Better signals
OSCP / OSWE / CREST + CVEs
Our view
A floor, not a measure

What the CEH is

The Certified Ethical Hacker, run by EC-Council and currently at version 13, is one of the most widely recognised security certifications in the world. The standard exam is 125 multiple-choice questions over four hours, covering 20 domains — reconnaissance, scanning, enumeration, system hacking, malware, web application attacks and more. It’s a ‘breadth’ certification: it maps the whole ethical-hacking workflow at the level of concepts and tools. There is also an optional six-hour, hands-on CEH Practical; passing both earns the ‘CEH Master’ designation, but the practical is the exception, not what most CEH holders have.

What it actually measures

A multiple-choice pass measures knowledge: that you can recognise the right answer about a technique, tool or concept. That’s genuinely useful — it’s a solid foundation, and it’s valued for analyst, SOC and government roles where breadth of understanding matters. What it does not measure is whether you can sit in front of an unfamiliar, hardened system and actually find a way in. Recognising an attack in a list of four options is a different skill from executing one against a live target that is trying to stop you.

Why the certificate alone is a poor measure of an ethical hacker

Because the thing you’re actually buying — when you hire an ethical hacker — is the ability to find real, exploitable weaknesses that a scanner and a checklist miss. The standard CEH doesn’t test that. Contrast it with the OSCP, which is a fully hands-on, time-pressured exam where you have to compromise machines and document exactly how; it’s widely treated as the ‘gold standard’ precisely because it proves execution rather than recall. Requiring ‘CEH’ by name in a tender can therefore let through someone who has never demonstrably broken into anything, while screening out a researcher with a shelf of CVEs who never bothered with that particular exam.

What actually indicates a capable ethical hacker

Weight these far above any single certificate:

  • Hands-on qualifications — OSCP, OSWE and CREST’s CRT/CCT are earned by doing, not by multiple choice.
  • A verifiable track record — published CVEs the person personally discovered, a bug-bounty history against real targets, and responsible-disclosure credits. These are independently checkable and very hard to fake.
  • Independent accreditation — CREST accredits the company against an audited standard for methodology, reporting and data handling.
  • A sample report and honest scoping — evidence they can communicate findings and won’t sell you a test you don’t need.

Being fair to the CEH

None of this makes the CEH a bad certification. It’s a credible foundation, it demonstrates commitment, it’s recognised internationally and it’s mandated for certain roles (including US Department of Defense workforce categories). Many excellent hackers hold it. The argument here is narrow and specific: don’t use the CEH badge as your measure of whether someone can actually hack. Use it as one data point, then look at what they’ve demonstrably done.

How we’d rather be judged

By the work — and there is a lot of it on record. Solusec holds company-level CREST accreditation, and our testing is led by a hacker with over 500 valid bug-bounty findings, published CVEs discovered first-hand, and responsible-disclosure credits from organisations including SAP, Red Bull, Western Union, Carta and American Express. He has been on the invitation-only Synack Red Team since 2022, earning Envoy, Hero, Olympian and Circle of Trust recognition, and holds hands-on qualifications including OSCP and OSWE — the product of a 25-year career and thousands of hours of hands-on testing. Every part of that is verifiable, which is more than any exam pass can offer, and it is the standard we think you should hold any ethical hacker to.

Common questions

Is the CEH worthless, then?

Not at all. It’s a credible, widely recognised foundation that proves breadth of knowledge, and it’s required for some roles. The point is narrower: a CEH on its own doesn’t prove someone can find and exploit real vulnerabilities, so it shouldn’t be your sole measure.

CEH or OSCP — which is better?

They measure different things. CEH is a broad multiple-choice knowledge exam; OSCP is a fully hands-on practical where you have to actually compromise systems and report how. For demonstrated offensive skill, OSCP (and real-world track record) carries far more weight.

Should I require a Certified Ethical Hacker in my tender?

We’d advise against requiring it by name. Ask instead for independent accreditation such as CREST and for evidence of demonstrated ability — a sample report, hands-on qualifications, and a verifiable track record. That gets you a better tester and a wider, fairer field.

Does Solusec hold the CEH?

Our testing is led by a hacker holding hands-on qualifications including OSCP and OSWE, backed by multiple published CVEs and Synack Red Team membership — the things that actually demonstrate ability. We’re happy to share specifics; we’d rather you judged us on verifiable work than on any single badge.

Related

Judge us on the work, not the badge

Ask us what we’ve personally found. You’ll get CVEs, disclosures and a CREST-accredited report — not a certificate on a CV.