The Complete Guide to EC-Council CEH v13 in 2026
Everything you need to understand the world's most recognized ethical hacking certification — the exam, the labs, the eligibility rules, and how to buy the official kit the right way.
Ask ten hiring managers to name an ethical hacking certification and nine will say CEH. That recognition is the whole point of the credential: it isn't the hardest offensive cert on the market, but it is the one that appears in job descriptions, procurement checklists, and DoD-aligned role requirements. If your goal is to get past the filter and into the interview, CEH is still the most efficient way there in 2026.
This guide covers what CEH v13 actually is, how the exam works, the eligibility rule that surprises most first-time buyers, and how to assemble a genuine kit without wasting money.
What CEH v13 is
CEH (Certified Ethical Hacker, exam code 312-50) is EC-Council's flagship offensive security certification. It teaches you to think like an attacker — reconnaissance, scanning, enumeration, exploitation, persistence, covering tracks — but with authorization and a defensive purpose.
Version 13 is the current release and the only version you can sit. Its headline change is the full integration of artificial intelligence into the ethical hacking curriculum — AI-assisted reconnaissance, automated vulnerability discovery, and the defensive side of AI-specific threats like prompt injection and model poisoning. In v12 that content was peripheral. In v13 it runs through the whole program.
The scope is deliberately broad. CEH v13 is structured around 20 modules, 221 hands-on labs, 550+ attack techniques, and 4,000+ tools, spanning networks, systems, web applications, wireless, mobile, IoT/OT, cloud, and cryptography. That breadth is both the strength and the criticism: CEH gives you a map of the entire offensive landscape rather than deep mastery of one corner of it.
The four phases: Learn, Certify, Engage, Compete
EC-Council built v13 around a four-part model, and understanding it explains what you're actually buying:
- Learn — the 20 modules of e-courseware, video lectures, and the guided iLabs range.
- Certify — the knowledge exam (312-50), and optionally CEH Practical.
- Engage — a four-part simulated ethical hacking engagement against a mock organization, where you capture flags across each phase in a consequence-free environment. It's your first "real" engagement, minus the career risk.
- Compete — year-long access to 12 CTF challenges of 4 hours each, released on a rolling basis to keep your skills current after certification.
Engage and Compete are package-dependent benefits, not automatic. Check what tier you're buying.
The exams
There are two, and the distinction matters more than most candidates realize.
CEH (knowledge exam — 312-50)
125 multiple-choice questions in 4 hours, delivered either through EC-Council's Remote Proctoring Service (RPS) from home or at a Pearson VUE test center.
The passing score is where people get confused. It varies between roughly 60% and 85% depending on the difficulty of your specific question pool — EC-Council uses a scaled scoring system, so harder question sets carry a lower threshold. You don't know your cut score in advance. Practically, aim for a consistent 80%+ on quality practice questions before you book.
Time isn't the enemy here — you have nearly two minutes per question. Breadth is. The exam ranges across all 20 modules and rewards recall of tool names, flags, port behaviors, and methodology order.
CEH Practical
A 6-hour practical exam with 20 real-life challenges in a live range. No multiple choice — you either get the flag or you don't. Passing both the knowledge exam and CEH Practical earns you the CEH Master designation.
Which should you take? If your target role is compliance-adjacent, government, or enterprise where the credential is a checkbox, CEH alone does the job. If you're aiming at a technical offensive role and want proof you can actually operate, CEH Master carries meaningfully more weight. Decide early, because it changes which package you buy.
The eligibility rule nobody expects
This catches almost every self-study candidate: you cannot simply buy a voucher and book the exam. EC-Council requires you to qualify first, via one of two routes:
- Official training route — complete EC-Council-accredited training (official courseware, iClass, an Authorized Training Centre, or an academic partner). Eligibility is automatic. This is why the courseware isn't optional overhead; it is the eligibility.
- Experience route — submit an eligibility application with proof of two years of information security work experience, plus a ~$100 application fee. Approval takes time and isn't guaranteed.
EC-Council requires candidates to complete the official CEH training to be entitled to take the certification exam unless they go the experience route. A pirated PDF satisfies neither. It doesn't register you, doesn't unlock labs, and doesn't make you eligible — it just costs you the exam attempt you thought you'd saved money on.
What a genuine CEH kit contains
Three components, and they do different jobs:
| Component | What it does | Can you skip it? |
|---|---|---|
| e-Courseware + video lectures | The 20 modules of official theory, and your eligibility | Only if you qualify by experience |
| iLabs (hands-on range) | 220+ guided labs on live targets — where CEH becomes a skill rather than a memory test | Technically yes; practically no, especially for CEH Practical |
| Exam voucher | Your seat, RPS (online proctored) or Pearson VUE | No |
Buying them separately usually costs more than a bundle. Buying them from a random marketplace usually costs more than both, once you count the codes that never redeem in Aspen.
Everything is redeemed and managed through Aspen, EC-Council's candidate portal at aspen.eccouncil.org — subscription codes, voucher release, exam dashboards, certificates, and ECE credits all live there. Use one consistent email address from day one; switching emails mid-process is the single most common source of voucher headaches. (See our Aspen portal walkthrough.)
CEH v13 packages at Security365
Four ways in, depending on how far you want to go:
🧪 CEH v13 AI Hands-On Labs — $149 (reg. $199) Official EC-Council iLab + lab guide videos + CTF challenges. The right pick if you already have courseware or eligibility and just need the range time.
📦 CEH v13 AI Complete Learning Bundle — $249 (reg. $499) Official labs + training videos + mock exam. Everything you need to learn CEH properly — add the voucher when you're ready to sit.
🎫 CEH v13 Elite Bundle (Global) — $849 (reg. $1,199) Official RPS exam voucher (online proctored) + LMS training + iLabs. The standard end-to-end path: learn, qualify, sit the exam from home.
🏆 CEH v13 AI Ultimate Certification Bundle — $999 (reg. $1,199) Official eCourseware + LSM training + labs + exam + the CEH Master path. If CEH Master is the goal, this is the cheapest route to it by a wide margin.
🛡️ Browse all EC-Council products
Everything we sell is 100% genuine, sourced through EC-Council's official distribution channels, delivered within 4–8 hours, with full official access durations — codes that redeem cleanly in Aspen, plus WhatsApp support if anything snags.
How to actually pass
A realistic 8–10 week plan for someone with basic networking and Linux under their belt:
- Weeks 1–2 — Networking and Linux refresh. Modules on footprinting, scanning, enumeration. Do every lab, don't just watch them.
- Weeks 3–5 — Vulnerability analysis, system hacking, web app attacks and SQL injection. These are the heaviest-weighted question areas.
- Weeks 6–7 — Wireless, mobile, IoT/OT, cloud, cryptography. Start timed question blocks of 50–75.
- Week 8 — Full-length mock exam. Fix the gaps. Book the exam immediately after — momentum matters more than one more week of reading.
- Weeks 9–10 (if going for Master) — CEH Practical prep. Two full 6-hour mock runs, recon to report.
Two habits that separate passers from repeat-takers: keep a lab journal (commands, flags, payloads, outcomes — it becomes your personal playbook and your interview material), and learn the methodology order, not just the tools. CEH questions frequently test when you'd use something, not just what it does.
Where CEH fits — strengths and honest limits
Strengths: unmatched name recognition; DoD 8140 approved, which keeps it on federal and cleared-contractor requirement lists; broad coverage that gives you a genuine map of the offensive landscape; a clear path to hands-on proof via CEH Practical and Master.
Limits: the knowledge exam is multiple choice, so it proves understanding rather than capability — OSCP holders will tell you this, and they're not wrong. It's broad rather than deep. And the eligibility step plus cost make it a real commitment.
The honest read: CEH gets you through HR filters and compliance requirements. If you also want technical credibility with practitioners, pair it — CEH Master for the hands-on proof, or CEH for the filter and something like OSCP for the depth. Many working pen testers hold both, for exactly these two different reasons.
For a rounded profile, CEH also pairs naturally with defense: see the complete guide to EC-Council CND for the blue-team counterpart. Offense plus defense is a combination employers consistently reward.
Renewal
CEH is valid for three years. Renewing means 120 ECE credits over those three years, plus the $80/year standard membership fee — and that one fee covers all of your standard EC-Council certifications, so stacking certs doesn't multiply the annual cost. Credits come from training, conferences, webinars, published research, and more. You submit them through Aspen. You don't re-sit the exam.
FAQ
Is CEH v13 worth it in 2026? If you need name recognition, a DoD 8140–approved credential, or a compliance checkbox — yes, and there's no close substitute. If you want to prove hands-on ability to a technical interviewer, CEH alone isn't enough; go for CEH Master or pair it with a practical cert.
Can I just buy a voucher and take the exam? No. You must either complete official EC-Council training or apply via the experience route (2 years in infosec, ~$100 application fee).
How hard is the CEH exam? Intermediate. Harder than Security+, easier than OSCP. The difficulty is breadth — 20 modules, hundreds of tools — not depth.
What's the passing score? It's scaled, typically 60–85% depending on your question pool. Target 80%+ on practice tests before booking.
CEH vs CEH Practical vs CEH Master? CEH is the 4-hour multiple-choice exam. CEH Practical is the 6-hour hands-on lab exam. Pass both and you're CEH Master.
Does my CEH v12 certification still count? Yes — your certification remains valid and renews through ECE like any other. v13 is what you'd sit for a new certification; there's no forced upgrade unless your employer requires it.
Do I need the labs? Technically no. Practically, yes. The labs are what turn CEH from a memorized glossary into a skill — and they're non-negotiable if you're attempting CEH Practical.
📘 CEH v13 Complete Learning Bundle · 🧪 CEH v13 Hands-On Labs · 🎫 CEH v13 Elite Bundle · 🏆 CEH v13 Ultimate Bundle · 🛡️ All EC-Council
Questions? Contact IT-MASTER Co. — fast response via WhatsApp. 👉 Get in touch
0 comments