Skip to content
RESEARCH INDEX BREACHROAD / INTELLIGENCE NOTE

OSCE3 roadmap: choosing OSEP, OSWE and OSED in 2026

OSCE3 requires OSEP, OSWE and OSED. Compare technical scope, practical exams, prerequisite skills and the best order for three OffSec certifications.

PUBLIC RESEARCH
AUTHOR
/ CEO of Breachroad · OSCP · PNPT
PUBLISHED
26 June 2026
READING TIME
11 min read
TOPIC
Careers and Certifications
OSCE3 roadmap: choosing OSEP, OSWE and OSED in 2026

OSCE3 has no separate exam. OffSec awards it automatically after earning OSEP through PEN-300, OSWE through WEB-300 and OSED through EXP-301. Each develops a different offensive specialism and currently uses a 48-hour proctored practical assessment.

Choose the order through daily work and career direction, not an assumed difficulty ranking.

OSEP: operations inside hardened networks

PEN-300 focuses on breaching layers of defence: client-side execution, process injection, antivirus and application-whitelisting bypass, post-exploitation, Windows credentials, lateral movement, MSSQL and Active Directory.

OSEP suits internal penetration testers and red teamers. Its core skill is combining techniques into a multi-stage operation when a standard tool is detected or network controls block the direct route.

Candidates should be comfortable with Windows, Active Directory, PowerShell and C#. OSCP+ provides a foundation, while PEN-300 expects greater independence in modifying tools.

OSWE: white-box application analysis

WEB-300 teaches discovery of complex flaws in application source and exploit construction. Topics include upload and regex bypasses, PHP type juggling, magic hashes, PostgreSQL UDFs, SSTI, XXE, weak tokens and database-function RCE.

OSWE is the natural route for application testers and AppSec engineers. The key is tracing HTTP input through code to a dangerous sink and then automating exploitation.

Burp Suite alone is insufficient. Candidates need to navigate unfamiliar projects, use debuggers and understand frameworks quickly.

OSED: Windows exploit development

EXP-301 centres on Windows user-mode exploit development. Candidates work with debuggers, x86 architecture, process memory, protection bypasses and reliable exploit construction.

OSED is furthest from a conventional network pentest. It suits vulnerability research, reverse engineering and exploit development, requiring patient debugging and comfort with assembly and Python.

Choosing the order

For a network tester, OSEP → OSWE → OSED is sensible. An AppSec engineer may start with OSWE, continue with OSEP and finish on OSED. A vulnerability researcher may choose OSED first, although the other exams still demand breadth.

Avoid taking all courses in parallel. Each needs a different note system and reasoning style. Earn one credential, apply its skills in authorised labs or work, then move on.

Shared exam demands

OffSec gives 47 hours and 45 minutes for the OSWE technical portion; its proctoring table lists OSWE, OSEP and OSED as 48-hour supervised exams. Another 24 hours follows for documentation.

Reports need reproducible steps. The continuous command, code and evidence workflow used for an OSCP+ report scales to all three.

No fourth OSCE3 exam

After OSEP, OSWE and OSED, OffSec grants OSCE3 without an additional test. Its FAQ lists a digital certificate and badge plus a printed certificate, card and challenge coin.

OSCE3 demonstrates breadth across network operations, web exploitation and exploit development. It does not replace a portfolio. Sanitised reports, tools, research and vulnerability reasoning remain valuable in hiring.

A practical decision

Choose the first course through the problems you want to solve over the next year. Advanced red team: OSEP. Code review and web: OSWE. Memory analysis and exploits: OSED. OSCE3 is the outcome of three specialisms, not a reason to learn all of them superficially.


Choosing the order

OSEP, OSWE and OSED assess different skills, so order should follow work rather than a supposed difficulty ladder. Map current tasks to enterprise operations, web source review or exploit development, compare them with the latest syllabus and sample one week of exercises from each path.

Plan laboratory, documentation and review time, not only content consumption. Keep a log of hypotheses, failed attempts and evidence. OffSec may update syllabi, proctoring and exam guides; check official documents before purchase and again before the exam. OSCE3 is awarded after meeting the current requirements described in OffSec’s FAQ.

Sources: OffSec OSCE3 FAQ, PEN-300 Syllabus, WEB-300 Syllabus, OffSec proctored exams.

SHARE / COPY