CREST vs OSCP vs CEH: Which Cert Actually Gets You Hired
The certification on your CV that impresses the hiring manager isn't always the one that took the most blood, sweat and caffeine to achieve.
I've spent six years placing penetration testers and security architects with US defence contractors and financial services firms, and there's a stark reality about security certifications that nobody seems willing to talk about: the value of a cert depends entirely on who's reading your CV.
The landscape has shifted dramatically
It's mid-2026 and the cybersecurity certification landscape looks nothing like it did three years ago. Some certs that used to open doors are now baseline expectations. Others have lost relevance entirely as the threat landscape evolved. Yet candidates keep grinding away for letters that might not actually advance their careers.
The practical, hands-on certs have pulled miles ahead of the theoretical ones. Hiring managers are tired of candidates who can recite textbook attack vectors but freeze when given access to a live environment.
Each cert tells a different story to a hiring manager.
Beyond Tick Boxes: Diversity Recruitment Strategies That Actually Transform UK Workplaces
Master the Virtual Hot Seat: 7 Video Interview Techniques Recruiters Don't Tell You
How to Master 'Tell Me About Yourself' Interview Question: UK Expert Insights
CREST: The UK standard-bearer
CREST certification remains the gold standard for UK security consultancies and financial institutions. Most serious penetration testing roles at British firms won't even look at you without it.
Why? The structured, methodical approach CREST-certified professionals bring aligns perfectly with the UK's regulatory environment. Financial services especially favour it because it demonstrates an understanding of governance alongside technical capability.
I placed a CREST-certified tester at a London bank last month at £115K. His American equivalent with an OSCP but no CREST couldn't get past the first interview for the same role.
What nobody talks about openly: CREST has a reputation problem in the US market. Many American firms consider it overly academic and less practical than its American counterparts. The structured methodology that UK firms love can be seen as rigid across the Atlantic.
So if you're looking to stay in the UK market, particularly in financial services or government-adjacent work, CREST is still king. But if you're hoping to follow some of my candidates to the States, you'll need something else.
OSCP: The hacker's choice
Offensive Security's OSCP is the certification that makes other security professionals nod with respect. The exam is legendarily difficult - a 24-hour practical hacking marathon that separates the script kiddies from the real thing.
US tech firms value OSCP above almost anything else for technical security roles. Why? Because it proves you can actually hack things, not just talk about hacking things. The practical nature of the certification aligns perfectly with the Silicon Valley "show, don't tell" mentality.
Over the past year, I've seen UK candidates with OSCP certifications snapped up by US firms offering remote roles with salaries 20-30% higher than their UK equivalents. The hands-on nature of the certification translates perfectly to the American market.
But OSCP has its limitations too. It doesn't demonstrate the governance, risk, and compliance knowledge that many enterprise security roles require. For technical roles, it's brilliant. For roles that interface with business stakeholders, less so.
CEH: The familiar name that's losing ground
The Certified Ethical Hacker qualification was once the entry ticket to the industry. Now? It's increasingly viewed as Security 101.
CEH still appears in job descriptions, particularly from organisations where HR writes the specs rather than security teams. It's got brand recognition outside the industry, which counts for something when non-technical managers are involved in hiring.
But among security professionals? The reputation has been in steady decline. The multiple-choice exam format and rote learning approach feels outdated in an era where practical skills are paramount.
I still see it requested for government contractor roles where certification boxes need ticking. But in 2026, a CEH alone won't differentiate you in a competitive market. It's become what ITIL was to IT service management - a baseline expectation rather than a differentiator.
I've placed candidates with CEH certifications, but never because of their CEH certification.
The real hiring secret: It depends who's hiring
The best certification is the one preferred by the specific segment of the industry you're targeting.
For UK consultancies and financial services: CREST For US tech firms and remote roles: OSCP For government contractors and large corporates: A combination approach
But certification preferences vary wildly by industry. Healthcare security teams prioritise different certifications than financial services. Critical infrastructure has its own preferences entirely.
The smartest move? Look at job postings from your target employers and see which certs appear most frequently. Then target those specifically.
Emerging certification trends to watch
The cloud-specific security certifications have exploded in value over the past 18 months. AWS Security Specialty and Azure Security Engineer certifications are now frequently requested alongside traditional security certs.
AI security specialisations are the new frontier. As companies integrate more AI into their infrastructure, the security implications are creating demand for specialists who understand both disciplines.
Remember that vendor-specific certifications (Palo Alto, Check Point, etc.) can often be more valuable than generic security certifications if you're targeting organisations that use those technologies.
What's actually on my candidates' CVs
The candidates I've successfully placed in the highest-paying roles typically have multiple certifications tailored to their career goals.
My most successful UK-to-US placements typically have:
- OSCP as their primary technical certification
- Cloud security certifications aligned to their target employer's infrastructure
- CISSP for roles with any management component
UK candidates staying in the domestic market typically have:
- CREST certification appropriate to their specialisation
- Industry-specific knowledge (financial services, healthcare, etc.)
- NCSC-approved certifications for government-adjacent work
There's no perfect answer that works for everyone. But there is a perfect answer for your specific career path.
Certificates don't get you hired. People who can demonstrate practical skills get hired. The right certification just gets your foot in the door for the interview where you can prove those skills.
Pursue whichever cert aligns with where you want your career to go, not where it's been.
Connor Walsh is a cybersecurity recruitment specialist who splits his time between London and New York, placing security professionals with US defence and financial services firms. He specialises in transatlantic security careers.

