- What "Requirements" Actually Means for C)PEH
- Confirming You Are Chasing the Right Credential
- The Suggested Background: Three Routes In
- What the Exam Asks of You
- Fees, the Exam Combo, and What Is Not Included
- Proctoring and Open-Book: What Is and Is Not Settled
- The Knowledge You Need to Qualify in Practice
- Sequencing Your Preparation Around the Curriculum
- After You Pass: Validity and Renewal Requirements
- Who Benefits From the Credential
- Frequently Asked Questions
- Mile2 suggests one of three backgrounds: C)SP, 12 months of IT experience, or 12 months of networking experience.
- Those prerequisites are suggestions; no mandatory degree, reference, or training-hour gate is verified.
- Mile2 expressly permits testing without buying its course.
- The written exam has 100 multiple-choice questions, roughly two hours, and a 70% minimum passing grade.
What "Requirements" Actually Means for C)PEH
When people search for C)PEH requirements, they usually want to know one thing: what must I have done before I am allowed to sit the exam? For the Certified Professional Ethical Hacker credential from Mile2, the honest answer is more relaxed than most candidates expect. The issuer lists suggested preparation, not a hard eligibility wall. There is no verified requirement for a college degree, a professional reference, a minimum number of classroom hours, or a signed work-history attestation.
That does not mean the exam is easy to walk into cold. It means the gatekeeping is done by the content rather than by paperwork. The requirements that matter are the ones you impose on yourself: enough networking fluency, enough security vocabulary, and enough hands-on familiarity with tools to handle 100 multiple-choice questions spanning reconnaissance, cryptography, web attacks, exploitation, and reporting.
This article separates three layers so you can plan accurately: the issuer's suggested background, the exam's formal mechanics, and the practical knowledge you need to actually pass. If you want a broader orientation first, see What Is C)PEH Certification? before returning here.
Confirming You Are Chasing the Right Credential
Before you spend money, make sure the credential you are researching is the one you want. Several certifications in the security world use similar acronyms or similar-sounding names, and a surprising amount of online content blends them together. The credential covered on this site is the Mile2 Certified Professional Ethical Hacker, official designation C)PEH. Mile2 is both the governing and administering body.
It is not the same thing as EC-Council's CEH, not a GAQM exam, and not Mile2's own penetration-testing credentials such as C)PTE or C)PTE-A. Each of those has its own requirements, pricing, and curriculum. If a forum post, reseller page, or practice-question site quotes fees, domain weights, or pass rates, check which certification and which issuer it is actually describing. Requirements facts in particular do not transfer between credentials.
The Suggested Background: Three Routes In
Mile2's credential documentation recommends that candidates hold any one of the following before attempting the exam:
- Mile2 C)SP, the issuer's own security-fundamentals-level certification.
- 12 months of IT experience in any capacity that exposes you to systems, support, or administration.
- 12 months of networking experience, such as supporting routers, switches, firewalls, or network troubleshooting.
Read that list carefully: it is "any one," not "all three," and it is framed as a suggestion. Nothing in the verified material says Mile2 audits your employment history or blocks registration if you have none of the three. The suggestion exists because the exam presumes you already understand how networks and operating systems behave. Without that, the Reconnaissance & Enumeration and Exploitation and Post-Exploitation material becomes memorization instead of understanding.
Which route fits which candidate
| Your situation | Closest suggested route | What to shore up |
|---|---|---|
| Help-desk or sysadmin background | 12 months of IT experience | Network protocols, packet-level thinking, scanning concepts |
| Network technician or engineer | 12 months of networking experience | Web application attacks, cryptography, reporting practice |
| Career changer with no IT job yet | C)SP as a stepping stone | Foundations first, then the ethical hacking curriculum |
| Self-taught with home-lab experience | None formally, but experience may substitute in practice | Document your lab work and confirm you can explain, not just run, each tool |
If you are in the last two rows, treat the suggested background as a self-assessment checklist. Can you explain what happens during a TCP handshake? Can you describe why a hash is not encryption? If those questions feel uncomfortable, build the foundation before booking.
What the Exam Asks of You
The formal exam requirements are straightforward. The written examination consists of 100 multiple-choice questions with a time allowance of approximately two hours, and a minimum passing grade of 70%. It is delivered online through Mile2's learning-management system. Mile2's security page identifies the platform as LearnDash and describes a two-hour timed window that cannot be paused, so plan to sit the whole thing in one uninterrupted block.
Several things the published material does not say are worth knowing. The split between scored and unscored questions is not published. No official percentage allocation by topic has been verified, and no current exam-version identifier has been confirmed, so any source claiming to know which area is "weighted highest" is guessing. Likewise, there is no verified separate hands-on performance exam in the C)PEH specification. The labs that appear in Mile2's materials belong to the training course, not to the exam.
The curriculum your questions are drawn from
The current Mile2 course outline lists eleven headings: a course introduction plus ten substantive modules. They are best understood as preparation-curriculum headings, not as eleven officially weighted exam domains and not as an exhaustive blueprint. The headings are:
- Course Introduction
- Introduction to Ethical Hacking
- Cybersecurity Foundation
- Reconnaissance & Enumeration
- Cryptography
- Vulnerability Scanning & Analysis
- Web and Application Attacks
- Exploitation and Post-Exploitation
- Social Engineering
- Wireless Pentesting
- Reporting & Ethics
For a section-by-section walkthrough of what each heading covers, read C)PEH Exam Domains 2026: Complete Guide to All 11 Content Areas. Older reseller and academy pages sometimes show a 16-module list; those belong to earlier course versions and should not be mixed with the current outline.
Fees, the Exam Combo, and What Is Not Included
Money is a requirement too, so it helps to understand what you are actually buying. Mile2's public search index shows the C)PEH Exam Combo at a sale price of $500, against an original list price of $795. The Combo bundles an exam, a simulator or practice resource, a preparation guide, and two attempts. It is not the full training package.
Two cautions apply. First, the price was visible in the public search index but not exposed in the retrieved body of the dynamic product page, so confirm the live checkout amount before you commit. Second, a separately listed C)PEH Electronic Book Kit (indexed at $400) is preparation material, not an exam fee. No member versus nonmember pricing tier is published.
| Item | What it is | What it is not |
|---|---|---|
| Exam Combo | Exam, practice resource, prep guide, two attempts | Not the full instructor-led course |
| Electronic Book Kit | Study material | Not an exam fee |
| Third-party training bundles | Provider-specific courses and pricing | Not Mile2's examination fee |
| Extra attempts after both are used | Another retail purchase, per Mile2's FAQ | Not automatically included |
Mile2 expressly permits testing without purchasing its course, so a full training package is not a prerequisite. That makes the Combo the leanest official path for experienced candidates. A full cost walkthrough lives in C)PEH Certification Cost 2026: Complete Pricing Breakdown.
Proctoring and Open-Book: What Is and Is Not Settled
This is the area where Mile2's own documents do not line up neatly, so be careful about what you assume. The FAQ indicates that most standard exams can start on demand without a live-proctor appointment, naming other credentials (C)ISSO-A and C)PTE-A) as exceptions. The broader Policies and Procedures document (dated May 26, 2026) describes LearnDash delivery, an open-book exam, live camera and screen proctoring scheduled at least 48 hours ahead, randomized items, the ability to return to skipped questions, and immediate results. That document also says some exams require a proctor, and it is not reconciled with the FAQ for the standard C)PEH product.
The same policies describe identification requirements, accommodations, and a 30-day wait before a third attempt. No C)PEH-specific adaptive-testing or calculator rule was verified. For scheduling logistics and timing, see C)PEH Exam Dates 2026.
The Knowledge You Need to Qualify in Practice
Since formal eligibility is light, the real requirement is competence across the curriculum. Here are the areas that tend to separate prepared candidates from underprepared ones.
Reconnaissance & Enumeration
You should understand the difference between passive information gathering (public records, search engines, DNS data) and active probing (port scans, service banners, directory enumeration).
- Why enumeration follows reconnaissance and what each phase yields
- How open ports map to services and likely weaknesses
- What an authorized scope allows you to touch and what it forbids
Cryptography
Expect conceptual questions rather than math. Know what each primitive is for.
- Symmetric versus asymmetric encryption and when each is used
- Hashing for integrity, and why a hash is not reversible encryption
- Digital signatures, certificates, and the role of key management
Vulnerability Scanning & Analysis
Running a scanner is the easy part; interpreting its output is what gets tested.
- Distinguishing false positives from confirmed findings
- Prioritizing by exploitability and business impact, not raw severity labels alone
- Recognizing common weakness classifications such as CWE-style categories
Web and Application Attacks
This heading rewards familiarity with the standard web-risk catalog and API-specific issues.
- OWASP-style injection, broken authentication, and access-control flaws
- How API weaknesses differ from classic page-based web flaws
- Why input validation and output encoding defend different layers
Reporting & Ethics
The final heading is easy to underestimate. A finding that cannot be communicated is not useful to a client.
- Authorization, scope, and rules of engagement before any testing
- Structuring findings with evidence, impact, and remediation guidance
- Handling sensitive data discovered during an engagement responsibly
Also budget time for Exploitation and Post-Exploitation, Social Engineering, and Wireless Pentesting. The cover of the outline spells the latter "Wireless Pentesting" while the detailed section prints "Wireless Pen testing"; both refer to the same module. Because no official weighting is published, treat all eleven headings as fair game rather than gambling on a favorite.
Sequencing Your Preparation Around the Curriculum
You do not need an elaborate method here; you need a sensible order. The curriculum builds from concepts to attacks to documentation, so study in that direction. A reasonable four-week arrangement for someone meeting the suggested background:
Foundations and Recon
- Course Introduction, Introduction to Ethical Hacking, Cybersecurity Foundation
- Reconnaissance & Enumeration: schedule it early because later modules assume it
Defensive Concepts and Analysis
- Cryptography concepts
- Vulnerability Scanning & Analysis, with emphasis on interpreting results
Attack Techniques
- Web and Application Attacks
- Exploitation and Post-Exploitation, Social Engineering, Wireless Pentesting
Integration and Reporting
- Reporting & Ethics
- Timed practice sets sized to the 100-question, two-hour format
For a deeper resource plan, see C)PEH Study Guide 2026: How to Pass on Your First Attempt. When you are ready to test yourself under time pressure, the C)PEH practice tests mirror the multiple-choice style. Remember that third-party question banks are not authenticated real exam content, so use them to find weak areas, not to predict specific questions.
After You Pass: Validity and Renewal Requirements
Qualifying is not a one-time event. The credential is valid for three years. Current central renewal guidance describes 60 documented qualifying CEUs across the three-year cycle (commonly expressed as 20 per year), purchase of the applicable renewal product, seven Code of Ethics questions, and agreement to current policies. There is no annual membership requirement. The FAQ gives a U.S. standard CEU-route renewal price of $200, with eligible developing-region pricing potentially as low as $100, subject to confirmation at checkout.
Mile2 also publishes alternative renewal paths, including an exam-based route that involves passing the latest relevant exam, which may cost more. Here the sources diverge. The C)PEH course PDF describes both a current-exam pass and annual CEUs as requirements, while the central renewal pages present them as alternative paths. The May 2026 policy mentions a recertification assessment and completion within seven days of expiry, and its sections are not consistent on what happens after that window. Do not assume a universal seven-day grace entitlement, and do not equate an unspecified recertification assessment with either the full 100-question exam or the seven-question ethics acknowledgment.
Key Takeaway
Start logging qualifying CEU evidence from the day you pass, and confirm your applicable renewal route and deadline with Mile2 well before expiry. Do not rely on a grace period you have not verified in writing.
Ultimate Combo course access and any included exam voucher are generally valid for one year, which is distinct from the three-year credential life; Cyber Range access can have a shorter separate term. Use your voucher within its window.
Who Benefits From the Credential
Because the eligibility bar is modest, the C)PEH suits people moving into security from IT or networking roles: system administrators, network engineers, and junior security analysts building toward offensive-security work. Its value to an employer is largely as evidence that you understand the full attack lifecycle and the ethics around it, from scoping through reporting.
Be cautious with salary claims. Mile2's outline advertises $80,077 in annual salary potential, but without a dated credential-holder sample or stated methodology; that is issuer marketing, not a verified 2026 average or proof that the credential caused a pay premium. For a balanced look, read C)PEH Salary Guide 2026 and Is the C)PEH Certification Worth It?. Note too that Mile2's policy identifies C)ISSO-A and C)PTE-A as ANAB-accredited offerings, but that does not establish accreditation for the standard C)PEH.
If you are comparing job outcomes, C)PEH Jobs explores the roles where this credential tends to be listed.
Frequently Asked Questions
No degree requirement is verified. Mile2 suggests one of three backgrounds (C)SP, 12 months of IT experience, or 12 months of networking experience), and these are recommendations rather than a mandatory gate.
No. Mile2 expressly permits testing without purchasing its course. The Exam Combo (exam, practice resource, preparation guide, and two attempts) is a separate, leaner option, though you should confirm the live checkout price before buying.
The written exam has 100 multiple-choice questions in approximately two hours, with a minimum passing grade of 70%. The scored versus unscored split is not published.
No separate hands-on performance exam is verified in the C)PEH specification. The 16 labs belong to the training course, not to the exam itself.
The current central guidance describes 60 documented qualifying CEUs over the cycle, the applicable renewal product, seven Code of Ethics questions, and agreement to current policies, with an exam-based alternative also published. Confirm your route and deadline with Mile2 before expiry, since sources do not align on every detail.