The International Council of E-Commerce Consultants (EC-Council) created the Certified Ethical Hacker (CEH) in 2003, which became one of the most widely held offensive security credentials in the world. EC-Council curriculum covers ethical hacking, digital forensics, network defense, and security operations, with programs deployed by the US Department of Defense, NATO member states, and security teams across more than 145 countries.
CEH and EC-Council credentials are formally approved under the US DoD 8570/8140 directive, making them effectively required for a large category of defense and government cybersecurity roles. For professionals building careers in penetration testing, incident response, or security operations, EC-Council certifications are a widely recognized baseline.
EC-Council organizes its 30-plus certifications into clear tiers. The Essentials series sits at the entry point: 9 beginner certifications including Ethical Hacking Essentials (EHE), Network Defense Essentials (NDE), and Digital Forensics Essentials (DFE), with no eligibility criteria and course bundles priced around $299. Above that sit the core role certifications, led by the flagship Certified Ethical Hacker (CEH) alongside Certified Network Defender (CND), Computer Hacking Forensic Investigator (CHFI), Certified SOC Analyst (CSA), Certified Incident Handler (ECIH), and Certified Threat Intelligence Analyst (CTIA). Specialist tracks cover cloud (CCSE), DevSecOps (ECDE), application security (CASE .NET and Java), encryption (ECES), ICS/SCADA, and disaster recovery (EDRP). At the top, the Certified Chief Information Security Officer (CCISO) targets security executives and relaunched as v4 in 2026.
Picking a starting point is mostly a budget and experience question. If you have no security background, an Essentials certification proves baseline skills for a fraction of CEH's cost: the CEH exam voucher alone runs $1,199 at Pearson VUE, and self-study candidates must clear an eligibility application before they can even buy it. If you already work in IT or security, CEH remains the credential hiring managers recognize, while specialists like CSA, ECIH, or CHFI map to specific SOC, incident response, and forensics roles and often make more sense than a second generalist cert. Whatever you pick, plan for renewal: every EC-Council certification is valid for 3 years and requires 120 ECE (EC-Council Continuing Education) credits per certification in that window, plus an $80 annual membership fee ($100 for CCISO).
CertCompanion carries practice banks for 20 EC-Council certifications, more than 12,000 questions in total. That includes all three original Essentials exams (EHE, NDE, and DFE with 626 to 627 questions each), the core lineup (594 CEH questions, plus CND, CHFI, CSA, ECIH, and a 740-question CTIA bank), the specialist tracks (ECES, ICS/SCADA, CASE .NET, CASE Java, CCSE, ECDE, EDRP, CCT, CSCU, and CEI), and 578 questions for CCISO. Every exam gives you 30 free questions, so you can gauge difficulty across two or three candidate certifications before committing to one.
The portfolio is moving fast right now. In February 2026 EC-Council launched an Enterprise AI Credential Suite, four role-based AI certifications (Certified AI Program Manager, Certified Offensive AI Security Professional, Certified Responsible AI Governance and Ethics, and AI Essentials) alongside the CCISO v4 overhaul, which EC-Council calls the largest single expansion in its 25-year history. If you are comparing EC-Council against other vendors in 2026, that AI push, plus AI-driven modules folded into CEH itself, is the clearest differentiator.
EC-Council · CASE-.NET
Validates the ability to build secure .NET applications throughout the software development lifecycle, covering secure requirements gathering, input validation, authentication and authorization, cryptographic practices, error handling, session management, and security testing.
EC-Council · CASE-Java
Validates the ability to build secure Java applications throughout the software development lifecycle, covering secure requirements gathering, input validation, authentication and authorization, cryptographic practices, error handling, session management, and security testing.
EC-Council · CCISO
Validates executive-level competency in information security leadership across five domains: governance, risk, and compliance; security controls and audit management; security program management and operations; core security competencies; and strategic planning, finance, and vendor management.
EC-Council · CCSE
Validates the ability to plan, configure, and secure cloud infrastructure across AWS, Azure, and GCP, covering platform and infrastructure security, identity and access management, data protection, security operations, cloud penetration testing, and incident response.
EC-Council · 212-82
Validates entry-level cybersecurity knowledge and hands-on skills across network defense, ethical hacking, forensics, incident response, cloud, risk, and security operations.
EC-Council · CEI
Validates instructional competency to deliver EC-Council certification training programs, covering instructor credibility, learning environment management, effective communication and questioning techniques, instructional methods and media, and learner performance evaluation.
EC-Council · CEH
Validates proficiency in ethical hacking techniques and tools across 20 security domains, including reconnaissance, network scanning, vulnerability analysis, system hacking, malware threats, social engineering, web application attacks, SQL injection, cryptography, and cloud and IoT security.
EC-Council · CND
Validates the ability to protect, detect, and respond to network security threats, covering network perimeter protection, endpoint security, firewall and IDS/VPN configuration, network traffic analysis, vulnerability scanning, and incident response.
EC-Council · CSCU
Validates foundational knowledge of personal and network security practices for end users, covering identity theft prevention, social engineering awareness, online fraud protection, malware defense, data security, and safe internet browsing habits.
EC-Council · CSA
Validates foundational and advanced skills in Security Operations Center monitoring and analysis, covering SOC operations, SIEM deployment and use cases, log management, incident triaging, indicators of compromise investigation, threat hunting, and malware analysis.
EC-Council · CTIA
Validates the ability to collect, analyze, and disseminate cyber threat intelligence at strategic, operational, tactical, and technical levels, covering threat actor profiling, cyber kill chain methodology, APT analysis, indicators of compromise, and OSINT techniques.
EC-Council · CHFI
Validates the ability to detect hacking attacks, extract and preserve digital evidence, and conduct forensic investigations, covering digital forensics methodology, evidence acquisition, chain-of-custody procedures, dark web forensics, IoT forensics, and malware forensics.
EC-Council · DFE
Validates foundational knowledge of digital forensics concepts and investigation processes, covering computer forensics fundamentals, disk storage and file systems, data acquisition, evidence handling for Windows, Linux, and Mac, network forensics, anti-forensics techniques, and malware analysis.
EC-Council · ECDE
EC-Council's current DevSecOps credential, exam 312-97, covering culture and secure practices across planning, coding, build and test, release and deployment, and operations and monitoring.
EC-Council · EDRP
Validates the ability to develop and implement business continuity and disaster recovery plans, covering business impact analysis, risk assessment, recovery strategy development, emergency response procedures, recovery site management, and disaster recovery plan testing and maintenance.
EC-Council · ECES
Validates expertise in cryptographic concepts and their practical application, covering symmetric and asymmetric algorithms (AES, DES, RSA, Elliptic Curve), hash functions, number theory, key management, and cryptanalysis techniques.
EC-Council · ECIH
Incident handling and response practice for ECIH v3 exam 212-89, covering the full response lifecycle and seven major incident categories.
EC-Council · EHE
Validates foundational understanding of ethical hacking and penetration testing concepts, covering information security fundamentals, threats and vulnerabilities, password cracking, web application attacks, IoT and OT security, cloud computing threats, and penetration testing methodology.
EC-Council · ICS-SCADA
Validates the ability to secure industrial control systems and SCADA networks, covering ICS/SCADA network defense, vulnerability assessment, risk analysis for IT and OT environments, intrusion detection, ICS-specific standards and regulations, and incident response for critical infrastructure.
EC-Council · NDE
Validates foundational knowledge of network security and defense concepts, covering identification, authentication, and authorization controls, firewall and IDS/IPS configuration, VPN and SIEM technologies, virtualization and cloud security, wireless and mobile device security, and administrative defense controls.
A domain-by-domain breakdown of the EC-Council CSCU exam (112-12): what it tests, where candidates stumble, study hours by background, and how to pass v3.
22 min readThe CCISO (712-50) isn't a technical exam. Here's what EC-Council is actually testing, how five domains break down, and how to prepare without wasting months.
20 min readEC-Council EHE (112-52) exam guide: 12 domains, pricing breakdown, trap questions, and what separates candidates who pass from those who fail.
27 min read