CEH: What It Verifies
- Published
- 2026-08-01
- Content type
- Certification / Standards Authority
- Read time
- 1 min
CEH — Certified Ethical Hacker — is EC-Council's credential for offensive-security skill: finding and demonstrating exploitable weaknesses before an attacker does. It covers reconnaissance, scanning, gaining access, maintaining access, and covering tracks — the full attacker methodology, applied defensively.
What it verifies
CEH confirms someone can run a structured penetration test against real systems, not just describe attack techniques in the abstract. EC-Council requires 2 years of information-security experience to sit the exam without official training, or completion of an approved training course.
Who typically holds it
On the calibre° roster, CEH is checked for SOC Analyst — where understanding attacker methodology directly informs detection and triage, alongside Security+ and GWEB.
How calibre° verifies it
CEH status is checked against EC-Council's ASPEN credential ID before roster eligibility — not accepted as a self-reported claim. Full procedure: Verification.
FAQ
Is CEH a hands-on or theoretical certification?
Practical. Newer CEH tracks include a hands-on practical exam in addition to the knowledge-based exam, testing actual exploitation skill.
How does CEH differ from a pentest job title?
CEH is a credential; penetration testing is a job function. calibre° checks the credential as one input, alongside the calibration procedure described on [Verification](/calibre/verification) — not a substitute for it.
Why is CEH checked for SOC Analyst specifically?
Because triaging an active incident requires understanding the attacker's likely next move — see [SOC Analyst](/calibre/roles#soc-analyst) for the full set of certifications checked on that role.
Specify the role. We calibrate the match.