Latest CEH Exam Pattern Changes
CEH exam pattern changes in v13 mean 125 multiple-choice questions over four hours, a separate six-hour practical exam with 20 live hacking challenges, and new modules covering AI-powered threats, cloud hacking, and OT/SCADA security. Domain weightings have shifted significantly from v11 and v12, making older study materials insufficient for 2025 and 2026 candidates.
- CEH v13 adds AI-driven attack and defence modules not present in v12, covering topics like AI-powered malware and automated threat hunting.
- The practical exam (CEH Practical) is now actively recommended alongside the knowledge exam by major hiring companies in India and globally.
- Question count and time limits have been revised: 125 MCQs, 4-hour window, with a passing score typically between 60-85% depending on the question set.
- Domain weightings have shifted, with footprinting, AI threats, and cloud hacking receiving more emphasis than before.
What Are the Latest CEH Exam Pattern Changes in 2026?
EC-Council officially released CEH v13 in late 2024, and the CEH exam updates that came with it are significant enough that candidates upgrading from v11 or v12 need to re-study core sections. The biggest structural change is the formal inclusion of artificial intelligence as both a threat vector and a defensive tool within the exam syllabus.
According to EC-Council’s official documentation, CEH v13 covers 20 modules, the same count as v12 but with substantially revised content across at least six of them. The AI and machine learning module is entirely new. Candidates are now tested on how attackers use AI to automate reconnaissance, generate phishing content, and evade detection systems.
The CEH Practical exam runs for six hours and requires candidates to complete 20 real-world hacking challenges in a live lab environment. It is proctored, timed, and cannot be cleared through memorisation alone. India’s IT and cybersecurity hiring managers at firms like Infosys, Wipro, and TCS increasingly ask for the CEH Practical badge alongside the knowledge certificate because it proves hands-on capability, not just theoretical recall.
CEH v13 Exam Format at a Glance
| Component | Details |
|---|---|
| Exam Type | Multiple Choice (Knowledge) + Practical (optional but recommended) |
| Number of Questions | 125 MCQs |
| Duration (Knowledge) | 4 hours |
| Duration (Practical) | 6 hours |
| Practical Challenges | 20 real-world hacking scenarios |
| Passing Score | 60-85% (adaptive, varies per question set) |
| Delivery | ECC Exam Centre or VUE Proctored |
| Validity | 3 years (ECE credits required for renewal) |
| New Focus Areas | AI threats, cloud hacking, OT/SCADA, modern malware analysis |
CEH v12 vs v13: Key Domain Weighting Shifts
| Domain Area | CEH v12 Emphasis | CEH v13 Emphasis |
|---|---|---|
| AI-Powered Threats | Not present | High (new dedicated module) |
| Cloud Hacking | Moderate | High (expanded coverage) |
| Footprinting and Reconnaissance | High | High (AI-assisted techniques added) |
| Session Hijacking | High | Moderate (proportionally reduced) |
| SQL Injection | High | Moderate (still tested, less weighted) |
| OT/SCADA Security | Low | Moderate (expanded) |
| IoT Hacking | Moderate | High (updated attack vectors) |
The CEH v13 exam pattern changes redistribute marks across domains compared to previous versions. Cloud computing threats, AI-assisted attacks, and IoT hacking have gained weight. Classic topics like session hijacking and SQL injection are still present but carry proportionally less emphasis than they did in v11.
EC-Council reports that over 6,000 organisations globally recognise CEH as a baseline cybersecurity credential, including US Department of Defense contractors under DoD 8570 compliance requirements. That institutional demand is part of why the exam keeps evolving: the threat environment changes, and a static exam becomes irrelevant fast.
Why CEH Exam Pattern Changes Matter for Students and Professionals
For students just entering cybersecurity, the updated pattern is good news. The practical component means your certificate signals real skill, not just the ability to memorise a textbook. Employers can trust it more, which translates to better starting salaries and faster shortlisting.
For working professionals holding an older CEH version, the changes create urgency. According to the (ISC)² Cybersecurity Workforce Study 2023, the global cybersecurity workforce gap stands at 4 million professionals. India alone needs hundreds of thousands of trained practitioners. Holding a current, v13-aligned certification puts you in a much stronger position in that market.
The AI module changes are particularly relevant. A 2024 IBM X-Force Threat Intelligence Index report found that AI-generated phishing attacks increased in sophistication and volume by over 40% year-on-year. If you can demonstrate you understand how attackers use AI, you are solving a problem that most security teams are actively worried about right now.
Impact on Indian IT Professionals Specifically
India has one of the largest pools of CEH-certified professionals in Asia. Many of them hold v10 or v11 certifications that are either expired or no longer aligned with current hiring expectations. The CEH exam pattern changes in v13 create a clear upgrade path, and Indian candidates who complete the practical exam component gain a competitive edge over peers who only hold the knowledge badge.
According to the Data Security Council of India (DSCI) Annual Information Security Survey, demand for certified ethical hackers and penetration testers in India grew by over 35% between 2022 and 2024, with average salaries for CEH-certified professionals ranging from INR 6 lakh to INR 18 lakh depending on experience and role. Candidates holding both the CEH knowledge and practical badges consistently command offers at the higher end of that range.
If you are working toward roles in SOC analysis, penetration testing, or red team operations, pairing your CEH preparation with a structured SOC Analyst Certification Course builds the contextual knowledge that makes the practical exam significantly easier to clear.
How Beginners Can Get Started with the New CEH Pattern
Start with the basics before you touch any CEH-specific material. You need a working understanding of networking (TCP/IP, DNS, HTTP), operating systems (Linux and Windows), and basic scripting (Python or Bash). Without that foundation, the practical sections of the CEH v13 exam format will feel overwhelming.
Once you have the fundamentals, map your study plan to the 20 modules in CEH v13. Do not treat every module equally. Modules on footprinting, scanning, system hacking, and the new AI threats module carry heavier practical weight. Spend more time in labs on those areas.
Recommended Preparation Path
- Build networking and OS fundamentals first, ideally with hands-on practice on a home lab or cloud VM.
- Enrol in a structured CEH v13 course that covers all 20 modules with updated labs. 3.0 University’s Certified Ethical Hacker v13 programme is built specifically around the updated exam pattern and CEH exam syllabus update for 2025 and 2026.
- Practice in live lab environments using tools like Kali Linux, Metasploit, Wireshark, and Burp Suite. The practical exam uses real tools, not simulations.
- Attempt mock tests that reflect the adaptive scoring format. Your target should be consistently clearing 75%+ before booking the actual exam.
- Register for the CEH Practical alongside the knowledge exam if your target employers or roles require demonstrated hands-on skill.
What Skills and Courses Help with CEH Exam Pattern Changes?
Beyond the CEH course itself, the skills that directly support exam success include network packet analysis, vulnerability assessment, web application testing, and basic malware analysis. The AI module requires you to understand how machine learning models can be used in attack chains, so even a surface-level familiarity with AI-powered penetration testing concepts helps.
Courses in cloud security, ethical hacking, and threat intelligence all reinforce CEH content. You can browse a full range of relevant programmes through 3.0 University’s full cybersecurity certification catalogue to find what fits your current level and career goal.
Frequently Asked Questions
What are the latest changes in the CEH exam pattern for 2026?
CEH v13, the current version going into 2026, includes 125 MCQs over four hours, a six-hour practical exam with 20 live hacking challenges, and new modules covering AI-powered threats, cloud hacking, and OT/SCADA security. Domain weightings have shifted to reflect modern attack techniques, and AI-assisted offensive and defensive methods are now testable topics under the updated CEH exam syllabus.
How many questions are in the CEH v13 exam?
The CEH v13 knowledge exam contains 125 multiple-choice questions delivered over a four-hour window. The separate CEH Practical exam does not use MCQs; instead, it presents 20 real-world hacking challenges in a live lab environment over six hours. Both components test different skill sets and together qualify you for the CEH Master designation.
What is the passing score for CEH v13?
The passing score for CEH v13 is adaptive and typically falls between 60% and 85% depending on the specific question set assigned to your exam session. EC-Council uses a cut-score methodology that adjusts based on question difficulty. Consistently scoring 75% or above on practice tests is a reliable benchmark before booking your actual exam.
Is the CEH Practical exam compulsory?
Technically, the CEH Practical is a separate, optional credential. In practice, many top employers, especially those working with US DoD contracts or large Indian IT firms, now strongly prefer or require it alongside the knowledge exam. Clearing both earns you the CEH Master designation, which carries significantly more weight in competitive hiring situations.
How long does it take to prepare for CEH v13?
Most candidates with a basic IT background need between three and six months of dedicated preparation. If you are coming in with networking and Linux experience, you can realistically prepare in 10 to 12 weeks. Beginners with no IT background should budget six months or more and spend the first month purely on foundational skills before touching CEH-specific content.
Why do CEH exam pattern changes matter for my career in India?
India’s cybersecurity talent gap is significant. The Data Security Council of India (DSCI) has consistently flagged that demand for trained security professionals far outpaces supply, with growth in certified ethical hacker roles exceeding 35% between 2022 and 2024. Holding a current, v13-aligned CEH with the practical component signals to Indian and global employers that your skills match real-world threats, not outdated exam content from five years ago.
Can I upgrade from CEH v11 or v12 to v13?
Yes. EC-Council offers an upgrade path for existing CEH holders. You will need to check your ECE (EC-Council Continuing Education) credit status and may need to sit an updated exam depending on when your certification was issued. Contact EC-Council directly or speak with an accredited training partner like 3.0 University to confirm the exact upgrade requirements for your situation.
The CEH exam pattern changes in v13 reflect where real-world threats have moved, and that is exactly why they matter. If you are serious about a career in ethical hacking or cybersecurity, getting aligned with the current pattern is the clearest step you can take right now.
Your next step is straightforward: review the updated syllabus, identify the modules where you need the most lab practice, and enrol in a course built around the v13 format. 3.0 University’s full cybersecurity certification catalogue covers CEH v13, SOC operations, cloud security, and more, all designed for working professionals and serious students who want credentials that actually open doors.
Last updated: June 2025. Reviewed by the 3University editorial team.


