Technology15 min read

CEH v13 Study Plan 2026: A Blueprint-Based 12-Week System

Build a current CEH v13 12-week plan from EC-Council's nine-domain blueprint, with verified eligibility, fees, retakes, labs, scoring, and renewal rules.

Ran Chen, EA, CFP®March 5, 2026

Key Facts

  • The CEH knowledge exam presents 125 multiple-choice questions in four hours and awards the CEH credential when a candidate passes.
  • EC-Council's Blueprint v5.0 allocates 125 questions across nine domains; Network and Perimeter Hacking is largest with 30 questions.
  • CEH v13's 20 training modules are not 20 exam domains; the current certification blueprint groups tested content into nine domains.
  • Current official materials publish no single fixed passing percentage; EC-Council's detailed explanation cites typical form-specific cut scores from 65% to 85%.
  • Official-training candidates bypass the eligibility application; self-study candidates need two years of information-security experience and a nonrefundable $100 application.
  • Current standalone knowledge-exam vouchers cost $950 for remote RPS delivery or $1,199 for Pearson VUE, before training or Practical costs.
  • The optional CEH Practical uses 20 challenges over six hours; passing both the knowledge and Practical exams earns the CEH Master designation.
  • The first retake has no waiting period; later retakes require 14 days, with no more than five attempts in twelve months.
  • CEH follows a three-year ECE cycle requiring 120 credits and the current $80 annual continuing-education fee to maintain certification.

📺 Watch the Video

CEH v13 in 2026: Use the Exam Blueprint, Not a Module List

A useful CEH v13 study plan starts with one identity check: EC-Council's current training program has 20 modules, but the certification knowledge exam follows the nine-domain CEH Exam Blueprint v5.0. Those are two different maps. Course modules organize instruction; the blueprint allocates the 125 exam questions.

As of August 24, 2026, the live EC-Council CEH page describes the knowledge exam as 125 multiple-choice questions in four hours. Passing that exam earns CEH. The separate six-hour, 20-challenge CEH Practical is optional; passing both earns the CEH Master designation.

This 12-week system is an editorial schedule, not an EC-Council requirement. It converts the official question counts into weekly outputs, retains hands-on context without confusing the two exams, and includes the eligibility, cost, retake, and renewal decisions that many study plans omit.

Current CEH Exam Snapshot

DetailCurrent information
CredentialCertified Ethical Hacker, currently marketed as CEH AI and CEH v13
Knowledge exam125 multiple-choice questions
Time4 hours, or 240 minutes
Exam code312-50 for the knowledge exam
Official exam mapCEH Exam Blueprint v5.0, effective April 10, 2024
Blueprint domainsNine
DeliveryRemote RPS through the ECC exam route or Pearson VUE testing-center delivery
Passing standardForm-specific; no single fixed raw percentage
CEH PracticalOptional, 20 challenges in six hours
CEH MasterPass both the knowledge exam and CEH Practical
Certification cycleThree years under the ECE program

Four hours divided by 125 questions is 1.92 minutes per displayed question, about one minute 55 seconds. That calculation is a pacing average, not a rule for every item. Some questions will take seconds; others require careful comparison.

The Official Nine-Domain Blueprint

The official CEH Exam Blueprint v5.0 publishes both question counts and rounded percentages. The counts total exactly 125. The displayed percentages total 101% because EC-Council rounds each domain independently, so use question counts when translating the blueprint into study time.

Official domainQuestionsPublished weight
Information Security and Ethical Hacking Overview76%
Reconnaissance Techniques2117%
System Hacking Phases and Attack Techniques1915%
Network and Perimeter Hacking3024%
Web Application Hacking1814%
Wireless Network Hacking65%
Mobile Platform, IoT, and OT Hacking1210%
Cloud Computing65%
Cryptography65%

The four largest domains contain 88 of 125 questions, or 70.4% of the blueprint: Network and Perimeter Hacking, Reconnaissance, System Hacking, and Web Application Hacking. Give them most of your time, but do not abandon the remaining 37 questions. Wireless, cloud, cryptography, and the overview domain can separate a broad candidate from one who prepared only familiar attack paths.

CEH v13 and AI: What Is Actually Official

EC-Council explicitly integrates AI-driven ethical-hacking content and labs into the current CEH v13 or CEH AI training program. That makes AI part of the current course identity. However, Blueprint v5.0 does not publish a separate AI domain or a fixed AI question percentage.

Study AI-related techniques where the official course and authorized materials place them, but do not invent an AI weight or trust a guide that promises a particular share of AI questions. For exam allocation, the nine-domain blueprint remains the controlling public map. This boundary also explains why mutable marketing counts for labs, tools, or attack techniques are poor study-allocation targets.

Eligibility: Choose the Correct Route Before Buying

The CEH Candidate Handbook v7.1 describes two routes to the knowledge exam.

Route 1: Complete Official Training

Candidates who complete an accepted EC-Council training route are eligible without the separate experience-based eligibility application. Keep the certificate of attendance because the official voucher store instructs training candidates to provide it when purchasing a voucher. Training prices vary by provider, region, and package, so there is no single defensible all-in course price.

Route 2: Apply Without Official Training

Self-study candidates must document at least two years of information-security work experience, submit the eligibility application, nominate a verifier, and pay the nonrefundable $100 application fee. Approval comes before the voucher purchase instructions. A random third-party course does not automatically replace this process.

Current knowledge-exam vouchers are valid for one year from release. Confirm eligibility and delivery before purchasing because vouchers are nontransferable and the operational terms can change.

Current CEH Fees and Delivery

EC-Council's official store listed these standalone prices on August 24, 2026:

PurchaseCurrent listed priceDelivery
CEH knowledge voucher - RPS$950Online, remotely proctored
CEH knowledge voucher - Pearson VUE$1,199Pearson VUE testing center
CEH Practical$550Online, remotely proctored cyber range
Self-study eligibility application$100Required only for the experience-based route

These are not all-in training totals. Packages can combine training, courseware, labs, retakes, or both exams, and regional pricing can differ. Recheck the official product page before paying.

Passing Score: Do Not Memorize One Percentage

EC-Council uses multiple exam forms, and their cut scores vary with form difficulty. Its detailed current scoring explanation says typical knowledge-exam cut scores range from 65% to 85%. Another current exam-details panel shows a broader 60%-85% range. Both official statements reject the idea of one universal raw passing percentage.

Your assigned form's passing standard controls. A self-chosen practice target is only a readiness signal, not an official guarantee. Track performance by blueprint domain and by reasoning error instead of assuming that hitting one percentage on an unrelated question bank proves readiness. EC-Council does not publish a current overall candidate pass rate, so ignore pages that attach an unsupported first-attempt success percentage to CEH.

The 12-Week Blueprint-Based Study System

Use seven to ten focused hours per week as a starting budget, then adjust it after a diagnostic. Every week should produce four artifacts: a blueprint checklist update, concise retrieval notes, an authorized lab or defensive analysis record, and a reviewed question set.

Week 1: Establish the Map and Baseline

CEH practicePractice questions with detailed explanations

Output: a red-yellow-green checklist for every official subdomain and a baseline error log.

Week 2: Footprinting and Scanning

Begin Reconnaissance Techniques with footprinting and network scanning. Connect passive and active information collection to authorization, scope, likely evidence, and countermeasures. For each tool named in your authorized materials, record its purpose and output rather than memorizing a long command list.

Output: one page comparing footprinting, host discovery, port and service discovery, banner grabbing, and OS fingerprinting.

Week 3: Enumeration and Reconnaissance Integration

Complete the blueprint's enumeration families, including the protocols and services it names. Practice choosing what information a technique can reveal and what defensive control reduces exposure. Mix all 21 reconnaissance questions' worth of objectives rather than studying enumeration as an isolated vocabulary list.

Output: a recon-to-enumeration decision map plus a timed domain set.

Week 4: Vulnerability Analysis and System Hacking

Study vulnerability classification, assessment types, tools, and reports before system-hacking phases. Follow the logic from validated weakness to authorized exploitation, privilege escalation, persistence, evidence, and remediation. Distinguish what a scanner reports from what a tester has actually verified.

Output: a comparison of assessment, exploitation, privilege escalation, persistence, and cleanup responsibilities.

Week 5: Malware and System-Hacking Review

Cover malware concepts, APTs, trojans, viruses, worms, fileless malware, analysis, and countermeasures. Build recognition around behavior and defensive evidence, not specimen recipes. Then mix all 19 questions' worth of System Hacking objectives with previous reconnaissance work.

Output: a behavior-to-detection table and a reviewed mixed set.

Week 6: Network and Perimeter Hacking, Part I

Start the 30-question largest domain with sniffing, social engineering, and denial-of-service concepts and countermeasures. Practice identifying the layer under attack, the observation that supports the diagnosis, and the safest control. Do not turn social-engineering study into real targeting; use fictional or explicitly authorized exercises.

Output: three attack-control maps and one timed network set.

Week 7: Network and Perimeter Hacking, Part II

Finish session hijacking and evasion of IDS, firewalls, NAC, endpoint security, and honeypots. Compare prevention, detection, and response. Review the entire 30-question domain alongside earlier scanning and system-hacking objectives because distractors often operate at the wrong layer.

Output: a session-versus-network control table and a cumulative domain review.

Week 8: Web Servers, Web Applications, and SQL Injection

Give all three six-question subdomains equal initial attention: web servers, web applications, and SQL injection. Practice recognizing trust boundaries, input handling, authentication, authorization, session management, application logic, APIs, and mitigations. Use deliberately vulnerable training targets only.

Output: a web attack-to-control matrix and an 18-objective checklist review.

Week 9: Wireless, Mobile, IoT, and OT

Study the six-question Wireless domain and the twelve-question Mobile, IoT, and OT domain. Compare wireless encryption and threats, mobile platform controls, device management, IoT constraints, and OT safety or availability priorities. Avoid treating IT and OT response choices as interchangeable.

Output: a platform comparison table and two short timed sets.

Week 10: Cloud and Cryptography

Finish the two six-question domains. For cloud, cover concepts, containers, serverless, threats, attack paths, and controls. For cryptography, connect algorithms, PKI, signatures, email or disk encryption, cryptanalysis, and countermeasures to their security purpose. Do not assume a product-specific cloud command belongs on the exam unless it maps to a published objective.

Output: one responsibility-boundary table and one cryptographic-purpose table.

Week 11: Mixed Retrieval and Timed Decisions

Stop reading in domain silos. Use mixed sets, retrieve the governing concept before viewing notes, and review every correct guess as well as every miss. Reallocate study time according to the official question counts and your own red objectives.

Output: three mixed-set reviews showing the objective, error cause, corrected rule, and next drill.

Week 12: Rehearsal and Logistics

Complete one full 125-question, four-hour rehearsal if you have a sufficiently varied original question source. Reproduce your chosen test environment, breaks policy, and pacing decisions as closely as current instructions allow. Then reduce volume: repair recurring errors, verify voucher and identification details, and avoid adding broad new resources.

Output: a final readiness sheet and a test-day logistics checklist.

Use Labs Without Confusing the Two Exams

Hands-on work can make knowledge-exam concepts concrete, but the knowledge exam remains multiple choice and the Practical remains a separate optional exam. A lab is useful when it helps you explain purpose, sequence, evidence, scope, and countermeasures. It is not useful merely because you copied a command that produced output once.

Only test systems you own or have explicit authorization to test. Keep exercises inside an isolated training environment, record the permitted scope, take snapshots before changes, and never scan public or workplace targets without written permission. For each exercise, log: the objective, expected evidence, actual evidence, defensive interpretation, and safe cleanup.

If CEH Master is your goal, extend the same notes into repeatable practical workflows after the knowledge foundation is stable. Do not assume that passing a multiple-choice mock proves cyber-range speed, or that lab comfort proves coverage of all nine knowledge domains.

Build an Error Log That Changes the Next Week

For every missed or guessed question, record five fields:

  1. Official domain and subdomain.
  2. What the stem actually asked.
  3. Why the selected option failed the scope or evidence.
  4. The short rule that makes the key unique.
  5. The next retrieval, comparison, or authorized lab drill.

Review the log by pattern. Repeated tool confusion needs a purpose-and-output comparison. Repeated sequence errors need an attack-and-control workflow. Repeated ethics or scope errors need authorization review. Pacing errors need short timed sets, not another passive chapter.

Retakes and Certification Renewal

The current EC-Council exam retake policy allows a second attempt without a cooling period after the first failure. A 14-day wait applies before the third, fourth, and fifth attempts. Candidates may not take the same exam more than five times in a twelve-month period; a twelve-month wait applies before a sixth attempt. A passed exam version cannot be taken again. Check any package-specific retake terms in addition to the general policy.

CEH is not a lifetime credential. Under the current EC-Council ECE policy, CEH has a three-year cycle requiring 120 ECE credits. Credits earned in a calendar year must be registered by February 1 of the following year. The current annual CE fee is $80 for a member holding at least one certification under the ECE policy. Missing maintenance requirements can lead to suspension and later revocation, so create the renewal record when you certify, not in the final month.

Final Readiness Bar

You are ready to schedule when you can account for every Blueprint v5.0 subdomain, explain why the four largest domains receive 88 of 125 questions, complete mixed questions near the overall one-minute-55-second pace, and close recurring errors without answer memorization. Your scores should be stable across multiple original sets, but no unofficial practice percentage guarantees an EC-Council result.

CEH practice questionsPractice questions with detailed explanations

Official CEH Sources

Use the live CEH certification page for the current program identity, exam format, scoring explanation, and CEH-versus-Master boundary; Blueprint v5.0 for the nine domains and exact question counts; the Candidate Handbook v7.1 for eligibility and candidate rules; the official RPS, Pearson VUE, and Practical store pages for current prices; and the retake and ECE policy pages for ongoing requirements.

Test Your Knowledge
Question 1 of 4

Which source should control CEH exam study allocation?

Learn More with AI

10 free AI interactions per day

CEH v13Certified Ethical HackerEC-CouncilEthical HackingCybersecurityStudy PlanExam Prep

Related Articles

Stay Updated

Get free exam tips and study guides delivered to your inbox.

Free exam tips & study guides. Unsubscribe anytime.