EC-Council (International Council of E-Commerce Consultants) — Vendor Overview
V017 · Ethical Hacking, Offensive Security, Penetration Testing · 5 active certifications · SA presence: Moderate
Quick pitch: EC-Council is a leading ethical hacking and offensive security certification authority; CEH (Certified Ethical Hacker) is widely valued by government cybersecurity teams and penetration testing firms, though OSCP remains the gold standard for advanced penetration testers.
Company Snapshot
| Field | Detail |
|---|---|
| Full name | EC-Council (International Council of E-Commerce Consultants) |
| Founded | 2001 — pioneered certified ethical hacking as a discipline |
| Headquarters | Albuquerque, New Mexico, USA |
| Employees | ~200 globally (2026) |
| Revenue | Private company; estimated ~$50–80M annually |
| Listed | Private |
| Core business | Develops and administers ethical hacking, penetration testing, and digital forensics certifications; provides training and labs. 100% certification and training revenue. |
| SA office | No direct office; moderate partner network including IS Global, Westcon-Comstech, regional training providers |
What EC-Council Does
EC-Council is a cybersecurity certification authority focused on ethical hacking, penetration testing, and offensive security. The organisation develops CEH (the most widely known ethical hacking certification), ECSA (penetration tester), and CHFI (computer hacking forensics investigator) certifications. EC-Council maintains practical labs and hacking scenarios aligned to real-world attacks, making certifications highly relevant to penetration testers and security professionals.
EC-Council maintains approximately 200,000+ CEH holders globally. The organization is vendor-neutral and widely recognised, though competitors include SANS/GIAC (more expensive but higher prestige), OffSec (OSCP, gold standard for advanced penetration testers), and CompTIA Security+. The certification program is designed for ethical hackers, penetration testers, and security researchers.
Certification Portfolio
Active certifications (5 total)
| Level | Cert Name | Code | Domain | Cost (USD) | Valid |
|---|---|---|---|---|---|
| Associate | CEH – Certified Ethical Hacker | CEH | Ethical Hacking Fundamentals | $1,199 | 3 yrs |
| Professional | ECSA – EC-Council Certified Security Analyst | ECSA | Penetration Testing | $1,299 | 3 yrs |
| Professional | CHFI – Computer Hacking Forensics Investigator | CHFI | Digital Forensics | $1,299 | 3 yrs |
| Professional | ECIH – EC-Council Certified Incident Handler | ECIH | Incident Response | $1,099 | 3 yrs |
| Expert | CEH Master | CEH-Master | Advanced Ethical Hacking | $1,499 | 3 yrs |
Recommended starting cert
CEH (Certified Ethical Hacker) — Entry-level ethical hacking credential validating knowledge of network attacks, hacking tools, penetration testing methodologies, and security controls. Suitable for security professionals, penetration testers, and security researchers. 4-hour exam; ~125 questions. 3-year validity. Prerequisites: 2 years cybersecurity experience (or equivalent). ~4–6 months study with lab access.
Cert ladder for new starters
CEH → ECSA (Penetration Testing) → CEH Master (Expert)
CEH → CHFI (Digital Forensics specialisation)
Why EC-Council Matters in 2026
CEH is widely recognised by government cybersecurity teams, defence contractors, and penetration testing firms. LinkedIn shows 8,000+ open CEH job postings globally. CEH is particularly valued by US Department of Defense (DoD) and government cybersecurity professionals. However, OSCP (OffSec) is increasingly preferred by elite penetration testers due to its practical, hands-on assessment methodology.
EC-Council's strength is breadth (ethical hacking, forensics, incident response) rather than depth. The certification ecosystem is healthy; EC-Council invests in labs and practical training. Exam content is updated regularly. For government cybersecurity roles, CEH is a valued credential. For advanced penetration testing careers, OSCP is increasingly the gold standard.
Job Market Data
Global demand
| Metric | Value | Source | Date |
|---|---|---|---|
| Active job postings mentioning CEH | 8,000+ | LinkedIn Jobs | May 2026 |
| Growth YoY | +7% | LinkedIn Salary Insights | 2025–2026 |
| Top job title hiring | Penetration Tester | May 2026 | |
| Top hiring countries | USA, Canada, UK, India, Australia | May 2026 |
Common job titles requiring EC-Council skills
| Job Title | Seniority | Median USD Salary | Median ZAR Salary |
|---|---|---|---|
| Security Analyst | Mid | $75,000 | R69,000/month |
| Penetration Tester | Mid | $95,000 | R87,400/month |
| Senior Penetration Tester | Senior | $130,000 | R119,600/month |
| Security Consultant / ECSA | Lead | $155,000+ | R142,600+/month |
South Africa Presence
Direct presence
EC-Council has no direct office in South Africa but operates through a moderate partner network. Partners include IS Global, Westcon-Comstech, and regional training providers. CEH is increasingly valued in SA government cybersecurity teams.
SA job market
South African government agencies, state-owned enterprises (Eskom, Transnet), and defence-related organisations increasingly value CEH for cybersecurity professionals. Private sector security consultancies also hire CEH-certified professionals. Demand is moderate and growing; government cybersecurity demand is the primary driver.
Median salary for CEH-certified Penetration Tester in SA is R87,400/month (approximately $4,800 USD), rising to R142,600+/month for senior consultants.
SA training providers
| Provider | Cert(s) offered | URL |
|---|---|---|
| IS Global | CEH, ECSA, CHFI | isglobal.co.za |
| Westcon-Comstech Academy | CEH, ECSA | westcon.co.za |
| EC-Council Training | All EC-Council certs | eccouncil.org/training |
| Linux Academy / A Cloud Guru | CEH | acloudguru.com |
Vendor Ecosystem
Key technologies and platforms
- Penetration testing tools (Metasploit, Burp Suite, etc.)
- Network analysis and packet capture
- Vulnerability assessment methodologies
- Ethical hacking tools and frameworks
- Digital forensics and incident investigation
- Cryptography and encryption
- Wireless security and hacking
Complementary vendors and certs
| Complementary Vendor | Why they pair well |
|---|---|
| SANS/GIAC | More expensive but higher prestige alternative |
| OffSec (OSCP) | Gold standard for advanced penetration testers |
| ISC² (CISSP) | Security professional complements ethical hacker |
| CompTIA Security+ | Entry-level cert before CEH |
Community and resources
| Resource | Type | URL |
|---|---|---|
| EC-Council Training Portal | Official | eccouncil.org/training |
| EC-Council Community | Community | eccouncil.org/community |
| r/ceh | Community | reddit.com/r/ceh |
| EC-Council YouTube | Learning | youtube.com/c/EcCouncil |
Vendor History & Roadmap
Key milestones
| Year | Event |
|---|---|
| 2001 | Founded; pioneered certified ethical hacking |
| 2003 | Launched CEH certification program |
| 2005 | Introduced ECSA (penetration testing) |
| 2008 | Launched CHFI (digital forensics) |
| 2015 | Expanded practical lab scenarios |
| 2020 | Updated certifications for cloud security and modern threats |
| 2024 | Introduced CEH Master (advanced specialisation) |
| 2025–2026 | Focus on AI-powered attacks, cloud security |
| 2026 | Cloud and AI security becoming certification focus |
Outlook
EC-Council is firmly positioned as a leading ethical hacking certification authority, though competition from SANS/GIAC (prestige, government preference) and OffSec/OSCP (hands-on methodology for elite penetration testers) limits market share. For certification professionals, CEH remains secure and in steady demand, particularly for government roles. ECSA and CHFI remain specialised. Exam content will evolve to include cloud penetration testing, AI-powered attacks, and advanced threat tactics over the next 12–24 months.
Frequently Asked Questions
Q: Is EC-Council worth investing in for my career? Yes, especially if interested in government cybersecurity or ethical hacking careers. CEH is widely valued by government teams.
Q: How often do EC-Council certs expire? All certifications expire after 3 years. Renewal requires passing a renewal exam or earning continuing professional education credits.
Q: Are EC-Council certs recognised in South Africa? Moderately. CEH is valued in government cybersecurity teams. For private sector penetration testing, OSCP is increasingly preferred.
Q: What's the best cert to start with from EC-Council? CEH. It requires 2 years experience or equivalent. Expect 4–6 months study with lab access.
Related Content
- Cert Roadmap → — Full progression diagram
- Ecosystem Deep Dive → — Technology landscape, tools, job market
- Individual Cert Files → — Per-exam breakdowns
Sources
| # | Source | URL | Used for |
|---|---|---|---|
| 1 | EC-Council Certifications | eccouncil.org/certifications | Company data, cert portfolio |
| 2 | EC-Council About | eccouncil.org/about | History, mission |
| 3 | LinkedIn Jobs – CEH | linkedin.com/jobs | Job market data |
| 4 | IS Global (SA Partner) | isglobal.co.za | SA presence, training |
Template version: 2026-05-03 | Maintained by IT Career Roadmap