If you’ve been studying for CEH v12 since 2023 and now see “CEH v13 AI” splashed across EC-Council’s marketing, the obvious question is: do my v12 prep materials still work, or do I need to start over? The short answer is that most of your knowledge carries — but the AI-attack-and-defense layer added in v13 is large enough that ignoring it will cost you exam points, and (more importantly) will leave a real skills gap in 2026 interviews where AI security has become a baseline expectation.
This guide breaks down what actually changed between CEH v12 and CEH v13, what stayed the same, what the new AI modules look like in practice, and how to plan a study path if you’re sitting the exam in India in 2026.
TL;DR — the 30-second answer
| Dimension | CEH v12 | CEH v13 (AI) |
|---|---|---|
| Released | 2022 | Late 2024 (current as of 2026) |
| Total modules | 20 | 20 (restructured) |
| AI / LLM coverage | Light, scattered mentions | Dedicated AI-attack-and-defense thread woven through every module + dedicated AI tooling labs |
| Lab platform | iLabs (cloud-based) | iLabs + new AI-powered playgrounds |
| Exam format | 125 MCQ, 4 hours | 125 MCQ, 4 hours (unchanged) |
| CEH Practical (optional) | 20 challenges, 6 hours | 20 challenges, 6 hours (unchanged) — AI use-cases added |
| Passing score | 60–85% (adaptive) | 60–85% (adaptive) |
| Validity | 3 years (with EC-Council CPE renewal) | 3 years (unchanged) |
| Indian ATC course price (typical) | ₹35,000–₹45,000 | ₹40,000–₹50,000 |
If you’ve already cleared CEH v12, you do not have to re-sit v13 for your title to remain valid — your existing CEH stays current as long as you maintain CPEs. CEH v13 is the version a new candidate sits in 2026.
What actually changed: AI woven through the curriculum
The headline change in v13 is that EC-Council stopped treating AI as a sidebar topic and rebuilt the curriculum so every phase of the attack lifecycle gets an AI lens. In v12 you could pass without ever opening a prompt-injection lab. In v13 you can’t — there are graded labs on prompt injection, model-poisoning, adversarial examples for image classifiers, jailbreak chains, and the defender side of every one of those.
Concretely, the new content shows up in three layers:
- AI as a target. Attacking large language models, image classifiers, voice models, and the systems that wrap them. Prompt injection, jailbreak prompts, data-exfiltration via tool-use, indirect prompt injection (poisoned web content the LLM later reads), model-stealing, and adversarial ML.
- AI as a weapon. Using LLMs and adversarial tools to accelerate reconnaissance, write working phishing copy at scale, generate evasive payloads, and obfuscate scripts. The v13 labs include hands-on with ShellGPT-style assistants for command-chain construction and with model-driven OSINT.
- AI as a defender. Detection patterns specific to AI-driven attacks — abnormal token patterns, model-output telemetry, AI-gateway logging, and how SOC analysts triage incidents that involve LLMs in the loop.
The MITRE ATLAS framework (the AI/ML analogue of MITRE ATT&CK) and the OWASP Top 10 for LLM Applications are referenced repeatedly throughout v13’s instructor notes — if you’re studying outside an EC-Council ATC, those two frameworks are the single most useful free study aids for the AI portion of v13.
What stayed the same — most of your v12 prep still works
The traditional offensive-security spine of CEH is unchanged. Reconnaissance, scanning, enumeration, vulnerability analysis, system hacking, malware threats, sniffing, social engineering, denial-of-service, session hijacking, evading IDS/firewalls/honeypots, web server / web application hacking, SQL injection, wireless network hacking, mobile platforms, IoT/OT hacking, cloud computing, and cryptography are all still there. The tools (Nmap, Burp Suite, Metasploit, Hashcat, Aircrack-ng, BurpSuite, sqlmap, Wireshark, John the Ripper, Hydra, etc.) are the same — most v12 labs will work in the v13 environment with minor UI shifts.
If you’ve already drilled Nmap host discovery, Burp intruder, Metasploit auxiliary modules, and Hashcat ruleset attacks, you do not need to redo any of that. Put your effort into the AI delta.
Exam format and scoring — no structural change
The CEH ANSI exam is still 125 multiple-choice questions over four hours, computer-based, adaptive-passing (the cut score sits between 60% and 85% depending on the question pool difficulty you draw — EC-Council does not publish individual cut scores). The optional CEH (Practical) exam is unchanged: 20 hands-on challenges over six hours, all done in iLabs, single sitting, scored on outcomes (not write-ups). Candidates who clear both ANSI and Practical earn CEH (Master).
Validity is three years. To renew, you submit 120 EC-Council Continuing Education credits over the three-year cycle.
Should you sit v12 or wait for v13 in India in 2026?
You can no longer voluntarily sit v12 — EC-Council retired v12 voucher sales in 2025 once v13 became the active version. Any reputable Indian Accredited Training Center now teaches v13. If a coaching shop is still advertising v12 in 2026, treat that as a red flag — they’re selling stale material against an exam you won’t actually receive.
How much does CEH v13 cost in India in 2026?
There are three cost components: the course, the exam voucher, and (optionally) the Practical exam voucher.
- Course fee at an EC-Council Accredited Training Center (ATC): typically ₹40,000–₹50,000 including iLabs access and an EC-Council eCourseware license. Self-study without an ATC is allowed but only if you have two years of documented information-security experience and pay an additional eligibility application fee.
- ANSI exam voucher: ₹22,000–₹28,000 when bought through an ATC alongside training (cheapest path); higher if bought standalone.
- Practical exam voucher (optional): roughly the same price range as ANSI. Worth taking if you want CEH (Master), which several Indian PSU and BFSI hiring panels still ask for over CEH (ANSI) alone.
Bundles vary by training center. Always ask the ATC to itemize what’s included — eCourseware, iLab months, voucher count, retake terms, and any included practice exams.
Who should pick CEH v13 in 2026?
CEH v13 is the right cert if you’re (a) early-career and need a broad, well-recognised offensive-security baseline, (b) targeting BFSI / GCC / IT-services security roles in India where CEH is the most-asked-for cert by recruiter ATS, or (c) preparing for the Indian government / PSU security audit profile, where CEH (along with CISM and CISA) is a frequent shortlisting filter.
CEH is not the right cert if you’ve already cleared OSCP+ or PNPT — both of those signal much higher hands-on skill to a technical interviewer, and pursuing CEH afterwards is mostly a paperwork move (still useful for HR filters but not skill-additive). For experienced practitioners, the better path after OSCP+ is usually OSWE (web application) or OSEP (evasive techniques and AD).
How Macksofy Trainings helps
Macksofy Trainings is an EC-Council Accredited Training Center delivering CEH v13 (AI) through instructor-led classroom programs at our Mumbai and Hyderabad centres and full-time online cohorts open to India and the GCC. Every cohort uses the official EC-Council iLab platform plus our internal red-team lab range, and trainees who clear the ANSI exam are encouraged (and supported) to sit Practical for the CEH (Master) credential.
If you want help deciding between CEH v13 and a hands-on alternative like OSCP+, or you’re looking at a multi-cert career roadmap (CEH → SOC analyst → CHFI → CISSP, or CEH → OSCP+ → OSEP for the offensive track), get in touch via the contact form or write to yasir@macksofy.com. CEH v13 cohort options for 2026 are available across our city pages — pick the city closest to you:
- Mumbai · Delhi-NCR · Bangalore · Hyderabad · Pune
- Chennai · Kolkata · Ahmedabad · Indore · Jaipur · Coimbatore
Frequently asked questions
Is CEH v13 worth doing if I already have CEH v12?
If you already hold a current CEH v12 certification, you do not need to re-sit v13 — your title stays valid as long as you maintain EC-Council CPEs. Re-sitting v13 only makes sense if you want the AI-attack content on your CV explicitly or your employer requires the latest version.
Can I take the CEH v13 exam without going through an Accredited Training Center?
Yes, but you have to file an EC-Council eligibility application proving two years of documented information-security work experience, and pay a non-refundable application fee. Most India candidates find an ATC bundle cheaper once you factor in the voucher and iLab access.
How hard is the AI section of CEH v13?
The exam questions on AI attacks lean toward conceptual understanding rather than tool-deep recall — you should know what prompt injection looks like, how indirect prompt injection differs, what MITRE ATLAS covers, and what defensive controls AI gateways apply. The labs are the heavier lift; expect to spend twenty to thirty hours practising in iLabs to feel confident on Practical-exam-style AI tasks.
Does CEH v13 cover Generative AI tooling and Copilot security?
Yes. The v13 curriculum includes coverage of generative AI in offensive workflows (LLMs assisting recon, payload crafting, phishing copy) and defensive coverage of AI-gateway logging, content filtering, and detection patterns for AI-driven attacks.
What is the typical salary in India after CEH v13?
Entry-level CEH-holders in BFSI / GCC / IT-services SOC roles see ₹4.5–7 lakh CTC at L1 in metro cities; mid-level analysts (CEH + two-to-four years experience) sit at ₹8–14 lakh; senior consultants with CEH plus hands-on offensive certs (OSCP+, OSEP) cross ₹18 lakh. These are 2026 India ranges from public salary platforms and recruiter snapshots — actual offers depend on city, employer, and interview performance.
Is CEH (Master) better than CEH (ANSI) alone?
For technical hiring panels, yes — the Practical adds a real hands-on signal that ANSI alone does not. For HR / ATS filtering, both versions tick the “CEH” box equally. If you can afford the additional voucher, sit Practical within twelve months of clearing ANSI while the material is still fresh.




