Cybersecurity Certification Roadmap: The Shortest Path to the Role You Want
Pick the job you want. See the three or four certifications that get you there, in order, with exam fees, study time and the experience rules nobody reads until it is too late.
- You, todaystart here
- Network+$399 · 80 to 150 h
- Security+$439 · 80 to 150 h
- CySA+$439 · 80 to 150 h
- SOC analysttarget role
No experience rule on this path: you can hold every cert as soon as you pass.
What is the best certification path for cybersecurity?
For most beginners: Network+ (or A+ first if you have no IT experience), then Security+, then one specialist cert that matches the job you want: CySA+ for SOC and defence, PenTest+ or OSCP for offensive work, a cloud security cert for cloud roles. Leave CISSP, CISM and CISA until you have the required years of experience.
The default path for a beginner fits on one line. Everything after Security+ depends on the job, which is why the roadmap above starts from the role, not the cert.
This roadmap answers one question: for role X, which three or four certs, in what order, at what cost and time. It is not a list of every certification in the field; for that, see Paul Jerimy's chart, which this page credits and narrows down.
Which cybersecurity certification should I get first?
Get Security+ first if you already understand networking basics; it is the most requested entry-level security cert and meets many US government baseline requirements. With no IT background, start with A+ or Network+ so Security+ makes sense, or the ISC2 Certified in Cybersecurity as a low-cost first step.
A quick test: if you can explain what a /24 is and why a firewall rule names a port, you are ready for Security+. If not, Network+ first saves you from memorising Security+ answers you do not understand.
the Security+ curriculum gives a really nice broad overview
What to take after Security+
After Security+ the path forks four ways. Many people pick offence because it sounds more exciting; pick on the day-to-day work instead, because that is what you will do for years.
SOC and blue team
Triage alerts, read logs, tune detections, write up incidents. Shift work is common in tier 1.
Suits people who like patterns and calm checklists under pressure.
Pentest and red team
Scope a test, break in, then spend days writing the report. The report is the product the client pays for.
Suits people who enjoy puzzles and writing about them.
Cloud security
Identity policies, logging, guardrails and infrastructure as code. Closer to engineering than to analysis.
Suits people who already build or run cloud systems.
GRC and audit
Map controls to frameworks, run audits, write policy, talk risk with leadership. Less keyboard, more meetings.
Suits people who like structure, writing and persuading.
The real fork is CySA+ vs PenTest+
Do cybersecurity certifications get you hired?
They get your resume past filters, not the job itself. Recruiters and government contracts often require Security+ or CISSP, while technical interviewers care more about labs, home projects and hands-on certs such as OSCP. Pair one recognised cert with visible practical work and you beat a longer list of certificates.
The people who hire say the same thing in different words. Read these together: certs open doors at HR and in contracts; skill and evidence get the offer.
sometimes HR/recruiter use these for filtering candidates
Certs are a marginal signal to me about your potential for discipline
The OSCP is the only certification in this list that I've ever even heard of being part of hiring discussions
DOD (8570/8140), some specific regulations, and some specific clients sometimes require them
it still holds pull with recruiters and management
The CISSP is a risk management cert that's sometimes oversold as an infosec cert.
Opinions are quoted with the author's handle and a link, and kept apart from our own recommendations above.
Every certification on the roadmap, compared
Exam fees come from each vendor's own page, linked under the price. Study hours are our estimates for someone with the usual prerequisite knowledge; no vendor publishes them. Sort by any number, or filter by track.
| Renewal | How practitioners rate it | |||
|---|---|---|---|---|
| A+CompTIA | $548two examscomptia.org | $75 CE fee every 3 years | 100 to 180 | Help desk entry ticket. Skip it if you already work in IT. |
| Network+CompTIA | $399comptia.org | $150 CE fee every 3 years | 80 to 150 | The networking base every later cert assumes. Practise with the subnet calculator. |
| Security+CompTIA DoD baseline | $439comptia.org | $150 CE fee every 3 years | 80 to 150 | the Security+ curriculum gives a really nice broad overview”andrewstuart2 · Hacker News |
| ISC2 CCISC2 | $199isc2.org | $50 a year | 30 to 60 | Low-cost first step. Light on its own; pair it with Security+. |
| CySA+CompTIA | $439comptia.org | $150 CE fee every 3 years | 80 to 150 | The defensive follow-on to Security+. Renews Security+ when you pass. |
| GSECGIAC | $999giac.org | $499 renewal every 4 years | 80 to 160 | Highly rated broad defence cert. Usually employer-paid. |
| GCIHGIAC | $999giac.org | $499 renewal every 4 years | 100 to 180 | Incident handling, respected in SOC and IR teams. |
| SecurityXCompTIA, formerly CASP+ | $544comptia.org | $150 CE fee every 3 years | 120 to 200 | Senior hands-on alternative to CISSP. Less known by recruiters. |
| PenTest+CompTIA | $439comptia.org | $150 CE fee every 3 years | 80 to 150 | A theory bridge into offence. Hiring teams ask more about OSCP. |
| PNPTTCM Security | $499with trainingcertifications.tcm-sec.com | No expiry | 120 to 250 | Practical exam plus a written report. Cheaper road into offence. |
| CEHEC-Council | $1,199store.eccouncil.org | $80 a year | 80 to 160 | they'll get you the jobs you don't really want”trash_panda · Hacker News |
| OSCPOffSec | $1,749course and examoffsec.com | No expiry | 250 to 500 | The one cert pentest hiring discussions mention by name.Paraphrasing tidepod12 · Hacker News |
| AWS SecurityAWS, Specialty | $300aws.amazon.com | Re-pass every 3 years | 80 to 160 | Hands-on AWS depth, valued by cloud teams. |
| SC-500Microsoft | Price varies by countrylearn.microsoft.com | Free yearly online assessment | 60 to 120 | Replaced AZ-500. For Azure-heavy employers. |
| CCSPISC2 5 yrs experience | $599isc2.org | $135 a year | 100 to 200 | Cloud governance and architecture. Strongest after CISSP. |
| CISAISACA 5 yrs experience | $760isaca.org | $85 a year | 100 to 200 | The audit standard in internal audit and assurance firms. |
| CISMISACA 5 yrs experience | $760isaca.org | $85 a year | 100 to 200 | Security management. Often paired with CISSP for leadership roles. |
| CISSPISC2 5 yrs experience | $749isc2.org | $135 a year | 150 to 300 | it still holds pull with recruiters and management”Charde · Hacker News |
they'll get you the jobs you don't really want
Experience rules nobody reads until it is too late
CISSP, CISM, CISA and CCSP all need five years of relevant paid work before you hold the full title. You can pass the exam first: ISC2 makes you an Associate until the years are in, and ISACA gives you five years after the exam to submit them.
CISSP
5yearsPaid work in at least two of the eight CISSP domains.
- A four-year degree or an approved cert waives one year.
- Pass without the years: Associate of ISC2, six years to earn them.
CISA
5yearsWork in IS audit, control, assurance or security.
- Degrees and some certs substitute up to three years.
- Experience counts from ten years before you apply to five years after you pass.
CISM
5yearsSecurity work, three of the years in security management.
- Waivers cover up to two years, never the management part.
- Same ten-year window as CISA.
CCSP
5yearsIT work, three years in security and one in a CCSP domain.
- Holding CISSP covers the whole requirement.
- Associate route as for CISSP.
What counts: paid work, full or part time, where security is a real part of the job. Internships often count in part. Help desk alone usually does not; help desk with firewall changes, access reviews or incident tickets often does. Write the duties down as you go, because you will need a referee to confirm them.
Cost and time planner
Pick any certs, in any order, to see exam fees plus three years of renewal fees, and how long the study takes at your pace. ISC2 and ISACA charge one yearly fee however many of their certs you hold, so the planner counts it once.
| Cert | Exam | Renewals, 3 yrs | Hours, est. |
|---|---|---|---|
| Network+ | $399 | $150 | 80 to 150 |
| Security+ | $439 | $150 | 80 to 150 |
| CySA+ | $439 | $150 | 80 to 150 |
Cheaper routes: Professor Messer's CompTIA videos cover A+, Network+ and Security+ at no cost; ISC2 has run no-cost CC training and exam offers, so check the current one. GIAC is excellent and expensive, which is why most holders had an employer pay.
Offensive Security certs are worthwhile, so is GIAC if you can get your employer to pay for them.
Three real paths
Roadmaps are tidy; careers are not. The first two routes come from people who described their own move on Hacker News; the third is the most common internal move into security.
Labs first, then OSCP
it helps to bypass HR
- Linux and home servers until they feel normal.
- Network+ and Security+ knowledge, exams optional.
- Months of hands-on labs.
- OSCP to get past the HR filter.
Expect a step back first
get ready to take a paycut and a role downgrade
- Application security work inside the current job.
- Security+ for the vocabulary.
- A junior consulting role, often at lower pay.
- Specialise: appsec, cloud or pentest.
The classic internal move
passing a higher-tier cert renews the lower ones automatically
- A+ and a help desk job.
- Network+, then Security+ while working.
- Volunteer for security tickets: phishing, access reviews.
- CySA+ and an internal move to SOC tier 1.
Mistakes that cost a year
Collecting certs instead of applying
Three foundation certs and no applications is a common stall. One recognised cert plus a home lab you can talk about beats a longer list.
Skipping networking
Security+ assumes you can read addresses, ports and CIDR blocks. Learn the subnetting Network+ expects before you start, or every firewall question becomes a guess.
Buying exam dumps
Dumps break vendor rules, can cost you the cert, and leave you unable to answer the first interview question on the topic.
A CEH-only resume for pentest jobs
CEH appears in job ads, but pentest interviewers ask about hands-on work. Pair it with labs or a practical cert such as PNPT or OSCP.
Taking CISSP to get a first job
Without five years of experience you hold Associate of ISC2, not CISSP. It is a management-track cert; take it when the experience is real.
Government and DoD 8140
US Department of Defense roles and many contractor jobs require a listed certification for the work role, whatever the hiring manager thinks of certs. DoD Manual 8140.03 replaced the old 8570 baseline chart: qualification now depends on the work role in the DoD Cyber Workforce Framework, and a cert is one of several ways to qualify.
In practice Security+ is the floor for a large share of entry-level government security roles, which is why the Government / DoD path above starts there. Check the role code in the job advert against the current qualification matrix on the DoD Cyber Exchange before you pay for anything above Security+.
a security certification like Security+ or better
Age, salary and career-change questions
Is 30 too old to get into cybersecurity?
No. Many people arrive from IT support, development, the military or audit in their thirties, and that earlier work often counts toward the experience rules above.
Is 45 too late?
Not too late, but plan for it: GRC, audit and security management value domain experience from other careers, and they are the tracks where age reads as an asset rather than a question.
Is cybersecurity still worth it?
Entry-level roles are competitive and fewer than course adverts suggest; the need for experienced people is steady. It pays off most for people who stick with one track long enough to get the experience.
Is cyber security a high-salary career?
We do not publish salary figures of our own. The US Bureau of Labor Statistics publishes median pay and job outlook for information security analysts, updated each year.
Credits and embed
The classic map of the whole field is Paul Jerimy's Security Certification Roadmap, with hundreds of certs on one chart. This page owes it a debt and tries to answer a narrower question: for one role, what next.
Career coaches, bootcamps and university career pages are welcome to embed the roadmap for the role selected above. It is CC BY 4.0; keep the credit link.
Questions people ask
Do I need a degree for cybersecurity?
No, but it helps at some employers and government agencies, and a four-year degree knocks a year off the CISSP experience rule. Without one, visible work (labs, write-ups, a home lab) carries more weight.
CySA+ or PenTest+ after Security+?
CySA+ if you want SOC and defensive roles, which have far more openings at entry level. PenTest+ if you are set on offence, though pentest hiring talks more about OSCP and PNPT.
Is CEH worth it?
Only if a job advert or contract you want asks for it by name. It is expensive for what it teaches, and practitioners rate hands-on certs higher.
How long does Security+ take?
Our estimate is 80 to 150 hours for someone with networking basics, which is 10 to 19 weeks at eight hours a week. Add Network+ time if subnetting and ports are new.
Do certifications expire?
Most do. CompTIA, ISC2 and ISACA certs run on three-year cycles, and passing a higher CompTIA cert renews the lower ones. GIAC renews every four years, Microsoft yearly with a free online assessment, AWS every three years. OSCP and PNPT do not expire.
Security+ is on almost every path above
When you are ready to test yourself, work through these Security+ practice questions, with an explanation for every answer.
Subnetting cheat sheet and practice
The /8 to /32 chart, how to draw it from memory in 90 seconds, and unlimited practice questions with the working shown.