Your path Back to the roadmap
SOC analyst: $1,277240 to 450 h, 7 to 13 months at 8 h a week
7 roles, 18 certifications7 roles, 18 certs Vendor fees with sources CC BY 4.0

Cybersecurity Certification Roadmap: The Shortest Path to the Role You Want

Pick the job you want. See the three or four certifications that get you there, in order, with exam fees, study time and the experience rules nobody reads until it is too late.

I want to become a
I want to become a
Worth adding later:GSECCISSP
I already have
8 h
of study a week
Exam fees still to pay$1,2773 exams: Network+, Security+, CySA+plus $450 in renewal fees over 3 years
Study time240 to 450 htypical range, our estimate
Earliest finish7 to 13 months30 to 57 weeks at 8 h a week

No experience rule on this path: you can hold every cert as soon as you pass.

What is the best certification path for cybersecurity?

Short answer

For most beginners: Network+ (or A+ first if you have no IT experience), then Security+, then one specialist cert that matches the job you want: CySA+ for SOC and defence, PenTest+ or OSCP for offensive work, a cloud security cert for cloud roles. Leave CISSP, CISM and CISA until you have the required years of experience.

The default path for a beginner fits on one line. Everything after Security+ depends on the job, which is why the roadmap above starts from the role, not the cert.

This roadmap answers one question: for role X, which three or four certs, in what order, at what cost and time. It is not a list of every certification in the field; for that, see Paul Jerimy's chart, which this page credits and narrows down.

Which cybersecurity certification should I get first?

Short answer

Get Security+ first if you already understand networking basics; it is the most requested entry-level security cert and meets many US government baseline requirements. With no IT background, start with A+ or Network+ so Security+ makes sense, or the ISC2 Certified in Cybersecurity as a low-cost first step.

A quick test: if you can explain what a /24 is and why a firewall rule names a port, you are ready for Security+. If not, Network+ first saves you from memorising Security+ answers you do not understand.

the Security+ curriculum gives a really nice broad overview
andrewstuart2 · Hacker News · Nov 2023

What to take after Security+

After Security+ the path forks four ways. Many people pick offence because it sounds more exciting; pick on the day-to-day work instead, because that is what you will do for years.

Defend

SOC and blue team

CySA+GCIHGSEC

Triage alerts, read logs, tune detections, write up incidents. Shift work is common in tier 1.

Suits people who like patterns and calm checklists under pressure.

Attack

Pentest and red team

PenTest+PNPTOSCP

Scope a test, break in, then spend days writing the report. The report is the product the client pays for.

Suits people who enjoy puzzles and writing about them.

Cloud

Cloud security

AWS SecuritySC-500CCSP

Identity policies, logging, guardrails and infrastructure as code. Closer to engineering than to analysis.

Suits people who already build or run cloud systems.

Govern

GRC and audit

CISACISMCISSP later

Map controls to frameworks, run audits, write policy, talk risk with leadership. Less keyboard, more meetings.

Suits people who like structure, writing and persuading.

The real fork is CySA+ vs PenTest+
LearnZapp blog, on the CompTIA ladder · learnzapp.com

Do cybersecurity certifications get you hired?

Short answer

They get your resume past filters, not the job itself. Recruiters and government contracts often require Security+ or CISSP, while technical interviewers care more about labs, home projects and hands-on certs such as OSCP. Pair one recognised cert with visible practical work and you beat a longer list of certificates.

The people who hire say the same thing in different words. Read these together: certs open doors at HR and in contracts; skill and evidence get the offer.

sometimes HR/recruiter use these for filtering candidates
kapilartistry · Hacker News · Nov 2018
Certs are a marginal signal to me about your potential for discipline
beardedwizard, hiring manager · Hacker News · Jul 2020
The OSCP is the only certification in this list that I've ever even heard of being part of hiring discussions
tidepod12 · Hacker News · Jan 2021
DOD (8570/8140), some specific regulations, and some specific clients sometimes require them
rdl · Hacker News · Jun 2022
it still holds pull with recruiters and management
Charde, on CISSP · Hacker News · Aug 2011
The CISSP is a risk management cert that's sometimes oversold as an infosec cert.
0xBDB, red team manager · Hacker News · Jul 2022

Opinions are quoted with the author's handle and a link, and kept apart from our own recommendations above.

Every certification on the roadmap, compared

Exam fees come from each vendor's own page, linked under the price. Study hours are our estimates for someone with the usual prerequisite knowledge; no vendor publishes them. Sort by any number, or filter by track.

Cybersecurity certifications: exam fee, renewal, study hours (our estimate) and how practitioners rate each
Renewal How practitioners rate it
A+CompTIA$548two examscomptia.org$75 CE fee every 3 years100 to 180Help desk entry ticket. Skip it if you already work in IT.
Network+CompTIA$399comptia.org$150 CE fee every 3 years80 to 150The networking base every later cert assumes. Practise with the subnet calculator.
Security+CompTIA
DoD baseline
$439comptia.org$150 CE fee every 3 years80 to 150the Security+ curriculum gives a really nice broad overview”andrewstuart2 · Hacker News
ISC2 CCISC2$199isc2.org$50 a year30 to 60Low-cost first step. Light on its own; pair it with Security+.
CySA+CompTIA$439comptia.org$150 CE fee every 3 years80 to 150The defensive follow-on to Security+. Renews Security+ when you pass.
GSECGIAC$999giac.org$499 renewal every 4 years80 to 160Highly rated broad defence cert. Usually employer-paid.
GCIHGIAC$999giac.org$499 renewal every 4 years100 to 180Incident handling, respected in SOC and IR teams.
SecurityXCompTIA, formerly CASP+$544comptia.org$150 CE fee every 3 years120 to 200Senior hands-on alternative to CISSP. Less known by recruiters.
Exam fees: vendor list prices, USD, standard non-member rate, checked 4 Oct. SC-500 replaced AZ-500 on 31 Aug; Microsoft prices it by country, so it is left out of every total. Dataset (CSV, JSON) CC BY 4.0.
they'll get you the jobs you don't really want
trash_panda, on CEH · Hacker News · Nov 2018

Experience rules nobody reads until it is too late

Short answer

CISSP, CISM, CISA and CCSP all need five years of relevant paid work before you hold the full title. You can pass the exam first: ISC2 makes you an Associate until the years are in, and ISACA gives you five years after the exam to submit them.

ISC2

CISSP

5years

Paid work in at least two of the eight CISSP domains.

  • A four-year degree or an approved cert waives one year.
  • Pass without the years: Associate of ISC2, six years to earn them.
ISACA

CISA

5years

Work in IS audit, control, assurance or security.

  • Degrees and some certs substitute up to three years.
  • Experience counts from ten years before you apply to five years after you pass.
ISACA

CISM

5years

Security work, three of the years in security management.

  • Waivers cover up to two years, never the management part.
  • Same ten-year window as CISA.
ISC2

CCSP

5years

IT work, three years in security and one in a CCSP domain.

  • Holding CISSP covers the whole requirement.
  • Associate route as for CISSP.

What counts: paid work, full or part time, where security is a real part of the job. Internships often count in part. Help desk alone usually does not; help desk with firewall changes, access reviews or incident tickets often does. Write the duties down as you go, because you will need a referee to confirm them.

Cost and time planner

Pick any certs, in any order, to see exam fees plus three years of renewal fees, and how long the study takes at your pace. ISC2 and ISACA charge one yearly fee however many of their certs you hold, so the planner counts it once.

Plan
Foundation
Defence
Offence
Cloud
GRC and management
8 h
of study a week
Total, 3 years$1,7273 certs
Exam fees$1,277vendor list prices
Renewals$450fees due in 3 years
Study time7 to 13 monthsest. 240 to 450 hours
CertExamRenewals, 3 yrsHours, est.
Network+$399$15080 to 150
Security+$439$15080 to 150
CySA+$439$15080 to 150

Cheaper routes: Professor Messer's CompTIA videos cover A+, Network+ and Security+ at no cost; ISC2 has run no-cost CC training and exam offers, so check the current one. GIAC is excellent and expensive, which is why most holders had an employer pay.

Offensive Security certs are worthwhile, so is GIAC if you can get your employer to pay for them.
robcohen · Hacker News · Jun 2021

Three real paths

Roadmaps are tidy; careers are not. The first two routes come from people who described their own move on Hacker News; the third is the most common internal move into security.

No IT background to pentest

Labs first, then OSCP

it helps to bypass HR
bashwizard, on OSCP · Hacker News
  1. Linux and home servers until they feel normal.
  2. Network+ and Security+ knowledge, exams optional.
  3. Months of hands-on labs.
  4. OSCP to get past the HR filter.
Developer to security consultant

Expect a step back first

get ready to take a paycut and a role downgrade
howlett · Hacker News
  1. Application security work inside the current job.
  2. Security+ for the vocabulary.
  3. A junior consulting role, often at lower pay.
  4. Specialise: appsec, cloud or pentest.
Help desk to SOC

The classic internal move

passing a higher-tier cert renews the lower ones automatically
LearnZapp blog, on CompTIA renewals · learnzapp.com
  1. A+ and a help desk job.
  2. Network+, then Security+ while working.
  3. Volunteer for security tickets: phishing, access reviews.
  4. CySA+ and an internal move to SOC tier 1.

Mistakes that cost a year

Collecting certs instead of applying

Three foundation certs and no applications is a common stall. One recognised cert plus a home lab you can talk about beats a longer list.

Skipping networking

Security+ assumes you can read addresses, ports and CIDR blocks. Learn the subnetting Network+ expects before you start, or every firewall question becomes a guess.

Buying exam dumps

Dumps break vendor rules, can cost you the cert, and leave you unable to answer the first interview question on the topic.

A CEH-only resume for pentest jobs

CEH appears in job ads, but pentest interviewers ask about hands-on work. Pair it with labs or a practical cert such as PNPT or OSCP.

Taking CISSP to get a first job

Without five years of experience you hold Associate of ISC2, not CISSP. It is a management-track cert; take it when the experience is real.

Government and DoD 8140

US Department of Defense roles and many contractor jobs require a listed certification for the work role, whatever the hiring manager thinks of certs. DoD Manual 8140.03 replaced the old 8570 baseline chart: qualification now depends on the work role in the DoD Cyber Workforce Framework, and a cert is one of several ways to qualify.

In practice Security+ is the floor for a large share of entry-level government security roles, which is why the Government / DoD path above starts there. Check the role code in the job advert against the current qualification matrix on the DoD Cyber Exchange before you pay for anything above Security+.

a security certification like Security+ or better
austin-cheney, on US government roles · Hacker News · Jul 2024

Age, salary and career-change questions

Is 30 too old to get into cybersecurity?

No. Many people arrive from IT support, development, the military or audit in their thirties, and that earlier work often counts toward the experience rules above.

Is 45 too late?

Not too late, but plan for it: GRC, audit and security management value domain experience from other careers, and they are the tracks where age reads as an asset rather than a question.

Is cybersecurity still worth it?

Entry-level roles are competitive and fewer than course adverts suggest; the need for experienced people is steady. It pays off most for people who stick with one track long enough to get the experience.

Is cyber security a high-salary career?

We do not publish salary figures of our own. The US Bureau of Labor Statistics publishes median pay and job outlook for information security analysts, updated each year.

Credits and embed

The classic map of the whole field is Paul Jerimy's Security Certification Roadmap, with hundreds of certs on one chart. This page owes it a debt and tries to answer a narrower question: for one role, what next.

Career coaches, bootcamps and university career pages are welcome to embed the roadmap for the role selected above. It is CC BY 4.0; keep the credit link.

HTML, SOC analyst
<a href="https://brutepost.com/cybersecurity-certification-roadmap?role=soc-analyst"><img src="https://brutepost.com/images/cybersecurity-certification-roadmap-soc-analyst.png" alt="SOC analyst certification roadmap: Network+, Security+, CySA+" width="800"></a>
<p>Roadmap by <a href="https://brutepost.com/cybersecurity-certification-roadmap">brutepost</a>, CC BY 4.0</p>

Questions people ask

Do I need a degree for cybersecurity?

No, but it helps at some employers and government agencies, and a four-year degree knocks a year off the CISSP experience rule. Without one, visible work (labs, write-ups, a home lab) carries more weight.

CySA+ or PenTest+ after Security+?

CySA+ if you want SOC and defensive roles, which have far more openings at entry level. PenTest+ if you are set on offence, though pentest hiring talks more about OSCP and PNPT.

Is CEH worth it?

Only if a job advert or contract you want asks for it by name. It is expensive for what it teaches, and practitioners rate hands-on certs higher.

How long does Security+ take?

Our estimate is 80 to 150 hours for someone with networking basics, which is 10 to 19 weeks at eight hours a week. Add Network+ time if subnetting and ports are new.

Do certifications expire?

Most do. CompTIA, ISC2 and ISACA certs run on three-year cycles, and passing a higher CompTIA cert renews the lower ones. GIAC renews every four years, Microsoft yearly with a free online assessment, AWS every three years. OSCP and PNPT do not expire.

Start with step one

Security+ is on almost every path above

When you are ready to test yourself, work through these Security+ practice questions, with an explanation for every answer.

Also: the subnet calculator you will use daily in any network or security job.

Sources

  1. Vendor fee pages: CompTIA, ISC2, ISACA, GIAC, OffSec, TCM Security, EC-Council, AWS, Microsoft
  2. Exam outlines: CompTIA Security+ objectives, ISC2 CISSP exam outline, ISACA CISA exam content outline
  3. NIST SP 800-181 Rev. 1, Workforce Framework for Cybersecurity (NICE Framework), and the NICE Framework Resource Center, NIST
  4. Cyber Career Pathways Tool, CISA NICCS
  5. DoD Manual 8140.03, Cyberspace Workforce Qualification and Management Program
  6. ISO/IEC 27001, information security management systems, ISO
  7. Security Certification Roadmap, Paul Jerimy
  8. DoD Cyber Exchange, 8140 qualification
  9. BLS Occupational Outlook, information security analysts

Changelog

  • 4 Oct: GCIH added to the table and dataset, fee and renewal checked on giac.org.
  • 4 Oct: SC-500 replaces AZ-500 in the cloud path.
  • 4 Oct: planner counts ISC2 and ISACA yearly fees once per vendor.
  • First published with seven role paths and the reputation dataset.