The honest summary. Certifications do two things well: they get your résumé past an automated filter, and they force you to study a syllabus properly. They do not substitute for hands-on experience, and no certification alone will get you hired. Budget for one, then spend the rest of your money and time on a home lab.
If you are US-based and targeting defence work, check the DoD 8140 approved baseline list before choosing — it narrows the field considerably.
Start here
CompTIA Security+
What it is: a vendor-neutral, entry-level exam covering threats, architecture, operations, governance and cryptography. Maximum 90 questions in 90 minutes, including performance-based simulations; pass mark 750/900.
Why it matters: it is the certification HR filters are most often configured to look for, and it appears on the DoD 8140 baseline list for multiple job categories — which makes it effectively mandatory for a large slice of US defence-adjacent work.
Reality check: it proves vocabulary, not capability. Pair it with a home lab or it will not carry you through a technical interview.
Renewal: three years, via continuing education units plus an annual fee.
Cheapest way in
ISC2 Certified in Cybersecurity (CC)
What it is: ISC2’s entry-level certification, priced at $199 with no experience requirement, covering security principles, business continuity, access control, network security and operations.
Why it matters: it is the lowest-cost credible first credential, and ISC2 has periodically run free-exam campaigns for newcomers — check before paying.
Reality check: less recognised by US HR filters than Security+. Treat it as a stepping stone or a budget alternative, not a replacement.
SOC track
CompTIA CySA+
What it is: the analyst-focused follow-on to Security+ — behavioural analytics, threat detection, vulnerability management and incident response.
Why it matters: it maps directly onto what a Tier 1–2 SOC analyst does daily, which makes it a more honest signal than a second general-purpose certification.
Reality check: only worth it if you are actually pointed at detection and response work. Cloud people should do CCSP or a provider certification instead.
Hard, and worth it
OffSec OSCP (PEN-200)
What it is: a fully hands-on penetration testing certification. The exam is a proctored, roughly 24-hour practical assessment against a live lab, followed by a professional report you must submit.
Why it matters: it is the most respected practical credential for aspiring pen testers because it cannot be passed by memorisation. Many offensive job ads list it explicitly.
Cost: the PEN-200 course-and-exam bundle is roughly $1,499 including 90 days of lab access and one attempt; the Learn One subscription is around $2,749 a year.
Reality check: expect three to six months of serious preparation. Do not attempt it as a first certification.
Career-defining, later
ISC2 CISSP
What it is: a broad management-oriented certification across eight domains, requiring five years of cumulative paid experience in at least two of them.
Why it matters: it is the single most-requested credential in senior US security job ads, and it is frequently a hard requirement for director and CISO roles.
Reality check: taking it before you have the experience earns you “Associate of ISC2” status, not CISSP. It is a mile wide and an inch deep by design — it will not make you technical.
Highest demand skill
ISC2 CCSP & the cloud provider certs
What it is: CCSP is the vendor-neutral cloud security certification ($599, five years’ experience). AWS Security Specialty and Microsoft SC-100 are the provider-specific equivalents.
Why it matters: cloud security is the #2 most-needed skill in ISC2’s 2025 workforce study, behind only AI/ML. This is where the pay premium currently sits.
Reality check: if you work in one cloud, the provider certification will teach you more useful things faster. CCSP is better for architects who must be neutral.
Management track
ISACA CISM & CRISC
What it is: CISM covers security governance, risk and programme management; CRISC focuses on IT risk. Both require around five years of relevant experience.
Why it matters: in regulated industries — banking, insurance, healthcare — these carry as much weight as CISSP and sometimes more.
Reality check: aimed squarely at people who manage programmes and budgets. Not useful early in a technical career.
Free, and underrated
What to do instead of a second certification
After your first certification, hands-on evidence beats another exam almost every time. Build a home lab and document it publicly. Work through TryHackMe or Hack The Box paths. Contribute detections to an open ruleset. Write up three investigations in plain English.
A hiring manager can fake-detect a certification in thirty seconds. They cannot fake-detect someone who can walk them through a real investigation they ran themselves.