Certification guide

Which cyber security certification is worth it?

What each major certification costs, who it is genuinely for, what it opens, and the order that makes sense. Prices are the published US list prices at the time of writing — always confirm on the vendor’s own site before you buy.

Last reviewed: 30 August 2026

The honest summary. Certifications do two things well: they get your résumé past an automated filter, and they force you to study a syllabus properly. They do not substitute for hands-on experience, and no certification alone will get you hired. Budget for one, then spend the rest of your money and time on a home lab.

If you are US-based and targeting defence work, check the DoD 8140 approved baseline list before choosing — it narrows the field considerably.

Cost and commitment at a glance

Published US exam prices. Training, books and lab time are extra and usually cost more than the exam itself.
CertificationBodyExam price (USD)Experience requiredBest for
ISC2 CC (Certified in Cybersecurity)ISC2$199NoneAbsolute beginners, budget-constrained
CompTIA Security+ (SY0-701)CompTIA~$425None (2 yrs suggested)The default first certification
ISC2 SSCPISC2$2491 yearHands-on operations staff
CompTIA CySA+CompTIA~$4253–4 yrs suggestedSOC analysts after Security+
ISC2 CCSPISC2$5995 yearsCloud security specialists
ISC2 CISSPISC2$7495 yearsSenior generalists and managers
OffSec OSCP (PEN-200)OffSec~$1,499 bundleStrong technical basePenetration testers
ISACA CISMISACA~$575–$7605 yearsSecurity managers, GRC leads

Sources: ISC2 exam pricing; CompTIA and OffSec published pricing. ISACA pricing varies by membership. Prices change — treat these as planning figures, not quotes, and see how we check them.

The ones that matter, one by one

Start here

CompTIA Security+

What it is: a vendor-neutral, entry-level exam covering threats, architecture, operations, governance and cryptography. Maximum 90 questions in 90 minutes, including performance-based simulations; pass mark 750/900.

Why it matters: it is the certification HR filters are most often configured to look for, and it appears on the DoD 8140 baseline list for multiple job categories — which makes it effectively mandatory for a large slice of US defence-adjacent work.

Reality check: it proves vocabulary, not capability. Pair it with a home lab or it will not carry you through a technical interview.

Renewal: three years, via continuing education units plus an annual fee.

Cheapest way in

ISC2 Certified in Cybersecurity (CC)

What it is: ISC2’s entry-level certification, priced at $199 with no experience requirement, covering security principles, business continuity, access control, network security and operations.

Why it matters: it is the lowest-cost credible first credential, and ISC2 has periodically run free-exam campaigns for newcomers — check before paying.

Reality check: less recognised by US HR filters than Security+. Treat it as a stepping stone or a budget alternative, not a replacement.

SOC track

CompTIA CySA+

What it is: the analyst-focused follow-on to Security+ — behavioural analytics, threat detection, vulnerability management and incident response.

Why it matters: it maps directly onto what a Tier 1–2 SOC analyst does daily, which makes it a more honest signal than a second general-purpose certification.

Reality check: only worth it if you are actually pointed at detection and response work. Cloud people should do CCSP or a provider certification instead.

Hard, and worth it

OffSec OSCP (PEN-200)

What it is: a fully hands-on penetration testing certification. The exam is a proctored, roughly 24-hour practical assessment against a live lab, followed by a professional report you must submit.

Why it matters: it is the most respected practical credential for aspiring pen testers because it cannot be passed by memorisation. Many offensive job ads list it explicitly.

Cost: the PEN-200 course-and-exam bundle is roughly $1,499 including 90 days of lab access and one attempt; the Learn One subscription is around $2,749 a year.

Reality check: expect three to six months of serious preparation. Do not attempt it as a first certification.

Career-defining, later

ISC2 CISSP

What it is: a broad management-oriented certification across eight domains, requiring five years of cumulative paid experience in at least two of them.

Why it matters: it is the single most-requested credential in senior US security job ads, and it is frequently a hard requirement for director and CISO roles.

Reality check: taking it before you have the experience earns you “Associate of ISC2” status, not CISSP. It is a mile wide and an inch deep by design — it will not make you technical.

Highest demand skill

ISC2 CCSP & the cloud provider certs

What it is: CCSP is the vendor-neutral cloud security certification ($599, five years’ experience). AWS Security Specialty and Microsoft SC-100 are the provider-specific equivalents.

Why it matters: cloud security is the #2 most-needed skill in ISC2’s 2025 workforce study, behind only AI/ML. This is where the pay premium currently sits.

Reality check: if you work in one cloud, the provider certification will teach you more useful things faster. CCSP is better for architects who must be neutral.

Management track

ISACA CISM & CRISC

What it is: CISM covers security governance, risk and programme management; CRISC focuses on IT risk. Both require around five years of relevant experience.

Why it matters: in regulated industries — banking, insurance, healthcare — these carry as much weight as CISSP and sometimes more.

Reality check: aimed squarely at people who manage programmes and budgets. Not useful early in a technical career.

Free, and underrated

What to do instead of a second certification

After your first certification, hands-on evidence beats another exam almost every time. Build a home lab and document it publicly. Work through TryHackMe or Hack The Box paths. Contribute detections to an open ruleset. Write up three investigations in plain English.

A hiring manager can fake-detect a certification in thirty seconds. They cannot fake-detect someone who can walk them through a real investigation they ran themselves.

Sequencing

A sensible order, by starting point

Complete beginner

  1. Networking fundamentals (Network+ or free equivalent)
  2. ISC2 CC or CompTIA Security+
  3. Home lab — six months, documented
  4. CySA+ once you are in a SOC

Already in IT

  1. Security+ to clear HR filters
  2. Your existing platform’s security certification (AWS, Azure, Cisco)
  3. Internal move to a security-adjacent duty
  4. CCSP or CISSP once you hit five years

Software engineer

  1. Skip Security+ if you can; go straight at appsec
  2. OWASP Top 10 and threat modelling, deeply
  3. Cloud provider security certification
  4. OSCP only if you want to go offensive

FAQ

Certification questions people actually ask

Will a certification alone get me a job?

No. It gets your application read. What gets you hired is being able to talk fluently about something you have actually done — an investigation you ran, a lab you built, a control you implemented. Treat the certification as the ticket to the interview and the hands-on work as the thing that wins it.

Is CISSP worth it if I have no management ambitions?

Often yes, purely for market access: a large number of senior US job ads list it as required or preferred, including individual-contributor roles. It will not make you technically better. If you are choosing between CISSP and a deep technical certification in your specialism, and your résumé is already getting interviews, take the technical one.

Should my employer pay for this?

Ask — most security teams have a training budget and it frequently goes unspent. Reasonable terms are the exam fee plus study materials, sometimes with a clawback if you leave within 12 months. If an employer refuses any professional development budget for a security role, that is useful information about the team.

Do certifications expire?

Most do. CompTIA certifications last three years and renew through continuing education units plus a fee. ISC2 credentials require continuing professional education plus an annual maintenance fee. OSCP historically did not expire, though OffSec has introduced renewable variants — check the current terms. Budget for maintenance, not just acquisition.

What about a degree or a bootcamp instead?

A degree helps most with large employers, federal roles and long-term progression, and the BLS lists a bachelor's degree as typical entry-level education for information security analysts. Bootcamps vary enormously; the good ones provide structure, cohort accountability and hands-on labs, while the worst sell a certification voucher and a job-placement claim they cannot support. Ask any bootcamp for verifiable outcomes data before paying.

Certification booked? Build the lab next.

The twelve-month roadmap shows exactly what to build, what to practise on and when to start applying.