Cybersecurity Certification Roadmap: Beginner to Expert

A complete cybersecurity certification roadmap from entry level to expert. Learn which certs to earn first, time and cost per tier, and how to choose between defensive, offensive, and management tracks.
- Certifications
- Career Paths
- Growth
- Confidence
- Mindset
Key facts
- CompTIA Security+ is listed as a baseline requirement in 78% of U.S. government cybersecurity job postings per DoD Directive 8570
- CISSP holders earn a median salary of $151,860 annually according to the ISC2 2025 Cybersecurity Workforce Study
- The global cybersecurity workforce gap reached 4.8 million unfilled positions in 2025 per the ISC2 Workforce Study
- Professionals with two or more certifications earn 22% more on average than those with a single certification according to CyberSeek data
- Cloud security certifications saw a 34% increase in demand from 2024 to 2025 as organizations accelerated cloud migration programs
TL;DR
The cybersecurity certification landscape includes over 300 vendor and vendor-neutral credentials, but a structured four-tier roadmap narrows the path to what actually matters. Start with foundation certs like CompTIA Security+ or ISC2 CC (2 to 4 months, under $500). Move to intermediate credentials like CySA+, CEH, or PenTest+ (3 to 6 months, $400 to $1,200). Pursue advanced certifications such as CISSP, OSCP, or GCIH (6 to 12 months, $750 to $2,500). Specialize with cloud security certs like AWS Security Specialty or Azure Security Engineer. Total investment across all four tiers ranges from 2 to 4 years and $3,000 to $8,000.
Priya had been staring at the same browser tab for forty minutes. Twenty-three open tabs, actually, each one displaying a different certification: CompTIA Security+, CISSP, CEH, OSCP, CySA+, AWS Security Specialty, and a dozen more she could barely keep straight. She was six months into her first help desk role, eager to move into security, and completely paralyzed by the sheer number of options. Every forum thread she read offered different advice. One said to start with Security+. Another said it was a waste of money and to go straight for OSCP. A third recommended skipping certifications entirely in favor of home labs and CTF competitions.
The problem was not a lack of information. It was the opposite. Too many credentials, too many opinions, and zero clarity on which ones actually mattered at each stage of a cybersecurity career. Priya needed a roadmap, not a catalog.
This guide provides that roadmap. Four clear tiers, specific certifications at each level, realistic time and cost estimates, and career track branching so you can chart a path that fits where you want to go, not just where the loudest voices on the internet tell you to start.
Why Certification Order Matters
Cybersecurity certifications build on each other. Each tier introduces concepts that the next tier assumes you already know. Attempting CISSP without understanding the fundamentals covered in Security+ is like trying to read a novel in a language where you only know the alphabet. You might recognize individual pieces, but the full picture never comes together.
The right sequence also maximizes your return on investment. Entry level certifications cost less, take less time, and open the door to roles where you gain the practical experience that makes advanced certifications achievable. A SOC analyst with two years of real incident response experience will pass GCIH on the first attempt. Someone studying GCIH material without ever having triaged a security alert will struggle with the same exam.
Beyond the knowledge, employers read your certification list as a career narrative. Security+ tells them you understand the fundamentals. CySA+ says you can analyze threats. CISSP communicates that you think at the enterprise level. The sequence tells a story of deliberate, structured growth, not random credential collecting.
Tier 1: Foundation (Entry Level)
Every cybersecurity career starts here. Foundation certifications prove that you understand core security concepts: threats, vulnerabilities, risk management, cryptography basics, identity management, and network security fundamentals. These are the certifications that get your resume past automated filters and into the hands of hiring managers.
CompTIA Security+
CompTIA Security+ is the gold standard entry point. It is listed as a baseline requirement in 78% of U.S. government cybersecurity job postings per DoD Directive 8570, and it appears in private sector postings almost as frequently. The exam covers six domains: threats, architecture, implementation, operations, governance, and compliance.
Time to prepare: 2 to 4 months of consistent study (1 to 2 hours daily). Cost: $439 for the exam voucher. Study materials range from $0 (Professor Messer's free YouTube series) to $300 for premium platforms. Prerequisite: None officially. CompTIA recommends CompTIA Network+ and two years of IT experience, but many people pass Security+ as their first certification.
ISC2 Certified in Cybersecurity (CC)
The ISC2 introduced the CC certification in 2022 as a free entry point into their ecosystem. The exam is free, and ISC2 membership for CC holders is also free. The content is lighter than Security+ but covers the same foundational domains. It is an excellent option if cost is a barrier, and it carries the ISC2 brand, which gains recognition at the advanced level through CISSP.
Time to prepare: 1 to 2 months. Cost: Free (exam and annual membership). Prerequisite: None.
Google Cybersecurity Professional Certificate
Google's certificate is not a traditional certification exam but a structured learning program on Coursera. It covers security fundamentals, network security, Linux, Python, and SIEM tools. Completing it earns a shared credential and prepares you for the CompTIA Security+ exam. It is particularly useful for career changers who need foundational IT knowledge before tackling Security+.
Time to prepare: 3 to 6 months at 7 hours per week. Cost: Coursera subscription ($49/month). Prerequisite: None.
Tier 2: Intermediate (Practitioner)
Intermediate certifications signal that you can do the work, not just understand the theory. These credentials demonstrate hands-on capability in specific security functions: threat analysis, ethical hacking, or vulnerability assessment. This is where your career path begins to branch.
CompTIA CySA+
CompTIA CySA+ is the natural next step for professionals on the defensive track. It focuses on threat detection, security monitoring, vulnerability management, and incident response. The exam uses performance-based questions that simulate real scenarios, testing your ability to analyze log data, interpret vulnerability scan results, and recommend mitigation strategies.
Time to prepare: 3 to 5 months. Cost: $439 for the exam voucher. Prerequisite: Security+ or equivalent knowledge, plus 3 to 4 years of hands-on experience recommended.
EC-Council Certified Ethical Hacker (CEH)
CEH is the most widely recognized offensive security certification at the intermediate level. It covers reconnaissance, scanning, enumeration, system hacking, malware analysis, sniffing, social engineering, and web application attacks. While some in the community criticize CEH as overly theoretical compared to OSCP, it remains a gate-opener for many offensive security positions, particularly in government contracting and consulting.
Time to prepare: 3 to 4 months. Cost: $1,199 for the exam (or $2,199 with official training). Prerequisite: Two years of information security experience or official EC-Council training.
CompTIA PenTest+
CompTIA PenTest+ bridges the gap between theory and practice for aspiring penetration testers. It covers planning, information gathering, vulnerability identification, attacks and exploits, and reporting. Unlike CEH, PenTest+ emphasizes vulnerability assessment and penetration testing methodology with performance-based questions that require you to demonstrate actual techniques.
Time to prepare: 3 to 5 months. Cost: $439 for the exam voucher. Prerequisite: Security+ and 3 to 4 years of hands-on experience recommended.
Tier 2 total investment: 3 to 6 months of study, $400 to $1,200 depending on the certification chosen. Most professionals earn one or two intermediate certs, not all three.
Tier 3: Advanced (Senior Professional)
Advanced certifications separate experienced practitioners from senior professionals. These credentials carry significant weight in hiring decisions and salary negotiations because they demand both deep knowledge and real-world experience. Professionals with two or more certifications earn 22% more on average than those with a single credential, and the jump from intermediate to advanced is where the salary differential becomes most pronounced.
ISC2 CISSP
CISSP is the most recognized advanced certification in cybersecurity. It covers eight domains: security and risk management, asset security, security architecture, communication and network security, identity and access management, security assessment, security operations, and software development security. CISSP holders earn a median salary of $151,860 annually.
CISSP is not a technical deep-dive certification. It tests your ability to think at the enterprise level: designing security programs, managing risk across business units, and making strategic decisions that balance security with operational needs. This is the certification that opens doors to CISO and director-level roles.
Time to prepare: 4 to 6 months for experienced professionals. Cost: $749 for the exam. Prerequisite: Five years of cumulative paid work experience in two or more CISSP domains. A four-year degree or approved credential substitutes for one year.
Offensive Security OSCP
OSCP is the benchmark for offensive security capability. Unlike multiple-choice exams, the OSCP is a 24-hour practical exam where you must compromise multiple machines in a controlled lab environment. There are no hints. There is no partial credit. You either get root access or you do not. This is the certification that penetration testing firms use to verify that candidates can actually perform the work.
Time to prepare: 3 to 6 months of intensive lab practice. Cost: $1,749 (includes 90 days of lab access and one exam attempt). Prerequisite: Strong networking and Linux skills. No official requirements, but attempting OSCP without PenTest+ or CEH-level knowledge is not recommended.
GIAC GCIH (Incident Handler)
GCIH validates your ability to detect, respond to, and resolve security incidents. It covers incident handling processes, computer crime investigation, hacker exploits, and hacker tools. GIAC certifications are highly respected in the incident response community and are backed by SANS Institute training, which many consider the highest quality security education available.
Time to prepare: 4 to 6 months. Cost: $2,499 (exam only) or $8,000+ with SANS training course. Prerequisite: Security experience recommended. No formal prerequisites.
Tier 3 total investment: 6 to 12 months of study, $750 to $2,500 per certification. Most professionals focus on one advanced cert aligned with their career track.
Tier 4: Specialist (Domain Expert)
Specialist certifications prove mastery in a specific technology ecosystem. As organizations accelerate cloud migration, cloud security certifications saw a 34% increase in demand from 2024 to 2025. These credentials complement your advanced certifications rather than replace them. A CISSP with AWS Security Specialty signals a security architect who can design and implement cloud-native security programs.
AWS Certified Security Specialty
AWS Security Specialty validates expertise in securing AWS workloads. It covers incident response on AWS, logging and monitoring, infrastructure security, identity and access management, and data protection. This is essential for security professionals working in AWS-heavy environments, which represent the largest share of cloud deployments globally.
Time to prepare: 2 to 4 months for AWS-experienced professionals. Cost: $300 for the exam. Prerequisite: 5+ years of IT security experience and 2+ years of hands-on AWS security experience recommended.
Microsoft Azure Security Engineer (AZ-500)
Azure Security Engineer covers identity and access management, platform protection, security operations, and data and application security within the Azure ecosystem. With Microsoft's enterprise market share, this certification is particularly valuable for professionals in corporate environments where Azure Active Directory and Microsoft 365 security are daily concerns.
Time to prepare: 2 to 3 months. Cost: $165 for the exam. Prerequisite: Azure administration experience recommended.
Google Cloud Professional Cloud Security Engineer
GCP Security validates your ability to design and implement secure infrastructure on Google Cloud Platform. While GCP has a smaller market share than AWS or Azure, Google's presence in data analytics, machine learning, and Kubernetes-heavy environments makes this certification increasingly valuable for security professionals in technology-forward organizations.
Time to prepare: 2 to 3 months. Cost: $200 for the exam. Prerequisite: GCP experience recommended.
Tier 4 total investment: 2 to 4 months of study, $165 to $300 per certification. Most professionals earn one cloud security cert aligned with their employer's cloud provider.
Career Track Branching: Choosing Your Path
After completing Tier 1, the certification roadmap branches into three distinct career tracks. Your choice depends on what excites you, what roles are available in your market, and where you see yourself in five to ten years.
Defensive Track (Blue Team)
Path: Security+ → CySA+ → GCIH → CISSP
This track leads to roles in security operations, incident response, threat intelligence, and eventually security leadership. You will spend your days monitoring alerts, analyzing threats, managing incidents, and building detection capabilities. Defensive professionals are the backbone of every security operations center and the largest hiring category in cybersecurity.
Target roles: SOC analyst, incident responder, threat intelligence analyst, security operations manager, CISO.
Offensive Track (Red Team)
Path: Security+ → PenTest+ or CEH → OSCP → GPEN
This track leads to penetration testing, red teaming, vulnerability research, and application security. You will spend your days finding vulnerabilities before attackers do, simulating real-world attacks, and helping organizations understand their actual security posture. Offensive roles are fewer in number but often command premium salaries.
Target roles: Penetration tester, red team operator, vulnerability researcher, application security engineer.
Management Track (GRC and Leadership)
Path: Security+ → CySA+ → CISSP → CISM or CRISC
This track leads to governance, risk, and compliance (GRC) roles and eventually to executive security leadership. You will spend your days translating technical risk into business language, building security programs, managing compliance frameworks, and advising executive leadership. This track requires strong communication skills alongside technical knowledge.
Target roles: Security manager, GRC analyst, security director, CISO.
Common Mistakes to Avoid
Collecting certifications without gaining experience. Certifications validate knowledge. Experience validates capability. Employers want both. After each certification, spend at least 12 to 18 months applying what you learned before pursuing the next one.
Skipping the foundation. Security+ exists for a reason. Every concept in CySA+, CEH, and CISSP assumes you already understand network protocols, cryptographic principles, and risk management frameworks. Skipping the foundation creates knowledge gaps that compound at every subsequent tier.
Chasing the highest salary certification first. CISSP commands impressive salaries, but earning it without the prerequisite experience means you will hold a credential you cannot fully leverage. The five-year experience requirement exists because CISSP tests strategic thinking that comes from years of hands-on work, not from study guides alone.
Ignoring renewal requirements. Most certifications require continuing education credits (CEUs) or periodic re-examination. CompTIA certifications require 50 CEUs over three years. CISSP requires 40 continuing professional education (CPE) credits annually. Factor renewal costs and time into your long-term planning.
Building Your Personal Roadmap
The right certification path depends on your starting point, timeline, and career goals. Use this framework to build your own plan:
-
Assess your current level. If you have no IT experience, start with the Google Cybersecurity Certificate or CompTIA A+/Network+ before attempting Security+. If you already work in IT, go directly to Security+.
-
Choose your track. Defensive, offensive, or management. You do not need to decide permanently, but having a direction prevents aimless credential accumulation.
-
Set a two-year goal. Map out which Tier 1 and Tier 2 certifications you will earn in the next 24 months. Budget both time and money.
-
Gain experience between certifications. Apply for roles after each cert. Real-world experience is what transforms certification knowledge into professional capability.
-
Reassess annually. The cybersecurity landscape evolves. New certifications emerge. Existing ones update their content. Review your roadmap once a year and adjust based on industry trends and personal interests.
The global cybersecurity workforce gap reached 4.8 million unfilled positions in 2025. The demand for qualified professionals is not shrinking. A structured certification roadmap, combined with hands-on experience and continuous learning, is the most reliable path from where you are now to where you want to be.
Priya closed twenty-two of her twenty-three browser tabs, kept the one for CompTIA's Security+ exam page, and scheduled her first study session for the following morning. The roadmap was clear. The first step was simple. Everything else would follow.
Frequently asked questions
- Which cybersecurity certification should I get first?
- CompTIA Security+ is the recommended first certification for most people entering cybersecurity. It covers foundational concepts across all security domains, is recognized by the U.S. Department of Defense, and serves as a prerequisite for many intermediate certifications. If cost is a concern, the ISC2 Certified in Cybersecurity (CC) is free to attempt and provides a solid alternative entry point.
- How long does it take to go from no certifications to CISSP?
- The typical timeline from zero certifications to CISSP is 3 to 5 years. CISSP requires five years of cumulative paid work experience in two or more of its eight domains, though a four year degree or an approved credential like Security+ can substitute for one year. Most professionals earn Security+ within their first year, add one or two intermediate certs over the next two years, and then pursue CISSP once they meet the experience requirement.
- Are cybersecurity certifications worth the cost?
- Yes, when chosen strategically. Professionals with certifications earn significantly more than those without. The key is selecting certifications that align with your target role and current career stage rather than collecting credentials randomly. A SOC analyst pursuing Security+ followed by CySA+ will see better returns than someone earning five unrelated entry level certs.
- Do I need a degree to get cybersecurity certifications?
- No. Most cybersecurity certifications have no degree requirement. CompTIA Security+, CEH, CySA+, PenTest+, and OSCP are all accessible without a college degree. CISSP requires five years of work experience, but a degree can substitute for one of those years. The certification path is one of the most accessible routes into cybersecurity for career changers.
- Should I focus on offensive or defensive certifications?
- Start with vendor-neutral defensive certifications like Security+ and CySA+ because they build the broadest foundation. Once you have 1 to 2 years of experience, choose based on what excites you. If you enjoy finding vulnerabilities and breaking into systems, pursue offensive certs like PenTest+, CEH, and OSCP. If you prefer monitoring, incident response, and threat analysis, stay on the defensive track with GCIH and eventually CISSP.
Daute built Unihackers after a decade defending airlines, managed SOCs and international organisations. He is an Associate C|CISO and a regular voice on AI and cybersecurity in international media. Silver Winner at the 2021 Cyber Security Excellence Awards. He teaches the way he wishes someone had taught him: skip the noise, train on what attackers actually do, and graduate people who are useful from day one.
View ProfileReady to Start Your Cybersecurity Career?
Join hundreds of professionals who've transitioned into cybersecurity with our hands-on bootcamp.

