Cybersecurity Certifications Roadmap: Security+ to OSCP to CISSP
Certifications remain the fastest way to signal cybersecurity competence to hiring managers, procurement teams, and government contractors, but the market is crowded with overlapping credentials that promise more than they deliver. Some certifications open doors within weeks of passing; others cost thousands of dollars and produce little measurable career lift. This roadmap walks you through the certifications that actually move salary bands and hiring decisions, sequenced by the role you want to hold in two, five, and ten years. You will get honest study time estimates, exam economics, employer perception data from job postings, and specific guidance for analyst, pentester, cloud engineer, and executive tracks. Read it once end to end, then return to the section that matches where you are right now.
Why certifications still matter in cybersecurity hiring
Cybersecurity is one of the few technology fields where certifications carry more weight than degrees for most non-managerial roles. The reason is regulatory: government contracts (DoD 8570, now 8140), PCI DSS assessor requirements, and cyber insurance underwriting all reference specific certifications by name. When a hiring manager writes a job description, HR often maps the required skills to certifications because certifications are searchable, verifiable, and defensible in an audit. A candidate with Security+ passes the DoD 8140 baseline filter for a huge swath of federal and contractor roles; a candidate without it does not, regardless of experience.
Beyond compliance, certifications compress the signal that experience alone struggles to send. Two candidates might both claim five years of SOC work, but the one with GCIA, GCIH, or CySA+ has demonstrated proctored competence in packet analysis, incident handling, or behavioral analytics. Hiring managers use certifications as a shortlist filter, not a final decision, but if you are not on the shortlist, the interview never happens. This is especially true when applying through job boards where an automated system parses your resume before a human reads it.
That said, certifications are not equivalent to skills, and the industry has grown skeptical of paper-only candidates who can pass multiple choice exams but freeze when handed a real alert. The credentials that survive this scrutiny share one trait: they include performance based components or hands on lab exams. OSCP, the GIAC practical exams, CCSP labs, and the newer CompTIA PenTest+ PBQs all require you to actually do the work, not just describe it. When you plan your certification path, weight performance based credentials higher than pure multiple choice ones, even when the latter are cheaper.
Finally, certifications signal commitment. Spending 200 hours studying for Security+ or 600 hours grinding through OSCP labs tells an employer that you will invest in your own growth without being asked. For entry level candidates without a security track record, this signal is often the deciding factor. If you want a broader view of how certifications fit into a full career trajectory, review the cybersecurity career guide for context on how credentials pair with experience milestones.
The certification landscape at a glance
The security certification market has five major vendors, each with a distinct positioning. CompTIA sits at the entry to mid level, vendor neutral, with reasonable pricing and broad recognition. (ISC)² owns the management and cloud governance tier with CISSP and CCSP, both requiring five years of verified experience for full certification. Offensive Security dominates the practical offensive skills space with OSCP, OSEP, OSWE, and OSED, all lab intensive and unforgiving. SANS/GIAC produces the deepest technical certifications in the industry through their five to six day courses, priced accordingly at $8,000 to $12,000 per cert. EC-Council fills the middle with CEH, which is widely recognized by HR but often dismissed by practitioners.
Beyond the big five, cloud providers issue their own security specialty exams: AWS Certified Security Specialty, Azure AZ-500, and Google Professional Cloud Security Engineer. Vendor certifications from Cisco (CCNP Security), Palo Alto (PCNSE), Fortinet (NSE), and Splunk (Core Certified Power User) matter when the employer runs that stack. ISACA covers governance with CISA, CISM, and CRISC, aimed squarely at audit and risk management roles rather than technical work.
Here is a rough map of where the major certifications sit by career stage and cost:
| Certification | Stage | Cost (USD) | Format | Study time |
|---|---|---|---|---|
| CompTIA Security+ | Entry | $392 | 90 min, 90 questions + PBQs | 80-150 hours |
| CompTIA CySA+ | Early | $392 | 165 min, 85 questions | 100-180 hours |
| CompTIA PenTest+ | Early-mid | $392 | 165 min, 85 questions | 120-200 hours |
| CEH (v13) | Early-mid | $1,199 | 240 min, 125 questions | 100-160 hours |
| OSCP | Mid | $1,749 (with 90 day lab) | 24 hour practical exam | 400-800 hours |
| GCIH / GCIA / GCFA | Mid-senior | $8,780+ (with SANS course) | 4 hour open book | Course + 60 hours |
| AWS Security Specialty | Mid | $300 | 170 min, 65 questions | 80-140 hours |
| CCSP | Senior | $599 | 4 hour, 150 questions | 120-200 hours |
| CISSP | Senior | $749 | 3-6 hour CAT | 150-300 hours |
Note the enormous cost variance. A candidate spending strategically can build a strong resume for under $2,000 by picking Security+, an AWS specialty, and a targeted vendor cert. Someone who takes three SANS courses back to back will spend $27,000+ for the same signal strength in most hiring contexts. Cost efficiency matters, especially if you are self funding.
Entry level: Security+ as the universal starting point
If you are new to cybersecurity, CompTIA Security+ is the correct first certification for 90% of readers. It is the DoD 8140 baseline for the IAT Level II category, meaning it unlocks a large portion of federal contractor jobs. It is vendor neutral, so nothing you learn is wasted if you later switch stacks. HR systems recognize it universally, so it clears the automated resume filter. And at $392 with study materials available for another $100 to $200, it is one of the highest ROI credentials in the entire technology industry.
The exam covers five domains: general security concepts, threats and vulnerabilities, security architecture, security operations, and program management and oversight. Expect roughly 90 questions with a handful of performance based questions (PBQs) that simulate configuring a firewall rule, analyzing a log, or matching attacks to mitigations. The passing score is 750 out of 900, scaled. Most first time takers report the PBQs as the hardest part because they consume time disproportionately; a good strategy is to skip them initially, answer all multiple choice, then return to PBQs with your remaining time.
Study time varies with background. Someone with two years of IT support or networking experience can pass in 80 to 120 hours; a complete beginner should plan for 150 to 200 hours. The canonical resources are Professor Messer's free video series, the Sybex Study Guide by Mike Chapple and David Seidl, Jason Dion's Udemy course and practice tests, and the CertMaster labs from CompTIA directly. Use two sources minimum: one for concepts (videos or book) and one for practice questions. Aim for 85% consistent on practice tests before scheduling the real exam.
After Security+, resist the urge to immediately stack another CompTIA cert. Get a job first, even a helpdesk or NOC role that touches security tickets, then let your employer or your daily work dictate the second certification. If you land a SOC role, CySA+ or a SANS entry cert makes sense next. If you land a cloud role, pivot to AWS or Azure security. If you get stuck in the job hunt after Security+ and 100+ applications, the problem is not usually the missing second certification, it is portfolio and networking. For structured lab practice and mentorship that fills the experience gap employers screen for, consider the Refonte Learning cybersecurity program and internship which pairs certification prep with hands on projects.
The SOC analyst track: CySA+, GCIA, GCIH
Security operations center roles are the most common entry point into cybersecurity, and the certification path is well defined. After Security+, the analyst track branches based on budget. Under $500 per credential: CompTIA CySA+ then Blue Team Level 1 (BTL1) from Security Blue Team. Under $2,000 per credential and employer funded: SANS SEC401 with GSEC, SANS SEC450 with GBFA, or SANS SEC503 with GCIA. The SANS path is the gold standard for depth but requires either an employer training budget or the SANS Work Study program.
CySA+ focuses on behavioral analytics, threat hunting, and incident response, with performance based questions on log analysis and SIEM queries. It is a strong second certification for anyone in a monitoring role, and it stacks well with a specialization in a specific SIEM (Splunk, Sentinel, QRadar). The exam is harder than Security+, with more scenario based questions that require you to reason about attacker behavior rather than recall definitions. Plan on 100 to 180 hours of study, with heavy emphasis on practicing log analysis in a real environment. Set up a home lab with Security Onion or the free tier of Elastic Security to practice.
GCIA (GIAC Certified Intrusion Analyst) is the deepest packet and network analysis certification available. It maps to SANS SEC503, a six day course that walks through tcpdump, Wireshark, Zeek, Snort, and Suricata in exhausting detail. If your role involves reading pcaps, writing detection rules, or investigating network based incidents, GCIA will make you noticeably better at the job within weeks of finishing the course. The exam is open book, but the book is 1,500+ pages across five volumes, and the questions require you to know where information lives, not just that it exists. Build a comprehensive index during the course; without one, you will run out of time.
GCIH (GIAC Certified Incident Handler) pairs with SEC504 and covers the attacker methodology from a defender's perspective. You learn reconnaissance, exploitation, and post exploitation techniques so you can recognize them in your logs and network traffic. GCIH is one of the most respected mid career analyst certifications and appears in more senior SOC and IR job descriptions than any other GIAC cert. If you can only take one SANS course as an analyst, choose SEC504/GCIH. Complement it with strong network fundamentals from the network security guide, which covers the traffic patterns you will spend your career investigating.
The offensive security track: PenTest+, CEH, OSCP, and beyond
Pentesting and red teaming attract many candidates, but the path is longer and more skills gated than the SOC path. Employers hiring pentesters look for demonstrated ability to compromise systems, not just knowledge of tools. Certifications matter here, but so do CTF write ups, HackTheBox rankings, bug bounty findings, and open source security tools you have published. Plan for the certification track to run alongside a public portfolio, not as a substitute for one.
CEH from EC-Council is the most commonly required pentest certification in job postings, largely because HR recognizes the name and DoD 8140 lists it under CSSP Analyst. Practitioners are ambivalent to hostile toward CEH because the exam is multiple choice and does not require you to actually exploit anything. If a job description mandates CEH, get it, but do not expect it to prepare you for real pentest work. Study time is 100 to 160 hours, and the exam costs $1,199 unless you take the official training, which pushes total cost to $2,500+.
CompTIA PenTest+ is a better technical baseline than CEH at a lower price. It includes performance based questions where you must actually run tools against a target, analyze output, and select next steps. Roughly 120 to 200 hours of study prepares most candidates, and the vendor neutral coverage aligns well with what junior pentesters do day one at a consultancy. Pair PenTest+ with active HackTheBox or TryHackMe practice; the exam validates knowledge, but the platforms build the reflexes.
OSCP is the certification that hiring managers actually respect for pentest roles. The 24 hour practical exam requires you to compromise a set of machines from scratch, capture proof files, and write a professional report. Pass rates hover around 30% on first attempt. The recommended prep is Offensive Security's PWK course (now PEN-200) with 90 or 180 days of lab access, plus additional practice on HackTheBox and Proving Grounds. Realistic study time is 400 to 800 hours over three to nine months. Budget for at least one exam retake ($249 currently); most successful candidates need two attempts.
After OSCP, the offensive path splits by specialty. OSEP (Offensive Security Experienced Penetration Tester) covers advanced Active Directory attacks and evasion. OSWE (Web Expert) focuses on source code review and web exploitation. OSED (Exploit Developer) covers Windows exploit development and shellcoding. CRTO (Certified Red Team Operator) from Zero Point Security teaches Cobalt Strike based operations and is increasingly common in red team job descriptions. For the deep dive on techniques and career progression in this space, work through the pentesting career and skills guide which sequences these credentials against real job requirements.
The cloud security track: AWS, Azure, GCP, and CCSP
Cloud security is the fastest growing subdiscipline in the field, and the certification market reflects that. Every major cloud provider has a security specialty, and (ISC)² offers CCSP as a vendor neutral capstone. Which order you pursue them depends entirely on the stack your employer or target employers use. Do not study AWS if the target companies are all on Azure; the domain knowledge does not transfer as cleanly as vendors claim.
AWS Certified Security Specialty is the most valuable single cloud security certification by hiring volume. It requires deep familiarity with IAM policies, KMS, GuardDuty, Security Hub, Config, CloudTrail, VPC networking, and incident response workflows in AWS. The exam is scenario based and does not include labs, but you cannot pass without hands on time in the console and CLI. Plan on 80 to 140 hours if you already have AWS Solutions Architect Associate; 150 to 250 hours if you are starting cold. The exam costs $300 and is one of the higher ROI cloud credentials available.
Azure AZ-500 is the equivalent for Microsoft's cloud, covering identity (Entra ID), platform protection, data and application security, and security operations. Microsoft's cloud grew fastest in enterprise environments, so AZ-500 is often required for internal enterprise security roles, whereas AWS Security is more common in tech companies and cloud native startups. Google's Professional Cloud Security Engineer covers GCP and is the least common of the three by job postings, but it commands a premium in the shops that use GCP heavily (media, ML companies, some fintech).
CCSP from (ISC)² sits above the vendor specific certs as a management and architecture credential. It covers cloud concepts, data security, platform and infrastructure security, application security, operations, and legal and compliance across all major providers. It requires five years of IT experience with three in information security and one in cloud, or CISSP as an experience substitute. CCSP is respected but not required; you can build an excellent cloud security career on AWS Security plus AZ-500 without ever taking CCSP. Study time is 120 to 200 hours from a solid IT security base.
Beyond the certifications, cloud security engineers need to understand modern architecture patterns like zero trust, service mesh, and workload identity. The zero trust architecture guide covers the design patterns you will implement, and the cloud security guide walks through the operational side of running these environments at scale.
The application and web security track
Application security is undersupplied relative to demand, and the certification landscape reflects that immaturity. There is no single dominant credential for AppSec engineers the way OSCP dominates pentesting or CCSP dominates cloud governance. Instead, AppSec specialists build credibility through a mix of certifications, published research, and code review portfolios.
The GIAC Web Application Penetration Tester (GWAPT) certification, paired with SANS SEC542, is the most respected general AppSec credential. It covers the full web attack surface: authentication flaws, session management, injection, XSS, SSRF, deserialization, and modern SPA and API concerns. The exam is open book with practical elements. If your employer will fund SANS, GWAPT is worth choosing over more general certs.
Offensive Security's OSWE is the deeper technical credential for AppSec, focused on white box source code review and chained exploit development. The 48 hour exam requires you to read application source code (typically Node, PHP, Java, or .NET), find authentication bypasses and RCE, and chain them into a full compromise. It is significantly harder than OSCP for candidates without a development background. Plan 400 to 700 hours of preparation, and expect the exam to be brutal on your endurance.
For DevSecOps and secure development lifecycle roles, the credentials that matter shift toward Certified Secure Software Lifecycle Professional (CSSLP) from (ISC)², plus vendor specific tooling knowledge in Snyk, Checkmarx, Semgrep, or GitHub Advanced Security. These are less about exams and more about being productive with the tools your employer already runs. If you are targeting web focused roles, work through the web application security guide which covers both the vulnerability classes and the SDLC integration patterns you will implement.
The management and governance track: CISSP, CISM, CISA
CISSP from (ISC)² is the most requested certification in senior security job postings globally. It is broad rather than deep, covering eight domains: security and risk management, asset security, security architecture and engineering, communication and network security, identity and access management, security assessment and testing, security operations, and software development security. Full certification requires five years of paid experience in two or more domains; passing the exam without the experience yields Associate of (ISC)² status while you accumulate the hours.
The CISSP exam is computerized adaptive testing (CAT) with 100 to 150 questions delivered over up to six hours (recently reduced from 175/8h in some regions). The adaptive algorithm adjusts question difficulty based on your responses, and the exam can end as early as 100 questions if the algorithm has enough confidence in your score. Study time ranges widely: 150 hours for a candidate with 10+ years of security experience, up to 300 hours for someone stretching to pass at the minimum experience threshold. The standard resources are the Official Study Guide by Chapple and Stewart, the 11th Hour Study Guide for review, and the Boson practice exams for realistic question difficulty.
CISSP earns its reputation but also its criticism. It is a mile wide and an inch deep, and passing it does not make you a competent security engineer, architect, or manager. What it does is signal that you have exposure across all major domains and can speak the language of governance, which matters when you are the security person in the room with the CFO, general counsel, and CEO. If you plan to hold senior IC or management titles, CISSP is effectively required. If you plan to remain a deep technical specialist, CISSP is optional but rarely a bad investment given its broad recognition.
CISM (Certified Information Security Manager) from ISACA is a strong alternative or complement to CISSP for candidates on a pure management track. It focuses on information security governance, risk management, program development, and incident management, with less coverage of technical architecture. CISM tends to be preferred in banking, insurance, and regulated industries where ISACA has deeper roots. CISA (Certified Information Systems Auditor) is essential if you plan to work in IT audit, third party risk, or compliance functions.
The GIAC portfolio: when the price is worth it
SANS/GIAC certifications are the most expensive in the industry and also the deepest. A single SANS course with the associated GIAC exam runs $8,000 to $12,000 depending on delivery format (OnDemand, Live Online, in person). For that price, you get six days of instruction from a practicing expert, a large courseware set (typically five to six volumes plus lab workbooks), and a four to five hour open book proctored exam. If your employer pays, take as many as you can get funded; the material is excellent and the credentials are respected.
If you are paying yourself, GIAC math changes. Consider the SANS Work Study program, which provides significantly discounted training in exchange for facilitation work at conferences. Consider whether an equivalent certification exists at a lower price point for your goal. CompTIA CySA+ covers much of the same ground as GSEC or GCIA at 5% of the cost, though at less depth. OSCP delivers more practical pentest signal than GPEN at half the price. Cloud provider certs deliver more cloud specific signal than SANS cloud courses at 3% of the cost.
The GIAC certifications with the strongest ROI even at retail price are GCIH (incident handling, universal utility), GCFA and GCFE (forensics, mandatory in DFIR roles), GNFA (network forensics, specialized but well paid), GREM (reverse engineering, specialized), and GPEN and GXPN (pentesting, though OSCP competes). For most other GIAC certs, ask yourself whether a cheaper credential covers 80% of what the hiring manager cares about.
One underappreciated feature of GIAC exams is that they are open book. This changes study strategy completely. Rather than memorizing every detail, you build an index during your course reading, tab the important pages, and rehearse locating information quickly. A well constructed index is the single biggest predictor of a high GIAC score. Plan two to three weeks of dedicated indexing after finishing the course material and before scheduling the exam.
Sequencing by role: analyst, pentester, cloud, executive
The right certification sequence depends on where you want to be in three to five years, not just next month. Here are four canonical paths with target roles, timing, and total investment.
The SOC analyst to detection engineer path
Year 0-1: Security+ ($400), then CySA+ ($400) or Blue Team Level 1 ($500). Total under $1,000. Land a Tier 1 SOC role.
Year 2-3: GCIH ($9,000 with employer funding) or GCIA. Target promotion to Tier 2 or Tier 3 analyst. Begin contributing detection content, threat hunting queries, and playbook improvements.
Year 4-5: GCFA for forensics depth, or GCTI (Cyber Threat Intelligence) for a pivot into CTI, or begin CISSP if the goal is management. Target senior analyst, detection engineer, or CTI analyst titles.
The pentester to red teamer path
Year 0-1: Security+ ($400), then PenTest+ ($400) or CEH if HR requirements dictate. Build HackTheBox and TryHackMe presence.
Year 1-2: OSCP ($1,750 with 90 day labs, expect one retake at $249). Land a junior pentest role at a consultancy or internal team.
Year 3-4: OSEP for AD depth, OSWE for web depth, or CRTO for red team operations. Choose based on the work you do most.
Year 5+: Specialize into a niche (cloud pentest, hardware, mobile, adversary simulation) or move toward pentest team lead with CISSP added for architectural conversations.
The cloud security engineer path
Year 0-1: Security+ ($400), then AWS Solutions Architect Associate ($150) to build the cloud foundation, then AWS Security Specialty ($300). Total under $1,000.
Year 2-3: AZ-500 or GCP Professional Cloud Security Engineer, based on target employers. Add a Kubernetes security cert (CKS, $395) if the role involves containers.
Year 4-5: CCSP for vendor neutral cloud governance breadth, or CISSP if the trajectory is toward cloud security architect or CISO track.
The executive and consulting path
Year 5-8: CISSP is table stakes for this trajectory. Add CISM for governance credibility, especially in regulated industries. Add CISA if audit or third party risk is in scope.
Year 8+: CCSP or CCSK for cloud governance, CIPP/CIPM for privacy focused roles, and industry specific credentials like HITRUST CCSFP for healthcare or PCI QSA for payments.
Executive certification is less about the exam content and more about signaling that you can be trusted in the room where risk decisions get made. The certifications matter mostly for procurement, board level credibility, and speaking engagements.
Exam economics: what you actually spend
Total certification spend across a career varies wildly. Here are realistic budgets for the four tracks over the first five years, assuming self funding with occasional employer support.
| Track | Certs | Realistic 5 year cost | Employer funded 5 year cost |
|---|---|---|---|
| SOC analyst | Sec+, CySA+, GCIH, GCFA | $19,000+ | $2,000 (Sec+, CySA+ self funded) |
| Pentester | Sec+, PenTest+, OSCP, OSEP, OSWE | $6,500 | $6,500 (usually self funded) |
| Cloud engineer | Sec+, AWS SAA + Sec, AZ-500, CKS | $1,900 | $1,900 |
| Executive | Sec+, CISSP, CISM, CCSP | $2,500 | $2,500 (employers often pay CISSP AMFs) |
Hidden costs add up. CISSP maintenance is $125 annually plus 40 CPEs per year; CCSP is $100 and 30 CPEs; each GIAC renewal costs $499 every four years plus 36 CPEs. OSCP does not currently require renewal, but Offensive Security has hinted at introducing continuing education requirements. Budget $500 to $1,500 per year in maintenance fees once you hold three to five certifications.
Study material adds another line item. Budget $100 to $300 per CompTIA cert in books and practice tests, $200 to $500 per Offensive Security cert in extra lab time and adjacent training (HackTheBox VIP, Proving Grounds), and $0 for SANS courses since materials are included. Practice exams are the highest ROI purchase; Boson, MeasureUp, and Jason Dion's practice sets are worth every dollar and consistently identify weak areas you would otherwise miss.
The economics of employer funded training deserve a separate calculation. If your employer offers a training budget of $10,000 per year and you can direct it toward a SANS course plus GIAC exam, that is $10,000 of tax free compensation you are leaving on the table if you do not use it. Negotiate training budget explicitly in offers and reviews; it is often easier for employers to grant than base salary and delivers durable career value.
What employers actually value: reading job postings correctly
Job postings list certifications in three ways: required, preferred, and equivalent experience accepted. Read this list carefully because it tells you exactly which credentials the employer thinks are non negotiable.
Required means the ATS will filter you out without the cert or a direct substitute. For federal and DoD roles, Security+ or CISSP is often literally required by contract. For SOC roles at MSSPs, GCIA or GCIH is sometimes required because the customer contract mandates it. If a cert is required and you do not have it, either get it before applying or find a similar posting that lists it as preferred.
Preferred means the cert will boost your candidacy but a strong resume without it will still get interviewed. Most CISSP mentions on senior IC job postings are preferred, not required, and candidates with 10+ years of experience frequently interview successfully without it. Preferred certifications are worth targeting for the next application cycle, not blocking your current search.
Equivalent experience accepted is the most common phrasing and the most flexible. It signals that the hiring manager cares about capability, not the specific credential. Show equivalent experience with portfolio work: bug bounty reports, CTF write ups, open source security tools, conference talks, published research.
To reverse engineer which certifications matter in your target market, spend an hour pulling 20 to 30 job postings from LinkedIn or Indeed for your target role and geography. Tally which certifications appear as required versus preferred. Patterns emerge quickly. In one geography or role, CISSP might appear in 80% of postings; in another, GIAC certs might dominate. Certification investment should follow this data, not generic career advice from certification vendors themselves.
Study strategies that actually work
Cramming does not work for security certifications, especially performance based ones. The candidates who pass efficiently share a small set of habits worth adopting.
Study daily, in small blocks. One hour per day for four months beats eight hours per day for two weeks. Spaced repetition builds durable memory; cramming produces exam day recall that fades immediately after. Use tools like Anki for definitions, port numbers, cryptographic parameters, and other flashcard suitable content.
Practice questions early and often. Do not wait until you finish the material to start practice questions. Start on day three. The practice questions surface what the exam actually tests, which often differs from what the study guide emphasizes. Track your accuracy by domain and reallocate study time to weak areas weekly.
Build a real lab. For every certification with a technical component, build a lab that mirrors the exam environment. For Security+, that is a small home network with pfSense, a vulnerable VM (Metasploitable), and a monitoring VM (Security Onion). For AWS Security Specialty, that is a dedicated AWS account with IAM policies, KMS keys, GuardDuty enabled, and a small workload to secure. For OSCP, it is a HackTheBox VIP subscription and dedicated time on Proving Grounds Practice.
Teach what you learn. Explaining a concept to someone else, or writing a public blog post about it, exposes the gaps in your understanding faster than any other technique. If you cannot explain how TLS 1.3 handshakes differ from 1.2 without referencing notes, you do not know it well enough for the exam.
Simulate exam conditions before the real exam. Take at least one full length practice exam under timed conditions in a single sitting, in a quiet room, without notes. For OSCP, do a full 24 hour practice window against retired HackTheBox machines to test your endurance. Exam day should feel like the tenth time you have done this, not the first.
Common mistakes and how to avoid them
Chasing certifications instead of experience. After Security+, get a job. A candidate with Security+ and 18 months of SOC work will out interview a candidate with Security+, CySA+, and CEH but no experience, every time. Certifications supplement experience; they do not substitute for it beyond the entry level.
Skipping the fundamentals. Many candidates jump from Security+ to OSCP without solid networking or Linux skills. They then spend the OSCP labs learning subnetting and bash instead of learning exploitation. Get comfortable with CCNA level networking, Linux command line, Python or Bash scripting, and Windows administration before layering security specializations on top.
Buying every certification a recruiter mentions. Recruiters sometimes list certifications aspirationally or copy them from other postings without understanding what the role actually requires. Verify with hiring managers and current employees which credentials matter. LinkedIn is your friend here; find people in the target role at the target company and see what they actually hold.
Ignoring maintenance requirements. A lapsed CISSP or expired GIAC can trigger the same ATS rejection as never having held the cert. Budget CPE time and maintenance fees when you commit to a certification, or plan explicitly to let it lapse.
Overspending on training materials. The certification market is flooded with $500+ boot camps that add little over $50 of curated study material and free YouTube content. For Security+, Professor Messer's videos are free and sufficient for the concepts; you need only add a practice question bank. Only pay for premium training when you have tried the free resources and identified a specific gap.
Combining certifications with hands on work
Certifications establish baseline credibility, but the candidates who accelerate fastest pair them with visible, dated, hands on artifacts. A GitHub with detection engineering repos, a personal blog with pentest write ups, a Medium series on cloud security misconfigurations, or a Twitter presence engaging with security researchers all compound the value of your certifications.
Choose one artifact stream and commit to it for six months minimum. If you are on the SOC track, publish detection rules for common attacks (KQL for Sentinel, SPL for Splunk, Sigma for portability) with commentary on the attacker technique and false positive tuning. If you are on the pentest track, publish CTF and HackTheBox write ups (after retirement, per the platform's rules), and share findings from public bug bounty programs. If you are on the cloud track, publish Terraform modules for secure baseline configurations, or open source policy as code for Open Policy Agent or Cedar.
An internship or apprenticeship program can compress the timeline from certification to first real job dramatically. Structured programs pair mentorship, hands on labs, and project work that produces portfolio artifacts hiring managers can inspect. The Refonte Learning cybersecurity study and internship track sequences Security+ preparation with SOC, pentest, and cloud security labs so you graduate with both a credential and demonstrable project experience. This combination out competes candidates who hold certifications alone.
The next five years: what is changing in security certifications
Certifications evolve slowly, but three shifts are underway that will affect your planning through the second half of the decade.
AI and machine learning content is being added everywhere. Security+ SY0-701 already includes AI/ML risk content, CISSP's next revision expands on secure AI system design, and every major vendor is adding GenAI security specializations. Do not chase every AI security certification that launches; wait for signal about which ones employers actually reference in job postings. Meanwhile, learn LLM security fundamentals through OWASP's LLM Top 10 and vendor documentation.
Cloud and platform specific certifications are gaining ground on vendor neutral credentials. Ten years ago, CISSP dominated senior role requirements almost exclusively. Today, senior cloud security engineer postings often require AWS Security Specialty or AZ-500 alongside or instead of CISSP. This trend will continue as more workloads move to cloud and fewer to on premise data centers.
Performance based and lab based credentials are outcompeting multiple choice certifications. OSCP's rise reflects hiring managers' preference for demonstrated skill over recall. Expect more certifications to add PBQs, and expect the pure multiple choice credentials to lose ground in technical hiring. This trend favors candidates willing to invest study time in labs rather than rote memorization.
Plan your certification path with these trends in mind, but do not overweight them. The core credentials in this roadmap (Security+, CySA+, OSCP, AWS Security, CCSP, CISSP) will remain valuable through the end of the decade. Return to the cybersecurity hub periodically for updated guidance as the landscape shifts.
FAQ
Do I need a college degree if I have Security+ and CySA+?
For most entry level SOC and IT security roles, no. Many employers now accept certifications plus demonstrated skill as equivalent to a degree, especially in tech companies and startups. Federal contractors and traditional financial services firms are the main exceptions where a bachelor's is often still required as an HR filter. If you lack a degree and get filtered out by ATS, target smaller employers, cybersecurity boutiques, and MSSPs where hiring managers have more discretion.
Should I get CEH or OSCP first if I want to be a pentester?
OSCP is more valuable for technical credibility, but CEH clears more HR filters. If a specific target employer requires CEH, get it first because it is faster and cheaper. Otherwise, skip CEH and go directly to OSCP. Some candidates take PenTest+ as a bridge because it includes performance based questions at CompTIA pricing.
Is CISSP worth pursuing if I want to stay hands on technical?
Yes, though with lower priority than deep technical certs. CISSP appears in enough senior IC job postings that not having it can filter you out of otherwise perfect roles. Get CISSP once you have five years of qualifying experience, treat the study as a broadening exercise, and then return to your technical specialization.
How long does it realistically take to get from zero to CISSP?
The exam requires five years of qualifying experience in two or more of the eight domains, or four years plus a qualifying degree or credential (CompTIA Security+ counts). So the minimum timeline is four to five years of security work plus 150 to 300 hours of study. Passing the exam without the experience gives you Associate of (ISC)² status while you accumulate hours.
Can I skip Security+ if I already have work experience?
If you have three plus years of security experience and are targeting mid or senior roles, yes. Security+ mostly filters entry level candidates and satisfies DoD 8140 baselines. Experienced professionals should invest their study time in role specific certifications (OSCP, CISSP, cloud specialties) instead. The exception is if you are pursuing federal contracting work that explicitly requires Security+.
Which certifications will my employer typically pay for?
Employers most commonly fund CompTIA certs, CISSP (including annual maintenance fees), vendor specific certs relevant to the stack (AWS, Azure, Splunk), and one SANS course per year in mature security programs. Employers rarely fund OSCP, CEH, or certifications unrelated to your current role. Ask about training budget in the offer and use it every year.
How do I keep certifications current without spending all my time on CPEs?
Attend one security conference per year (BSides, DEF CON, RSAC, SANS Summit) for a large CPE bulk. Publish blog posts, give internal presentations, and contribute to open source; all count toward CPE. Track CPEs quarterly in a spreadsheet rather than scrambling at renewal time. Most active practitioners generate more than enough CPEs from normal professional activity and only need to log them.
What if I fail an exam? How does that affect my career?
Nobody sees your failed attempts except you and the certification body. OSCP publishes no pass rate on individual candidates; CompTIA and (ISC)² do not report attempt counts to employers. Fail attempts are learning experiences with a retake fee. Most candidates who eventually earn OSCP fail once or twice; do not treat a fail as career damaging. Take a two to four week break, identify what went wrong (time management, specific technical gap, exam anxiety), and retake with a clear improvement plan.
