CISSP Certification Guide for Beginners
·11 min read
A plain-English beginner's guide to CISSP — the eight domains, CAT exam format, experience rules, costs and the exact process from booking to endorsement.
Continue readingBuild a cybersecurity certification path from Security+ to CISSP, OSCP or CISM — entry, intermediate and advanced certs mapped by specialism.

Nobody needs seven security certifications. What a cybersecurity career needs is two or three of the right ones, earned in an order that matches how the work itself progresses — and the certification market is deliberately confusing on this point, because every provider markets its own ladder as the whole staircase. CyberSeek, the US supply-demand tracker built on the NIST NICE framework, reported roughly 450,000–514,000 US cybersecurity job openings across its 2025–2026 data windows, and employers filling those roles filter CVs by credentials constantly. The certifications that matter, though, differ sharply depending on whether you are heading towards defence, offence, or governance.
Short answer: almost every strong cybersecurity career path runs through CompTIA Security+ (or ISC2's Certified in Cybersecurity) at the start, then forks: CySA+ and GIAC certifications for blue-team work, PenTest+ then OSCP for offensive roles, and CISSP or CISM once you have the years to qualify for leadership. The mistake to avoid is collecting entry-level certs sideways instead of climbing.
This guide maps that fork-by-specialism structure in full. It stays at the planning altitude — for deep dives on any single exam, or head-to-head verdicts like Security+ versus CISSP as career moves, follow the links to the dedicated guides throughout.
Think of the certification landscape as a railway map rather than a ladder. There is a trunk line everyone rides — foundational IT and security knowledge — and then three branches:
The US government formalised this role-based view: the NICE Workforce Framework (NIST SP 800-181) defines 52 distinct cyber work roles in its 2024 component update, and the US Department of Defense's 8140 policy — which replaced the old 8570 directive and is now fully in effect — maps qualifications to specific work roles rather than blanket "levels". If you are aiming at government or defence-contractor work, the authoritative list of which certifications qualify you for which role is the DoD 8140 qualification matrix at cyber.mil, not any blog table.
Your first planning decision is therefore not "which cert?" but "which branch?" — and if you genuinely cannot choose yet, that is fine: the trunk line below serves all three.
Two credentials dominate the entry stage, and they are complements as much as competitors. ISC2's Certified in Cybersecurity (CC) is the low-cost proof-of-concept: $199, no experience requirement, a two-hour adaptive exam on security fundamentals. CompTIA Security+ (SY0-701) is the heavier, more employer-recognised baseline: a 90-question, 90-minute exam spanning threats, architecture, operations and programme management, priced around $425–$439 as of 2026 (CompTIA raised prices in June 2026 — confirm at store.comptia.org).
Neither enforces prerequisites. Many candidates take CC early for momentum, then Security+ within the year. Which one suits your background, and how the learning curves compare, is the subject of our dedicated guide to the best cybersecurity certifications for beginners — one sentence of guidance here: weak IT background favours CC first, solid IT background goes straight to Security+.
Worth flagging for trunk-line planners: CompTIA Network+ is the standard remedial stop if networking fundamentals are shaky, and Security+ has long served US DoD workforce requirements in general terms, which makes it unusually valuable if a government branch is on your horizon.
Do not start with CISSP, CISM or CISA study. All three let you sit the exam early, but certification requires five years of relevant experience (ISACA and ISC2 both offer deferred paths — ISC2's Associate status gives you six years to earn the experience after passing). Front-loading a management cert before you have done the work it manages is the single most common roadmap error. Equally, do not stack CC, Security+, and other foundational certs indefinitely — a second entry-level credential adds far less than a first intermediate one.
Blue-team work is where most cybersecurity careers actually begin, because SOC analyst roles are the volume hiring at the entry-to-mid boundary.
The Cybersecurity Analyst (CySA+) is CompTIA's intermediate blue-team exam, sitting between Security+ and SecurityX on CompTIA's own pathway. As of August 2026 two versions are live: CS0-004 launched in June 2026, while the English CS0-003 exam retires on 22 December 2026 — pick your version deliberately and match your study materials to it. CS0-004 runs to 85 questions in 165 minutes, weighted heavily towards security operations (34%) and vulnerability management (26%), which mirrors real analyst workloads. CompTIA recommends about four years of analyst-adjacent experience, but as with all its exams that is guidance rather than gatekeeping.
The SANS-affiliated GIAC body offers the most respected hands-on defensive credentials: GSEC for essentials, and the Certified Incident Handler (GCIH) as the classic next step for incident-response work — 106 questions over four hours, open-book (printed materials only), with hands-on CyberLive lab components. Every GIAC practitioner exam costs $999 standalone with no training requirement; the affiliated SANS courses are excellent but cost several thousand dollars more, so most self-funders reserve GIAC for when an employer pays. GIAC certifications renew on a four-year cycle.
The Systems Security Certified Practitioner requires one year of paid experience across its seven operational domains and costs $249. It is less commonly demanded by employers than CySA+ in analyst postings, but ISC2 lists it as approved under DoD 8140, and it suits systems administrators formalising a security-heavy role.
Offensive security has the steepest jump between its intermediate and advanced certifications of any branch — plan for it.
PenTest+ (PT0-003, current since December 2024) is the structured introduction: up to 90 questions in 165 minutes, mixing multiple-choice with performance-based questions, around the same June-2026-adjusted price point as CySA+. The PT0-003 revision added AI-based attacks and expanded cloud and API exploitation, which keeps it honest about where offensive work is heading. It certifies that you understand penetration-testing methodology; it does not certify that you can breach a network.
The Certified Ethical Hacker (v13 as of 2026) occupies an odd niche: a 125-question, four-hour multiple-choice knowledge exam whose brand recognition among recruiters exceeds its hands-on rigour. It is also expensive — roughly $1,199 via Pearson VUE, or about $950 via EC-Council's remote proctoring, with a $100 application fee on the self-study route (which itself requires two years of documented infosec experience). CEH earns its place where a job posting or government contract names it; otherwise many candidates route around it.
The OSCP is the offensive branch's terminus for most careers: a 24-hour hands-on proctored exam against live machines, followed by a professional report. There is no exam-only path — the PEN-200 course-plus-attempt bundle costs $1,749 with 90 days of lab access. A significant recent change: since November 2024, passing awards both the lifetime OSCP and a time-limited OSCP+ that expires after three years unless renewed, so "OSCP never expires" is now only half the story. How OSCP's difficulty compares with everything else in security is examined in our ranking of the hardest cybersecurity certification exams.
The CISSP is the most-cited advanced security certification, and its gate is experience, not exam fees: five years of cumulative paid work across two or more of its eight domains, with one year waivable via a degree or an approved credential such as Security+. The exam itself is computerised adaptive testing — 100 to 150 items in a maximum of three hours, at $749 — and results are pass/fail. Candidates short of the experience can pass now as an Associate of ISC2 and certify within six years, which is the legitimate answer to "should I wait?". Maintenance is real: a three-year cycle of 120 CPE credits plus an annual fee.
ISACA's Certified Information Security Manager (CISM) targets people who run security programmes rather than build them: 150 multiple-choice questions over four hours, $575 for ISACA members and $760 for non-members, with five years of information-security management experience required to certify (waivers up to two years). Its sibling CISA serves audit careers on the same exam mechanics. Both let you sit the exam before you have the experience, with five years to apply after passing. Note for CISM planners: ISACA updates the CISM exam content outline effective 3 November 2026, so check which outline your materials cover.
Not everyone senior wants to manage. SecurityX (CAS-005) — the certification formerly called CASP+ — is CompTIA's advanced practitioner exam, pass/fail with no scaled score, aimed at architects and senior engineers with a recommended ten years in IT. Its 2024 revision pulled in AI/ML threat modelling, post-quantum cryptography and zero trust. If your goal is staying hands-on at a senior level, SecurityX and the GIAC specialisations are the management-free summit. Candidates preparing for this track can drill with CompTIA Advanced Security Practitioner (CASP+ CAS-004) practice questions for the legacy material, while checking every study resource against the current CAS-005 objectives on comptia.org.
The management-versus-technical fork at this level deserves its own analysis, which our guide to the best certifications for experienced security professionals provides.
| Stage | Defensive track | Offensive track | Governance track |
|---|---|---|---|
| Entry (0–2 yrs) | CC → Security+ | CC → Security+ | CC → Security+ |
| Intermediate (2–5 yrs) | CySA+, GCIH, SSCP | PenTest+ (CEH where demanded) | CISA groundwork, risk experience |
| Advanced (5+ yrs) | GIAC specialisations, SecurityX | OSCP/OSCP+, GIAC pen-test certs | CISSP, CISM |
| Typical roles | SOC analyst → IR lead → detection engineer | Junior pentester → penetration tester → red team | Analyst → security manager → CISO track |
The helpdesk analyst, age 24. Two years on a service desk, no security title yet. Path: Security+ within six months, apply for SOC roles immediately after, CySA+ at the two-year security mark, then either GCIH (if the employer funds SANS) or detection-engineering depth. CISSP paperwork starts once the five qualifying years exist — not before.
The developer moving to offence, age 30. Strong scripting, weak infrastructure. Path: Security+ for the vocabulary and CV filter, PenTest+ within a year to formalise methodology, then straight at the OSCP with heavy lab time — the development background compresses the exploit-writing curve. CEH only if a target employer names it.
The project manager targeting governance, age 38. No technical depth, strong organisational experience. Path: CC then Security+ for credibility, a risk or compliance role as fast as possible, then the CISM exam early (sitting it before the experience is complete is allowed) with certification following once the five years of security-management experience accrue.
Certification costs compound beyond vouchers, and honest planning prices all three layers:
A sensible self-funded trajectory to a mid-level defensive career — Security+, then CySA+, with practice materials — can stay near the four-figure mark in exam fees alone; an offensive path through OSCP roughly doubles that; a GIAC-heavy path only makes financial sense with employer backing.
Whichever leg you are on, the preparation rhythm stays constant: study the official exam objectives, use practice questions diagnostically to find weak domains rather than to memorise answers, and finish with a timed full-length practice-test simulation to benchmark readiness before booking. Exam pages for the certifications above are collected in the certification exams directory.
1. Collecting sideways instead of climbing. Three entry-level certifications signal indecision, not depth. Employers reading a CV with CC, Security+ and two more foundational credentials — but nothing intermediate — see someone who studies rather than progresses. One trunk-line cert, then move up your branch.
2. Studying for retired or expiring exam versions. The security catalogue churned heavily through 2024–2026: CASP+ became SecurityX, PenTest+ moved to PT0-003, CySA+ CS0-003 retires in December 2026, and CompTIA lists Security+ SY0-701 as current with a successor expected but unannounced. Before buying any course or book, match its exam code against the provider's live page — a cheap second-hand guide for a dead code is expensive.
3. Ignoring the experience clock. CISSP and CISM certification requires five years of qualifying experience, and both bodies count specific kinds of work. If governance is your terminus, the roles you take in years two to five matter as much as the exams — a candidate who deliberately moves into risk or security-management work at year two arrives at the CISM application years ahead of one who stays purely technical and backfills later.
4. Letting a training budget choose your certification. GIAC-plus-SANS is a superb combination when an employer pays, and a distorting one when you self-fund: candidates sometimes pick a $999 exam with a multi-thousand-dollar course culture over a better-fitting $439 exam because the prestige feels like progress. Choose the credential your target role asks for, then find the affordable study route to it.
5. Preparing by memorisation. Performance-based questions, adaptive testing and hands-on exam formats exist precisely to defeat rote learning. Use practice questions to locate weak domains, re-study those domains from the objectives, and only then re-test — a loop that builds the transferable understanding interviews probe for after the CV filter has done its work.
A certification path is planned one credential ahead, not five. Pick the branch that matches the work you want to be doing in three years, take the trunk-line cert that unlocks your first security role, and let the job itself tell you whether the defensive, offensive or governance line fits — people switch branches at the intermediate stage constantly, and Security+ serves all three. The full stage-by-stage sequencing, including timing rules of thumb, lives in our master cybersecurity certification roadmap; this article's job was the map of the territory. The next move is the same for everyone: identify your branch, name your next exam, and start on its objectives this week.
They answer different questions for employers, and no certification in this article requires a degree. Whether certifications can substitute for one in hiring — and where non-graduates hit experience-requirement snags — is covered in our guide to cybersecurity certifications without a degree.
Formally yes — CompTIA, GIAC and ISC2 enforce no prerequisites on the intermediate exams discussed here. Practically, Security+ appears in enough job filters that skipping it usually costs more in missed screenings than it saves in exam fees, unless you already hold equivalent credentials.
DoD 8140 (which replaced 8570) maps qualifications to specific work roles rather than publishing one universal list. Check the qualification matrices at cyber.mil for the role you are targeting; certifications approved under the legacy 8570 scheme — Security+, GSEC, SSCP, CISSP, CISM among them — carried forward under 8140.
Typically one per career stage plus your current target. Maintenance obligations (CPEs and annual fees) make large collections expensive to keep alive, and employers weight your most advanced relevant credential far above the count.
Exam facts in this guide were checked against official certification-provider pages on . Fees, exam codes and policies change — confirm on the provider’s own site before you book.
Put it into practice
Reading about an exam only takes you so far. Work through practice questions for your certification and find the gaps before exam day does.
·11 min read
A plain-English beginner's guide to CISSP — the eight domains, CAT exam format, experience rules, costs and the exact process from booking to endorsement.
Continue reading·9 min read
A practical CISSP exam preparation guide covering the managerial mindset, how to choose study materials, and how to use practice tests to measure readiness.
Continue reading·7 min read
What actually makes the CISSP exam hard — breadth, adaptive testing and managerial judgement — who struggles most, and how it compares with SSCP and CCSP.
Continue reading