Exampractice
Certification Comparisons

CEH vs Security+: Which Is Better?

CEH vs Security+ compared on cost, difficulty, prerequisites and career value, with a decision framework for security newcomers choosing their first cert.

Aisha Rahman · 10 min read
Balance scale comparing a single low-cost exam voucher against an expensive stacked training bundle

One of these certifications can be sat for roughly $439; the other typically costs between $1,199 for a bare exam voucher and $1,699 or more once official training is included. That price gap — often four to one — is the single most misunderstood fact in the CEH vs Security+ debate, and it changes the answer for most people asking the question.

Short answer: for most security newcomers, CompTIA Security+ is the better first certification. It is far cheaper, broader, aimed squarely at entry level, and widely used as a hiring baseline. The Certified Ethical Hacker (CEH) from EC-Council is a mid-level credential with an experience-or-training gate, and it makes more sense after you have a security foundation and a reason to specialise in offensive topics. Neither is universally "better" — the rest of this article explains which fits your circumstances.

What each certification actually is

The two credentials come from different providers and sit at different rungs of the ladder, which is why comparing them as equals misleads people.

CompTIA Security+ (current exam SY0-701, live since November 2023) is CompTIA's vendor-neutral baseline security certification. It covers five domains: general security concepts; threats, vulnerabilities and mitigations; security architecture; security operations; and security programme management and oversight. It is a generalist credential — defence, operations, governance and offence-awareness in one exam — and CompTIA recommends (but does not require) Network+ plus around two years in a security or systems administration role. Note that CompTIA lists SY0-701 with an estimated retirement in 2026 and a successor is expected but unannounced, so check comptia.org for the current version before booking.

Certified Ethical Hacker (CEH) is EC-Council's flagship offensive-security credential, currently at version 13, which EC-Council markets as "CEH AI" because AI-assisted attack and analysis content is woven through the curriculum. It teaches attacker tools and methodology: reconnaissance, scanning, exploitation concepts, malware, social engineering and related topics across 20 modules. Despite the hands-on subject matter, the core CEH exam is a knowledge test, not a practical one — a common misconception corrected below.

CEH vs Security+ comparison table

FactorCompTIA Security+ (SY0-701)EC-Council CEH (v13)
LevelEntry-level baselineIntermediate, offensive-focused
PrerequisitesNone required; Network+ and ~2 years' experience recommendedOfficial EC-Council training, OR a $100 eligibility application with 2 years' infosec experience
Exam formatMax 90 questions (multiple-choice + performance-based), 90 minutes125 multiple-choice questions, 4 hours (optional separate 6-hour practical for CEH Master)
Passing score750 on a 100–900 scaleBanded cut score of 60–85% depending on question form (no single published pass mark)
Exam cost (US, 2026)~$439 retail as listed by CompTIA's authorised resellers in June 2026; varies by region$1,199 (Pearson VUE) or $950 (EC-Council portal) voucher; training bundles from $1,699
Best forFirst security cert, SOC/analyst/admin roles, government baselinesCandidates targeting ethical-hacking-branded roles or employer-funded upskilling
Career pathFeeds CySA+, PenTest+, SSCP, later CISSPFeeds CEH Master, more advanced offensive certs
Skills emphasisBroad defensive and operational securityAttacker tools, techniques and terminology
Renewal3-year CompTIA CE cycle (50 CEUs for Security+)3-year EC-Council ECE cycle (120 credits and an annual membership fee are widely reported)

How the costs really compare

Exam-fee comparisons flatter CEH; total-cost comparisons do not.

Security+ is close to an all-in price. You buy a voucher — around $439 US retail as listed by CompTIA's authorised resellers in June 2026, less through discounters, varying by country — study with materials of your choosing, and sit a 90-minute exam at Pearson VUE or online. There is no eligibility application and no mandatory training.

CEH's pricing has more layers. If you skip official training, you must file a $100 eligibility application and show two years of information-security work experience, then buy the exam voucher: $1,199 for Pearson VUE delivery or $950 for EC-Council's remote-proctored portal, as listed on the EC-Council store in 2026. If you lack the experience, official training is your route in, and EC-Council's bundles are listed "starting at" $1,699 for on-demand and $2,499 for live online — final quotes come through sales. Renewal adds cost too: EC-Council's ECE scheme runs on three-year cycles, with 120 credits and an annual membership fee widely reported (confirm current figures with EC-Council).

A realistic self-funded newcomer is therefore choosing between roughly $439 and somewhere between $1,050 and $2,500+. If an employer or a government training scheme is paying, the calculus changes — which is exactly the situation where CEH most often gets taken.

Which is harder: CEH or Security+?

Difficulty comparisons should look at format and assumed knowledge, not pass rates — neither provider publishes pass rates, and any percentage you see quoted is invented.

Security+ is a 90-minute sprint: up to 90 questions including performance-based items that ask you to apply concepts in simulated scenarios, scored on a 100–900 scale with 750 to pass. Its difficulty comes from breadth — five domains spanning everything from cryptography basics to programme oversight — under real time pressure.

CEH gives you 4 hours for 125 multiple-choice questions, so time pressure is lower per question, but the assumed knowledge is deeper: it expects familiarity with attack tooling and technique across a large curriculum (20 modules and over 200 labs in the current courseware). Its cut score is banded between 60% and 85% depending on the difficulty of the question form you draw, so the oft-repeated "70% to pass" is false. Candidates coming in without networking and security fundamentals generally find CEH content harder to absorb; candidates with a couple of years of security work often find the exam itself less stressful than Security+'s pace.

One more format note: the base CEH is multiple choice only. The hands-on element is a separate, optional 6-hour, 20-challenge practical exam — pass both and you hold CEH Master. If a genuinely practical exam matters to you, the comparison you want is OSCP vs CEH for penetration-testing careers, which we cover separately.

CEH or Security+ first?

For sequencing, the certifications' own entry requirements answer the question. Security+ has no gate at all. CEH requires either paid official training or two documented years of information-security experience — which a true newcomer does not have. Taking Security+ first, working in a security-adjacent role, and then adding CEH (if your target roles ask for it) is the sequence the requirements themselves imply.

There is also a knowledge-stacking argument. Security+'s defensive and architectural grounding makes CEH's attack content far more meaningful: it is easier to understand why an attack works when you already know what it is defeating.

What about salary?

Salary data for certifications is noisy and source-dependent, so treat every figure as context rather than a promise — pay varies enormously by location, experience and role.

For CEH specifically, published US figures diverge widely: ZipRecruiter listed an average of $161,013 for Certified Ethical Hacker roles as of February 2026, Payscale reported an average of $96,490 for CEH holders in 2026, and Infosec Institute estimated around $126,547 in June 2025. That $96K–$161K spread reflects different methodologies and role mixes, not a contradiction to resolve — never average them.

For the roles Security+ typically opens, the US Bureau of Labor Statistics reported a median of $124,910 for information security analysts (May 2024 data) with projected employment growth of 29% from 2024 to 2034. No credible source isolates a "Security+ salary", because it is a baseline held by people at many levels. The honest conclusion: neither certification "pays" a figure — the role, seniority and market do. How employers actually weigh the two credentials in hiring is examined in our companion piece on whether CEH is better than Security+ for jobs.

A decision framework: four questions to settle it

  1. Who is paying? Self-funded: Security+ wins on value for almost everyone. Employer- or programme-funded CEH training: the cost objection disappears, and CEH becomes reasonable.
  2. Do you meet CEH's gate honestly? No two years of infosec experience and no training budget means CEH is not currently available to you at sane cost. Take Security+ now; revisit CEH later.
  3. What do your target job adverts say? Pull ten postings you would actually apply for. Baseline analyst and administrator roles overwhelmingly name Security+; some government-adjacent and "ethical hacker"-titled roles name CEH. Let the postings vote.
  4. Defensive breadth or offensive vocabulary? If you do not yet know which side of security you want, breadth first is the lower-regret choice — you can specialise afterwards.

Two realistic scenarios

The career changer. A helpdesk analyst with 18 months of support experience and no formal security background wants into a SOC. She cannot meet CEH's experience requirement without paying for training she cannot afford. Security+ is attainable in a few months of structured study for around a tenth of the cost, and it is the credential her target job adverts actually list. Security+ is the clear call; CEH can wait until year two or three, funded by an employer.

The funded upskiller. A network engineer with four years of experience has an employer training budget and a mandate to join the internal red-team rotation. He qualifies for CEH's eligibility route, the employer pays for live-online training, and the role's HR requisition names CEH explicitly. Here CEH is the right choice — Security+ would add breadth he largely has.

Common mistakes candidates make with this choice

A few recurring errors are worth naming, because each one costs real money or months.

  • Comparing exam vouchers only. CEH's true cost usually includes training or the eligibility application, and both certifications carry renewal costs. Budget the full three-year picture, not the sticker price.
  • Assuming CEH is hands-on. The base exam is multiple choice; candidates expecting a practical assessment either want the optional CEH Master practical or a different credential entirely.
  • Believing quoted pass marks and pass rates. CEH's cut score is banded (60–85%), Security+'s 750 is a scaled score rather than a percentage, and neither provider publishes pass rates — plan your readiness with practice-test evidence instead of forum folklore.
  • Taking CEH first to "stand out". Without fundamentals, an offensive credential impresses recruiters less than interviewers might make painfully clear; the standing-out that works at entry level is a solid baseline plus demonstrable lab work.
  • Ignoring the version cycle. SY0-701's successor is expected, and CEH versions roll every few years; always confirm the current exam code on the provider's site before buying materials.

Using practice questions to test the choice

Before committing money to either exam, spend an evening with sample questions for both — how the material feels is real data. Free CompTIA Security+ sample questions will show you the breadth-under-time-pressure style, and Certified Ethical Hacker practice questions will show you whether the tool-and-technique recall style suits you. When you later prepare in earnest, use timed practice tests to find weak domains and target them — not to memorise answers, which teaches you nothing the real exam will reward.

Frequently asked questions

Is CEH a replacement for Security+?

No. They occupy different levels and lanes: Security+ is a generalist baseline, CEH an intermediate offensive-focused credential with an experience-or-training entry gate. Many professionals eventually hold both.

Does CEH have a practical exam?

Only as an optional add-on. The core CEH exam is 125 multiple-choice questions over 4 hours; the separate 6-hour practical (20 challenges) leads to the CEH Master designation when combined with the knowledge exam.

Do both certifications expire?

Both run on three-year cycles. Security+ renews through CompTIA's CE programme (50 CEUs, or retake, or a higher CompTIA cert). CEH renews through EC-Council's ECE scheme; the commonly cited 120 credits per cycle plus an annual membership fee are widely reported figures — confirm current requirements with EC-Council.

Can I take Security+ after CEH?

Yes — there are no prerequisites in either direction. It is an unusual order, but professionals who entered via a funded CEH course sometimes add Security+ later to satisfy a government or employer baseline requirement.

Is Security+ SY0-701 still current?

As of August 2026, yes — SY0-701 is the only live version. CompTIA estimates its retirement in 2026 and a successor is expected but unannounced, so verify the current code on comptia.org before you book.

Where each certification fits in your plan

Treat this less as a duel and more as sequencing. Security+ is the broad foundation that entry-level security hiring is built on and that later certifications assume; CEH is a specialisation you add when your direction — and ideally someone else's budget — points at offensive security. If your fork is instead between CompTIA and ISC2 at entry level, see Security+ vs SSCP; if you are wondering how far the ladder extends, Security+ vs CISSP maps the far end. Whichever you pick, benchmark yourself with a full-length timed practice test before booking, and spend your remaining weeks on the domains it exposes.

Exam facts in this guide were checked against official certification-provider pages on . Fees, exam codes and policies change — confirm on the provider’s own site before you book.

Put it into practice

Test what you have just read

Reading about an exam only takes you so far. Work through practice questions for your certification and find the gaps before exam day does.

You may also like