"What comes after Security+?" is the wrong question — or at least an incomplete one. Security+ is deliberately broad, a survey of five domains from threats to governance, and every serious follow-on certification narrows that breadth into a job. So the productive question is: which job? A security operations centre (SOC) analyst, a penetration tester and a governance specialist all hold Security+ on day one, and within eighteen months they hold three completely different second certifications.
Short answer: for the analyst path, CompTIA CySA+ is the most direct continuation. For offensive security, CompTIA PenTest+ is the structured next rung. For governance, risk and compliance (GRC), look at ISACA's CISA or CRISC. If you are early enough in your career that networking fundamentals are still shaky, a networking credential such as Cisco's CCNA may quietly be worth more than any of them. And if you have five years of experience already, CISSP — or the Associate of ISC2 route if you do not — belongs on the shortlist.
Below, each branch gets its case, its costs and its honest caveats, so you can pick by destination rather than by what a forum thread happened to recommend. (This is a routing decision, not an exam guide — if you are still preparing for SY0-701 itself, come back once it is passed.)
Why demand still justifies a second certification
Two dated data points frame the decision. The US Bureau of Labor Statistics reports a median salary of $124,910 for information security analysts (May 2024 data) with projected employment growth of 29% from 2024 to 2034 — roughly 16,000 openings a year. And ISACA's State of Cybersecurity 2025 survey found 55% of cybersecurity teams understaffed and 65% carrying unfilled positions. Neither number guarantees anyone a job — pay varies enormously with location, experience and role — but together they say the ladder above Security+ is worth climbing, and that specialisation is what employers are short of.
Branch one: the security analyst path
Next cert: CompTIA CySA+.
If you want to work in or advance through a SOC — triage, threat detection, vulnerability management, incident response — CySA+ is the purpose-built continuation. It stays vendor-neutral, stacks on the same CompTIA continuing-education system (renewing CySA+ later renews your Security+ automatically, and you pay CE fees only for your highest cert), and its domains read like a SOC job description: on the current CS0-004 exam, Security Operations carries 34%, Vulnerability Management 26%, Incident Response and Management 24%, and Reporting and Communication 16%.
Timing note for 2026: two versions are live. CS0-004 launched on 23 June 2026; the older CS0-003 retires for English-language candidates on 22 December 2026. Starting fresh, choose CS0-004 — buying materials for an exam with months to live only makes sense if you are nearly ready to sit it.
Two caveats. First, CompTIA recommends around four years of analyst-adjacent experience for CySA+; nothing enforces that, but the exam assumes practical fluency, not just Security+ recall. Second, the US retail fee is $439 as listed by CompTIA's authorised resellers in June 2026 (varies by region) — the same tier as Security+, so budget accordingly.
An alternative on this branch is Cisco's CCNA Cybersecurity (the renamed CyberOps Associate), which teaches SOC work with a Cisco-tooling flavour — a reasonable pick where your employer runs Cisco security products.
Branch two: the offensive security path
Next cert: CompTIA PenTest+.
Penetration testing attracts a large share of Security+ holders and rejects most of the unprepared ones, so pick this branch for the work, not the mystique. PenTest+ (PT0-003, launched December 2024) covers the engagement lifecycle — scoping, reconnaissance, exploitation, reporting — with performance-based questions across a maximum of 90 items in 165 minutes. CompTIA recommends three to four years of relevant experience with Security+-level knowledge assumed; US retail is $439 (June 2026, via authorised resellers; varies by region).
The EC-Council's Certified Ethical Hacker (CEH) occupies similar territory and appears in some job filters; our research pack for this article did not verify current CEH pricing or format, so compare it directly on EC-Council's site if a specific employer names it. Whichever you choose, offensive security is the branch where hands-on lab hours count for more than any credential — the certificate opens the interview, the practical skill survives it.
Branch three: governance, risk and compliance
Next certs: ISACA CISA or CRISC.
GRC is the most under-considered branch, and often the shrewdest for people who write well, think in frameworks and would rather assess controls than chase alerts. Two ISACA credentials dominate:
CISA (Certified Information Systems Auditor) — the audit-and-assurance standard. ISACA's own page cites 151,000+ holders and a US$149K+ average annual salary (ISACA's figure, as of August 2026 — treat any vendor's average with the usual caution).
CRISC (Certified in Risk and Information Systems Control) — IT risk management and control, for those heading towards risk analyst and risk manager roles.
A structural point most Security+ holders miss: you can sit any core ISACA exam with zero experience. The experience requirement (five years for CISA, with waivers up to three; three years for CRISC, no waivers) applies to certification, not the exam, and you have five years after passing to accumulate it and apply. Both exams cost US$575 for ISACA members / US$760 for non-members, run 150 questions over four hours, and pass at 450 on a scaled 200–800 range. Browse the ISACA exam pages to see how their question style differs from CompTIA's — it is noticeably more judgement-and-scenario driven.
CISM sits in this neighbourhood too, but it targets security management — programme ownership, not analysis — and makes more sense a few years later; where it leads afterwards is covered in what certification to take after CISM.
Branch four: the management trajectory — CISSP, SSCP and the experience problem
ISC2's CISSP is the credential most often named as "the one after Security+", and for experienced practitioners it is a fair target: broad, managerial in outlook, and priced at $749 in the Americas. But it carries a real gate — five years of cumulative paid experience across two or more of its eight domains. Two softeners exist: Security+ itself can waive one year (a degree can do the same, but only one waiver applies), and you can pass the exam without the experience to become an Associate of ISC2, with six years to earn the remaining time.
If five years is far away and you want an ISC2 credential now, SSCP is the honest intermediate: one year of experience required, $249, and an operational (rather than managerial) focus across seven domains. It will not carry CISSP's weight in job filters, but it is attainable and reputable.
Where CISSP leads once you hold it — concentrations, cloud security, management credentials — is its own decision tree, mapped in what certification to take after CISSP.
The unglamorous option that outperforms: networking depth
If you came to Security+ without infrastructure experience, consider taking Cisco's CCNA before any security follow-on. Almost everything in security operations — reading packet captures, understanding lateral movement, segmenting networks — rests on networking fundamentals, and a Security+-plus-CCNA pairing signals a candidate who can actually reason about the systems they are defending. The branching decision after CCNA is a separate fork we cover in what certification to take after CCNA.
The four branches side by side
Factor
CySA+ (analyst)
PenTest+ (offensive)
CISA/CRISC (GRC)
CISSP (management track)
Provider
CompTIA
CompTIA
ISACA
ISC2
Cost (US, 2026, varies by region)
~$439
~$439
$575 member / $760 non-member + $50 application
$749
Experience gate
None enforced; ~4 yrs recommended
None enforced; 3–4 yrs recommended
Exam open to all; 5 yrs (CISA, waivers) / 3 yrs (CRISC) to certify
5 yrs to certify; Associate route to sit exam
Renewal
3-yr CompTIA CE (stacks with Security+)
3-yr CompTIA CE
20 CPE/yr, 120 per 3-yr cycle + annual fee
3-yr cycle, 120 CPEs + $135 annual fee
Best for
SOC and detection roles
Penetration testing roles
Audit, risk, compliance roles
Broad senior/management aspirations
Skills flavour
Defensive, operational
Offensive, hands-on
Frameworks, controls, judgement
Breadth across 8 domains
No universal winner exists in that table on purpose: each column wins for a different reader.
A decision sequence that avoids the common traps
Name the job title you want in three years. Not the certification — the job. Read five live postings for it and list the credentials they actually mention.
Check your foundations. Weak networking? CCNA first. Solid networking, no security seat yet? CySA+ plus aggressive job hunting beats hoarding a third certificate.
Match the branch, then the exam version. In late 2026 that means CS0-004 over CS0-003, and checking current outlines before buying any course.
Mind the renewal economics. Staying inside CompTIA's ladder means one CE cycle renews everything downward; jumping vendors means parallel renewal fees and CPE obligations. Neither is wrong — just budget for it.
Only then book. When your chosen exam's domains feel covered, a timed set of practice questions in simulation mode will tell you which domain needs another pass before you spend the fee — analyse the per-domain results rather than chasing an overall score.
The trap all five steps guard against is the same one: collecting certifications as a substitute for choosing a direction. Two well-chosen credentials and a home lab beat five unfocused ones every time an interviewer starts asking follow-up questions.
Frequently asked questions
Does my Security+ stay valid while I pursue the next certification?
Yes — it is valid for three years from your pass date. If you stay with CompTIA, earning a higher certification such as CySA+ or PenTest+ renews Security+ automatically under the CE programme. Certifications from ISACA, ISC2 or Cisco do not renew it, so track your expiry if you branch out.
Is Security+ alone enough to get a cybersecurity job first?
Sometimes, particularly in support-adjacent or government-connected roles, but the surveys cited above show employers short of specialised skills. Treat Security+ as the entry ticket and the next credential as the specialisation — ideally chosen after you are in a seat and can see which branch your organisation actually needs.
Should I wait for the next version of Security+ before planning anything?
No. CompTIA lists SY0-701 as current as of August 2026, with a successor expected but unannounced. Your certification remains valid for three years from your pass date regardless of exam-version changes, so the follow-on decision is unaffected.
Can I do two branches at once — say CySA+ and PenTest+?
You can, and defensive-plus-offensive is a coherent pairing for detection engineers. But sequence them rather than studying in parallel: each assumes multi-year practical fluency, and split attention is the most common self-report in failed-attempt post-mortems.
Where Security+ fits in the longer arc
Security+ was never the destination; it is the junction where the cybersecurity field splits into its real professions. Choose the analyst branch if incidents energise you, the offensive branch if you want to break things for a living and can back it with lab hours, GRC if frameworks and judgement are your strengths, and the CISSP trajectory once the experience clock supports it. The certification after Security+ that pays off is the one attached to a job description you can name — everything else is expensive shelf decoration.
Exam facts in this guide were checked against official certification-provider pages on . Fees, exam codes and policies change — confirm on the provider’s own site before you book.
A five-step decision process for choosing a professional certification: goals, market demand, true cost, prerequisites and renewal — with a comparison worksheet.
The strongest professional certifications for 2026, ranked on demand, recognition and cost of ownership — with the year's retirements and AI-driven changes factored in.