CISSP Certification Guide for Beginners
·11 min read
A plain-English beginner's guide to CISSP — the eight domains, CAT exam format, experience rules, costs and the exact process from booking to endorsement.
Continue readingMap a multi-year cybersecurity certification path across defensive, offensive and management tracks, with sequencing, costs and renewal planning.

A workable cybersecurity certification roadmap has three stages — entry, intermediate, advanced — and forks into three tracks: defensive (blue team), offensive (red team), and management/governance. Most people start with CompTIA Security+ or ISC2 Certified in Cybersecurity (CC), specialise at the intermediate stage, and only then commit to an expensive expert credential such as CISSP, OSCP or CISM. The mistake that costs candidates the most money is buying the expert exam first.
This article is the full map: which certifications sit at which stage, which order to take them in, where the tracks diverge, and how to plan the whole journey over three to six years without paying for exams you do not need. If you want a shortlist for one stage rather than the whole map — say, the friendliest first certs — the sibling guide to the easiest cybersecurity certifications for beginners covers that in depth, and advanced practitioners choosing a single next credential should read the guide to the best cybersecurity certifications for experienced professionals.
Two rules keep the map honest.
First, certifications are gated by experience far more than by other certifications. Almost no security exam has an enforced certification prerequisite: you can legally sit CISSP tomorrow. But ISC2 requires five years of cumulative paid experience in two or more of its eight domains before it awards the CISSP credential (one year is waivable with a relevant degree or an approved cert such as Security+), and ISACA requires five years of information security management experience for CISM. The roadmap below therefore sequences by the experience you are realistically accumulating, not just by exam difficulty.
Second, tracks are lenses, not cages. A SOC analyst who takes CompTIA CySA+ and later pivots to penetration testing has wasted nothing — defensive fundamentals make better attackers, and vice versa. Choose a track at the intermediate stage because employers hire for specialisms, but expect to borrow from the other lines.
The US National Institute of Standards and Technology's NICE Framework — which in its March 2024 component update defines 7 categories and 52 distinct cybersecurity work roles — is a useful reality check here: "cybersecurity" is dozens of jobs, and no single certification ladder serves all of them.
Everyone shares the same trunk line. The goal at this stage is a credential that proves baseline security literacy to a hiring manager, at a price and difficulty you can absorb while working a helpdesk, IT support, or non-technical job.
Security+ is the most commonly cited first security certification, and for most people it is the correct default. The current exam, SY0-701, runs to a maximum of 90 questions in 90 minutes, mixing multiple-choice with performance-based items, with a passing score of 750 on a 100–900 scale. There are no prerequisites, though CompTIA recommends Network+ knowledge and around two years of IT administration with a security focus. The voucher costs about $425–$439 as of 2026 following CompTIA's June 2026 price rise — confirm the current figure at store.comptia.org. Note that CompTIA lists SY0-701 as current with a successor expected but unannounced; check the live code before buying study materials.
Two facts make Security+ the trunk of the map. It has long appeared on US Department of Defense approved-certification lists (the legacy 8570 baseline placed it at IAT Level II, and certs approved under 8570 carried forward under the current DoD 8140 framework), which matters enormously for government and contractor roles. And it is the reference point every other cert on this map is compared against.
If Security+ feels like too big a first bite, ISC2's CC is the gentler on-ramp: no experience requirement, a $199 standard exam fee, and a scope limited to genuine fundamentals. Be aware that ISC2's famous free-exam programme closed to new enrolments on 20 May 2026, so budget for the fee. CC is a stepping stone, not a destination — plan to reach Security+ within a year of earning it.
CompTIA A+ and Network+ are not security certifications, but if you are entering IT itself from scratch, Network+ before Security+ is the classic sequence — CompTIA's own recommended experience for Security+ assumes networking knowledge. Vendor fundamentals such as Microsoft's SC-900 also fit here for people in Microsoft-centric organisations; the SC-900 Security, Compliance and Identity Fundamentals exam page shows what that exam covers.
Entry-stage decision rule: no IT background at all → CC (or Network+ first), then Security+. Some IT experience already → straight to Security+.
With Security+ and a junior role behind you, the map splits. Pick the line whose daily work you actually want.
The defensive line leads through security operations: monitoring, triage, incident response, vulnerability management.
The truly hands-on offensive credential, OSCP, belongs to Stage 3 below. If you want to know exactly how brutal each of these gets, the ranking of the hardest cybersecurity certification exams compares them directly.
There is no intermediate management certification worth buying at year two, because the credentials that matter — CISSP, CISM — are gated by five years of experience. The management-track move at this stage is to keep collecting technical evidence (CySA+ or SSCP serve fine) and start logging the experience that will qualify you later. If you must sit an exam early, remember that ISC2 lets you pass CISSP as an Associate of ISC2 and ISACA lets you sit CISM before your experience is complete — you hold the pass, then certify once qualified (ISACA gives you five years from the pass date to apply).
This is where the tracks reach their named destinations — and where exams get long, expensive, or both.
CompTIA SecurityX (CAS-005) — the certification formerly called CASP+, renamed in December 2024 — is the advanced practitioner cert for people who want to stay deeply technical rather than move into management. It is about 90 questions over 165 minutes, graded pass/fail with no scaled score, and CompTIA recommends ten years of IT experience with five hands-on in security. CAS-005 elevated zero trust, post-quantum cryptography and AI/ML threat modelling. Do not buy CAS-004 materials; that exam retired in June 2025.
GIAC's specialised certifications (forensics, industrial control systems, detection engineering and more) serve defenders who want depth in one niche — the GICSP industrial cybersecurity exam page is one example of how specific these get.
OffSec's OSCP (PEN-200) is the credential that proves hands-on exploitation ability: a 24-hour proctored practical exam against live machines, followed by a professional report. Since November 2024, passing awards both the lifetime OSCP and a three-year OSCP+ that renews via OffSec's CPE programme or further exams. There is no cheap exam-only habit to fall into here — the standard Course & Cert bundle is $1,749 for 90 days of lab access and one attempt, with a Learn One subscription at $2,749 per year including two attempts. Budget both money and months of lab time.
ISC2 CISSP is the broadest senior credential on the map and the standard gateway into security leadership. Since April 2024 it is a computerised adaptive test of 100–150 items in a maximum of 3 hours, priced at $749, with the five-year experience requirement described earlier. It renews on a 3-year cycle of 120 CPE credits.
ISACA CISM is the purer management play — governance, programme management, incident management — with 150 questions over 4 hours, passing at a scaled 450/800, priced at $575 for ISACA members and $760 for non-members plus a $50 application fee. Its sibling CISA takes the audit line at the same price and format. One scheduling note: ISACA updates the CISM exam content outline effective 3 November 2026, so match your prep to whichever outline you will sit.
Choosing between CISSP and CISM at this stage is a genuine fork, and it deserves more than a paragraph — the guide for experienced professionals weighs them head to head.
| Stage | Defensive | Offensive | Management |
|---|---|---|---|
| Entry (0–2 yrs) | ISC2 CC → Security+ | ISC2 CC → Security+ | ISC2 CC → Security+ |
| Intermediate (2–4 yrs) | CySA+, SSCP or GSEC | PenTest+ (CEH if required) | Technical cert + log experience |
| Advanced (4–7 yrs) | SecurityX, GIAC specialisms | OSCP → OSEP/OSWE | CISSP → CISM or CISA |
Budget the whole line, not one ticket. A defensive path of Security+ → CySA+ → SecurityX costs roughly $1,300–$1,400 in vouchers alone at 2026 pricing, before study materials and renewal fees. The offensive path is heavier: OSCP's cheapest route is $1,749. Management is exam-cheap but fee-long: CISSP carries an annual maintenance fee and a 120-CPE cycle.
Renewals stack in your favour if you stay in one vendor family. CompTIA's continuing education model renews lower certifications automatically when you earn or renew a higher one, and you pay CE fees only for your highest cert — so Security+ effectively stops costing anything once you hold CySA+ or SecurityX. ISC2 similarly maintains its certifications on a rolling CPE cycle. Factor this in before mixing five vendors across your map.
Three sequencing traps to avoid:
Two worked itineraries show how the map plays out in real careers.
The helpdesk-to-SOC route (defensive line). A helpdesk analyst with eighteen months of ticket experience takes Security+ in year two, moves into a junior SOC seat, and sits CySA+ in year four once the analyst work has made its vulnerability-management and incident-response domains familiar rather than theoretical. By year six she has a choice: SecurityX to become the senior technical defender on the team, or a swerve onto the management line — her five years of security-relevant experience now qualify her for CISSP, with Security+ able to waive one of them. Nothing on her itinerary was wasted, and every exam was sat when the experience made it cheapest to pass.
The sysadmin-to-pentester route (offensive line). A systems administrator with strong Linux and scripting skills clears Security+ quickly, takes PenTest+ in the same year to signal offensive intent, and lands a junior assessment role. He then spends a full year inside PEN-200 labs before attempting OSCP — the sequencing insight being that OSCP preparation is measured in lab hours, not reading hours, so he budgets calendar time the way management-track peers budget CPE credits. CEH enters his plan only if a specific employer or contract names it.
The experience-first principle behind both: sit each exam at the moment your day job has just finished teaching its hardest domain. Exams taken two years too early are paid for twice — once in the voucher, once in the extra study months replacing experience you did not yet have.
Practice testing belongs at every stage. Whichever stop you are approaching, a timed practice run against the exam's objective list tells you which domains need another pass before you book — ExamPractice's practice test simulation supports exactly that benchmarking, with free samples on individual exam pages across its certification exams directory. For no-cost question sources specific to security exams, see the roundup of free cybersecurity practice questions.
No exam on this map enforces a certification prerequisite (OSCP included). The order exists because each stop assumes knowledge from the previous one and because credential-awarding experience requirements (CISSP, CISM, SSCP) accumulate in real time whatever you do. Skipping ahead is legal; it is just rarely efficient.
DoD 8140 (DoDM 8140.03) replaced the old 8570 directive and is now fully in effect; it maps qualifications to specific work roles rather than broad levels. Certifications approved under 8570 — Security+, GSEC, SSCP, CISSP, CISM, CISA and SecurityX among them — carried forward. The authoritative source is the DoD 8140 Qualification Matrix at cyber.mil; do not rely on third-party tables.
CyberSeek, the US supply-demand tracker built on the NICE framework, reported roughly 450,000–514,000 US cybersecurity job openings across its 2025–2026 data windows, with far fewer available workers than openings. Check cyberseek.org for current figures before making decisions on a single number.
ISC2's CCSP is the natural cloud-security stop on the management/architecture line, and an active CISSP satisfies its entire experience requirement — a common CISSP-plus-one pairing. Cloud provider security specialisations slot into whichever track matches your role.
Locate yourself on the map, then take the single next step — not the destination. If you have no credential, that step is choosing between CC and Security+ and downloading the official exam objectives, which every provider publishes free. If you are mid-track, it is confirming the current exam code and booking a date far enough out to prepare properly. The map spans years; the only stage you can act on is the next stop. Revisit the whole route once a year — exam versions, prices and even certification names change (as CASP+ becoming SecurityX proved), and a roadmap drawn in 2026 deserves a 2027 fact-check before you buy the next voucher.
Exam facts in this guide were checked against official certification-provider pages on . Fees, exam codes and policies change — confirm on the provider’s own site before you book.
Put it into practice
Reading about an exam only takes you so far. Work through practice questions for your certification and find the gaps before exam day does.
·11 min read
A plain-English beginner's guide to CISSP — the eight domains, CAT exam format, experience rules, costs and the exact process from booking to endorsement.
Continue reading·9 min read
A practical CISSP exam preparation guide covering the managerial mindset, how to choose study materials, and how to use practice tests to measure readiness.
Continue reading·7 min read
What actually makes the CISSP exam hard — breadth, adaptive testing and managerial judgement — who struggles most, and how it compares with SSCP and CCSP.
Continue reading