Exampractice
Cybersecurity

Cybersecurity Certification Roadmap

Map a multi-year cybersecurity certification path across defensive, offensive and management tracks, with sequencing, costs and renewal planning.

Alexander Novak · 12 min read
Metro-map style diagram showing three cybersecurity certification tracks branching from a shared entry point toward advanced credentials

A workable cybersecurity certification roadmap has three stages — entry, intermediate, advanced — and forks into three tracks: defensive (blue team), offensive (red team), and management/governance. Most people start with CompTIA Security+ or ISC2 Certified in Cybersecurity (CC), specialise at the intermediate stage, and only then commit to an expensive expert credential such as CISSP, OSCP or CISM. The mistake that costs candidates the most money is buying the expert exam first.

This article is the full map: which certifications sit at which stage, which order to take them in, where the tracks diverge, and how to plan the whole journey over three to six years without paying for exams you do not need. If you want a shortlist for one stage rather than the whole map — say, the friendliest first certs — the sibling guide to the easiest cybersecurity certifications for beginners covers that in depth, and advanced practitioners choosing a single next credential should read the guide to the best cybersecurity certifications for experienced professionals.

How to read this roadmap

Two rules keep the map honest.

First, certifications are gated by experience far more than by other certifications. Almost no security exam has an enforced certification prerequisite: you can legally sit CISSP tomorrow. But ISC2 requires five years of cumulative paid experience in two or more of its eight domains before it awards the CISSP credential (one year is waivable with a relevant degree or an approved cert such as Security+), and ISACA requires five years of information security management experience for CISM. The roadmap below therefore sequences by the experience you are realistically accumulating, not just by exam difficulty.

Second, tracks are lenses, not cages. A SOC analyst who takes CompTIA CySA+ and later pivots to penetration testing has wasted nothing — defensive fundamentals make better attackers, and vice versa. Choose a track at the intermediate stage because employers hire for specialisms, but expect to borrow from the other lines.

The US National Institute of Standards and Technology's NICE Framework — which in its March 2024 component update defines 7 categories and 52 distinct cybersecurity work roles — is a useful reality check here: "cybersecurity" is dozens of jobs, and no single certification ladder serves all of them.

Stage 1: entry (years 0–2)

Everyone shares the same trunk line. The goal at this stage is a credential that proves baseline security literacy to a hiring manager, at a price and difficulty you can absorb while working a helpdesk, IT support, or non-technical job.

CompTIA Security+ (SY0-701)

Security+ is the most commonly cited first security certification, and for most people it is the correct default. The current exam, SY0-701, runs to a maximum of 90 questions in 90 minutes, mixing multiple-choice with performance-based items, with a passing score of 750 on a 100–900 scale. There are no prerequisites, though CompTIA recommends Network+ knowledge and around two years of IT administration with a security focus. The voucher costs about $425–$439 as of 2026 following CompTIA's June 2026 price rise — confirm the current figure at store.comptia.org. Note that CompTIA lists SY0-701 as current with a successor expected but unannounced; check the live code before buying study materials.

Two facts make Security+ the trunk of the map. It has long appeared on US Department of Defense approved-certification lists (the legacy 8570 baseline placed it at IAT Level II, and certs approved under 8570 carried forward under the current DoD 8140 framework), which matters enormously for government and contractor roles. And it is the reference point every other cert on this map is compared against.

ISC2 Certified in Cybersecurity (CC)

If Security+ feels like too big a first bite, ISC2's CC is the gentler on-ramp: no experience requirement, a $199 standard exam fee, and a scope limited to genuine fundamentals. Be aware that ISC2's famous free-exam programme closed to new enrolments on 20 May 2026, so budget for the fee. CC is a stepping stone, not a destination — plan to reach Security+ within a year of earning it.

Optional feeders

CompTIA A+ and Network+ are not security certifications, but if you are entering IT itself from scratch, Network+ before Security+ is the classic sequence — CompTIA's own recommended experience for Security+ assumes networking knowledge. Vendor fundamentals such as Microsoft's SC-900 also fit here for people in Microsoft-centric organisations; the SC-900 Security, Compliance and Identity Fundamentals exam page shows what that exam covers.

Entry-stage decision rule: no IT background at all → CC (or Network+ first), then Security+. Some IT experience already → straight to Security+.

Stage 2: intermediate — the fork (years 2–4)

With Security+ and a junior role behind you, the map splits. Pick the line whose daily work you actually want.

Defensive track: SOC and analysis

The defensive line leads through security operations: monitoring, triage, incident response, vulnerability management.

  • CompTIA CySA+ is the natural next stop after Security+ on CompTIA's own pathway. As of August 2026 two versions are live: CS0-004 launched on 23 June 2026, while the English CS0-003 exam retires on 22 December 2026 — pick one version and match your study materials to it. CS0-004 runs to a maximum of 85 questions over 165 minutes (passing 750/900), weighted toward Security Operations (34%) and Vulnerability Management (26%). CompTIA recommends about four years in an analyst role, but that is guidance, not a gate.
  • ISC2 SSCP is the operational alternative: since 1 October 2025 a computerised adaptive exam of 100–125 items in up to 2 hours, priced at $249, requiring one year of paid experience across its seven domains (or the Associate of ISC2 route while you earn it). ISC2 states SSCP is approved under DoDM 8140.03.
  • GIAC GSEC (Security Essentials) is the premium option: 106 questions over 4 hours, open-book with printed notes, no prerequisites, passing at 72% for versions released on or after 6 April 2026. The exam attempt alone is listed around $999 (some trackers say $949 — check giac.org/pricing), and the affiliated SANS course costs thousands more but is not required. GSEC makes most sense when an employer or government role pays for it. Browse the GIAC Security Essentials exam page to see the territory it covers.

Offensive track: penetration testing

  • CompTIA PenTest+ (PT0-003) is the accessible entry to red-team work: up to 90 questions in 165 minutes, passing 750/900, with the current PT0-003 version (launched December 2024) adding AI-based attacks and expanded cloud and API exploitation. It is a knowledge exam, which is both its virtue (affordable, schedulable) and its limit (it cannot prove you can pop a live box).
  • EC-Council CEH v13 occupies an odd but real niche: a 125-question, 4-hour multiple-choice exam that is heavily recognised by HR filters and commonly cited for US government-adjacent roles. It is expensive — roughly $950–$1,199 for the voucher depending on delivery, plus a $100 eligibility application fee for self-study candidates with two years' experience — so take it when a target employer names it, not on spec.

The truly hands-on offensive credential, OSCP, belongs to Stage 3 below. If you want to know exactly how brutal each of these gets, the ranking of the hardest cybersecurity certification exams compares them directly.

Management track: holding pattern, deliberately

There is no intermediate management certification worth buying at year two, because the credentials that matter — CISSP, CISM — are gated by five years of experience. The management-track move at this stage is to keep collecting technical evidence (CySA+ or SSCP serve fine) and start logging the experience that will qualify you later. If you must sit an exam early, remember that ISC2 lets you pass CISSP as an Associate of ISC2 and ISACA lets you sit CISM before your experience is complete — you hold the pass, then certify once qualified (ISACA gives you five years from the pass date to apply).

Stage 3: advanced (years 4–7)

This is where the tracks reach their named destinations — and where exams get long, expensive, or both.

Defensive terminus: SecurityX and GIAC specialisations

CompTIA SecurityX (CAS-005) — the certification formerly called CASP+, renamed in December 2024 — is the advanced practitioner cert for people who want to stay deeply technical rather than move into management. It is about 90 questions over 165 minutes, graded pass/fail with no scaled score, and CompTIA recommends ten years of IT experience with five hands-on in security. CAS-005 elevated zero trust, post-quantum cryptography and AI/ML threat modelling. Do not buy CAS-004 materials; that exam retired in June 2025.

GIAC's specialised certifications (forensics, industrial control systems, detection engineering and more) serve defenders who want depth in one niche — the GICSP industrial cybersecurity exam page is one example of how specific these get.

Offensive terminus: OSCP

OffSec's OSCP (PEN-200) is the credential that proves hands-on exploitation ability: a 24-hour proctored practical exam against live machines, followed by a professional report. Since November 2024, passing awards both the lifetime OSCP and a three-year OSCP+ that renews via OffSec's CPE programme or further exams. There is no cheap exam-only habit to fall into here — the standard Course & Cert bundle is $1,749 for 90 days of lab access and one attempt, with a Learn One subscription at $2,749 per year including two attempts. Budget both money and months of lab time.

Management terminus: CISSP, then CISM or CISA

ISC2 CISSP is the broadest senior credential on the map and the standard gateway into security leadership. Since April 2024 it is a computerised adaptive test of 100–150 items in a maximum of 3 hours, priced at $749, with the five-year experience requirement described earlier. It renews on a 3-year cycle of 120 CPE credits.

ISACA CISM is the purer management play — governance, programme management, incident management — with 150 questions over 4 hours, passing at a scaled 450/800, priced at $575 for ISACA members and $760 for non-members plus a $50 application fee. Its sibling CISA takes the audit line at the same price and format. One scheduling note: ISACA updates the CISM exam content outline effective 3 November 2026, so match your prep to whichever outline you will sit.

Choosing between CISSP and CISM at this stage is a genuine fork, and it deserves more than a paragraph — the guide for experienced professionals weighs them head to head.

The roadmap at a glance

StageDefensiveOffensiveManagement
Entry (0–2 yrs)ISC2 CC → Security+ISC2 CC → Security+ISC2 CC → Security+
Intermediate (2–4 yrs)CySA+, SSCP or GSECPenTest+ (CEH if required)Technical cert + log experience
Advanced (4–7 yrs)SecurityX, GIAC specialismsOSCP → OSEP/OSWECISSP → CISM or CISA

Planning the journey: money, renewals and sequencing traps

Budget the whole line, not one ticket. A defensive path of Security+ → CySA+ → SecurityX costs roughly $1,300–$1,400 in vouchers alone at 2026 pricing, before study materials and renewal fees. The offensive path is heavier: OSCP's cheapest route is $1,749. Management is exam-cheap but fee-long: CISSP carries an annual maintenance fee and a 120-CPE cycle.

Renewals stack in your favour if you stay in one vendor family. CompTIA's continuing education model renews lower certifications automatically when you earn or renew a higher one, and you pay CE fees only for your highest cert — so Security+ effectively stops costing anything once you hold CySA+ or SecurityX. ISC2 similarly maintains its certifications on a rolling CPE cycle. Factor this in before mixing five vendors across your map.

Three sequencing traps to avoid:

  1. Buying CISSP as a beginner. Interest in CISSP among newcomers is huge, but without five years of qualifying experience you can only become an Associate of ISC2 — a legitimate path, but not the credential employers are searching CVs for.
  2. Studying for a retired exam version. CASP+ CAS-004, PenTest+ PT0-002 and (soon) CySA+ CS0-003 are examples of versions that retired or are retiring; always confirm the live exam code on the provider's site before spending on materials.
  3. Collecting certificates instead of a track. Six unrelated badges signal indecision; three sequenced credentials on one line signal a career.

Two worked itineraries show how the map plays out in real careers.

The helpdesk-to-SOC route (defensive line). A helpdesk analyst with eighteen months of ticket experience takes Security+ in year two, moves into a junior SOC seat, and sits CySA+ in year four once the analyst work has made its vulnerability-management and incident-response domains familiar rather than theoretical. By year six she has a choice: SecurityX to become the senior technical defender on the team, or a swerve onto the management line — her five years of security-relevant experience now qualify her for CISSP, with Security+ able to waive one of them. Nothing on her itinerary was wasted, and every exam was sat when the experience made it cheapest to pass.

The sysadmin-to-pentester route (offensive line). A systems administrator with strong Linux and scripting skills clears Security+ quickly, takes PenTest+ in the same year to signal offensive intent, and lands a junior assessment role. He then spends a full year inside PEN-200 labs before attempting OSCP — the sequencing insight being that OSCP preparation is measured in lab hours, not reading hours, so he budgets calendar time the way management-track peers budget CPE credits. CEH enters his plan only if a specific employer or contract names it.

The experience-first principle behind both: sit each exam at the moment your day job has just finished teaching its hardest domain. Exams taken two years too early are paid for twice — once in the voucher, once in the extra study months replacing experience you did not yet have.

Practice testing belongs at every stage. Whichever stop you are approaching, a timed practice run against the exam's objective list tells you which domains need another pass before you book — ExamPractice's practice test simulation supports exactly that benchmarking, with free samples on individual exam pages across its certification exams directory. For no-cost question sources specific to security exams, see the roundup of free cybersecurity practice questions.

Frequently asked questions

Do I have to follow the tracks in order?

No exam on this map enforces a certification prerequisite (OSCP included). The order exists because each stop assumes knowledge from the previous one and because credential-awarding experience requirements (CISSP, CISM, SSCP) accumulate in real time whatever you do. Skipping ahead is legal; it is just rarely efficient.

Which certifications matter for US government and defence work?

DoD 8140 (DoDM 8140.03) replaced the old 8570 directive and is now fully in effect; it maps qualifications to specific work roles rather than broad levels. Certifications approved under 8570 — Security+, GSEC, SSCP, CISSP, CISM, CISA and SecurityX among them — carried forward. The authoritative source is the DoD 8140 Qualification Matrix at cyber.mil; do not rely on third-party tables.

How does the demand picture look for this multi-year investment?

CyberSeek, the US supply-demand tracker built on the NICE framework, reported roughly 450,000–514,000 US cybersecurity job openings across its 2025–2026 data windows, with far fewer available workers than openings. Check cyberseek.org for current figures before making decisions on a single number.

Where do cloud security certifications fit?

ISC2's CCSP is the natural cloud-security stop on the management/architecture line, and an active CISSP satisfies its entire experience requirement — a common CISSP-plus-one pairing. Cloud provider security specialisations slot into whichever track matches your role.

Where to start this week

Locate yourself on the map, then take the single next step — not the destination. If you have no credential, that step is choosing between CC and Security+ and downloading the official exam objectives, which every provider publishes free. If you are mid-track, it is confirming the current exam code and booking a date far enough out to prepare properly. The map spans years; the only stage you can act on is the next stop. Revisit the whole route once a year — exam versions, prices and even certification names change (as CASP+ becoming SecurityX proved), and a roadmap drawn in 2026 deserves a 2027 fact-check before you buy the next voucher.

Exam facts in this guide were checked against official certification-provider pages on . Fees, exam codes and policies change — confirm on the provider’s own site before you book.

Put it into practice

Test what you have just read

Reading about an exam only takes you so far. Work through practice questions for your certification and find the gaps before exam day does.

You may also like