CISSP vs CCNA: which should you take first?
The CISSP vs CCNA choice comes down to timing: take the CCNA (Cisco Certified Network Associate, a networking exam with no prerequisite) first if you are heading for networks. You can hold the CISSP (Certified Information Systems Security Professional) only after five years of security work, though its exam can come sooner; a CCNA replaces one year.
With no IT job yet, start with the first steps for beginners. On Adzuna, a job-ad search site, the CCNA appeared in 1,557 of the 9,475 US ads for network engineers (who build and run company networks) in October 2026, and the CISSP in 338 of the 8,110 US security-analyst ads. These describe different jobs, not a head-to-head score.
| CCNA | CISSP | |
|---|---|---|
| Awarded by | Cisco, the network-equipment maker | ISC2, a membership body for security professionals |
| Before you can hold it | Nothing: "Prerequisites: None" | Five years of security work in two or more of eight domains (topic areas); one year can be waived |
| Exam | 200-301, 120 minutes, graded pass/fail | Adaptive (each question picked from your earlier answers), 100 to 150 items, 3 hours |
| Exam fee | $300 (US price) | $749 (Americas and Asia Pacific) |
| How long it lasts | 3 years, then renew | 3-year cycles with 120 CPE (continuing professional education) credits and a yearly fee |
Source: Cisco and ISC2 pages listed under Sources.
Show the numbers
| Item | CCNA | CISSP |
|---|---|---|
| Exam time | 120 minutes (2 h) | 180 minutes (3 h) |
| Passing score | not published by Cisco | 700 of 1,000 |
| Languages | English, Japanese | 5 languages |
| Where you take it | test center · online, proctored | test center |
CCNA or CISSP: which do employers name more?
Instant answer from October 2026 job ads. No email needed.
CCNA is named in more job ads in the United States.
Source: Adzuna job ads, October 2026.
Get your full report
Two optional questions shape your first step. No email needed.
On this page
- What should you do first if you have no IT job yet?
- Why can't a beginner hold the CISSP?
- Which job ads name the CCNA and the CISSP?
- How do the CCNA and CISSP exams differ?
- What do the CCNA and CISSP cost over three years?
- How do you keep the CCNA and the CISSP active?
- What path leads from the CCNA to the CISSP?
- What do Reddit posters ask about the CCNA and the CISSP?
- What we did not check
- Sources
What should you do first if you have no IT job yet?
Start with networking basics and a first IT job; the CISSP can wait until your work history meets ISC2's rule.
- Learn the basics. If networking is new to you, start with CompTIA Network+, a vendor-neutral networking exam from CompTIA, an IT exam body.
- Check what local employers name. On any job site, read a dozen junior ads for network technicians or help-desk staff (the team that fixes colleagues' computer problems), and write down every credential they list.
If the ads keep naming the CCNA, book it. If they name A+ (CompTIA's entry-level IT support exam) instead, start with that; if they name neither, begin with Network+ from the step above. Our CCNA page covers study time and costs, and our cybersecurity roadmap lays out the security route from a first job onward.
Which one fits your situation?
- Help desk or IT support today, networks next: the CCNA is the natural next exam.
- Help desk or IT support today, security next: compare the CCNA with Security+, CompTIA's general security exam, in our CCNA vs Security+ comparison.
- Network administrator or engineer moving toward security: log the security tasks in your job and match them to the eight CISSP domains. Your CCNA can count for one of the five years.
- Four years of security work plus a CCNA, or five years without one: you meet the experience rule; book the CISSP.
- Experienced, but unsure whether to manage or to test: our CISM vs CISSP comparison covers the management route, and our CISSP vs OSCP comparison the hands-on attack route.
Why can't a beginner hold the CISSP?
ISC2 ties the credential to proven work: passing the exam is only the first part. Its experience page asks for at least five years of full-time security work in two or more of eight domains, the topic areas of the CISSP exam.
A waiver can shorten the five years by one. ISC2 accepts either a bachelor's or master's degree in computer science, IT or a related field, or a credential from its approved list. Its waiver update adds: "Only one waiver is permitted; a degree and credential cannot be combined to reduce two years of experience."
Passing the exam does not finish the process. If you already have the experience, you complete endorsement, the step where your experience is confirmed, within nine months of your exam date.
What if you pass the CISSP exam before you have the experience?
You become an Associate of ISC2, a status for people who passed without the work history. In ISC2's words: "The Associate of ISC2 will then have six years to earn the five years required experience." Associates pay a $50 annual maintenance fee (AMF, ISC2's yearly charge) and earn 15 CPE credits a year. Once your experience is approved, an $85 upgrade fee starts your first three-year CISSP cycle.
Does the CCNA count toward the CISSP experience rule?
Yes, for one year. ISC2's approved list for the credential waiver includes the entry "Cisco Certified Network Associate (CCNA)" on both its experience page and its waiver update. The same list names CompTIA Security+, CompTIA CySA+ (CompTIA's security-analyst exam), the SSCP (ISC2's security-administrator credential), and CCNP Security and CCIE Security (Cisco's security certifications at professional and expert level), among others.
Our reading: the CCNA itself is a credential, not experience. Network work you do after it may fit the Communication and Network Security domain, but you still need a second domain, and ISC2 decides at endorsement whether your duties qualify.
Which job ads name the CCNA and the CISSP?
The CCNA shows up in network-engineer ads and the CISSP in security-analyst and SOC-analyst ads (SOC: security operations center, the team that watches for attacks). We search Adzuna by job title and count an ad when its text contains the phrase ccna or cissp, whether the ad lists it as required, preferred or one option among several.
| Country | Network-engineer ads | Containing ccna |
Security-analyst ads | Containing cissp |
|---|---|---|---|---|
| United States | 9,475 | 1,557 | 8,110 | 338 |
| United Kingdom | 658 | 74 | 235 | 29 |
| India | 775 | 121 | 250 | 45 |
| Brazil | 260 | 32 | 434 | 4 |
Source: Adzuna API, job ads collected in October 2026. Analysis: CertWorthIt. Brazilian searches use the Portuguese titles analista de redes and analista de segurança with the English credential phrase.
In the US, the CISSP also appeared in 32 of the 233 SOC-analyst ads in October 2026. For what each job's ads name, see our pages on network engineers, cybersecurity analysts and SOC analysts.
How do the CCNA and CISSP exams differ?
The CCNA is a two-hour exam on building and running networks, graded pass/fail. The CISSP is a three-hour adaptive exam across eight security domains, scored out of 1,000.
| CCNA 200-301 v1.1 | CISSP | |
|---|---|---|
| Time | 120 minutes | 3 hours |
| Questions | Number not published by Cisco | 100 to 150 items, adaptive |
| Question formats | Not listed on the pages we read | Multiple choice and advanced item types |
| Result | Pass/fail, online within 48 hours; no passing score published | 700 out of 1,000 to pass |
| Languages | English and Japanese per the exam page; the certification page lists English | Chinese, English, German, Japanese and Spanish |
Source: Cisco CCNA certification and exam pages; ISC2 CISSP exam outline.
The topic weights come from Cisco's 200-301 v1.1 exam topics and ISC2's CISSP exam outline.
| CCNA topic area | Weight | CISSP domain | Weight |
|---|---|---|---|
| Network Fundamentals | 20% | Security and Risk Management | 16% |
| Network Access | 20% | Asset Security | 10% |
| IP Connectivity | 25% | Security Architecture and Engineering | 13% |
| IP Services | 10% | Communication and Network Security | 13% |
| Security Fundamentals | 15% | Identity and Access Management (IAM) | 13% |
| Automation and Programmability | 10% | Security Assessment and Testing | 12% |
| Security Operations | 13% | ||
| Software Development Security | 10% |
Source: Cisco 200-301 v1.1 exam topics; ISC2 CISSP exam outline.
The two exams meet in one place. The CCNA's security area asks you to configure access control lists (rules on a router or switch that allow or block traffic), and the CISSP's Communication and Network Security domain covers securing networks. The other seven CISSP domains, such as risk management and secure software development, go beyond the CCNA, though its security area also touches access control. Cisco notes that its topic list is a guideline that "may change at any time without notice."
Our CISSP page covers study time.
What do the CCNA and CISSP cost over three years?
With one exam attempt each, the CCNA comes to $600 over its first three-year cycle if you renew by retaking the exam, and the CISSP to $1,154 at ISC2's Americas price.
| Item | CCNA, US price | CISSP, Americas and Asia Pacific |
|---|---|---|
| Exam | $300 x 1 attempt | $749 x 1 attempt |
| Staying certified | $300 x 1 exam retake, assuming the same fee | $135 x 3 annual maintenance fees |
| Three-year total | $600 | $1,154 |
Source: Cisco CCNA exam and recertification pages; ISC2 exam pricing and AMF pages.
Cisco lists the fee as $300. Instead of a retake, you can renew the CCNA with Continuing Education (CE) credits, points for approved training, or with a higher Cisco exam. After a failed CCNA attempt, Cisco makes you wait five calendar days and charges the same fee again, unless you bought CCNA Exam Safeguard, its retake add-on.
Show the numbers
| Item | Fee |
|---|---|
| Fees to get certified: Exam | $749 |
| Fees to get certified: Annual fee, $135 a year × 3 years | $405 |
How do you keep the CCNA and the CISSP active?
The CCNA lasts three years and is renewed by exam or with CE credits; the CISSP renews in three-year cycles with 120 CPE credits plus a yearly fee.
CCNA. Cisco names three routes. You can retake the CCNA exam, move up to the next Cisco level or earn CE credits, which Cisco awards for approved training and exams; passing an associate-level exam earns 30. Cisco's credits pile up until you renew your highest Cisco level, and that renews every Cisco certification at that level and below. So a current CCNP (Cisco's professional-level certification) keeps the CCNA current; our CCNA vs CCNP comparison explains when to move up. If the CCNA expires, Cisco requires the full exam again.
CISSP. ISC2 asks for 120 CPE credits per three-year cycle and suggests 40 a year. CPE (continuing professional education) covers courses, conferences and similar learning that you log with ISC2. The $135 annual maintenance fee is due every year on top.
What path leads from the CCNA to the CISSP?
In our reading, a networking job is the bridge: CCNA, then network work, then growing security duties, then the CISSP once ISC2's experience rule is met. Cisco's CCNA pages do not mention the CISSP, so treat this as a plan, not a vendor route.
- Pass the CCNA. It needs no earlier credential and, on ISC2's list, can later cover one of the five CISSP years.
- Take a network job. Ask for tasks that touch security, such as access control lists or VPNs (encrypted links between sites or for remote users), both topics in the CCNA's security area.
- Add security duties and, if your target ads name it, Security+. Our Security+ page covers that exam.
- Log your work by domain. Keep dates, hours and duties for each job, because ISC2 counts experience month by month and by domain.
- Take the CISSP. With four years of qualifying work and the CCNA waiver, you meet the rule. You can take the exam earlier and finish the years as an Associate.
To stay in networking instead, look at the CCNP. For security administration, the SSCP is ISC2's credential for that work and sits on the same waiver list. Our CISSP vs Security+ comparison explains where each fits in a security career.
What do Reddit posters ask about the CCNA and the CISSP?
Posters ask what to add after the CCNA and how young someone can hold the full CISSP. They come from posts we collected on r/ccna, r/cissp, r/CompTIA and r/SecurityCareerAdvice. Reddit posters are a self-selected group, so read these as questions, not statistics.
- The next exam after the CCNA. Posters ask what to do after the CCNA and whether to add Network+ (r/ccna, r/CompTIA). In our reading, Network+ covers networking again; Security+ suits a move into security, and the CCNP suits staying in networks.
- A credential stack for a first security job. One thread lists Security+ and the CCNA and asks what to add (r/SecurityCareerAdvice). The CISSP does not belong in that early stack, because its experience rule puts it years later.
- How young a full CISSP can be. One poster asked whether anyone they knew had reached full CISSP status at a young age (r/cissp). The ISC2 pages we read set no age rule; the five years of work, or four with a waiver, decide it.
What we did not check
- CCNA question count and passing score. Cisco publishes neither on the pages we read.
- CE credits for CCNA renewal. The Cisco pages we read did not say how many CE credits renew the CCNA without an exam.
- Prices outside the US and the Americas. We did not check local CCNA prices or ISC2's other regional prices.
- Whether an expired CCNA still counts as a waiver. ISC2's list names the credential but, on the pages we read, does not say whether it must be current.
- How the CCNA is delivered, and whether the CISSP can be taken online.
- Pass rates, the CISSP retake fee and salaries. We found no official, dated figures on the pages we read.
Sources
All pages below were read October 8, 2026. Cisco's site blocked our reader, so its pages come from archived copies on archive.org (saved copies of a page), each with its own capture date.
- Cisco: CCNA certification and CCNA exam, archived copies of October 5, 2026; 200-301 v1.1 exam topics (live PDF); recertification and continuing education, archived copies of July 12, 2026; CE qualifying options, archived copy of June 23, 2026.
- ISC2: CISSP experience requirements, CISSP waiver update, CISSP exam outline, exam pricing, AMF overview, member policies, Associate of ISC2, endorsement.
- Job ads: Adzuna API, October 2026, network-engineer, security-analyst and SOC-analyst ads; phrases
ccnaandcissp. Analysis: CertWorthIt. Method. - Reddit: posts collected from r/ccna, r/cissp, r/CompTIA and r/SecurityCareerAdvice, linked where cited.
Questions people ask
Should I take the CCNA or the CISSP first?
Take the CCNA (Cisco Certified Network Associate) first if you are heading for networks. Cisco lists no prerequisites. The CISSP (Certified Information Systems Security Professional) can only be held after five years of security work in at least two of its eight domains, the topic areas of ISC2's exam outline. ISC2, the membership body that awards the CISSP, also accepts the CCNA as a waiver: a credential that replaces one of those five years.
Does the CCNA count toward the CISSP experience requirement?
Yes, for one year. ISC2's approved list for the CISSP experience waiver (a credential or degree that replaces part of the required work) names the Cisco Certified Network Associate (CCNA), so holding it can cover one of the five years. ISC2 allows only one waiver, so a CCNA and a computer science or IT degree cannot be combined to remove two years. The other four years must be security work in at least two of the CISSP's eight domains (topic areas).
Can I take the CISSP exam without experience?
Yes, but you would not hold the full CISSP (Certified Information Systems Security Professional) yet. If you pass without five years of security work, you become an Associate of ISC2, a status for people who passed but still need the experience, and you then have six years to earn the five years. Associates pay a $50 annual maintenance fee (AMF, ISC2's yearly charge) and earn 15 CPE credits a year, points for logged learning such as courses and conferences.
How much do the CCNA and CISSP cost over three years?
With one exam attempt each, the CCNA (Cisco Certified Network Associate) costs $600 over its first three-year cycle in the US: the $300 exam plus $300 to retake it for renewal. Cisco also renews it through Continuing Education (CE) credits, points for approved training, which we did not price. The CISSP (Certified Information Systems Security Professional) costs $1,154 over three years at ISC2's Americas price: the $749 exam plus three annual maintenance fees of $135. Neither total includes training, books or failed attempts.
Which job ads name the CCNA and the CISSP?
We count them in different jobs on Adzuna, a job-ad search site. In October 2026, the CCNA (Cisco Certified Network Associate) appeared in 1,557 of the 9,475 US network-engineer ads. The CISSP (Certified Information Systems Security Professional) appeared in 338 of the 8,110 US security-analyst ads and in 32 of the 233 US SOC-analyst ads (security operations center, the team that watches for attacks). An ad counted when its text contained the phrase ccna or cissp.
Is the CCNA useful for a cybersecurity career?
It can be a networking base. Cisco's 200-301 exam topics give security fundamentals 15% of the CCNA (Cisco Certified Network Associate) exam, including access control lists, rules that allow or block network traffic. ISC2 accepts the CCNA as a one-year waiver toward the five years of work the CISSP (Certified Information Systems Security Professional) requires. We count the CCNA only in network-engineer ads on Adzuna, a job-ad search site, so we cannot say how often security employers ask for it.