CISSP vs CompTIA Security+: which should you take first?

Job-ad data: October 2026 · Editor: · Updated

In the CISSP vs CompTIA Security+ choice, take Security+ first if you are new to security: it needs no experience. The CISSP needs five years across two domains; Security+ counts for one of those years. Of 8,110 US security-analyst ads in October 2026 (Adzuna), cissp appeared in 4.2% of the ads and comptia security in 1.4% of the ads.

CompTIA Security+ is CompTIA's general security certification. CompTIA calls it "the first security certification IT professionals should earn." The CISSP (Certified Information Systems Security Professional) from ISC2 is aimed at practitioners with about five years in the field. It covers eight domains from risk management to software development security, and ISC2 lets you take the exam earlier as an Associate. They sit at different career stages: the question is which one you qualify for now.

Quick answer · What they test · Job ads · Experience · Cost · Difficulty · Order · Security+ V8

CompTIA Security+ CISSP
Issuer CompTIA ISC2
Level and focus First security certification in CompTIA's path; 5 domains Experienced practitioners; 8 technical and management domains
Experience None required (CompTIA recommends Network+ and two years in a security or systems-administrator role) 5 years of cumulative, full-time work in at least 2 of the 8 domains; 1 year can be waived
Exam Up to 90 questions, multiple-choice and performance-based, 90 minutes 100 to 150 items, 3 hours, adaptive
Passing score 750 on a scale of 100 to 900 700 out of 1,000
Exam fee $439 (US voucher) $749 in the Americas and Asia Pacific
Renewal 50 continuing education units (CEUs) per 3 years, $150 fee 120 CPE credits per 3 years, $135 a year

Source: CompTIA Security+ (SY0-701) and continuing-education pages; ISC2 CISSP exam outline, experience requirements, exam pricing and AMF pages, as of October 5, 2026. CPE stands for continuing professional education.

CISSP vs CompTIA Security+: share of cybersecurity analyst job ads naming each
CISSP is named more often than CompTIA Security+ in 4 of 4 countries with enough ads (India, the United Kingdom, the United States, Brazil).
Show the numbers
CISSP vs CompTIA Security+: share of cybersecurity analyst job ads naming each. Share of job ads that name each item. Source: Adzuna job ads, October 2026.
CountryCISSPCompTIA Security+
India18%3%
United Kingdom12%5%
United States4.2%1.4%
Brazil4 of 4342 of 434

CISSP or CompTIA Security+: which do employers name more?

Instant answer from October 2026 job ads. No email needed.

Country

CISSP is named in more job ads in the United States.

  1. CISSP338 of 8,110 ads4.2%
  2. CompTIA Security+112 of 8,110 ads1.4%

Source: Adzuna job ads, October 2026.

On this page
  1. Which should you take, by situation?
  2. What do the CISSP and Security+ exams test?
  3. Do job ads ask for the CISSP or Security+?
  4. Does Security+ count toward the CISSP?
  5. How much do the CISSP and Security+ cost over three years?
  6. Is the CISSP harder than Security+?
  7. Security+ vs CISSP: who should take which first?
  8. Security+ V8: launch expected November 17, 2026
  9. Sources

Which should you take, by situation?

  • No security job yet, or in IT support: take Security+. CompTIA sets no prerequisite for the exam, and Security+ counts later as one year toward the CISSP. If you still work in support, our page on IT-support jobs lists what those ads name.
  • Up to four years of work in CISSP domains, no relevant degree: Security+ is the credential you can hold now, and it brings the CISSP one year closer. Four years of work across two domains plus Security+ meets the experience rule; your application still needs an endorsement.
  • Four years of work, no relevant degree, weighing the $439: Security+ lets you apply for the CISSP title a year earlier. Without it, you can pass the CISSP exam now and hold Associate status until the fifth year is in.
  • Up to four years of work in CISSP domains and a degree in computer science, IT or a related field: the degree already covers the one waiver year, and ISC2 allows only one. Take Security+ for the jobs that ask for it, not to shorten the CISSP path.
  • Five years of full-time work in two or more CISSP domains: go straight to the CISSP. Security+ would not change your eligibility.
  • Short of the years but ready for the CISSP exam: you can pass it now and become an Associate of ISC2, with six years to earn the experience. You pay $749 for the exam, then $50 a year and 15 CPE credits a year, but you cannot use the CISSP title until the years are in place.
  • Booking Security+ this fall: CompTIA expects the V8 exam (SY0-801) on or around November 17, 2026, and SY0-701 retires in English on June 11, 2027. Pick the version your study material covers before you buy a voucher; see Security+ V8.
  • Choosing between Security+ and a networking route: our CCNA vs Security+ comparison and Network+ vs Security+ comparison cover that choice, and CCNA vs CISSP covers the longer path.

What do the CISSP and Security+ exams test?

Security+ tests the security tasks of a first security role. Its largest domain is security operations; the CISSP spreads its weight more evenly across eight domains, including management topics such as governance and risk.

Security+ (SY0-701) domain Weight
General security concepts 12%
Threats, vulnerabilities, and mitigations 22%
Security architecture 18%
Security operations 28%
Security program management and oversight 20%

Source: CompTIA Security+ (V7) exam objectives summary for SY0-701, current until the expected V8 launch; checked October 5, 2026.

CISSP domain Weight
Security and Risk Management 16%
Asset Security 10%
Security Architecture and Engineering 13%
Communication and Network Security 13%
Identity and Access Management (IAM) 13%
Security Assessment and Testing 12%
Security Operations 13%
Software Development Security 10%

Source: ISC2 CISSP exam outline, effective April 15, 2024, checked October 5, 2026.

The two outlines share their headings: architecture, operations, and program management or risk appear in both. The difference is depth and point of view. Security+ asks what a security analyst or administrator does with threats and controls. The CISSP adds asset security, identity and access management, and software development security as domains of their own, and it expects answers from the point of view of someone who designs and runs security, not someone who only operates it.

CISSP vs CompTIA Security+ exams side by side: questions, time, format
CompTIA Security+, 90 questions in 90 minutes.
Show the numbers
CISSP vs CompTIA Security+ exams side by side: questions, time, format. Source: isc2.org, comptia.org, checked October 3, 2026.
ItemCISSPCompTIA Security+
Questions100–150 questions90 questions
Exam time180 minutes (3 h)90 minutes (1 h 30 min)
Passing score700 of 1,000750 (scale 100–900)
FormatMultiple choice, adaptive testingMultiple choice, performance-based tasks
Languages5 languages5 languages

Do job ads ask for the CISSP or Security+?

We count job ads with the title security analyst (or the local equivalent) and check how many contain each phrase anywhere in the text: cissp for the CISSP and comptia security for Security+. An ad can contain both. The method is on our methodology page.

Country Security-analyst ads Containing cissp Containing comptia security
United States 8,110 338 112
United Kingdom 235 29 12
India 250 45 8

Source: Adzuna API, security-analyst ads collected in October 2026. Analysis: CertWorthIt.

In US security-analyst ads in October 2026 (Adzuna), the share for cissp was 4.2% and the share for comptia security was 1.4%. The UK and Indian counts in the table come from small samples, so a handful of postings can change them noticeably from one month to the next. The other countries we collect gave too few security-analyst ads to report shares.

The two columns are not measured the same way. The phrase cissp is the credential's own abbreviation. The comptia security count is approximate: it misses ads that write only Security+ or Sec+, and it may also catch other CompTIA names that begin the same way, such as SecurityX. Read it as a rough signal, not an exact count.

The counts show how often employers hiring analysts write each name into an ad, not whether they require it: an ad may list a credential as required, as preferred or as one of several options. The counts do not set the order; the experience rule does. We do not count salary by credential, so these figures say how often employers name each one, not what either pays. Our cybersecurity-analyst page shows what else those ads name, and our cybersecurity field page lists every security credential we count.

What cybersecurity analyst job ads name in the United States: certifications and skills
CISSP is named in 4.2% of these ads; SIEM leads with 5.1%.
Show the numbers
What cybersecurity analyst job ads name in the United States: certifications and skills. Share of job ads that name each item. Source: Adzuna job ads, October 2026.
ItemAdsShare of ads
SIEM4155.1%
CISSP3384.2%
CompTIA1622.0%
CISM1341.7%
CompTIA CySA+1191.5%
CompTIA Security+1121.4%
Splunk1001.2%
CEH8181 of 8,110

Does Security+ count toward the CISSP?

Yes, for one year. ISC2 asks for at least five years of cumulative, full-time experience in two or more of the eight CISSP domains, and it lets one approved credential or one relevant degree replace one of those years. CompTIA Security+ is on the approved list, next to CySA+, the CISM and the SSCP.

Only one waiver applies. ISC2 revised the list with effect from April 1, 2026. Its May 2026 update says: "Only one waiver is permitted; a degree and credential cannot be combined to reduce two years of experience." A Security+ holder with a computer science degree still needs four years of work. One poster asked on Reddit whether several waivers add up (r/cissp); under that rule, they do not.

The Associate of ISC2 route. You can take the CISSP exam before you have the experience. After passing, you have nine months to complete the certification application. If the years are not there yet, you choose the Associate of ISC2 route in that application. Associates have six years to earn the five years of experience, pay a $50 annual maintenance fee and earn 15 CPE credits a year. Once the experience is in place, an $85 upgrade payment starts a new three-year CISSP cycle.

Endorsement. To become a CISSP, your application also needs an endorsement: an ISC2-certified professional in good standing endorses you, or ISC2 does so itself with proof of employment.

Security+ has no experience rule. CompTIA recommends Network+ and two years in a security or systems-administrator role, but it does not require either. That is why Security+ fits the start of a security career, and the CISSP fits once you have five years of work. ISC2's rule counts years of qualifying work, not age.

A worked example: an IT-support technician who moves into a security-analyst job and earns Security+ meets the CISSP experience rule after four years of full-time work in two domains, such as security operations and identity and access management. With a relevant degree instead of Security+, the date is the same, and holding both does not bring it forward.

How much do the CISSP and Security+ cost over three years?

Security+ costs $439 on day one and $150 more only if you renew through continuing education; the CISSP costs $749 on day one and $135 every year once you are certified, or $50 a year as an Associate. Over a first three-year cycle that is $589 for Security+ in the US and $1,154 for a certified CISSP in the Americas.

CompTIA Security+ CISSP (ISC2)
Exam fee $439 in the US; €323 in CompTIA's Europe store; the UK store lists $439 $749 in the Americas and Asia Pacific; €719.04 in Europe; £606.69 in the UK
Retake option Voucher with Retake Assurance: $579 (€426 in Europe) No separate retake price on ISC2's pricing page; retest after 30 test-free days following a first attempt, with longer waits after later ones; up to 4 attempts in 12 months
Renewal cycle 3 years 3 years
Continuing education 50 CEUs per cycle 120 CPE credits per cycle, at least 90 in Group A
Renewal fee $150 per cycle, due when you renew through CEUs $135 annual maintenance fee (AMF) every year
Before full certification Not applicable $50 a year as an Associate of ISC2, then an $85 upgrade

Source: CompTIA Security+ V7 page, CompTIA continuing-education fee and CEU pages; ISC2 exam pricing, AMF overview, after-your-exam and Associate of ISC2 pages, checked October 3 and 5, 2026.

For Security+, $439 for the voucher plus the $150 continuing-education fee comes to $589 for a first cycle. For the CISSP in the Americas, $749 for the exam plus three years at $135 comes to $1,154. In the UK the CISSP exam is £606.69 and in Europe €719.04, with the same $135 yearly fee. On the Associate route you pay the $749 exam, then $50 a year as an Associate, then the $85 upgrade, after which the $135 yearly fee applies. Courses and books are extra for both.

ISC2 lists no separate retake price. Its rules allow a retest after 30 test-free days following a first attempt, with longer waits after later ones, and up to 4 attempts in 12 months; check them before you budget for the CISSP.

Security+ has a second way to renew. CompTIA renews it when you earn a higher-level CompTIA certification, such as CySA+, PenTest+ or SecurityX, and you then pay no continuing-education fee for Security+. CompTIA also offers renewal through CertMaster CE.

CISSP vs CompTIA Security+: what each certification costs
Cheapest route: CISSP $749, CompTIA Security+ $439. Keeping CISSP costs $135 a year ($405 over the 3-year cycle).
Show the numbers
CISSP vs CompTIA Security+: what each certification costs. Source: isc2.org, comptia.org, checked October 3, 2026.
ItemFee
CISSP: Fees to get certified: Exam$749
CISSP: Fees to get certified: Annual fee, $135 a year × 3 years$405
CompTIA Security+: Fees to get certified: Exam$439
CompTIA Security+: Fees to get certified: Renewal, every 3 years$150

Is the CISSP harder than Security+?

The CISSP sets the higher bar: it covers eight domains against five, runs 100 to 150 adaptive items in three hours and requires five years of work to hold the title.

The CISSP stops somewhere between 100 and 150 items within three hours, depending on your answers, and needs 700 out of 1,000, according to ISC2's exam outline. Security+ has up to 90 questions in 90 minutes, a mix of multiple-choice and performance-based questions, and needs 750 on a scale of 100 to 900.

On study time, the Reddit posts we collected give a median of three months for the CISSP, from 36 first-person statements, with the middle half between two and four months. Another 10 people gave their CISSP study time in weeks, with a median of three and a half; the two figures differ, and the posts do not explain why. For Security+, 13 people who gave their study time in months reported a median of two months, and 10 who gave it in weeks reported a median of two and a half weeks. These are self-reports from people who chose to post, so they lean toward those who passed, and they are not matched for background. Our CISSP page covers CISSP study resources in more detail.

Security+ vs CISSP: who should take which first?

Security+ first if you are starting out and want a first security job. For the CISSP itself, Security+ saves one of the five years only if you have no relevant degree; with five years in two domains, go to the CISSP.

On a technical path, Security+ comes at the start, while you move from IT support or a degree into a first security job. The CISSP comes once you have five years across at least two of its domains, or four with Security+ or a relevant degree. If you hold a degree, Security+ still helps you get hired, but it does not bring the CISSP closer. Our cybersecurity roadmap sets out the wider sequence.

For US defense work, both credentials appear in the Department of Defense's cyber workforce rules under DoDM 8140.03. ISC2 states that the CISSP is approved under DoDM 8140.03, and CompTIA's framework page lists Security+ as approved for 20 work roles, including cyber defense analyst. Approval is set per work role, so find the work role in the job posting and check which credentials it lists before choosing.

For the choice between Security+ and networking, read CCNA vs Security+. Whether A+ or Network+ should come before Security+ is covered on our Security+ page. For a mid-level step between the two, compare CISSP vs CySA+ and CISSP vs SSCP. If you already hold the CISSP, our CISM vs CISSP comparison covers the management route and our CEH vs CISSP comparison covers hands-on testing.

Security+ V8: launch expected November 17, 2026

CompTIA expects to launch Security+ V8 (SY0-801) on or around November 17, 2026. CompTIA's V8 page lists up to 90 questions in 90 minutes with 750 to pass, in English. The current exam, SY0-701, retires in English on June 11, 2027, and in Japanese, Portuguese, Spanish and Thai on August 13, 2027. The domain weights and the $439 voucher price on this page describe SY0-701; check the V8 page before you buy. The CISSP outline in force has been effective since April 15, 2024.

Sources

Edited by Elena Marsh · Data checked October 5, 2026

Questions people ask

Can I take the CISSP with only Security+?

You can take the exam, but Security+ alone does not make you a CISSP. ISC2 asks for five years of cumulative, full-time work in at least two of the eight CISSP domains, and CompTIA Security+ counts for one of those years, so a Security+ holder still needs four years of work. Pass the CISSP exam before you have the years, and you can choose the Associate of ISC2 route in your certification application. Associates pay $50 a year, earn 15 CPE credits a year and have six years to gain the five years of experience.

Does Security+ count toward the CISSP?

Yes, for one year. CompTIA Security+ is on ISC2's list of approved credentials that can replace one of the five years of experience the CISSP requires. ISC2 allows only one waiver, and a degree and a credential cannot be combined, so Security+ shortens nothing if you already use a relevant bachelor's or master's degree for that year. ISC2 revised the list on April 1, 2026, and Security+ stayed on it.

Is Security+ enough, or do I need the CISSP?

For a first security job, Security+ is the one you can earn now: CompTIA sets no experience requirement, while the CISSP needs five years of work in its domains. The CISSP becomes the next step once your years are in place. Our US ad counts for both credentials are in the job-ads section of this page.

Is the CISSP harder than Security+?

The CISSP sets the higher bar. It is adaptive, with 100 to 150 items in three hours and a passing score of 700 out of 1,000, and you need five years of experience to hold the title. CompTIA Security+ has up to 90 multiple-choice and performance-based questions in 90 minutes, with 750 on a scale of 100 to 900 to pass, and no experience rule. In the Reddit posts we collected, people who stated a CISSP study time in months reported a median of three months (36 statements); for Security+, the median was two months (13 statements). These are not hours of study and not matched for background, so they do not rank the exams.

Which costs more over three years, the CISSP or Security+?

The CISSP. In the Americas, its exam costs $749 and ISC2 charges a $135 annual maintenance fee every year once you are certified, so a first three-year cycle comes to $1,154. In the US, the CompTIA Security+ voucher costs $439, and renewing through continuing education costs $150 at the end of the three-year cycle, $589 in total. Prices are from the ISC2 and CompTIA pages we read on October 3, 2026; courses and books are extra.

CompTIA Security+ vs CISSP: should I take Security+ first?

Yes, if you are starting out or want a first security job: Security+ has no experience requirement. For the CISSP itself, ISC2 accepts Security+ for one of the five years of experience, unless you already use a relevant degree for that year. With five years of full-time work in two or more CISSP domains, you can go straight to the CISSP, which costs $749 in the Americas; Security+ would not shorten anything.