CISSP vs CompTIA Security+: which should you take first?
In the CISSP vs CompTIA Security+ choice, take Security+ first if you are new to security: it needs no experience. The CISSP needs five years across two domains; Security+ counts for one of those years. Of 8,110 US security-analyst ads in October 2026 (Adzuna), cissp appeared in 4.2% of the ads and comptia security in 1.4% of the ads.
CompTIA Security+ is CompTIA's general security certification. CompTIA calls it "the first security certification IT professionals should earn." The CISSP (Certified Information Systems Security Professional) from ISC2 is aimed at practitioners with about five years in the field. It covers eight domains from risk management to software development security, and ISC2 lets you take the exam earlier as an Associate. They sit at different career stages: the question is which one you qualify for now.
Quick answer · What they test · Job ads · Experience · Cost · Difficulty · Order · Security+ V8
| CompTIA Security+ | CISSP | |
|---|---|---|
| Issuer | CompTIA | ISC2 |
| Level and focus | First security certification in CompTIA's path; 5 domains | Experienced practitioners; 8 technical and management domains |
| Experience | None required (CompTIA recommends Network+ and two years in a security or systems-administrator role) | 5 years of cumulative, full-time work in at least 2 of the 8 domains; 1 year can be waived |
| Exam | Up to 90 questions, multiple-choice and performance-based, 90 minutes | 100 to 150 items, 3 hours, adaptive |
| Passing score | 750 on a scale of 100 to 900 | 700 out of 1,000 |
| Exam fee | $439 (US voucher) | $749 in the Americas and Asia Pacific |
| Renewal | 50 continuing education units (CEUs) per 3 years, $150 fee | 120 CPE credits per 3 years, $135 a year |
Source: CompTIA Security+ (SY0-701) and continuing-education pages; ISC2 CISSP exam outline, experience requirements, exam pricing and AMF pages, as of October 5, 2026. CPE stands for continuing professional education.
Show the numbers
| Country | CISSP | CompTIA Security+ |
|---|---|---|
| India | 18% | 3% |
| United Kingdom | 12% | 5% |
| United States | 4.2% | 1.4% |
| Brazil | 4 of 434 | 2 of 434 |
CISSP or CompTIA Security+: which do employers name more?
Instant answer from October 2026 job ads. No email needed.
CISSP is named in more job ads in the United States.
Source: Adzuna job ads, October 2026.
On this page
- Which should you take, by situation?
- What do the CISSP and Security+ exams test?
- Do job ads ask for the CISSP or Security+?
- Does Security+ count toward the CISSP?
- How much do the CISSP and Security+ cost over three years?
- Is the CISSP harder than Security+?
- Security+ vs CISSP: who should take which first?
- Security+ V8: launch expected November 17, 2026
- Sources
Which should you take, by situation?
- No security job yet, or in IT support: take Security+. CompTIA sets no prerequisite for the exam, and Security+ counts later as one year toward the CISSP. If you still work in support, our page on IT-support jobs lists what those ads name.
- Up to four years of work in CISSP domains, no relevant degree: Security+ is the credential you can hold now, and it brings the CISSP one year closer. Four years of work across two domains plus Security+ meets the experience rule; your application still needs an endorsement.
- Four years of work, no relevant degree, weighing the $439: Security+ lets you apply for the CISSP title a year earlier. Without it, you can pass the CISSP exam now and hold Associate status until the fifth year is in.
- Up to four years of work in CISSP domains and a degree in computer science, IT or a related field: the degree already covers the one waiver year, and ISC2 allows only one. Take Security+ for the jobs that ask for it, not to shorten the CISSP path.
- Five years of full-time work in two or more CISSP domains: go straight to the CISSP. Security+ would not change your eligibility.
- Short of the years but ready for the CISSP exam: you can pass it now and become an Associate of ISC2, with six years to earn the experience. You pay $749 for the exam, then $50 a year and 15 CPE credits a year, but you cannot use the CISSP title until the years are in place.
- Booking Security+ this fall: CompTIA expects the V8 exam (SY0-801) on or around November 17, 2026, and SY0-701 retires in English on June 11, 2027. Pick the version your study material covers before you buy a voucher; see Security+ V8.
- Choosing between Security+ and a networking route: our CCNA vs Security+ comparison and Network+ vs Security+ comparison cover that choice, and CCNA vs CISSP covers the longer path.
What do the CISSP and Security+ exams test?
Security+ tests the security tasks of a first security role. Its largest domain is security operations; the CISSP spreads its weight more evenly across eight domains, including management topics such as governance and risk.
| Security+ (SY0-701) domain | Weight |
|---|---|
| General security concepts | 12% |
| Threats, vulnerabilities, and mitigations | 22% |
| Security architecture | 18% |
| Security operations | 28% |
| Security program management and oversight | 20% |
Source: CompTIA Security+ (V7) exam objectives summary for SY0-701, current until the expected V8 launch; checked October 5, 2026.
| CISSP domain | Weight |
|---|---|
| Security and Risk Management | 16% |
| Asset Security | 10% |
| Security Architecture and Engineering | 13% |
| Communication and Network Security | 13% |
| Identity and Access Management (IAM) | 13% |
| Security Assessment and Testing | 12% |
| Security Operations | 13% |
| Software Development Security | 10% |
Source: ISC2 CISSP exam outline, effective April 15, 2024, checked October 5, 2026.
The two outlines share their headings: architecture, operations, and program management or risk appear in both. The difference is depth and point of view. Security+ asks what a security analyst or administrator does with threats and controls. The CISSP adds asset security, identity and access management, and software development security as domains of their own, and it expects answers from the point of view of someone who designs and runs security, not someone who only operates it.
Show the numbers
| Item | CISSP | CompTIA Security+ |
|---|---|---|
| Questions | 100–150 questions | 90 questions |
| Exam time | 180 minutes (3 h) | 90 minutes (1 h 30 min) |
| Passing score | 700 of 1,000 | 750 (scale 100–900) |
| Format | Multiple choice, adaptive testing | Multiple choice, performance-based tasks |
| Languages | 5 languages | 5 languages |
Do job ads ask for the CISSP or Security+?
We count job ads with the title security analyst (or the local equivalent) and check how many contain each phrase anywhere in the text: cissp for the CISSP and comptia security for Security+. An ad can contain both. The method is on our methodology page.
| Country | Security-analyst ads | Containing cissp |
Containing comptia security |
|---|---|---|---|
| United States | 8,110 | 338 | 112 |
| United Kingdom | 235 | 29 | 12 |
| India | 250 | 45 | 8 |
Source: Adzuna API, security-analyst ads collected in October 2026. Analysis: CertWorthIt.
In US security-analyst ads in October 2026 (Adzuna), the share for cissp was 4.2% and the share for comptia security was 1.4%. The UK and Indian counts in the table come from small samples, so a handful of postings can change them noticeably from one month to the next. The other countries we collect gave too few security-analyst ads to report shares.
The two columns are not measured the same way. The phrase cissp is the credential's own abbreviation. The comptia security count is approximate: it misses ads that write only Security+ or Sec+, and it may also catch other CompTIA names that begin the same way, such as SecurityX. Read it as a rough signal, not an exact count.
The counts show how often employers hiring analysts write each name into an ad, not whether they require it: an ad may list a credential as required, as preferred or as one of several options. The counts do not set the order; the experience rule does. We do not count salary by credential, so these figures say how often employers name each one, not what either pays. Our cybersecurity-analyst page shows what else those ads name, and our cybersecurity field page lists every security credential we count.
Show the numbers
| Item | Ads | Share of ads |
|---|---|---|
| SIEM | 415 | 5.1% |
| CISSP | 338 | 4.2% |
| CompTIA | 162 | 2.0% |
| CISM | 134 | 1.7% |
| CompTIA CySA+ | 119 | 1.5% |
| CompTIA Security+ | 112 | 1.4% |
| Splunk | 100 | 1.2% |
| CEH | 81 | 81 of 8,110 |
Does Security+ count toward the CISSP?
Yes, for one year. ISC2 asks for at least five years of cumulative, full-time experience in two or more of the eight CISSP domains, and it lets one approved credential or one relevant degree replace one of those years. CompTIA Security+ is on the approved list, next to CySA+, the CISM and the SSCP.
Only one waiver applies. ISC2 revised the list with effect from April 1, 2026. Its May 2026 update says: "Only one waiver is permitted; a degree and credential cannot be combined to reduce two years of experience." A Security+ holder with a computer science degree still needs four years of work. One poster asked on Reddit whether several waivers add up (r/cissp); under that rule, they do not.
The Associate of ISC2 route. You can take the CISSP exam before you have the experience. After passing, you have nine months to complete the certification application. If the years are not there yet, you choose the Associate of ISC2 route in that application. Associates have six years to earn the five years of experience, pay a $50 annual maintenance fee and earn 15 CPE credits a year. Once the experience is in place, an $85 upgrade payment starts a new three-year CISSP cycle.
Endorsement. To become a CISSP, your application also needs an endorsement: an ISC2-certified professional in good standing endorses you, or ISC2 does so itself with proof of employment.
Security+ has no experience rule. CompTIA recommends Network+ and two years in a security or systems-administrator role, but it does not require either. That is why Security+ fits the start of a security career, and the CISSP fits once you have five years of work. ISC2's rule counts years of qualifying work, not age.
A worked example: an IT-support technician who moves into a security-analyst job and earns Security+ meets the CISSP experience rule after four years of full-time work in two domains, such as security operations and identity and access management. With a relevant degree instead of Security+, the date is the same, and holding both does not bring it forward.
How much do the CISSP and Security+ cost over three years?
Security+ costs $439 on day one and $150 more only if you renew through continuing education; the CISSP costs $749 on day one and $135 every year once you are certified, or $50 a year as an Associate. Over a first three-year cycle that is $589 for Security+ in the US and $1,154 for a certified CISSP in the Americas.
| CompTIA Security+ | CISSP (ISC2) | |
|---|---|---|
| Exam fee | $439 in the US; €323 in CompTIA's Europe store; the UK store lists $439 | $749 in the Americas and Asia Pacific; €719.04 in Europe; £606.69 in the UK |
| Retake option | Voucher with Retake Assurance: $579 (€426 in Europe) | No separate retake price on ISC2's pricing page; retest after 30 test-free days following a first attempt, with longer waits after later ones; up to 4 attempts in 12 months |
| Renewal cycle | 3 years | 3 years |
| Continuing education | 50 CEUs per cycle | 120 CPE credits per cycle, at least 90 in Group A |
| Renewal fee | $150 per cycle, due when you renew through CEUs | $135 annual maintenance fee (AMF) every year |
| Before full certification | Not applicable | $50 a year as an Associate of ISC2, then an $85 upgrade |
Source: CompTIA Security+ V7 page, CompTIA continuing-education fee and CEU pages; ISC2 exam pricing, AMF overview, after-your-exam and Associate of ISC2 pages, checked October 3 and 5, 2026.
For Security+, $439 for the voucher plus the $150 continuing-education fee comes to $589 for a first cycle. For the CISSP in the Americas, $749 for the exam plus three years at $135 comes to $1,154. In the UK the CISSP exam is £606.69 and in Europe €719.04, with the same $135 yearly fee. On the Associate route you pay the $749 exam, then $50 a year as an Associate, then the $85 upgrade, after which the $135 yearly fee applies. Courses and books are extra for both.
ISC2 lists no separate retake price. Its rules allow a retest after 30 test-free days following a first attempt, with longer waits after later ones, and up to 4 attempts in 12 months; check them before you budget for the CISSP.
Security+ has a second way to renew. CompTIA renews it when you earn a higher-level CompTIA certification, such as CySA+, PenTest+ or SecurityX, and you then pay no continuing-education fee for Security+. CompTIA also offers renewal through CertMaster CE.
Show the numbers
| Item | Fee |
|---|---|
| CISSP: Fees to get certified: Exam | $749 |
| CISSP: Fees to get certified: Annual fee, $135 a year × 3 years | $405 |
| CompTIA Security+: Fees to get certified: Exam | $439 |
| CompTIA Security+: Fees to get certified: Renewal, every 3 years | $150 |
Is the CISSP harder than Security+?
The CISSP sets the higher bar: it covers eight domains against five, runs 100 to 150 adaptive items in three hours and requires five years of work to hold the title.
The CISSP stops somewhere between 100 and 150 items within three hours, depending on your answers, and needs 700 out of 1,000, according to ISC2's exam outline. Security+ has up to 90 questions in 90 minutes, a mix of multiple-choice and performance-based questions, and needs 750 on a scale of 100 to 900.
On study time, the Reddit posts we collected give a median of three months for the CISSP, from 36 first-person statements, with the middle half between two and four months. Another 10 people gave their CISSP study time in weeks, with a median of three and a half; the two figures differ, and the posts do not explain why. For Security+, 13 people who gave their study time in months reported a median of two months, and 10 who gave it in weeks reported a median of two and a half weeks. These are self-reports from people who chose to post, so they lean toward those who passed, and they are not matched for background. Our CISSP page covers CISSP study resources in more detail.
Security+ vs CISSP: who should take which first?
Security+ first if you are starting out and want a first security job. For the CISSP itself, Security+ saves one of the five years only if you have no relevant degree; with five years in two domains, go to the CISSP.
On a technical path, Security+ comes at the start, while you move from IT support or a degree into a first security job. The CISSP comes once you have five years across at least two of its domains, or four with Security+ or a relevant degree. If you hold a degree, Security+ still helps you get hired, but it does not bring the CISSP closer. Our cybersecurity roadmap sets out the wider sequence.
For US defense work, both credentials appear in the Department of Defense's cyber workforce rules under DoDM 8140.03. ISC2 states that the CISSP is approved under DoDM 8140.03, and CompTIA's framework page lists Security+ as approved for 20 work roles, including cyber defense analyst. Approval is set per work role, so find the work role in the job posting and check which credentials it lists before choosing.
For the choice between Security+ and networking, read CCNA vs Security+. Whether A+ or Network+ should come before Security+ is covered on our Security+ page. For a mid-level step between the two, compare CISSP vs CySA+ and CISSP vs SSCP. If you already hold the CISSP, our CISM vs CISSP comparison covers the management route and our CEH vs CISSP comparison covers hands-on testing.
Security+ V8: launch expected November 17, 2026
CompTIA expects to launch Security+ V8 (SY0-801) on or around November 17, 2026. CompTIA's V8 page lists up to 90 questions in 90 minutes with 750 to pass, in English. The current exam, SY0-701, retires in English on June 11, 2027, and in Japanese, Portuguese, Spanish and Thai on August 13, 2027. The domain weights and the $439 voucher price on this page describe SY0-701; check the V8 page before you buy. The CISSP outline in force has been effective since April 15, 2024.
Sources
- CompTIA: Security+ V7 page, Security+ V8 page, Europe store page, earning CEUs, continuing-education renewal fees, continuing-education FAQ, framework alignment (DoD 8140), what is Security+. Read October 3 and 5, 2026.
- ISC2: CISSP page, experience requirements, waiver update, May 2026, exam outline (effective April 15, 2024), exam pricing, after your exam (retakes), AMF overview, Associate of ISC2, endorsement, member policies (CPE). Read October 3 and 5, 2026.
- Job ads: Adzuna API, October 2026, security-analyst ads in ten countries; phrases
cisspandcomptia security. Analysis: CertWorthIt. Method. - Reddit: posts collected from r/cissp, linked where cited; no usernames.
Edited by Elena Marsh · Data checked October 5, 2026
Questions people ask
Can I take the CISSP with only Security+?
You can take the exam, but Security+ alone does not make you a CISSP. ISC2 asks for five years of cumulative, full-time work in at least two of the eight CISSP domains, and CompTIA Security+ counts for one of those years, so a Security+ holder still needs four years of work. Pass the CISSP exam before you have the years, and you can choose the Associate of ISC2 route in your certification application. Associates pay $50 a year, earn 15 CPE credits a year and have six years to gain the five years of experience.
Does Security+ count toward the CISSP?
Yes, for one year. CompTIA Security+ is on ISC2's list of approved credentials that can replace one of the five years of experience the CISSP requires. ISC2 allows only one waiver, and a degree and a credential cannot be combined, so Security+ shortens nothing if you already use a relevant bachelor's or master's degree for that year. ISC2 revised the list on April 1, 2026, and Security+ stayed on it.
Is Security+ enough, or do I need the CISSP?
For a first security job, Security+ is the one you can earn now: CompTIA sets no experience requirement, while the CISSP needs five years of work in its domains. The CISSP becomes the next step once your years are in place. Our US ad counts for both credentials are in the job-ads section of this page.
Is the CISSP harder than Security+?
The CISSP sets the higher bar. It is adaptive, with 100 to 150 items in three hours and a passing score of 700 out of 1,000, and you need five years of experience to hold the title. CompTIA Security+ has up to 90 multiple-choice and performance-based questions in 90 minutes, with 750 on a scale of 100 to 900 to pass, and no experience rule. In the Reddit posts we collected, people who stated a CISSP study time in months reported a median of three months (36 statements); for Security+, the median was two months (13 statements). These are not hours of study and not matched for background, so they do not rank the exams.
Which costs more over three years, the CISSP or Security+?
The CISSP. In the Americas, its exam costs $749 and ISC2 charges a $135 annual maintenance fee every year once you are certified, so a first three-year cycle comes to $1,154. In the US, the CompTIA Security+ voucher costs $439, and renewing through continuing education costs $150 at the end of the three-year cycle, $589 in total. Prices are from the ISC2 and CompTIA pages we read on October 3, 2026; courses and books are extra.
CompTIA Security+ vs CISSP: should I take Security+ first?
Yes, if you are starting out or want a first security job: Security+ has no experience requirement. For the CISSP itself, ISC2 accepts Security+ for one of the five years of experience, unless you already use a relevant degree for that year. With five years of full-time work in two or more CISSP domains, you can go straight to the CISSP, which costs $749 in the Americas; Security+ would not shorten anything.