Cybersecurity certification roadmap: four stages, checked against 8,110 US job ads
Start the cyber security certification roadmap with CompTIA Security+, add CySA+ or the CEH once you meet their experience or training rule, and leave the CISSP or CISM until you have five years of experience. Of the 8,110 US "security analyst" ads we counted in October 2026 (Adzuna), at least 112 named Security+ and 338 named the CISSP.
The CEH needs official training or two years in security; CompTIA recommends about four years of analyst work for CySA+. CySA+ is CompTIA's Cybersecurity Analyst+, the CEH is the Certified Ethical Hacker, the CISSP is the Certified Information Systems Security Professional and the CISM is the Certified Information Security Manager. Adzuna is a job-ad search site.
The roadmap follows the vendors' own entry rules. Two cautions go with the counts. The Security+ figure is a minimum, because we searched comptia security and an ad that writes only "Security+" without the vendor name is missed. Second, an ad that names the CISSP asks for, or prefers, a credential that itself needs five years of work (you can pass the exam earlier; see the section on the CISSP and CISM). The count does not show whether an employer requires the certification or only prefers it.
Where to start:
- If you are new to IT: book Security+ first. Add A+ or Network+ only if IT and networking basics are unfamiliar, because none of the three requires another. The comparison of the first steps has the detail.
- IT support staff can book Security+ now, since CompTIA recommends but does not require experience. System administrators with two years in the role already have the background CompTIA recommends: two years as a security or systems administrator.
- Anyone already studying for Security+ should know that CompTIA expects a new version (V8) on or around November 17, 2026. Check which version your book or course covers before you buy a voucher; the V8 section has the dates.
On this page:
- The stages and their entry rules: the right order
- Ad counts for each step in four countries: how often ads name each step
- What the paths cost: cost of each path
- Routes for SOC, penetration testing, system administration and management: roadmap by job
- Questions from Reddit, answered: what posters ask
Which certificates do employers name for your job?
Instant answer from October 2026 job ads. No email needed.
Certificates named
Skills asked for
Source: Adzuna job ads, October 2026.
On this page
- What is the right order of cybersecurity certifications?
- How often do job ads name each step on the roadmap?
- Which certification comes first: A+, Network+ or Security+?
- What does the main path cost?
- Which certification comes after Security+, and where does the Google course fit?
- Certification roadmap by job
- When do the CISSP and CISM make sense?
- Do you need every certification on the roadmap?
- Is 40 too late for cybersecurity?
- Can you make $500,000 a year in cybersecurity?
- What Reddit posters ask about the order
- Sources
What is the right order of cybersecurity certifications?
The order follows the vendors' own entry rules: exams with no requirement first, exams that recommend or require two to four years of security work next, and the two credentials that require five years last. Four stages cover the certifications we compare, with stages 3 and 4 split by direction.
Terms used in this guide:
- CompTIA, ISC2, ISACA and EC-Council are the four bodies that run these exams.
- The OSCP is OffSec's Offensive Security Certified Professional.
- A proctored exam is one taken under supervision, at a test center or online with a webcam. A voucher is the prepaid code you buy to book the exam.
- Except for OffSec's original OSCP, which does not expire, every exam-based certification in this guide expires unless you pay a renewal fee and log continuing education; the newer OSCP+ expires after three years.
- CompTIA counts that education in CEUs (continuing education units), ISC2 and ISACA in CPE (continuing professional education) credits, and EC-Council in ECE credits.
- A SOC (security operations center) is the team that watches an organization's systems for attacks.
- SY0-701 is the exam code of the current Security+ version, V7.
| Stage | Certification | Exam fee (US) | Entry rule set by the vendor | To keep it |
|---|---|---|---|---|
| Stage 1: groundwork, optional | CompTIA A+ (two exams) | $274 per exam | No requirement; CompTIA recommends 12 months in IT support | Renewed by Security+ |
| Stage 1: groundwork, optional | CompTIA Network+ | $399 | No requirement; CompTIA recommends A+ and 9 to 12 months of network work | Renewed by Security+ |
| Stage 1: groundwork, optional | ISC2 Certified in Cybersecurity (CC) | $199 | No requirement | $50 a year and 45 CPE credits per three years |
| Stage 1: groundwork, optional | Google Cybersecurity Certificate (course, no exam) | $49 a month on Coursera | No requirement | None stated |
| Stage 2: entry exam | CompTIA Security+ (SY0-701, version V7) | $439 | No requirement; CompTIA recommends Network+ and two years as a security or systems administrator | $150 and 50 CEUs per three years |
| Stage 3: mid-level, defense | CompTIA CySA+ (CS0-004) | $439 | No requirement; CompTIA recommends about four years as a SOC or vulnerability analyst | $150 and 60 CEUs per three years |
| Stage 3: mid-level, offense | CEH (EC-Council) | $950 online, $1,199 at a test center | Official training, or two years in information security plus a $100 application fee | $80 a year and 120 ECE credits per three years |
| Stage 3: mid-level, offense | OSCP (OffSec) | $1,699 for the exam alone | No formal prerequisite stated; OffSec recommends networking, Windows and Linux administration and basic scripting | The newer OSCP+ expires after three years; the original OSCP does not; we did not verify which one a new pass earns |
| Stage 4: senior | CISSP (ISC2) | $749 | Five years in at least two of eight domains (the subject areas of its exam outline) | $135 a year and 120 CPE credits per three years |
| Stage 4: management | CISM (ISACA) | $760, or $575 for ISACA members, plus a $50 application fee | Five years of security management within the 10 years before you apply | $85 a year ($45 for members) and 120 CPE credits per three years |
Source: vendor pages listed under Sources, checked October 6, 2026.
Stage 1 is optional because no stage-2 exam requires it. A+ and Network+ cover IT and networking basics, the CC is ISC2's entry exam at $199, and the Google course is nine online courses with no exam at the end. Stage 2 is the first exam we suggest paying for: it has no entry requirement, and CompTIA's own blog, a vendor describing its own exam, calls it the first security certification IT professionals should earn. Stage 3 splits by direction. Stage 4 waits for the years of work its vendors demand; you can pass the CISSP exam earlier and become an Associate of ISC2 while you earn the years, as the section on the CISSP and CISM explains.
On study time, people who wrote about these exams in the Reddit posts we collected report a median of two months for Security+ (13 reports) and three months for the CISSP (36 reports). They are people who chose to post, so read these medians as a rough guide. The long wait on this roadmap is the five years of work, not the study.
How often do job ads name each step on the roadmap?
In October 2026, Adzuna's 8,110 US ads with "security analyst" in the title named Security+ in at least 112. They named the CISSP in 338, the CISM in 134 and the CEH in 81. The Google Cybersecurity Certificate appeared in none of the 8,110 ads.
We searched Adzuna for ads with the title security analyst (in Brazil, analista de segurança) in October 2026 and counted those that contain each certification by an exact phrase. The phrases were comptia security, ceh, cissp, cism and google cybersecurity.
| Security-analyst ads, October 2026 | US | UK | India | Brazil |
|---|---|---|---|---|
| Ads counted | 8,110 | 235 | 250 | 434 |
Stage 1: Google Cybersecurity (google cybersecurity) |
0 | 0 | 0 | 0 |
Stage 2: Security+ (comptia security, a minimum) |
112 | 12 | 8 | 2 |
Stage 3: CEH (ceh) |
81 | 4 | 17 | 3 |
Stage 4: CISSP (cissp) |
338 | 29 | 45 | 4 |
Stage 4: CISM (cism) |
134 | 11 | 29 | 1 |
| A+, Network+, CC, CySA+, OSCP | Not counted | Not counted | Not counted | Not counted |
Source: Adzuna API, security-analyst job ads collected in October 2026, matched by exact phrase; each cell is the number of ads that contain the phrase. Analysis: CertWorthIt. How we count.
Read a row to follow one certification across four markets, or a column to see one market. Three limits apply to every cell:
- Security+ is searched as
comptia security, so an ad that writes only "Security+" without the vendor name is missed and that row is a minimum. - CompTIA CySA+ and OffSec's OSCP have no row because we did not count them for this role; the missing rows are not evidence of low demand.
- A zero in any cell means the exact phrase was not found in that sample; employers may describe a certification in other words. Each cell records whether an ad names a certification, not whether the employer requires it or only prefers it.
The UK, India and Brazil samples are small: 235, 250 and 434 ads. In samples that size, one ad more or less can change the picture, so treat those columns as signs of what employers there write, not as stable rates. Brazilian ads are written in Portuguese, but the certification names are the same, so we searched the same phrases. Mexico, Spain, France, Germany, Italy and Poland are left out: their security-analyst samples are small, and we publish no per-certification figure for them.
The full analyst picture, including skills such as SIEM (security information and event management, software that collects logs and raises alerts), is on our cybersecurity-analyst page. This page uses the counts for one question only: which step of the roadmap shows up in the ads.
Which certification comes first: A+, Network+ or Security+?
Security+ comes first if you will pay for one exam. CompTIA recommends A+ before Network+ and Network+ before Security+, but none of the three requires another, and CompTIA's own blog calls Security+ the first security certification IT professionals should earn.
The groundwork exams earn their place when the material is new to you. CompTIA's Security+ V7 page recommends Network+ and two years as a security or systems administrator. Its page for the next version, Security+ V8, recommends two years of hands-on work as a security administrator and does not name Network+. Because no exam requires another, our view is that you can go straight to Security+ if you work in IT support and already know ports, subnets and protocols. If you do not, CompTIA's V7 page is the one that recommends Network+ first. Our A+ vs Security+ comparison sets those two exams side by side.
The Security+ exam has up to 90 questions in 90 minutes, a mix of multiple-choice and performance-based items (hands-on tasks in a simulated system). Our Security+ page covers the passing score and preparation.
A degree changes the timing, not the order. ISC2 lets a degree or an approved credential, Security+ among them, count for one of the five CISSP years. That credit is called a waiver, and only one waiver is allowed, so holding both does not save two years.
Should you wait for Security+ V8?
Nothing forces you to wait. CompTIA expects Security+ V8 (exam SY0-801) on or around November 17, 2026, and the English version of the current exam, SY0-701, retires on June 11, 2027, so by CompTIA's dates you can take SY0-701 until June 11, 2027. CompTIA's V8 page lists no price yet; the $439 in this guide is the fee for SY0-701. Before buying a voucher, check which version your study material covers.
What does the main path cost?
Security+ alone costs $589 over a first three-year cycle (exam $439, CompTIA renewal $150). The main path here (Security+, then CySA+, then the CISSP) costs $2,182 in exam fees plus first-cycle renewal fees. A path that lasts five years or more adds another CompTIA renewal ($150) for each further three years, and that is not in this figure. Only exam and renewal fees from the vendors' US pages are counted; courses, books and practice tests are left out.
| Path | Exam fees | Renewal in the first three years | Total |
|---|---|---|---|
| Security+ only | $439 | $150 CompTIA fee | $589 |
| Full CompTIA groundwork: A+ (two exams at $274), Network+ ($399), Security+ ($439) | $1,386 | $150 CompTIA fee (Security+ renews A+ and Network+) | $1,536 |
| Security+, then CySA+ | $439 + $439 = $878 | $150 CompTIA fee (CySA+ renews Security+), if you pass CySA+ within three years of Security+; later, add one more $150 cycle | $1,028 |
| CISSP after five years | $749 | $135 a year for three years ($405) | $1,154 |
| Security+, CySA+ and CISSP | $439 + $439 + $749 = $1,627 | $150 + $405 = $555 | $2,182 |
| CEH, online exam | $950 | $100 application fee on the experience route, plus $80 a year for three years ($240) | $1,290; official training, the other route, is not included and we did not verify its price |
| CISM, non-member | $760 | $50 application fee, plus $85 a year for three years ($255) | $1,065 (for ISACA members $575 + $50 + $135 = $760, before ISACA membership dues, which we did not verify) |
| Google Cybersecurity Certificate | None | 6 months at $49 a month, the pace the Coursera page estimates | $294, an estimate at that pace |
| OSCP | $1,699 for the exam alone | We did not verify the renewal fee for the OSCP+ | $1,699 before any renewal |
Source: CompTIA, ISC2, ISACA, EC-Council, OffSec and Coursera fee pages, checked October 6, 2026; sums by CertWorthIt.
The CompTIA renewal works in your favor. CompTIA's renewal rules say that renewing CySA+ also renews Security+, Network+ and A+, and that renewing Security+ also renews Network+ and A+. The ladder of certifications therefore costs one $150 fee per cycle, plus 50 CEUs for Security+, 60 for CySA+ or one CertMaster CE course (CompTIA's own renewal course). A Security+ voucher with Retake Assurance, which includes a second attempt if you fail, costs $579.
The optional six-hour CEH practical exam, which together with the knowledge exam earns the CEH Master title, adds $550. For the OSCP, OffSec also sells 90 days of the PEN-200 course with one exam attempt for $1,749. Its $2,749 option gives a year of course access with two attempts.
Which certification comes after Security+, and where does the Google course fit?
After Security+, choose by the work you do. On the defensive side the next step is CompTIA CySA+; on the offensive side it is the CEH or the OSCP. The Google course is a stage-1 option, so it fits before Security+ rather than after it.
CompTIA CySA+. The current exam, CS0-004, launched on June 23, 2026: up to 85 questions in 165 minutes, with a passing score of 750 on the same 100-to-900 scale as Security+, for $439. CompTIA lists about four years as a SOC or vulnerability analyst as recommended experience, not as a requirement. The previous version, CS0-003, retires in English on December 22, 2026, so check which version your study material covers. CompTIA's framework-alignment page lists both CySA+ and Security+ as approved for the Cyber Defense Analyst role under the US Department of Defense (DoD) 8140 rules, which list the certifications that qualify staff for each DoD cyber job.
CEH (Certified Ethical Hacker). The knowledge exam has 125 multiple-choice questions in four hours. EC-Council requires official training, or two years in information security plus an application. The CEH appeared in 81 of the 8,110 US security-analyst ads in October 2026 (Adzuna). EC-Council states that the exam is approved under DoD 8140. Our CEH page covers its cost and renewal in full.
Google Cybersecurity Certificate. It has nine courses on Coursera, about six months at seven hours a week by the Coursera page's estimate, and teaches Python, Linux, SQL, SIEM tools (Chronicle and Splunk) and an intrusion detection system (Suricata). Coursera says the course helps prepare for Security+ and gives a discount on the exam. The phrase google cybersecurity appeared in none of the 8,110 US security-analyst ads in October 2026 (Adzuna). That count shows only whether ads use that exact phrase, not whether employers value the course. We have no pay data by certificate, so we cannot say which course leads to a better-paid job. Our Google Cybersecurity page has the details.
Certification roadmap by job
SOC analysts and system administrators start with Security+, penetration testers can skip the CompTIA ladder if they have the background the CEH or the OSCP assumes, and governance routes aim at the CISM. These routes use only vendor entry rules; our ad counts cover security-analyst ads only, so they say nothing about the other three titles, and we did not count help-desk or entry-level SOC titles.
SOC analyst certification roadmap
A SOC analyst monitors alerts and investigates incidents. Take Security+ first, get hands-on practice with a SIEM next, then take CySA+ once you have SOC experience; CompTIA's recommendation of about four years in that work is guidance, not a gate, so CySA+ is optional if you are job-hunting now. The Google course fits before Security+ if you want lessons first. Our SOC-analyst page shows what SOC-analyst ads name.
Penetration tester certification roadmap
A penetration tester attacks systems with permission to find weaknesses. Skip the CompTIA ladder only if you already have the background these exams assume: for the CEH, official training or two years in information security; for the OSCP, the skills OffSec recommends. If you lack that background, Security+ is the cheaper way in, and it is optional on this route. The OSCP has no formal prerequisite; OffSec recommends TCP/IP networking (the protocols that carry internet traffic), Windows and Linux administration and basic scripting in Bash (a Linux command-line language) or Python, and Security+ is not on that list. Neither vendor names the other's exam, or Security+, as a prerequisite, so the vendors set no order between the CEH and the OSCP. The OSCP exam is a 24-hour proctored (supervised) practical test. Take Security+ on this route if you want the $439 entry exam; CompTIA's framework-alignment page lists it as approved for the Cyber Defense Analyst role under DoD 8140, and we did not check which certifications DoD accepts for penetration-testing roles. Our penetration-tester page and CEH vs OSCP comparison go further.
System administrator certification roadmap
A system administrator already has the background CompTIA's Security+ V7 page recommends, two years as a security or systems administrator, so Security+ is the first exam on this route. Network+ is optional if networking basics are thin, and CompTIA's V8 page no longer names it. Our system-administrator page covers what admin ads ask for.
Governance, risk and management roadmap
Governance, risk and compliance (GRC) is the policy and audit side of security. The entry step is the same: Security+ or the CC. The destination is the CISM, which ISACA grants after five years of information security management; ISACA allows experience waivers of up to two of those years, and we did not verify which degrees or credentials qualify. You can take the CISM exam first and apply within five years of passing. The CISM asks specifically for security management work. The CISSP asks for five years in any two of its eight domains (subject areas), so it also fits this route; our CISM vs CISSP comparison explains how to order the two. This route is not exhaustive: we did not cover ISACA's audit and risk credentials.
When do the CISSP and CISM make sense?
Both make sense once you are close to five years of qualifying work, not before. The CISSP needs five years of full-time work in at least two of its eight domains; the CISM needs five years of security management within the 10 years before you apply.
ISC2 offers a way to take the exam early. If you pass the CISSP without the experience, you become an Associate of ISC2 and have six years to earn the five years. Keeping that status costs $50 a year and 15 CPE credits a year; upgrading to the full CISSP costs an $85 difference and starts a new three-year cycle. Part-time work of 20 to 34 hours a week counts pro rata (in proportion to the hours), and paid or unpaid internships count with a letter on company letterhead.
ISACA sets its deadline from the exam date too, but a longer one: you can apply for the CISM within five years of passing the exam. ISACA says an updated CISM exam content outline, the list of topics the exam tests, takes effect on November 3, 2026, so check which outline your study material follows.
An active CISSP also counts for the entire experience requirement of the CCSP, ISC2's cloud security certification, so a CISSP holder needs no further years for that branch. Our CISSP page covers the exam itself.
Do you need every certification on the roadmap?
No. The US Bureau of Labor Statistics says employers may prefer analysts with a professional certification; it names no certification as required. The stage-4 credentials in our count require five years of work, so an ad that names one is asking for, or preferring, experience a beginner does not have yet.
For a first job, our view is that one entry exam plus practice you can describe in an interview is a reasonable target; that is our judgment, not a vendor or BLS statement. US government and defense work may differ: CompTIA's framework-alignment page lists approved certifications per role under the DoD 8140 rules, and we did not read DoD's own tables, so check the role's listing. If the missing piece is a degree rather than a certificate, our guide to cybersecurity without a degree covers that route, and the cybersecurity field overview lists every security credential we track.
Is 40 too late for cybersecurity?
No certification rule we checked sets an age limit for starting a cybersecurity career. The requirements are about experience: Security+, the CC and the Google course need none, and the CISSP and CISM need five years. Someone starting at 40 reaches the CISSP experience requirement at the same pace as someone starting at 25.
The BLS lists a bachelor's degree as the typical entry education for information security analysts, plus less than five years of experience in a related occupation. Job ads do not state an age, and we have no data on hiring by age, so we cannot tell you how employers weigh it.
Can you make $500,000 a year in cybersecurity?
No source we found puts a cybersecurity salary at $500,000. The highest figure in our sources is $347,395 to $429,727 a year for a chief information security officer, a Salary.com range that EC-Council quotes. That is an executive role, and no source we have ties it to a certification. The BLS puts the median wage of information security analysts at $129,180 in May 2025.
What Reddit posters ask about the order
Questions asked on r/CompTIA, r/SecurityCareerAdvice, r/ITCareerQuestions, r/cissp, r/oscp and r/coursera, with our answers. Posters are a self-selected group, so these show what people ask, not how many share a view.
- Whether to wait before taking Security+ (r/CompTIA, September 2026): by CompTIA's dates, nothing forces a wait; SY0-701 can be taken until June 11, 2027, and the Security+ V8 section has the details.
- Security+ or the CEH before the OSCP, and which suits someone already practicing on Hack The Box Academy, a website with hacking exercises (r/oscp, October 2025, r/oscp, April 2026, r/SecurityCareerAdvice, September 2026): neither is a prerequisite for the OSCP, which OffSec says needs networking, Windows and Linux administration and scripting skill, and neither exam requires the other. Security+ has no entry rule and costs $439, against $950 for the online CEH exam. The OSCP's 24-hour practical exam tests hands-on attack skills; the CEH's core exam is 125 multiple-choice questions.
- Whether the CEH helps land a first security job (r/SecurityCareerAdvice, August 2026): EC-Council's own rule is two years of information security work or its official training. A beginner with neither the work nor the training does not meet the entry rule yet.
- Security+ or the CCNA (Cisco's networking exam) (r/SecurityCareerAdvice, August 2026): we count the CCNA for network engineers, not security analysts; the network-engineer page has that figure.
- Security+, TryHackMe's SAL1 (a certificate from the TryHackMe practice site) or a GRC credential (r/ITCareerQuestions, September 2026): this page has no job-ad count and no vendor rule for SAL1. For GRC, the governance route sets out the steps.
- Which gap to close next: Python, SIEM (software that collects logs and raises alerts), the CEH or the CISSP (r/SecurityCareerAdvice, September 2026): the CISSP depends on years of work, so it cannot close a gap now; SIEM practice and the stage-3 exam for your direction can.
- What comes after the CISSP, and whether anyone younger than the poster had reached "full CISSP certification status" (r/cissp, May 2026, r/cissp, May 2026): the CCSP for cloud work, where an active CISSP covers the whole experience rule, or the CISM for management. The five-year rule sets the pace, not age, and the Associate route lets you pass the exam first.
- Whether Security+ expires before a degree ends (r/CompTIA, September 2026): Security+ runs on a three-year cycle renewed with 50 CEUs and $150, or one CertMaster CE course, so a student can renew it instead of taking the exam again.
- What to do after the Google course, and whether it is worth it, including in India (r/SecurityCareerAdvice, September 2026, r/coursera, February 2026, r/SecurityCareerAdvice, August 2026): Security+ is the exam Coursera says the course helps prepare for. The phrase
google cybersecurityappeared in none of the 250 Indian security-analyst ads on Adzuna in October 2026; that count does not show whether employers value the course. The course teaches Python, Linux, SQL and SIEM tools.
Study resources, exam strategy and practice-question advice are outside this page; our Security+ page and CISSP page cover preparation.
Sources
- Adzuna job-ad counts, security-analyst ads, October 2026; analysis: CertWorthIt. How we count.
- CompTIA, Security+ V7, Security+ V8, CySA+, A+, Network+, renewal fees, renewing multiple certifications, framework alignment and the blog post on Security+, checked October 6, 2026.
- ISC2, CISSP experience requirements, exam pricing, annual maintenance fees, Associate of ISC2, endorsement, after your exam, CCSP experience and Certified in Cybersecurity, checked October 6, 2026.
- ISACA, CISM, getting CISM certified, CISM exam content outline and maintaining the CISM, checked October 6, 2026.
- EC-Council, CEH eligibility, CEH program page, continuing education fees and ethical hacking salary page, checked October 6, 2026.
- OffSec, PEN-200 and OSCP, checked October 6, 2026.
- Coursera, Google Cybersecurity, checked October 6, 2026.
- US Bureau of Labor Statistics, Occupational Outlook Handbook: Information Security Analysts, read October 6, 2026.
- Reddit threads linked in the text, from the posts we collected.
Edited by Elena Marsh · Data checked October 6, 2026
Questions people ask
What is the best roadmap for cyber security?
Start with CompTIA Security+ ($439 in the US, no experience required). Add CompTIA CySA+ or the CEH once you meet their experience or training rule. CompTIA recommends about four years as a SOC or vulnerability analyst for CySA+. EC-Council asks for two years in information security, or its official training, for the CEH. Leave the CISSP or CISM until you have the five years of experience both require. A+ and Network+ are optional groundwork before Security+. In October 2026, CompTIA Security+ (searched as "comptia security") appeared in at least 112 and the CISSP in 338 of the 8,110 US security-analyst ads we counted on Adzuna.
Can you make $500,000 a year in cyber security?
We found no source that puts a cybersecurity salary at $500,000. The highest figure we found is $347,395 to $429,727 a year for a chief information security officer, a Salary.com range quoted by EC-Council; it describes an executive job, not a certification outcome.
Is 40 too late for cyber security?
No age limit for starting a cybersecurity career appears in any certification rule we checked, and we found no data on hiring by age. Experience is the gate: the CISSP and CISM ask for five years of work whatever your age, while CompTIA Security+ and ISC2 Certified in Cybersecurity need none.
Should I take Security+ or the CEH first?
Take CompTIA Security+ first. It costs $439 and has no entry requirement, while EC-Council lets you take the CEH exam ($950 online) only after its official training or with two years of information security work plus a $100 application fee. In October 2026, the CEH appeared in 81 of the 8,110 US security-analyst ads we counted on Adzuna, and Security+ (searched as "comptia security") in at least 112.
How long does the cybersecurity certification roadmap take?
The exams are the short part. People who wrote about Security+ in the Reddit posts we collected report a median of two months of study (13 reports), and for the CISSP a median of three months (36 reports). The long part is experience: ISC2 asks for five years before you can hold the CISSP, or four with a degree or an approved credential such as Security+, and ISACA asks for five years of security management for the CISM.