Cybersecurity analyst certifications: what 8,110 US job ads name

Job-ad data: October 2026 · Editor: · Updated

Cybersecurity analyst certifications appear in a minority of job ads, and none of them works as a ticket to a first job. Of the 8,110 US security-analyst ads we counted in October 2026 (Adzuna), the CISSP appeared in 4.2%, the CISM in 1.7% and CompTIA Security+ in at least 1.4%. The Google Cybersecurity Certificate appeared in none of the 8,110 ads. SIEM (security information and event management), a tool category used in security operations center (SOC) work, appeared in 5.1% of the ads. Our verdict for beginners: Security+ is the first exam worth paying for ($439 in the US, no experience required), together with hands-on SIEM practice. The CISSP and CISM require five years of experience, so they come later.

What do cybersecurity analyst job ads ask for?

Instant answer from October 2026 job ads. No email needed.

Country

Certificates named

  1. CISSP4.2%
  2. CompTIA2.0%
  3. CISM1.7%
  4. CompTIA CySA+1.5%
  5. CompTIA Security+1.4%

Skills asked for

  1. SIEM5.1%
  2. Splunk1.2%

Source: Adzuna job ads, October 2026.

What cybersecurity analyst job ads name in the United States: certifications and skills
Employers name SIEM in 5.1% of these ads and CISSP in 4.2%.
Show the numbers
What cybersecurity analyst job ads name in the United States: certifications and skills. Share of job ads that name each item. Source: Adzuna job ads, October 2026.
ItemAdsShare of ads
SIEM4155.1%
CISSP3384.2%
CompTIA1622.0%
CISM1341.7%
CompTIA CySA+1191.5%
CompTIA Security+1121.4%
Splunk1001.2%
CEH8181 of 8,110
On this page
  1. Which certifications do cybersecurity-analyst ads name, by country?
  2. Which skills do security-analyst ads ask for?
  3. Which certification is best for a cybersecurity analyst?
  4. Entry-level cybersecurity certifications for beginners
  5. CISSP, CISM, CySA+ and CEH: certifications for later in your career
  6. Is a cybersecurity certificate worth it?
  7. What is the salary of a cybersecurity analyst?
  8. Do you need a certification to be a cybersecurity analyst?
  9. Best certifications for cybersecurity analysts: what Reddit posters ask
  10. Related roles and where to go next
  11. Sources

Which certifications do cybersecurity-analyst ads name, by country?

We searched one month of Adzuna job ads for the title security analyst (in Brazil analista de segurança, in Mexico and Spain analista de ciberseguridad, in France analyste cybersécurité, in Poland analityk bezpieczeństwa). Then we counted the ads that contain each certificate or skill by its exact name. Four countries returned enough ads for a table.

Country Security-analyst ads CISSP CISM Security+ (minimum) CEH Google Cybersecurity SIEM Splunk
US 8,110 338 134 112 81 0 5.1% 1.2%
UK 235 29 11 12 4 0 25% 5%
India 250 45 29 8 17 0 20% 6%
Brazil 434 4 1 2 3 0 2% 0 of 434

Source: Adzuna API, security-analyst job ads collected in October 2026, matched by exact phrase. Certificate columns give the number of ads that name the certificate; skill columns give the share of all ads for the role. Analysis: CertWorthIt. How we count.

In the US, each certificate we track is named in a small minority of ads. The CISSP appeared in 4.2% of the ads, the CISM in 1.7%. Both are credentials for experienced staff. Of the two certificates that require no experience, Security+ appeared in at least 112 of the 8,110 US ads and the Google certificate in none of the 8,110. Our reading: when a US security-analyst ad names a certificate, it is often one that a beginner cannot hold yet.

The UK sample is much smaller, 235 ads, so each ad carries a lot of weight in the shares. The CISSP appeared in 12% of the ads for UK security analysts and Security+ in at least 5%. SIEM appeared in 25% of the ads.

India's sample is also small (250 ads). In Indian ads, the CISSP appeared in 18%, the CISM in 12% and the CEH in 7%. Security+ appeared in at least 3%. Read these as signs of what some Indian employers write into ads, not as precise rates.

In Brazil, the CISSP appeared in 4 of the 434 ads for analista de segurança, and SIEM in 2% of the ads. For the other six countries we report only the ad totals for October 2026, because a handful of ads cannot carry a share. The totals were 72 ads in Germany, 59 in France, 21 in Italy, 12 in Mexico, 7 in Spain and 4 in Poland.

What the count misses: we match exact names. Security+ is searched as comptia security, so an ad that writes only "Security+" is not counted, and its figure is a minimum. An ad asking for "a recognized security certification" without naming one is not counted either. Our data also does not separate ads that require a credential from ads that only prefer one. The figures show how often employers name a credential in the ad text. They do not show how a recruiter weighs one on a resume.

Certifications in cybersecurity analyst job ads, by country
CISSP reaches its highest share in India (18%).
Show the numbers
Certifications in cybersecurity analyst job ads, by country. Share of job ads that name each item. Source: Adzuna job ads, October 2026.
ItemUnited StatesUnited KingdomIndiaBrazil
CISSP4.2%12%18%4 ads
CompTIA2.0%10%6%0 ads
CISM1.7%5%12%1 ad
CompTIA CySA+1.5%4%4%0 ads
CompTIA Security+1.4%5%3%2 ads
CEH81 ads2%7%3 ads
CompTIA SecurityX (CASP+)48 ads1 ad2 ads0 ads
SSCP46 ads2%1%0 ads

Which skills do security-analyst ads ask for?

We track two skills for this role: SIEM, and the product name Splunk. In US ads, SIEM appeared in 5.1% of the ads and Splunk in 1.2%. In India, the two figures are 20% and 6%; in the UK, 25% and 5%.

Other SOC skills, such as incident response, log analysis or network traffic analysis, are not on our list for this role. We have no share for them and will not estimate one. An ad can also describe that work in its own words without naming a tool, and our phrase count would miss it.

For a beginner, this changes where the hours go. A certificate exam tests what you know. A SIEM is something you learn by using it: collecting logs, writing a search and explaining an alert. If the ads you plan to answer name SIEM or Splunk, a small home lab you can describe in an interview gives a recruiter something no certificate shows. To check your own market, read 20 ads for the job title you want in your city and note every tool and credential they repeat.

Which certification is best for a cybersecurity analyst?

No single certification is best for every cybersecurity analyst. The right one depends on how much experience you have, because the credentials named most in our count require years of work before you can hold them. The table sorts the common options by the stage at which each makes sense.

Your situation Credential to consider Why
No IT background, need structured lessons Google Cybersecurity or IBM Cybersecurity Analyst Beginner course certificates on Coursera, no exam, no experience needed
Want a low-cost first exam ISC2 Certified in Cybersecurity (CC) $199, no work experience required
Ready for the entry exam employers name CompTIA Security+ $439, no requirement; counted in US, UK and Indian ads
Several years in a SOC CompTIA CySA+ CompTIA recommends about four years as a SOC or vulnerability analyst
Five years in security CISSP ISC2 requires five years in at least two of eight domains
Moving into security management CISM ISACA requires five years of security management work
An employer or contract names it CEH US Department of Defense 8140 approved, per EC-Council

Source: vendor pages listed in the Sources section, checked October 3 and 4, 2026.

Judged by our ad data, the best certification for a cybersecurity beginner is Security+: it is the entry exam that shows up in the counts, and it has no prerequisite. Which cybersecurity certification is best after that depends on direction. Analysts who stay in operations can move to CySA+; those heading toward architecture or management aim for the CISSP or the CISM once they have the years.

For a cybersecurity engineer, our count gives no answer: it covers analyst ads only. We cannot say which credential engineering ads name, so we do not rank certifications for that title.

Entry-level cybersecurity certifications for beginners

An entry-level cybersecurity analyst certification should require no experience and teach what the ads ask for. Five credentials meet the first condition. Three are proctored exams, and two are course certificates with no exam.

Credential Type Price (US) Format or length Experience Renewal
ISC2 Certified in Cybersecurity (CC) Exam $199 100 to 125 questions in 2 hours, Pearson test center None $50 a year and 45 CPE credits per 3 years
CompTIA Security+ (SY0-701) Exam $439 Up to 90 questions in 90 minutes, multiple-choice and performance-based None required; Network+ and two years in a security or systems administrator job recommended $150 and 50 CEUs per 3 years
CompTIA Network+ (N10-009) Exam $399 Up to 90 questions in 90 minutes None required; A+ and 9 to 12 months of network work recommended $150 and 30 CEUs per 3 years
Google Cybersecurity Course certificate, 9 courses $49 a month About 6 months at 7 hours a week None None stated
IBM Cybersecurity Analyst Course certificate, 14 courses Not shown on the program page About 4 months at 10 hours a week Beginner level None stated

Source: ISC2 CC exam outline and CC program page; CompTIA Security+ and Network+; Coursera program pages for Google Cybersecurity and IBM Cybersecurity Analyst. Checked October 3, 2026.

For a beginner, the order matters more than the brand. CompTIA recommends Network+ and two years of experience before Security+, but neither is required. If networking terms such as subnets and ports are new to you, a networking course first will make the Security+ material easier. A course certificate fits when you want lessons with a schedule before you pay for an exam.

ISC2's CC exam used to be free under its One Million Certified in Cybersecurity program. ISC2 closed new enrollments on May 20, 2026; people who already hold an unexpired exam code can still take it free until December 31, 2026. Other candidates pay $199. We do not count the CC in job ads, so we cannot tell you how often employers name it.

How much does a Security+ cert cost?

The Security+ voucher costs $439 on CompTIA's US store; the UK store charges the same amount in US dollars, and the Europe store lists €323. A version with Retake Assurance costs $579. To keep it, you pay $150 per three-year cycle and earn 50 continuing education units, or complete one CertMaster CE course instead. The current exam is SY0-701. CompTIA expects its successor, SY0-801, around November 17, 2026, and the English SY0-701 exam retires on June 11, 2027.

People who posted about their preparation on Reddit report a median of two months of study (13 reports, middle half one to four months). That is a self-selected group of people who passed and chose to post, so read it as a rough guide.

Is the Google Cybersecurity Certificate worth it?

As a structured introduction, it can be; as a line employers search for, not in our data. The certificate appeared in none of the 8,110 US security-analyst ads, none of the 235 UK ads and none of the 250 ads in India in October 2026. It is a course certificate with nine courses and no proctored exam.

At $49 a month and Google's estimate of six months at seven hours a week, it costs about $294; finish faster and you pay less. It carries an American Council on Education recommendation of up to nine college credits, and Google says over 150 US employers in its consortium consider people who hold it. Whether a college accepts the credits, or an employer interviews you, is their decision. If you want both lessons and an exam, the course can come first and Security+ second. Our Security+ vs Google Cybersecurity comparison sets the two side by side.

Entry-level cybersecurity certifications in the UK

In the UK, Security+ appeared in 5% of the ads for security analysts in October 2026. The CEH appeared in 4 of the 235 UK ads. CompTIA's UK site prices the Security+ voucher in US dollars ($439), so the cost in pounds depends on the exchange rate on the day you buy. For a UK beginner who pays for one exam, Security+ is the entry credential our UK count can measure.

Best certification for cybersecurity in India

The certificates Indian ads name in our count are mostly ones for experienced staff. The CISSP appeared in 18% of the ads for Indian security analysts, the CEH in 7% and Security+ in at least 3%. One poster asked whether Google Cybersecurity, Security+ or eJPT are worth it in India (r/SecurityCareerAdvice, August 2026). Our answer: none of the three needs experience, but only Security+ is in our India count. The CISSP figure describes jobs for people with five years in security. A beginner in India who pays for one exam gets the most from Security+, priced at $439 in US dollars because CompTIA has no regional site for India. The CEH makes sense there only if an employer or college pays for its training.

CISSP, CISM, CySA+ and CEH: certifications for later in your career

These four come after a first job. Each states an experience requirement or recommendation that a beginner cannot meet.

CISSP (ISC2). The exam costs $749 in the Americas and Asia Pacific and has 100 to 150 questions in three hours, adaptive (the questions adjust to your answers). To hold the CISSP, you need five years of full-time work in at least two of its eight domains; a degree or an approved credential can count for one of those years. Without the experience, you can pass the exam and become an Associate of ISC2, then earn the experience within six years. Keeping it costs $135 a year and 120 CPE credits per three years. A poster who became a fully endorsed CISSP at 23 asked, in a thread with 49 points in r/cissp, whether anyone younger had reached "full CISSP certification status" rather than Associate status (r/cissp, May 2026). The question comes from the five-year rule. People who posted about their study time report a median of three months (36 reports, middle half two to four months).

CISM (ISACA). The exam costs $760, or $575 for ISACA members, plus a $50 application fee, and has 150 questions. To be certified, you need five years of information security management experience within the 10 years before you apply. ISACA updates the exam content outline on November 3, 2026. Maintenance costs $45 a year for members or $85 for non-members, plus 120 CPE hours per three years. Our CISM page covers its cost, experience rule and renewal in full. If you are choosing between the CISM and the CISSP, our CISM vs CISSP comparison covers how their experience waivers interact and which to take first.

CompTIA CySA+. The current exam, CS0-004, launched on June 23, 2026: up to 85 questions in 165 minutes, $439. CompTIA recommends about four years as a SOC or vulnerability analyst. It is the closest credential to the analyst job by name, but our count does not include it, so we have no figure for how often ads name it.

CEH (EC-Council). The exam voucher costs $950 online or $1,199 at a test center, plus a $100 eligibility fee if you skip official training, which you can do only with two years of information security work. EC-Council says the CEH is approved under the US Department of Defense 8140 rules. In October 2026, the CEH appeared in 81 of the 8,110 US security-analyst ads and in 17 of the 250 Indian ones. Our CEH page covers its cost, renewal and alternatives in full; for the head-to-head choices, see CEH vs Security+ and CISSP vs CISM.

Is a cybersecurity certificate worth it?

A cybersecurity analyst certification is worth it when it gets you past a stated requirement or makes you learn the job. It is not worth it as a substitute for experience, because the credentials ads name most in our count require that experience first. Security+ at $439 is worth it for most beginners who can explain what they learned. A $49-a-month course is worth it if you need the lessons. A $749 exam you are not yet eligible to hold is not worth paying for until you are close to the experience it requires.

What the CISSP certification costs to get and keep (USD)
The required CISSP fees add up to $749. Keeping CISSP costs $135 a year ($405 over the 3-year cycle).
Show the numbers
What the CISSP certification costs to get and keep (USD). Source: isc2.org, checked October 5, 2026.
ItemFee
Fees to get certified: Exam$749
Fees to get certified: Annual fee, $135 a year × 3 years$405

Can you get a job with a cybersecurity certificate?

On its own, rarely, judging by the ads. In the US, the entry-level credentials appear in few security-analyst ads: Security+ in at least 112 of the 8,110 and the Google certificate in none of the 8,110. The US Bureau of Labor Statistics says information security analysts typically need a bachelor's degree in a computer science field and may need experience in a related occupation. IT support and network jobs are where that related experience can come from; our IT-support page and network-engineer page cover what their ads ask for. A certificate helps most next to that experience or a degree, not instead of them.

What is the salary of a cybersecurity analyst?

The US Bureau of Labor Statistics puts the median annual wage for information security analysts at $129,180 in May 2025, for about 192,900 jobs. That median covers every experience level, so it is not a starting figure.

For starting pay, the closest figures we have come from EC-Council's salary page, which quotes about $60,382 a year for an entry-level security analyst (Indeed) and $65,946 for an entry-level SOC analyst (Salary.com). These are third-party estimates for job titles, quoted by a certification vendor.

There is no reliable starting salary for a cybersecurity certification as such. None of our sources measures what a certificate adds to pay, as distinct from the job title, the location and the years of experience behind it. Pay depends on the role you get; the certificate is one of the things that can help you get it.

Do you need a certification to be a cybersecurity analyst?

No. We found no law or licensing body that requires a certification for the job, and most of the 8,110 US ads we counted named none of the certificates we track. Some employers do ask for one, and the counts in the country section show how many. Government and defense work is the main exception, because there a role can require a credential from an approved list, which is why EC-Council points to the US Department of Defense 8140 rules for the CEH.

If your gap is a degree, not a certificate, our guide to getting into cybersecurity without a degree covers that route.

Best certifications for cybersecurity analysts: what Reddit posters ask

We grouped the questions in the Reddit posts we collected on r/SecurityCareerAdvice, r/CompTIA, r/ccna, r/coursera and r/cissp. Reddit posters are a self-selected group, so these show what people ask, not how many hold a view.

A SOC analyst does the monitoring side of this job full time, and a penetration tester works on the attack side. For every security credential we cover in one place, see the cybersecurity field overview.

Sources

Edited by Elena Marsh · Data checked October 4, 2026

Questions people ask

What certifications do I need for cybersecurity?

None is required by law or by a licensing body we could find, and most ads we count name none. For a first analyst job, CompTIA Security+ is the exam to start with: $439 in the US, no experience required, and counted in US, UK and Indian security-analyst ads. The CISSP and CISM are also named in our October 2026 count, but both require five years of experience, so they are not an option for a beginner.

Is the Google Cloud cybersecurity certification worth it?

Two different products share the name. Most people who ask mean the Google Cybersecurity Certificate, a beginner course on Coursera ($49 a month, about six months at seven hours a week). It appeared in none of the 8,110 US security-analyst ads in October 2026, so treat it as training. Google Cloud's proctored exams are a separate product: its professional level includes Cloud Security Engineer and Security Operations Engineer, and Google recommends three or more years of experience for professional exams. We do not count those exams in security-analyst ads, so we cannot say how often employers name them; for a beginner, they are not the first step.

How much does a Security+ cert cost?

The Security+ exam voucher costs $439 on CompTIA's US store, and the UK store shows the same price in US dollars. CompTIA's Europe store lists €323. A voucher with Retake Assurance costs $579. Renewal costs $150 for each three-year cycle plus 50 continuing education units, or one CertMaster CE course.

Can you make $500,000 a year in cybersecurity?

None of the pay figures in our sources reaches $500,000. The highest is for a chief information security officer: $347,395 to $429,727 a year, a Salary.com range that EC-Council quotes on its salary page. That is an executive role. For comparison, the US Bureau of Labor Statistics puts the median wage of information security analysts at $129,180 (May 2025).

Is 30 or 40 too late for cybersecurity?

The entry requirements we checked depend on experience, not age. Security+, ISC2 Certified in Cybersecurity and the Google Cybersecurity Certificate require no experience at all. The CISSP and the CISM require five years, which a career changer has to build first, whatever their age. Job ads do not state an age and we have no data on hiring by age, so we cannot say how employers treat older beginners.

Is cybersecurity still worth it in 2026?

Employers are hiring for it: we counted 8,110 US security-analyst ads in October 2026 (Adzuna). For the longer view, the US Bureau of Labor Statistics projects employment of information security analysts to grow much faster than the average for all occupations from 2025 to 2035. Our own count covers one month, so we make no claim about the direction of demand.

What qualifications do I need to be a cybersecurity analyst?

The US Bureau of Labor Statistics says information security analysts typically need a bachelor's degree in a computer science field and may need work experience in a related occupation. Certifications come on top of that: Security+ is the usual first exam, and the CISSP becomes an option after five years of security work. If you have no degree, see our guide to getting into cybersecurity without a degree.