SOC analyst certification: which exam to take first, and what job ads name

Job-ad data: October 2026 · Editor: · Updated

A security operations center (SOC) is the team that watches an organization's systems for attacks. For a first SOC job, take one SOC analyst certification that lists no required work experience: CompTIA Security+ ($439) or ISC2 Certified in Cybersecurity, known as CC ($199). Both are beginner exams; Security+ only recommends IT experience, which the path below covers.

CompTIA and ISC2 are the certification bodies that run them. Security+ appeared in 17 of the 233 US SOC-analyst ads on Adzuna, a job-ad search site, in October 2026, and CC in none of the 233. Both counts are minimums; what the count misses explains why.

CySA+, CompTIA's mid-level analyst exam, comes after time in a SOC; the requirements table shows CompTIA's advice.

Your first step: pick one beginner exam, CC if money is tight or Security+ if you can pay $439. While you study, practice in a SIEM. A SIEM (security information and event management software) collects logs, the records computers keep of what happened, and raises the alerts a SOC analyst works through. If you have no IT job yet, look for one (help desk, for example) at the same time; the path for career changers shows the order.

What do soc analyst job ads ask for?

Instant answer from October 2026 job ads. No email needed.

Country

Certificates named

  1. CompTIA CySA+15%
  2. CEH13%
  3. CompTIA Security+7%
  4. SSCP4%

Source: Adzuna job ads, October 2026. Small sample: 233 ads. Treat this as a rough guide.

What SOC analyst job ads name in the United States: certifications and skills
CompTIA CySA+ is named most often (15%); 2 of 6 certifications appear in fewer than 1 in 100 ads.
Show the numbers
What SOC analyst job ads name in the United States: certifications and skills. Share of job ads that name each item. Source: Adzuna job ads, October 2026.
ItemAdsShare of ads
CompTIA CySA+3415%
CEH3013%
CompTIA Security+177%
SSCP94%
ISC2 CC00 of 233
Google Cybersecurity00 of 233
On this page
  1. Which SOC analyst certifications do job ads name, by country?
  2. What skills does SOC analyst work involve?
  3. Which certification is best for a SOC analyst?
  4. How much does a SOC analyst certification cost?
  5. How is a SOC analyst different from a cybersecurity analyst?
  6. What is a SOC analyst certification path for career changers?
  7. Is a SOC analyst certification worth it?
  8. Best certifications for SOC analysts: what Reddit posters ask
  9. Related roles and next steps
  10. Sources

Which SOC analyst certifications do job ads name, by country?

In US SOC-analyst ads on Adzuna in October 2026, CompTIA CySA+ appeared in 34 of the 233 ads. The CEH (Certified Ethical Hacker, an ethical-hacking exam from the certification body EC-Council) appeared in 30, the SSCP (Systems Security Certified Practitioner, an ISC2 exam) in 9 and Security+ in 17 (a minimum; see below). All these US counts come from job ads titled soc analyst.

CySA+ is not the first exam for a beginner, whatever its count: it is the exam for people already doing SOC work. CompTIA recommends, but does not require, "About 4 years in a SOC analyst or vulnerability analyst role" before it (a vulnerability analyst finds and ranks security weaknesses).

We did not collect a US figure for the CISSP, ISC2's credential for experienced security staff, in SOC-analyst ads for October 2026, so its US cell says no figure. Three beginner credentials were counted as well. Of the same 233 US SOC-analyst ads, 0 named ISC2 CC, 0 named the Google Cybersecurity Certificate and 0 named the IBM Cybersecurity Analyst certificate. The Google and IBM credentials are course certificates on Coursera, an online course site, not exams.

Credential (search phrase) US UK India
All SOC-analyst ads (title soc analyst) 233 69 54
CompTIA CySA+ (cysa) 34 17 8
CEH (ceh) 30 3 11
CompTIA Security+ (comptia security) 17 9 4
SSCP (sscp) 9 2 0
CISSP (cissp) no figure 7 8
ISC2 CC (isc2 certified in cybersecurity) 0 0 0
Google Cybersecurity (google cybersecurity) 0 0 0
IBM Cybersecurity Analyst (full certificate name) 0 0 0

Source: Adzuna API, job ads titled soc analyst collected in October 2026. The first row is the number of ads; each other cell is the number of those ads that contain the search phrase. Analysis: CertWorthIt. How we count.

The UK column rests on 69 SOC-analyst ads and the India column on 54 (Adzuna, October 2026). We treat any country with fewer than 200 ads for a role as a small sample: read its figures with care, because one ad more or less moves them. We base no advice for that country on them.

For Brazil we give only the total: 40 ads titled analista SOC (Portuguese for SOC analyst) on Adzuna in October 2026. We publish no certificate figures for a country with fewer than 50 ads for the role.

What the count misses

Each figure counts ads that contain an exact phrase, so a credential written another way is missed. CySA+ is searched as cysa, which misses ads that name it only as "Cybersecurity Analyst+" in full. Security+ is searched as comptia security, and ads that write only "Security+" go uncounted, so its count is a minimum. The CEH and ISC2 CC counts miss ads that write only "Certified Ethical Hacker" or only "ISC2 CC" in the same way, so a low CC count does not show that employers ignore CC. We do not separate required from preferred credentials, and one month of ads says nothing about trends over time.

What skills does SOC analyst work involve?

SOC analyst work involves sorting alerts, checking which are real attacks and passing the real ones on. That description comes from a vendor, not from a count of ads. Microsoft's page for its SOC exam lists triage (sorting alerts by urgency), responding to incidents (confirmed attacks or breaches), hunting for threats (looking for attackers who have not triggered an alert) and writing detections (rules that raise alerts). The work is done in Microsoft Sentinel (Microsoft's SIEM) and Microsoft Defender XDR (its tools for detecting attacks). We have not counted how often SOC-analyst ads name SIEM tools such as Splunk (a SIEM product), so we cannot say which tools those ads ask for.

The vendors' SOC-related exams name the tools. Microsoft's Security Operations Analyst exam (SC-200) covers managing a security operations environment, responding to incidents and threat hunting, with searches written in KQL (Kusto Query Language, Microsoft's log-search language). Splunk Core Certified User is Splunk's entry-level exam on its own search software. The Google Cybersecurity Certificate teaches two SIEM tools, Chronicle (Google's SIEM) and Splunk, plus Python (a programming language), Linux (an operating system) and SQL (a database query language), and Google lists SOC analyst among the job titles it prepares for. ISC2's SSCP gives 15% of its exam to the domain (topic area) Risk Identification, Monitoring and Analysis and 14% to Incident Response and Recovery.

A certificate tells an employer what you studied. A SIEM search you wrote yourself, and can explain line by line in an interview, shows what you can do on a first shift. Check which SIEM is named in SOC-analyst ads in your city, and practice on that one, whether it is Splunk, Microsoft Sentinel or another product.

Which certification is best for a SOC analyst?

The best certification for a SOC analyst depends on how long you have worked in security. Before a first SOC job, take one beginner exam; once you work in a SOC, CySA+ or the SSCP matches the work you already do.

Entry-level SOC analyst certification for beginners

For beginners, the entry-level SOC analyst certification is ISC2 CC or CompTIA Security+. ISC2 CC costs $199 for 100 to 125 questions in two hours at a Pearson test center (an exam room run by the testing company Pearson VUE), with 700 out of 1,000 to pass, and it requires no work experience. ISC2 closed new enrollments in its free-exam program on May 20, 2026; codes already issued can be used until December 31, 2026.

CompTIA Security+ (exam SY0-701) costs $439 for up to 90 questions in 90 minutes, with 750 on a 100-to-900 scale to pass. If you book Security+ now, you take the current exam (SY0-701), whose English version stays available until June 11, 2027. The next version (SY0-801) is expected around November 17, 2026, and has no published price. CompTIA's page for the next version recommends two years as a security administrator and no longer names Network+; the vendor pages list neither version's experience as a requirement.

In a US job search, take Security+ if the budget allows; the ad counts above show how often US ads name each exam. CC is the cheaper way to show the basics, and our Google Cybersecurity vs ISC2 CC comparison sets it against Google's course for readers who want lessons first.

SOC analyst certification requirements

The SOC analyst certification requirements are each vendor's rules for holding its credential; a vendor is the company that sells the exam. A requirement must be met; a recommendation is advice only. The quotes come from each vendor's page, and ISC2's "domains" are the topic areas of its exam outlines. Rows marked "Start here" are the beginner options: pick one of the two exam rows (CC or Security+); the two courses are lesson options. Rows marked "Optional" are tool exams you do not need in order to practice.

Level Credential (type) What the vendor asks for
Start here Google Cybersecurity Certificate (Coursera; beginner course) "No degree or experience required"
Start here IBM Cybersecurity Analyst (Coursera; beginner course) Listed at beginner level
Start here ISC2 CC (beginner exam) "No Work Experience Required"
Start here CompTIA Security+ (beginner exam) No requirement listed on the vendor page; recommended: "CompTIA Network+ and two years of experience working in a security/ systems administrator job role" (Network+ is CompTIA's networking exam)
Optional Splunk Core Certified User (tool exam) No prerequisites
Optional Microsoft SC-200 (Microsoft-stack exam) Rated intermediate by Microsoft
Later SSCP (after a year in security) "a minimum of one-year full-time experience in one or more of the domains"
Later CompTIA CySA+ (after SOC experience) No requirement listed on the vendor page; recommended: "About 4 years in a SOC analyst or vulnerability analyst role"
Later EC-Council CSA (training route) "Enrollment in the official training program is required"
Later CEH (training or experience) "two years of work experience in an Information Security role" (self-study route), or EC-Council's official training
Later CISSP (senior) "a minimum of five years cumulative, full-time experience in two or more of the eight domains"

Source: vendor pages listed under Sources, checked October 6, 2026.

Two ISC2 routes soften those rules. Without the year of experience, you can pass the SSCP and become an Associate of ISC2 (a holder who passed the exam but still owes the experience), with two years to earn it. For the CISSP, a degree or one approved credential can count for one of the five years, and ISC2's list includes Security+ and CySA+.

The best certification also depends on the SIEM an employer runs. Microsoft rates SC-200 intermediate and ties it to its own security products; it renews free every 12 months with an online assessment. Microsoft says it will update the English SC-200 exam on October 21, 2026, so check its skills outline (the list of topics the exam tests) before you start studying. The Splunk exam has no prerequisites and fits a job that uses Splunk.

We do not count practical blue-team exams (hands-on tests of defense work rather than multiple-choice questions) in job ads, and we have not checked their vendors' pages for this page, so we do not rate them here.

How much does a SOC analyst certification cost?

Among the exams in this table with a published US price, a SOC analyst certification costs from $130 (Splunk Core Certified User) to $1,199 (the CEH at a test center) in exam fees, before training. Upkeep, meaning the renewal fees and continuing-education credits that keep a certificate valid, comes on top: ISC2, CompTIA and EC-Council charge a renewal fee and ask for those credits (CPE or CEU: logged hours of training or other learning).

Credential US exam price Upkeep First three years, exam plus upkeep
ISC2 CC $199 $50 a year and 45 CPE credits per three years $199 + three yearly fees of $50 = $349
CompTIA Security+ $439 $150 and 50 CEUs per three years $439 + $150 = $589
Splunk Core Certified User $130 per attempt Not stated on the exam page $130, upkeep not stated
Microsoft SC-200 Set by the country where you take it Free online assessment every 12 months Exam price only
ISC2 SSCP $249 $135 a year and 60 CPE credits per three years $249 + three yearly fees of $135 = $654
CompTIA CySA+ $439 $150 and 60 CEUs per three years $439 + $150 = $589
EC-Council CEH $950 online, $1,199 at a test center $80 a year and 120 credits per three years $950 + $100 application fee + three yearly fees of $80 = $1,290
EC-Council CSA Not listed on EC-Council's page Not checked Not available
ISC2 CISSP $749 (Americas) $135 a year and 120 CPE credits per three years $749 + three yearly fees of $135 = $1,154
Google Cybersecurity Certificate $49 a month on Coursera None stated Six months at $49 = $294

Source: ISC2, CompTIA, Splunk, Microsoft Learn, EC-Council and Coursera pages listed under Sources, checked October 6, 2026. Prices are US prices; check the vendor page for your country. Upkeep totals assume three full years of fees from the exam date. The CISSP price is ISC2's price for the Americas. The CEH total is for the online exam on the self-study route: the $100 is EC-Council's application fee for candidates without its official training; with the training, the price is set by EC-Council's training partners. The Google certificate is a course paid by the month, so the exam-fee range above leaves it out; its total uses Coursera's estimate of six months at seven hours a week.

CompTIA's renewal rules help if you later add CySA+: renewing CySA+ also renews Security+. This works if you pass CySA+ within three years of Security+, while Security+ is still current. Then the two exams and the first three-year renewal cost:

$439 + $439 + $150 = $1,028

Each later three-year cycle adds one $150 fee, not two. Both CompTIA exams are also sold as a $579 voucher (a prepaid exam code) with Retake Assurance, CompTIA's option that adds a second attempt.

Two beginner budgets with the optional Splunk exam, before retakes and upkeep: ISC2 CC plus the Splunk exam comes to $199 + $130 = $329, and Security+ plus the Splunk exam to $439 + $130 = $569.

What the CompTIA CySA+ certification costs to get and keep (USD)
The required CompTIA CySA+ fees add up to $439.
Show the numbers
What the CompTIA CySA+ certification costs to get and keep (USD). Source: comptia.org, checked October 3, 2026.
ItemFee
Fees to get certified: Exam$439
Fees to get certified: Renewal, every 3 years$150

How is a SOC analyst different from a cybersecurity analyst?

A SOC analyst works inside a security operations center and handles its alerts and incidents. "Cybersecurity analyst" is a wider title that can include SOC work, vulnerability work and other analyst jobs; in our data it is searched as security analyst.

SOC analyst Cybersecurity analyst
Title we search in US ads soc analyst security analyst
US ads on Adzuna, October 2026 233 8,110
Exams named after the job EC-Council Certified SOC Analyst (CSA); Microsoft SC-200 CompTIA CySA+

Source: Adzuna API, October 2026; analysis: CertWorthIt.

The two counts can overlap. Adzuna matches every word of the title we search, so an ad titled "SOC Security Analyst" contains both titles and can appear in both counts.

EC-Council builds its CSA for "current and aspiring Tier I and Tier II SOC analysts." Tier 1, which EC-Council writes as Tier I, is the first line of a SOC, where alerts are sorted before anyone investigates further. Our reading: for a career changer, soc analyst is the title to search first, because EC-Council aims its SOC exam at aspiring tier 1 analysts too. Our cybersecurity-analyst page covers the wider title, with its own certificate counts by country.

What is a SOC analyst certification path for career changers?

The path we suggest into a SOC has two stages: an IT job with a beginner exam alongside it, then a tier 1 SOC role. The certificates help at each stage but do not replace the IT experience the vendors assume. CompTIA recommends two years as a security or systems administrator before Security+, and EC-Council recommends foundational IT or security knowledge, such as networking and firewalls (software that blocks unwanted network traffic), before its SOC exam.

  1. Pick one beginner exam and start studying: ISC2 CC ($199) if money is tight, or Security+ ($439) if you can pay. If you want lessons first, the Google Cybersecurity Certificate takes about six months at seven hours a week, and the IBM Cybersecurity Analyst certificate about four months at ten hours a week. Google says its program helps prepare for Security+ and comes with a discount on the exam.
  2. Get an IT job at the same time if you have none. In our reading, help-desk work teaches the systems a SOC watches: user accounts, computers and networks. Our IT-support page shows what those ads name; if networks interest you, our network-engineer page covers the CCNA, Cisco's networking exam.
  3. Learn a SIEM by using it. Pick Splunk or Microsoft Sentinel, the two SIEMs with exams described on this page, choosing the one named in ads in your city. Load sample alerts into it, run searches on them, and write down in your own words why each alert fired. We have not checked which SIEM tools or sample data sets are free to practice on, so look on the training page of the vendor you pick. You do not need an exam to practice: use an exam outline only as a task list. SC-200 tests managing a security operations environment, responding to incidents and threat hunting with KQL searches; the Splunk exam tests Splunk's own search software. Later, the Splunk exam ($130) or SC-200 can turn that practice into a certificate, if you want one.
  4. Apply for tier 1 SOC jobs, where your work is sorting alerts and passing real incidents on.
  5. Once you work in a SOC, take CySA+ or the SSCP. For CySA+, CompTIA's experience advice is a recommendation, not a requirement (see the requirements table); our reading is to take it when you handle alerts daily and its exam objectives read like your own work. Five years in security makes you eligible for the CISSP; our CISM vs CISSP comparison covers that later choice.

What a tier 1 interviewer may ask (our reading, not a verified hiring rule). Be ready to:

  • take one alert from the raw log lines (the computer's own records) to a short note in the ticket (the work record);
  • say what looks normal in a sign-in log or an email header (the technical lines at the top of an email that show where it came from);
  • explain basic networking, such as DNS (how names become network addresses) and ports.

The step no exam replaces is the first job. Our Adzuna count does not record how much experience SOC-analyst ads ask for.

If you have no degree, the entry credentials on this path are still open to you: CC requires no work experience, Security+ lists no requirement, and Google says "No degree or experience required" for its certificate. The US Bureau of Labor Statistics (BLS) lists a bachelor's degree as the typical entry education for information security analysts, the nearest official occupation; our count does not record degree requirements in SOC-analyst ads.

CompTIA CySA+ vs CEH exams side by side: questions, time, format
CompTIA CySA+, 85 questions in 165 minutes; CEH, 125 questions in 240 minutes.
Show the numbers
CompTIA CySA+ vs CEH exams side by side: questions, time, format. Source: comptia.org, eccouncil.org, cert.eccouncil.org, checked October 3, 2026.
ItemCompTIA CySA+CEH
Questions85 questions125 questions
Exam time165 minutes (2 h 45 min)240 minutes (4 h)
Passing score750 (scale 100–900)60–85%
FormatMultiple choice, performance-based tasksMultiple choice, hands-on practical

Is a SOC analyst certification worth it?

A SOC analyst certification is worth it when it meets a requirement in the ads you apply to, or when studying for it teaches work you can show. For a beginner, one exam at $199 or $439 plus SIEM practice is worth paying for. Our reading: a second beginner exam adds less to a first application than a SIEM lab you can explain.

US defense work is one place where a credential can be a formal condition. The Department of Defense (DoD) approves credentials for each work role under Directive 8140, a US rule on which credentials defense jobs accept. CompTIA says Security+ and CySA+ are approved for the Cyber Defense Analyst work role, a DoD job category with the code 511. EC-Council says the CEH is approved under Directive 8140, and the work roles it lists include Cyber Defense Analyst and Cyber Defense Incident Responder. These approvals are the vendors' statements; we could not read DoD's own tables.

Do SOC analysts need certifications?

No vendor rule we found requires a certification for a SOC job; the exam rules apply only to the exam. The exception we found is US defense work, where Directive 8140 can make an approved credential a condition of the role. Outside defense work, each employer decides, and the BLS says that "Employers may prefer to hire analysts who have professional certification."

Best certifications for SOC analysts: what Reddit posters ask

We grouped the questions in the Reddit posts we collected. Reddit is a forum site, and each r/ name is a topic group. Posters are a self-selected group, so these show what people ask, not how many hold a view.

A poster with four to five months of CCNA study ahead asked whether to "pause CCNA, pursue CySA+, and start applying for SOC roles sooner" (r/ccna, August 2026). Our answer: CySA+ is built for people with SOC experience, so for a first SOC job, Security+ or CC is the beginner exam to take (ISC2 requires no work experience for CC; CompTIA lists none for Security+). Finishing the CCNA makes sense if network jobs are your way into IT.

Three posts on September 22, 2026, on r/CompTIA, r/ITCareerQuestions and r/SecurityCareerAdvice, asked whether to focus on Security+ or CySA+ (r/CompTIA). Two posts also asked whether CySA+ is a waste of time without enough experience (r/ITCareerQuestions). Our answer: Security+ first; CySA+ is for people with SOC experience (see the requirements table).

One poster asked whether the CEH is worth it for a first cybersecurity job (r/SecurityCareerAdvice, August 2026). For a SOC goal, the CEH costs $950 or more and needs two years of security work or paid official training; it fits when an employer or a DoD work role names it.

Others asked what to learn next. Three September posts listed Python, Terraform (a tool that sets up cloud servers from code), SIEM, the CEH and the CISSP as options (r/SecurityCareerAdvice); for SOC work, our answer is SIEM first. Two posts weighed Security+ against SAL1, a certificate from TryHackMe (a hands-on training site), and GRC (governance, risk and compliance) work (r/ITCareerQuestions, September 2026). A poster on r/AzureCertification asked for a study path to a blue-team role, one that defends systems (June 2026). We do not count TryHackMe certificates, so we cannot say how often employers name them.

Our cybersecurity-analyst page covers the wider security-analyst title and its certificate counts by country. A penetration tester works on the attack side, and IT support is the first stage of the path we suggest. Our cybersecurity certification roadmap orders the exams across all security jobs, and the cybersecurity field overview lists every security credential we cover.

Sources

Edited by Elena Marsh · Data checked October 6, 2026

Questions people ask

Which certification is best for SOC analysts?

A security operations center (SOC) is the team that watches an organization's systems for attacks. For a first SOC job, the best start is one beginner exam that lists no required work experience: CompTIA Security+ ($439 in the US) or ISC2 Certified in Cybersecurity, known as CC ($199). CompTIA CySA+, CompTIA's mid-level analyst exam, comes later, after SOC experience (recommended by CompTIA, not required). In US SOC-analyst ads on Adzuna, a job-ad search site, in October 2026, Security+ appeared in 17 of the 233 ads and CySA+ in 34 of the 233.

Do you need a certification to be a SOC analyst?

Not by any vendor rule we found: the SOC exams we checked set rules for taking the exam, not for getting a job, and each employer decides what to ask for. The exception is US Department of Defense work, where Directive 8140 lists approved credentials for each work role (a DoD job category); CompTIA says Security+ and CySA+ are approved for the Cyber Defense Analyst role. The US Bureau of Labor Statistics says employers may prefer analysts with a professional certification. In US SOC-analyst ads on Adzuna in October 2026, CompTIA Security+ appeared in 17 of the 233 ads.

How do you become a SOC analyst without a degree?

Start in an IT job such as help desk, and take one beginner exam that lists no degree requirement: ISC2 Certified in Cybersecurity at $199 or CompTIA Security+ at $439. Practice in a SIEM, the software a security operations center uses to collect logs and raise alerts, until you can explain an alert. Then apply for tier 1 SOC jobs, the first line that sorts incoming alerts. Our Adzuna count of 233 US SOC-analyst ads in October 2026 does not record degree requirements, so we cannot say how many of those employers hire without one.

Can a SOC analyst career change work without IT experience?

It can, in two stages: an IT job first, such as help desk or IT support, then a tier 1 job in a security operations center (SOC). The vendors assume IT experience. CompTIA recommends Network+ (its networking exam) and two years as a security or systems administrator (someone who runs an organization's computers or security tools) before Security+, though its Security+ page lists neither as a requirement. ISC2 Certified in Cybersecurity ($199) requires no work experience, so it fits the first stage.

Is the Certified SOC Analyst (CSA) worth it?

Not as a first exam if you are a beginner paying for it yourself: EC-Council, the certification body behind the CSA, lists no price on its CSA page and requires enrollment in its official training to earn it. The exam (312-39) has 100 multiple-choice questions in three hours, with 70% to pass, and EC-Council aims it at current and aspiring Tier I and Tier II SOC analysts (the first and second lines of a security operations center). We do not count the CSA in job ads. By contrast, ISC2 Certified in Cybersecurity ($199) and CompTIA Security+ ($439) both have published US prices.

Does a SOC analyst job pay well?

It can, but the only SOC analyst pay figures we have are estimates. Salary.com's figures, quoted by EC-Council (the company that sells the CSA exam, so not an independent source), give $71,449 to $85,113 a year for a US SOC analyst and $65,946 for an entry-level one. These are third-party estimates for a job title, not the pay of certificate holders, and whether they count as high pay depends on where you live and what you earn now. Our cybersecurity-analyst page gives official US pay figures for the wider occupation.

Is CySA+ worth it without SOC experience?

Not as a first exam: CompTIA recommends about four years of SOC or vulnerability work before CySA+ but sets no entry requirement, so the exam is built for people who already do the job. CySA+ (exam CS0-004, the current version since June 23, 2026) costs $439 in the US. A beginner's first step is CompTIA Security+ or ISC2 Certified in Cybersecurity, plus practice in a SIEM, the log and alert software a SOC uses. In US SOC-analyst ads on Adzuna in October 2026, CySA+ appeared in 34 of the 233 ads.