Certifications Map
Updated April 2026 · 14 min read

The cybersecurity certifications roadmap.

There are over 300 cybersecurity certifications on the market. You don't need 47 of them — you need 3 to 5, in the right order, paired with real experience. This roadmap cuts the noise: five tiers, verified Q1 2026 pricing, what each cert actually opens, and where it stops paying off.

What's inside
  • 5-tier progression, entry to exec
  • 16 certs ranked by ROI
  • Verified 2026 pricing & renewals
  • Track-specific stacking paths
2026 Update · Important Change

ISC2 cut the CISSP experience-waiver list in half on April 1, 2026.

The qualifying-credentials list dropped from roughly 50 to 25. Notable removals include CEH, CISA, CRISC, and OSCP — all of which previously knocked one year off the CISSP's 5-year experience requirement. If you were planning to use any of these as a waiver, verify the current ISC2 list before you commit your study budget.

01 / The Reality

Why certifications matter in 2026.

By the numbers

Certifications won't make you a great defender or attacker — but in 2026 they're the filter your resume has to clear before a human ever reads it. The data is unambiguous.

89%
Of hiring managers won't interview uncertified candidates
CyberSeek 2026
91%
Of employers prefer or require certified candidates
ISC2 Workforce Study
$25K+
Average annual salary premium for CISSP holders
Glassdoor / Levels.fyi
6–18mo
Typical payback window on a cert investment
BLS, Q1 2026
02 / The Path

Five tiers, in order.

Foundation → Executive

Each tier corresponds to a phase of your career. The flagship cert in each tier is highlighted — that's the one most candidates should pick if they're picking only one. All prices are USD verified Q1 2026.

01
Foundation · 0–1 years

Get in the door.

First credential to prove baseline competence. Required for many US government and DoD 8570/8140 roles.
Pick 1
CompTIA

Security+ (SY0-701)

Flagship

The default first cybersecurity cert. Vendor-neutral, broadly recognized, and meets DoD 8570 IAT II compliance for federal contractor roles.

Exam fee $425
Total budget $600–$1,000
Study time 2–4 months
Renewal $150 / 3 yrs
Vendor-neutral DoD 8570 No prereq
ISC2

Certified in Cybersecurity (CC)

ISC2's newest entry-level cert, currently free for the first million candidates as part of the One Million Certified in Cybersecurity initiative. Solid resume signal.

Exam fee Free*
Total budget $0–$200
Study time 3–6 weeks
Renewal $50 / yr
Free voucher Beginner Limited time
CompTIA

Network+ (N10-009)

Networking is the foundation under every security skill. If subnetting, routing, and protocols feel shaky, take this before Security+.

Exam fee $390
Total budget $500–$900
Study time 2–3 months
Renewal $150 / 3 yrs
Foundational Optional
Microsoft

SC-900 Security Fundamentals

Strong fit for Microsoft-heavy environments. Covers identity, compliance, and Microsoft 365/Azure security basics.

Exam fee $99
Total budget $100–$300
Study time 3–6 weeks
Renewal Free annual
Microsoft Cloud
02
Analyst · 1–3 years

Specialize toward Blue Team or Red Team.

You've passed your foundation cert and you're working in security. This is where the path branches — pick defense or offense.
Pick 1–2
CompTIA · Blue Team

CySA+ (CS0-003)

Flagship

The defensive analyst's mid-tier credential. Covers SIEM operations, threat hunting, vulnerability management, and incident response. Highly visible in SOC job postings.

Exam fee $425
Total budget $600–$1,200
Study time 2–3 months
Renewal $150 / 3 yrs
SOC Threat hunt DoD 8570
EC-Council · Red Team

CEH v13 (Ethical Hacker)

The most widely recognized offensive cert at this level. v13 adds AI-powered threat detection and cloud exploitation. Theory-heavy, ATS-friendly — useful for resume screens.

Exam fee $1,199
Total budget $1,200–$3,600
Study time 2–3 months
Renewal $80 / yr + CPE
Recognized More theory DoD 8570
Microsoft · Blue Team

SC-200 Security Operations

Hands-on with Microsoft Sentinel, Defender, and KQL. If your employer runs on Microsoft, this is the highest-impact analyst cert you can hold.

Exam fee $165
Total budget $200–$500
Study time 6–10 weeks
Renewal Free annual
Microsoft Sentinel KQL
CompTIA · Red Team

PenTest+ (PT0-003)

Practical pentesting cert at a fraction of CEH's price. More hands-on than CEH but less rigorous than OSCP. Solid mid-tier offensive credential.

Exam fee $425
Total budget $600–$1,200
Study time 2–4 months
Renewal $150 / 3 yrs
Hands-on Affordable
03
Specialist · 3–6 years

Become genuinely good at one thing.

Cloud, offensive, or analyst depth. This is where salaries jump from "decent" to "in demand". Pick the one that matches your day job.
Pick 1
OffSec · Red Team

OSCP (PEN-200)

Flagship

The gold standard for pentesters. 24-hour hands-on hacking exam, manual exploitation only. Passing this immediately changes how you're treated in interviews.

Exam + course $1,749
Total budget $1,749–$2,749
Study time 3–6 months
Renewal Lifetime
Hands-on No expiry High signal
AWS · Cloud

Security Specialty (SCS-C02)

Cloud security is the highest-demand specialty in 2026. AWS Security Specialty covers IAM, encryption, monitoring, and incident response on AWS — the leading cloud platform.

Exam fee $300
Total budget $400–$900
Study time 2–4 months
Renewal 3 yrs · re-exam
AWS High demand
Microsoft · Cloud

AZ-500 Azure Security Engineer

Microsoft's flagship cloud security cert. Covers identity, platform protection, security operations, data and app security on Azure. Pair with SC-100 for senior cloud roles.

Exam fee $165
Total budget $200–$600
Study time 2–3 months
Renewal Free annual
Azure Affordable
SANS / GIAC · Blue Team

GCIH Incident Handler

SANS-backed and deeply respected for incident response work. Expensive, but the curriculum and credibility are unmatched in the IR space.

Exam fee $979
Total budget $8K–$10K*
Study time 3–6 months
Renewal $469 / 4 yrs
SANS course Premium IR-focused
04
Senior · 5+ years experience

The certs that pay for themselves.

This is where the biggest salary jump in cybersecurity happens. CISSP and CISM are the two credentials hiring managers gate senior roles behind.
Pick 1
ISC2

CISSP

Flagship

The most recognized security certification globally and a near-requirement for senior architect, manager, and consultant roles. CAT exam, 8 domains, requires 5 years of paid experience.

Exam fee $749
Total budget $1,200–$2,500
Study time 3–6 months
Renewal $135 / yr + CPE
5 yrs req Industry standard +$25K salary
ISACA · Management

CISM

Pure management focus — risk, governance, program design. Better than CISSP if your trajectory is purely managerial rather than technical-architect.

Exam · member $575
Exam · non-member $760
Study time 3–4 months
Renewal $45–85 / yr
5 yrs req Management CISO track
ISC2 · Cloud

CCSP

CISSP-equivalent depth, focused entirely on cloud security architecture and operations. The senior cert for cloud-first security careers.

Exam fee $599
Total budget $900–$2,000
Study time 3–4 months
Renewal $135 / yr + CPE
5 yrs req Cloud architect
ISACA · Audit

CISA

The audit-track equivalent. Required by Big Four and corporate IT audit teams. Note: CISA was removed from the CISSP waiver list in April 2026.

Exam · member $575
Exam · non-member $760
Study time 3–5 months
Renewal $45–85 / yr
5 yrs req Audit track
05
Expert · 8+ years

Differentiator credentials.

You don't need these to get a job — you have one. These signal genuine expertise to peers and unlock specialized senior roles.
Optional
OffSec · Red Team Elite

OSEP / OSEE

Elite

OSEP for evasion and advanced exploitation; OSEE for the hardest exam in offensive security — exploit development, kernel work. Both are clear differentiators in the red team market.

Exam + course $1,799+
Total budget $2K–$5K
Study time 6–12 months
Renewal Lifetime
Top-tier OSCP req No expiry
SANS / GIAC · Forensics

GCFA / GREM

GCFA for advanced forensic analysts; GREM for malware reverse engineering. The two most respected technical certifications in DFIR and threat research.

Exam fee $979
Total budget $8K–$10K*
Study time 4–6 months
Renewal $469 / 4 yrs
DFIR Premium Specialist
ISACA · Risk

CRISC

Senior risk and IT control credential. Pairs naturally with CISM for governance leaders. Note: CRISC was removed from the CISSP waiver list in April 2026.

Exam · member $575
Exam · non-member $760
Study time 3–4 months
Renewal $45–85 / yr
3 yrs req Risk leader
ISC2 · Architect

CISSP-ISSAP

CISSP concentration in security architecture. Requires existing CISSP plus 2 years of architecture experience. Strong fit for staff and principal architect roles.

Exam fee $599
Total budget $700–$1,500
Study time 2–4 months
Renewal Bundled w/ CISSP
CISSP req Architect
03 / Track Stacking

Cert sequences by career track.

Pick your path

Six common career trajectories with the cert sequences hiring managers actually look for. Estimated total time assumes one cert at a time alongside full-time work.

Blue Team Track

SOC Analyst → Senior → Manager

5–7 yrsTotal path
Security+ CySA+ CISSP CISM

The default defensive progression. Security+ opens the SOC door, CySA+ deepens analytical skills, CISSP gates senior roles, CISM completes the management pivot.

Red Team Track

Pentester → Red Team Lead

4–6 yrsTotal path
Security+ CEH / PenTest+ OSCP OSEP

Hands-on offensive path. Skip CEH if budget is tight — OSCP carries the hiring weight. OSEP differentiates senior red teamers from generalist pentesters.

Cloud Security Track

Cloud Engineer → Architect

4–6 yrsTotal path
Security+ AZ-500 / AWS Sec CCSP Cloud Architect

Cloud security is the highest-demand specialty in 2026. Pick AWS or Azure based on employer footprint, then validate breadth with CCSP for senior roles.

GRC Track

Analyst → Audit Lead → Risk Director

5–7 yrsTotal path
Security+ CISA CRISC CGEIT

The ISACA-heavy governance, audit, and risk pathway. Security+ adds technical literacy. CGEIT is for senior risk and enterprise governance roles.

Architect Track

Engineer → Architect → CISO

7–10 yrsTotal path
Security+ CISSP CCSP / ISSAP CISM

For engineers moving into architecture and ultimately leadership. Many seasoned professionals hold both CISSP and CISM — they signal different things to different audiences.

DFIR / Research Track

Responder → Forensic Lead → Researcher

6–9 yrsTotal path
Security+ CySA+ GCIH GCFA / GREM

Premium SANS-heavy path for incident response and malware research specialists. Expensive, but the courses themselves are the differentiator — not just the cert.

04 / Quick Reference

Side-by-side comparison.

Verified Q1 2026

Every major cert at a glance — pricing, difficulty, time investment, validity. Use this to spot-check before committing study time and budget.

CertificationIssuerExamDifficultyStudyValidity
Security+CompTIA$425
2–4 mo3 yrs
ISC2 CCISC2Free*
3–6 wk3 yrs
SC-900Microsoft$99
3–6 wkAnnual renew
CySA+CompTIA$425
2–3 mo3 yrs
CEH v13EC-Council$1,199
2–3 mo3 yrs
PenTest+CompTIA$425
2–4 mo3 yrs
SC-200Microsoft$165
6–10 wkAnnual renew
AZ-500Microsoft$165
2–3 moAnnual renew
AWS Security SpecialtyAWS$300
2–4 mo3 yrs
OSCPOffSec$1,749
3–6 moLifetime
CISSPISC2$749
3–6 mo3 yrs
CISMISACA$575–$760
3–4 mo3 yrs
CCSPISC2$599
3–4 mo3 yrs
CISAISACA$575–$760
3–5 mo3 yrs
OSEPOffSec$1,799+
6–12 moLifetime
GCFA / GREMSANS / GIAC$979*
4–6 mo4 yrs
05 / The Long Tail

What renewals actually cost.

Recurring spend

The exam fee is just the entry ticket. Most certifications need annual maintenance fees and continuing education credits to stay valid. Plan for the recurring cost before you buy.

CompTIA

Security+, CySA+, PenTest+

Annual fee $50
3-year total $150
CEUs required 50

Higher-tier CompTIA certs auto-renew lower ones. Pass CySA+ and your Security+ stays current. Free CEU sources cover most candidates' annual quota.

ISC2

CISSP, CCSP, CC

Annual fee (AMF) $135
3-year total $405
CPEs required 120 / 3 yrs

CISSP requires 40 CPEs annually. ISC2 webinars are free and count. Conferences and on-the-job training cover the rest for most professionals.

ISACA

CISM, CISA, CRISC

Annual fee · member $45
Annual fee · non-mem $85
CPEs required 120 / 3 yrs

Membership pays for itself if you hold multiple ISACA certs. CPEs come from chapter events, ISACA Journal quizzes, and webinars.

06 / Don't Do This

Five expensive mistakes.

Save your money

The most common ways candidates waste time and money chasing certs that won't move their career forward. Recognize the patterns, skip the traps.

01
Stacking certs without working in security
Five certifications and zero professional experience reads as red flag, not green light. Hiring managers want hands-on work — get the first job with one cert, then layer the rest. Certifications validate experience; they don't replace it.
02
Buying CEH when OSCP is the actual goal
CEH costs $1,199 and is largely theoretical. OSCP costs $1,749 and is the credential that actually changes how you're treated as a pentester. If your trajectory is offensive security, skip CEH and put the money toward OffSec's PEN-200 lab time.
03
Attempting CISSP without 5 years of experience
You can pass the exam early as an Associate of ISC2, but the cert isn't valid until you complete the experience requirement. Many candidates who rush in then forget to maintain Associate status and lose their hard-won pass. Wait, or stay disciplined about endorsement.
04
Paying full price when employer reimbursement is on the table
A high percentage of mid-size and enterprise employers reimburse cybersecurity certifications. Ask before you pay. Many candidates self-fund $4,000+ in certs that their employer would have covered with a simple form.
05
Ignoring the renewal trap
Holding CISSP, CCSP, and a CompTIA cert simultaneously costs over $500 per year in maintenance fees alone — before any training time. Plan your stack so renewals reinforce each other, or let lower-tier certs lapse once you've moved past them.

Not sure where you sit on this map?

Take the 2-minute career fit quiz to find your track, then we'll point you at the right certification to start with.

Take The Quiz