Cybersecurity Certifications by Career Stage: What I’d Take First, Second, and Never

You have eleven tabs open. One list says CISSP is number one. Another says start with Security+. A third opens with a bootcamp. None of them agree, and every single one is ordered by something other than the question you actually have, which is: given where I am standing right now, what should I buy next?

That is the problem with almost every “best cybersecurity certifications” roundup, and with every “best certifications for cybersecurity” list that is the same page with the words shuffled. They rank by popularity, or by salary claims, or by whatever the publisher happens to sell. A list ordered by popularity puts a credential you cannot legally hold for five years next to one you could sit next month, and leaves you to work out which is which.

So this is the version I would write for a friend: the same certifications, but ordered by career stage, with an explicit “not yet, and here is the documented reason” section. Ranked by what each one gets you at the point you are standing.

Who is writing this, and what I have not done

Before a single recommendation, the disclosure, because it changes how you should weigh everything below.

I do not hold any of the certifications on this page. Not Security+, not CISSP, not ISACA CISA, not A+ or Network+. I am not going to pretend otherwise, and if that ends your interest here, fair enough.

What I do have is three relevant things. I am a software engineer by training, from NUST, and I spent years building machine learning systems and product tools before becoming a founder. Across 2022 and 2023 I delivered a run of cybersecurity webinars for a software vendor, GFI Software, sometimes solo and sometimes alongside their regional channel manager, on security directives, email security, network performance, and firewall-as-a-service, plus a fair amount of marketing work with cybersecurity companies. And I have sat on the hiring side, reading resumes and deciding who gets a call.

I also build the practice question banks people study these exams with, so I have a commercial interest in you buying certifications. That is exactly why the “never” section below exists, and why it argues against three of the five certifications I sell prep for.

The exam-taking you will do better than me. What I can tell you is what these credentials signal to the person deciding whether to interview you, and where the prerequisite traps are hidden.

The quick answer, by stage

Where you are Take this Why The trap
No IT job at all CompTIA A+ The only genuine zero-experience entry point Skip it if you already work in IT
Working in IT, no security yet CompTIA Security+ No formal prerequisite, and it is the cert that appears in entry security job postings Assumes networking you may not have
Networking is your gap CompTIA Network+ The bridge Security+ quietly assumes you already crossed CompTIA suggests 9 to 12 months of hands-on networking first
2 to 4 years in, going deeper CySA+, PenTest+, or a cloud security cert Specialisation is where the pay actually moves Do not stack breadth certs sideways
5+ years, heading to management CISSP The recognised senior and management credential Five years across two of eight domains, or you are an Associate, not a CISSP
Moving into audit, risk, or GRC ISACA CISA The audit-track credential Five years of IS audit or control experience, and the priciest exam here

Two of those are genuinely beginner-friendly. The rest have either an experience gate or an assumed foundation, and the roundups almost never say so.

Why every list you have read disagrees with the last one

Once you see the shape of these pages you can read them properly.

The Coursera roundup at the top of this search is a competent, popularity-ordered list of eight certifications, accurate about what each one is. It is not trying to answer “which one next,” because it sells courses for most of them, and ordering by career stage would mean telling most readers not to buy yet.

The NICCS catalogue run by the US Cybersecurity and Infrastructure Security Agency lists dozens of certifications with filters, no ordering and no opinion, which is complete and completely unhelpful at 11pm with a decision to make. The University of Florida list is from April 2024, opens with CISSP at number one, and includes a bootcamp in a list of certifications. The Reddit thread ranking third is the most honest source on the page and the least usable: forty comments of contradictory, context-free experience, most of it from people far further along than whoever is reading it. The vendor pages, CompTIA and ISC2, each recommend their own ladder, which is reasonable and also not a comparison.

Nobody in the top five tells you which certifications you are not allowed to hold yet. That is the gap this page exists to fill.

Stage 0: no IT job at all

If you have never worked a help desk, never touched a ticket queue, and are switching in from something unrelated, the honest starting point is CompTIA A+.

A+ is support fundamentals: hardware, operating systems, mobile devices, troubleshooting, basic security hygiene. It is the one credential here that assumes literally nothing, which is both its value and its limit. It does not make you a security professional. It makes you employable in the job that leads to the job. CompTIA runs it as two core exams rather than one, currently 220-1201 and 220-1202, so budget for two vouchers, and CompTIA lists A+ as a recommended, though not required, prerequisite for Network+.

Skip it entirely if you already work in IT. This is the most common money-waster I see: people already doing desk-side support buying the certification that proves they can do desk-side support. If your resume already says you did the job, A+ tells a hiring manager nothing they did not just read.

The whole zero-to-first-job order is in the entry-level cert order I would actually follow.

Stage 1: your first security certification

CompTIA Security+ is the right first security cert for almost everyone, for a boring practical reason rather than a technical one: it has no formal prerequisite, it is the credential that actually appears in entry-level security job requirements, and it satisfies the US Department of Defense 8570 and 8140 baseline for a lot of information assurance roles. That is why it clears HR filters that better certifications do not.

On price, be careful with any number you read, including mine. The SY0-701 voucher sits at $425 on CompTIA’s own store as I write this. I quoted $404 in an earlier piece and CompTIA has moved it since. Treat every roundup’s price as a starting point and check the vendor store.

Here is the caveat the vendor pages skip. Having no formal prerequisite is not the same as being a beginner exam. Security+ assumes you understand networking well enough that ports, protocols, and segmentation are background rather than new material. If they are new material, you will spend most of your study time learning networking badly inside a security course.

That is what Network+ is for, and it is why the “should I do Network+ first” question keeps returning. My answer: only if networking is genuinely your gap. I worked through both cases in Network+ versus Security+ and why order actually matters. CompTIA suggests roughly 9 to 12 months of hands-on networking experience as ideal background for Network+, which tells you who it is written for.

For Security+ itself, the study approach that matters is performance-based questions under time, not flashcards, which I set out in how I would study for Security+.

Stage 2: the specialisation fork, two to four years in

This is the stage the roundups handle worst, because there is no single right answer and a list needs one.

Once you hold Security+ with a couple of years of real work behind it, breadth certifications stop paying. Stacking another general-knowledge credential sideways signals that you collect certifications. Depth in one direction is what moves things: CompTIA CySA+ for defensive and analyst work, a hands-on lab credential if you are aiming at penetration testing, where hiring managers weigh a practical exam well above a multiple-choice one, or a provider-specific cloud security cert if your organisation already lives on one platform, which is close to worthless if it does not.

The rule at this stage: pick the direction your next job title contains, not the certification with the best salary graphic.

Stage 3: senior and management, CISSP

CISSP from ISC2 is the recognised credential for senior and management-track security work, and it deserves the reputation. It is broad across eight domains, written at a leadership altitude, and it tests judgment rather than recall. ISC2 describes the exam itself as asking for the best answer among several defensible ones, which is a different skill from knowing the material.

Here is the part that belongs at the top of every roundup and appears at the bottom of most. CISSP formally requires five years of cumulative paid work experience across at least two of its eight domains, with one year waivable through a qualifying degree or an approved certification. You can sit the exam before you have that. What you cannot do is hold the credential: you become an Associate of ISC2 until you earn the years.

So a list telling a beginner that CISSP is the number one cybersecurity certification is technically true and practically useless. The letters you paid for are not the letters you get to put on your resume.

A certification you cannot hold yet is not a credential. It is a deposit on one.

What the exam actually measures is in why the CISSP tests judgment and not recall, and the timing question, which is really “when do I stop being an engineer,” is in Security+ to CISSP and when to make the jump.

Stage 3b: audit, risk, and governance, ISACA CISA

Worth the full name at least once, because it collides with something else: ISACA CISA is the Certified Information Systems Auditor from ISACA. It is not the US Cybersecurity and Infrastructure Security Agency, also abbreviated CISA, which confusingly runs one of the certification catalogue pages ranking on this exact search.

ISACA CISA is the audit and assurance credential: control design, evidence, governance, and the discipline of assessing a system rather than fixing it. If your career is bending toward IT audit, risk, or GRC, this is the one that carries weight, and CISSP is not a substitute.

The same experience gate applies, harder. Full certification requires around five years of professional experience in information systems auditing, control, or security, with education-based waivers that can bring it to roughly two. You can sit the exam any time. It is also the most expensive exam on this page at $575 for ISACA members and $760 for non-members, before study materials, with continuing education obligations after that.

The useful question is not whether it is worth it in the abstract but whether it is worth it from where you stand, which I broke down in is the ISACA CISA worth it, by where you actually are. ISACA’s CISM sits alongside it for the pure management and governance track.

What I would never take first, and why

This is the section every roundup owes you and none of them write, because “do not buy this yet” is a bad business model. Each of these has a documented reason, not a vibe.

Never CISSP as your first certification. Not because it is too hard, but because of the five-year rule. Pass it at year one and you are an Associate of ISC2 for four more years. You have spent the money and the study months to arrive at a credential you cannot yet claim, while a hiring manager filtering for entry-level roles is scanning for Security+ anyway.

Never ISACA CISA as your first certification. Same trap, higher price. Five years of information systems audit, control, or security experience, education waivers notwithstanding, and the most expensive exam here. If you want the audit track, get into the work first and let the employer fund the exam, which many of them do.

Never A+ if you are already working in IT. It is a recommended prerequisite, not a required one, and its whole job is to prove you can do work you are demonstrably already doing. Spend that money on Network+ or Security+ instead.

Never a certification before you have somewhere to use it. This one is opinion rather than documented fact, so weigh it as such. Every strong candidate I have interviewed could describe something they built or broke. Every weak one had a longer certification list. A home lab, a CTF, a documented project, one real incident you can narrate: those are what turn a credential into an interview.

Never exam dumps. They are the fastest route to passing an exam and failing the interview it was supposed to get you, and on judgment-based exams like CISSP they actively train the wrong instinct. I went into why, and what I would use instead, in why I would never touch exam dumps.

The uncomfortable part: only two of these are beginner-friendly

If you searched “cyber security certifications for beginners” or “beginner security certifications” to get here, this is the honest cut, and it is smaller than the lists suggest.

I build practice question banks for five of the certifications on this page, so let me be straight about what that catalogue looks like when you order it by who can actually use it.

A+ and Network+ are genuinely beginner-friendly. No experience gate, no assumed foundation beyond curiosity, and a clear path from studying to a first job.

Security+ is entry-level for security and is not a beginner exam. There is no formal prerequisite, which is a real advantage, but the material assumes networking fluency. Calling it beginner-friendly is how people end up eight weeks into a course wondering why subnetting keeps appearing.

CISSP and ISACA CISA are not beginner certifications in any meaningful sense, because the credential itself is gated behind five years of work. Selling either as a starting point would be selling a deposit.

So of the five certifications I build prep for, two are genuinely beginner-friendly, one is entry-level with an assumed foundation, and two you should not touch for years. That is a worse sales pitch than the roundups make, and it is the accurate one.

Common questions

What are the top 5 cybersecurity certifications? By stage rather than popularity: A+ if you are outside IT entirely, Security+ as your first security credential, CySA+ or a hands-on offensive credential as your specialisation, CISSP for the senior and management track, and ISACA CISA for audit and governance. That ordering beats any ranked list, because four of the five are wrong for you at any given moment.

Which cybersecurity certifications are worth getting? The one that matches the job title you want next. A certification is worth getting when it either clears an HR filter you are currently failing or teaches you something you will use within six months. The ones bought for neither reason are the ones people regret.

What is the highest paying cybersecurity certification? I do not have salary data of my own and I will not repeat another site’s numbers as though I verified them. Structurally, certification salary tables are correlation dressed as causation. CISSP holders earn more than Security+ holders largely because CISSP holders have five or more years of experience, and the experience is doing most of the work. The certification is the ticket, not the engine.

Can you make $200,000 or $500,000 a year in cyber security? Both figures exist at the top end of the market, in specific roles, in specific cities, usually with equity attached. Neither is a certification outcome. Seniority, scarcity of skill, and where you work decide that number, and any page implying a credential moves you into that band is selling something.

Is CISSP still worth it? For the senior and management track, yes, and the five-year requirement is a large part of why: the gate is what keeps the signal meaningful. It is worth nothing to someone at year one, which is the context most answers strip out.

Can I get a cybersecurity job with just a certification? Sometimes, and it is not the way to bet. Security+ plus a demonstrable project beats Security+ alone by a wide margin, and the realistic timeline from a standing start is longer than most roundups imply. I wrote an honest version of it in how long it really takes to go from zero to Security+.

Where I would actually put your next hundred dollars

Take the ordering rule if nothing else: buy the certification that matches the stage you are standing on, not the one at the top of somebody’s list. Almost every wasted certification I have watched someone buy was bought one or two stages ahead of where they were.

The practical version is to find out where you are before you commit. Sit one full-length timed practice exam for the certification you are considering, cold, before you buy a course. If the fundamentals rather than the details are what break you, you are a stage early and Network+ or A+ is the better purchase.

That diagnostic-first order is why I built PrepClubs the way I did. Every certification cluster starts with a free full-length diagnostic, and the paid banks sit deliberately behind it: A+, Network+, and Security+ at $69 each, CISSP at $89, and ISACA CISA at $99, one-time rather than a subscription, with a pass guarantee. I am obviously biased about the platform. I am not biased about the sequence: take the free diagnostic first, and if it says you are a stage early, the right move is to not give me your money yet.

For the full ladder in one place, the companion piece is the CompTIA certification path and how I would study for each.

Published by

Junaid Khalid

CEO @ Ertiqah Building AI tools for Early-Stage founders, agency owners & solopreneurs.

Leave a ReplyCancel reply

Exit mobile version