A role-based roadmap for selecting cyber security certifications according to foundation, hands-on capability, platform, governance and career direction.
Why a roadmap beats a shopping list
There are well over a hundred cyber security certifications, and most "top 10" lists rank them by salary without saying who they are actually for. A CISSP will not help someone with no experience get their first job — it formally requires five years of work first. An OSCP is superb evidence for a penetration tester and largely irrelevant for a compliance analyst.
The useful question is not "which certification pays most" but "which column am I in, and which tier am I ready for".
The four columns
| Column | Day-to-day work | Suits people who |
|---|---|---|
| Security operations | Monitor alerts, triage incidents, investigate, contain and write up what happened | Like puzzles, pattern-spotting and working through evidence under time pressure |
| Governance, risk & compliance | Map controls to standards, run audits, manage supplier risk, write and evidence policy | Are organised, write clearly and enjoy working across business teams |
| Offensive security | Test systems for weaknesses, run engagements, report exploitable findings | Enjoy taking things apart and are comfortable with long, frustrating problem-solving |
| Cloud security | Secure identity, network and workload configuration in AWS, Azure or GCP | Already have cloud or infrastructure background and want to specialise |
Most people should pick one column and go deep. Employers hire for a role, not for a badge collection.
Foundation tier (0–2 years)
CompTIA Security+
The most commonly requested entry-level certification in job adverts, and a US Department of Defense baseline requirement, which keeps demand high. Vendor-neutral and broad rather than deep.
- Cost: roughly $404 USD per attempt
- Study time: 8–12 weeks for someone with basic IT knowledge
- Prerequisites: none formally; CompTIA suggests Network+ knowledge first
- Learn: CompTIA official exam objectives — download these first and use them as your syllabus. Professor Messer publishes a complete free video course on YouTube that many candidates use as their primary resource.
ISC2 Certified in Cybersecurity (CC)
ISC2 has been offering this entry credential free (exam plus training) through its One Million Certified in Cybersecurity initiative. Worth taking purely because the price is zero and it builds governance vocabulary.
Professional tier (2–5 years)
| Certification | Column | Why employers value it |
|---|---|---|
| CompTIA CySA+ | Security operations | Analyst-level detection and response rather than definitions |
| Blue Team Level 1 (BTL1) | Security operations | Fully hands-on, 24-hour practical exam; strong evidence of real capability |
| ISO 27001 Lead Auditor | Governance | The standard most European buyers ask suppliers about |
| OSCP | Offensive | 24-hour practical exam under exam conditions; widely treated as the credibility line for pentest roles |
| AZ-500 / AWS Security Specialty | Cloud | Platform-specific security configuration, the fastest-growing demand area |
OSCP deserves a specific note: it correlates with among the highest offers in the field precisely because it cannot be passed by memorising question banks. Budget three to six months and expect the lab time, not the exam fee, to be the real cost.
Specialist tier (5+ years)
CISSP and CISM — the salary certifications
These are the two credentials that consistently show the largest measured pay premium, and both are management-track rather than technical.
| Credential | Experience required | Reported premium | Typical holder |
|---|---|---|---|
| CISSP (ISC2) | 5 years in 2+ domains | Around +20% on base, US medians commonly $150k–$185k | Security manager, architect, consultant |
| CISM (ISACA) | 5 years security management | +$20k–$28k typical | Security manager, GRC lead, CISO track |
| CCSP (ISC2) | 5 years IT, 3 in security | $140k–$170k US median | Cloud security architect |
The pairing of CISSP plus CISM is one of the highest-value combinations reported in the field, but both assume you already hold the underlying experience — neither is a shortcut into the industry.
- Learn: ISC2 CISSP · ISACA CISM
SANS/GIAC — excellent, expensive
GIAC certifications (GCIH, GCIA, GCFA) are widely respected and priced accordingly — courses commonly run into five figures. Realistically these are employer-funded. Do not self-fund a SANS course early in your career; the same money spent on a home lab plus OSCP will usually move you further.
What actually gets people hired
Certifications open the CV screen. They rarely close the interview. In practice hiring managers ask you to walk through something you have actually investigated, built or broken. Pair every certification with:
- A home or cloud lab you can describe from memory
- One written incident write-up, audit finding or engagement report — even from a self-built scenario
- A clear explanation of one thing you got wrong and what you changed
Frequently asked questions
Do I need a degree as well?
No. Requirements vary by employer and region, but cyber security is one of the more credential- and evidence-flexible parts of technology. Demonstrable capability, communication and relevant experience frequently substitute for a specific degree.
How many certifications should I hold?
At any given time, one current certification in your column plus visible practical work beats three unrelated ones. Renewals cost money and continuing-education credits, so collecting badges has an ongoing carrying cost.
Are the free and low-cost options credible?
Yes, at foundation level. ISC2 CC is free, Professor Messer's Security+ material is free, and TryHackMe and Hack The Box offer low-cost practical training that hiring managers recognise.

