Foundational
General IT and security groundwork. Signals that you understand the vocabulary and the basics of how systems are defended.
Cyber Certifications
A cybersecurity certification proves knowledge against a defined standard. It does not prove you can perform the work. Start with the credential your target role or employer requires, then progress from foundational to role-specific and specialist certifications. Compare cybersecurity certifications by role, skills, and job family, and find the training that prepares you for each.
What order
Cybersecurity certifications generally fall into four bands, each signaling something different to employers. The common pathway moves from foundational to role-specific, specialist, and leadership credentials. Your target role and existing experience determine where you should start.
General IT and security groundwork. Signals that you understand the vocabulary and the basics of how systems are defended.
Detection, response, and security operations. Signals readiness for a named analyst role rather than general awareness.
Program ownership, risk, and management. Usually carries documented experience requirements set by the certifying body.
Training available
Training aligned to the published exam objectives for each credential, with hands-on practice alongside the theory. More credentials are added as courses are released.
Foundational band
Broad security fundamentals: threats, architecture, operations, governance, and incident response basics.
Commonly asked for in entry-level security and analyst job postings.
Roles it supports
Leadership and governance band
Security program design, risk management, and governance across eight domains.
Asked for in senior engineering, architecture, and security management roles.
Roles it supports
Not every credential in the pathway above is one we train for. Where another provider is the right answer, the comparison below says so.
Side by side
Read down the level column if you are working out where to start, or across a single row if you already have a credential in mind.
| Certification | Level | Who it suits | Core skills covered | Roles that ask for it | Prerequisite |
|---|---|---|---|---|---|
| CompTIA A+ | Foundational | Entering technology with no IT background | Hardware, operating systems, endpoint support | IT Support Technician | None |
| CompTIA Network+ | Foundational | Building infrastructure grounding first | Networking, routing, segmentation, troubleshooting | Network Engineer, IT Support | None |
| CompTIA Security+ | Foundational | Entering security from IT or from scratch | Threats, architecture, operations, governance basics | SOC Analyst, Security Analyst | None |
| CompTIA CySA+ | Role-specific | Moving into detection and response work | Threat detection, log analysis, incident response | SOC Analyst, Detection Engineer | Security+ recommended |
| Microsoft SC-200 | Role-specific | Working in a Microsoft security stack | Sentinel, Defender, threat mitigation | SOC Analyst, Security Engineer | None stated |
| ISC2 CCSP | Specialist | Specializing in cloud security | Cloud architecture, data security, cloud operations | Cloud Security Engineer | Documented experience |
| ISC2 CISSP | Leadership | Moving into management, architecture, or governance | Risk, security program design, eight domains | Security Manager, Architect | Documented experience |
Security+ or CySA+ next? The detailed comparison lives in our certifications guide
Role first
Certification pathways start with credentials, but hiring starts with roles. Begin with your target role, then identify the credential employers request. The certificate may clear the filter, while the skills behind it matter in the interview.
Security+ to get past the filter, CySA+ or SC-200 to signal readiness for the work itself. Detection logic and log analysis matter more in interview than either credential.
Security+ early, then depth. Employers weigh architecture and automation experience heavily, and often accept engineering background in place of a named credential.
CCSP where governance is central, or a platform credential where a specific cloud is. Hands-on cloud experience is rarely substitutable.
CEH satisfies some filters, but practical testing evidence carries further. Check what the job postings you are targeting actually list.
CISSP and CISM are the common asks, both with documented experience requirements. These are later-career credentials rather than entry points.
An honest limit
Certifications pass hiring filters and prove knowledge against a defined standard. Many roles require them. Employers also look for evidence you can apply that knowledge through projects, assessment results, and verified skills. Pair the credential with proof of capability.
The training
Courses are built against the published exam objectives for each credential, with hands-on practice alongside the theory so you are not only preparing to pass. Afterwards, you can verify that you can apply the skills, track the credential, and add both to your Skills Wallet.
Course structure follows the certifying body’s published objectives, not a generic syllabus.
Applied exercises alongside the theory, so the knowledge has somewhere to attach.
Optional skills verification afterwards, recording that you can do the work and not only pass the exam.
The credential and the verified skills are recorded together, with renewal dates tracked.
Frequently asked questions
Which credential, in what order, and what a certification can and cannot do for you.
Your next step
Training built against the published exam objectives, with the practice and verification
that make the credential worth more than the certificate.