Skip to main content

Back to Resources

Cybersecurity certifications

Cybersecurity certifications:
which to get and in what order

A clear map of the options, how to choose for your goal and stage, and where to train.

The short answer

What are cybersecurity certifications?

  • Entry

    Security+ and foundations

  • Intermediate

    CySA+, CEH and GIAC

  • Advanced

    CISSP and CCSP

  • Issuers

    CompTIA, ISC2, GIAC

  • Roadmaps

    SOC, cloud, GRC paths

  • Training

    Prepare on Learn

The landscape

The main cybersecurity certifications

Mapped by domain and level. Each entry links to its Learn page where one exists, or to the issuing body.

The main cybersecurity certifications
Certification Issuer Level Where it links
CompTIA Security+ Issuer CompTIA Level Entry Where it links CompTIA Security+ on Learn
CompTIA CySA+ Issuer CompTIA Level Intermediate Where it links Learn certification hub Issuer
CISSP Issuer ISC2 Level Advanced Where it links CISSP on Learn
CCSP Issuer ISC2 Level Advanced · cloud Where it links Learn certification hub Issuer
CEH Issuer EC-Council Level Intermediate Where it links Learn certification hub Issuer
GIAC certifications Issuer GIAC Level Intermediate → advanced Where it links Learn certification hub Issuer

Levels are general guidance. Confirm current prerequisites, CE requirements and exam versions with the issuing body.

How to choose

Which certification should you get first?

Start from your stage and goal — entry level to Security+, advanced to CISSP.

Certification roadmap by career path

It depends on your career stage and goal. If you are new to security, CompTIA Security+ is the usual starting point because it covers broad fundamentals and appears often in entry-level job requirements. If you already work in security, choose the credential that matches the direction you want to go next.
There is no single ranked list. The right certification depends on your domain and level: Security+ for entry-level foundations, CySA+ or CEH at intermediate level, GIAC for specialist depth, and CISSP or CCSP for advanced security and cloud roles. Use the map above to match a credential to where you are and where you want to go.
Not always. Many employers use certifications as a hiring filter, but they also look for evidence you can do the work, such as projects, assessment results and verified skills. The strongest applications pair a relevant certification with proof of capability. Our cybersecurity skills guide covers what employers look for.
Follow your career path. A common pattern starts with a foundational credential such as Security+, moves to an intermediate or role-specific certification for security operations, cloud or governance, and reaches advanced credentials such as CISSP once you meet their documented experience requirements.
Often, when a target role or employer asks for one and the knowledge is useful for the work. A certification proves you know a defined body of knowledge; it does not prove you can perform the role. Weigh the cost against the roles you are targeting and pair the credential with hands-on evidence.

Frequently asked questions

Certification questions,
answered

Short, direct answers to the questions people ask most.

Next step

Choose the right certification, then train for it