Skip to main content
Cybersecurity Certifications Roadmap: CompTIA to CISSP
securitycertificationscybersecuritylearning-roadmapscareer-exploration

Cybersecurity Certifications Roadmap: CompTIA to CISSP

The certification ladder from CompTIA to CISSP stage by stage: 2026 exam costs, experience requirements, and the order that gets career changers hired.

Vladislav KovnerovAugust 27, 20269 min read
Share

The mandatory part of a cybersecurity certification path is two exams long: CompTIA Security+ to get hired, and CISSP years later, once the experience is behind you. Everything between those two rungs is a choice, and one rule explains most of the schedule. ISC2 will not certify you as a CISSP until you show five years of cumulative, full-time experience in two or more of its eight domains, and no exam substitutes for that time. Study the ladder around the clock you are also spending inside a real security job.

This matters because the field pays and screens hard. Information security analysts earn a median of $124,910, with employment projected to grow 29 percent from 2024 to 2034, and recruiters filter the resulting queue of applicants with certification checklists. This roadmap walks the ladder rung by rung, with 2026 exam prices and the experience requirement attached to each step.

Why the order matters more than the listPermalink to “Why the order matters more than the list

Large employers, including every U.S. defense contractor, staff security roles against the Department of Defense's DoDM 8140.03 approved-credential list. CC and SSCP carry that approval directly on their ISC2 product pages, and Security+ maps to a long list of DoD 8140 work roles, from cyber defense analyst to incident responder. Hiring software screens for those exact strings, so a certification earned out of sequence is a certification that does nothing for the applications you are sending now.

The second reason is money. CompTIA raised its voucher prices in May 2026, putting Security+, CySA+, and PenTest+ at $439 each and SecurityX at $544. An exam bought for the wrong rung is $400 or more spent on a credential you will not use.

The ladder at a glancePermalink to “The ladder at a glance

RungCertification2026 exam costExperience requiredWhat it is for
0ISC2 CC$199NoneCheap orientation and a first line for an empty resume
0, conditionalCompTIA A+$274 per exam, two examsNoneOnly if you have never worked in IT
0, conditionalCompTIA Network+$399NoneOnly if networking is genuinely new to you
1CompTIA Security+$439NoneThe baseline employers and DoD 8140 screen for
2CompTIA CySA+ or PenTest+$439None requiredSpecialization: defensive analytics or offensive testing
2, alternativeISC2 SSCP$2491 year in security operationsAn ISC2 credential mid-ladder
3, technicalCompTIA SecurityX$544None required, 10 years in IT recommendedSenior technical and architecture roles
3, leadershipCISSP$7495 years in 2+ of 8 domainsSenior, lead, and management roles

CompTIA prices are U.S. retail voucher prices after the May 2026 increase; ISC2 prices come from the official exam pricing page.

Stage 0: the cheap on-ramp, if you need onePermalink to “Stage 0: the cheap on-ramp, if you need one

ISC2's CC exists for people who want proof they are serious before they commit $439. It requires no work experience, covers five foundation domains, and costs $199. One warning, because outdated advice is everywhere: the CC exam is no longer free. The One Million Certified in Cybersecurity pledge that covered training and the exam has concluded, and the exam now runs $199 plus a $50 annual maintenance fee. Any article telling you otherwise was written before May 2026.

Below CC sit A+ and Network+. Skip both if you already work with systems, networks, or infrastructure in any capacity, because your experience answers what those exams teach. Take A+ ($274 per exam, and it takes two exams) only if you have never held an IT job and want help-desk work as your entry. Take Network+ ($399) only if terms like subnet or packet still feel foreign, because every later exam assumes that vocabulary.

Stage 1: Security+ is the first rung that changes your applicationsPermalink to “Stage 1: Security+ is the first rung that changes your applications

Security+ (SY0-701) asks up to 90 questions in 90 minutes, with a passing score of 750 out of 900 across five domains: general security concepts at 12 percent, threats and mitigations at 22, architecture at 18, operations at 28, and program management at 20. No experience is required, and the credential opens the exact job filters that entry-level security postings use.

I had a head start on this exam without planning one. Years of running HealthTech infrastructure as a systems administrator had already drilled me on access reviews, patch cycles, and reading logs when something looked wrong, which is most of what Security+ examines. Studying for it felt like revision with new vocabulary attached, not a new subject. If your current job touches systems, networks, or compliance reporting, open the official exam objectives and mark the tasks you already do weekly. The marked lines tell you how close you are to sitting the exam, and a 90-day study plan structured around those gaps fits Security+ preparation almost perfectly.

For how the certification fits the wider switch, including roles, salaries, and lab platforms, read the complete cybersecurity career change guide. This article stays on the ladder itself.

Stage 2: specialize toward the job you wantPermalink to “Stage 2: specialize toward the job you want

After Security+ the ladder forks, and the fork should follow your target postings, not your mood. CySA+ is the defensive branch, built around threat detection, analytics, and response, and it is the natural second cert for SOC and analyst roles. PenTest+ covers the offensive branch, and both sit at $439. The third option is ISC2's SSCP at $249, which differs from the CompTIA pair in one way that matters: it requires one year of paid work in security operations, so it certifies what you have done rather than what you studied.

Here is the detail most roadmaps miss. Every cert in this tier does double duty, because ISC2's approved-credential list includes Security+, CySA+, SecurityX, and the SSCP, and holding any one of them satisfies one full year of the CISSP experience requirement. A relevant degree has the same effect. The waivers do not stack, so plan on four years of paid security work as your realistic minimum even with the right credential in hand.

Stage 3: CISSP is an experience gate, not an examPermalink to “Stage 3: CISSP is an experience gate, not an exam

The exam itself costs $749. The gate around it is the five years, accumulated monthly at a minimum of 35 hours per week for four weeks per month, across at least two of the eight CISSP domains. Two details work in a career changer's favor: part-time work counts at a documented rate of 1,040 hours equaling six months, and internships count too, paid or unpaid, as long as they are documented on company letterhead.

If you pass the exam before the experience exists, you become an Associate of ISC2 with six years to earn the five. That path exists, and it rarely pays off for someone early in the switch, because the $749 buys a designation that entry-level hiring does not screen for. The cert earns its price at the other end: CISSP holders report a median of $127,000 globally and $150,000 in North America.

Two branches sit beside the top rung. SecurityX ($544) is CompTIA's expert-level certification for senior technical roles, recommended for people with about 10 years in IT. If your direction is cloud security, ISC2's CCSP at $599 is the later fork.

What the ladder costs, and what it paysPermalink to “What the ladder costs, and what it pays

The mandatory spine is $1,188: $439 for Security+, $749 for CISSP. Add the CC orientation step and one $439 specialization and the exam total lands near $1,830, with study materials adding a few hundred dollars depending on how much you self-study. Against a field paying a $124,910 median, that ratio explains why self-study plus one exam at a time is the standard route for career changers. The cybersecurity engineer salary page breaks the pay ranges down by region and seniority so you can run the numbers for your market.

One honest caveat belongs next to every price above. Certifications get you past the filter; they do not get you hired on their own. What convinces a hiring manager is proof you can do the work, and the tradeoffs between collecting credentials and building that proof are laid out in certificates vs portfolio for career changers.

Mistakes that add years to the climbPermalink to “Mistakes that add years to the climb

Sitting CISSP first. The instinct is understandable, because CISSP has the strongest brand. But the Associate designation is a weak signal early in a switch, and the exam assumes operational experience across the eight domains that no course can simulate.

Collecting entry-level certs in a row. A+ into Network+ into CC into Security+ feels like progress and reads like stalling. Once Security+ is passed, the next rung is a job, and the specialization cert comes after a year of real work, informed by it.

Paying for retake bundles as motivation. The May 2026 increase hit retake bundles hardest: Security+ with a retake voucher now runs $579, up $105. Buy the single voucher, prepare properly, and keep the difference.

Waiting until the ladder is finished to apply. Applications should start the week you pass Security+, not after CISSP. The sequencing of study, search, and first security-adjacent work is what sets your calendar, and the career change timeline method shows how to estimate it from your starting skills.

How Traecta helpsPermalink to “How Traecta helps

Traecta — Your Personalized Career Roadmap turns this ladder into a sequence fitted to your history. Tell it you have five years of sysadmin work and it crosses out A+, Network+, and CC, starts you at Security+ with a short review of the domains you already practice, and schedules CySA+ only if your target postings name it. Tell it you are coming from nursing or teaching and the same ladder starts one rung lower and moves at a pace that fits a full-time job. The plan carries the exam dates, the study weeks between them, and the portfolio work that runs alongside, so nothing waits on a decision you already made.

Key takeawaysPermalink to “Key takeaways

  • Security+ is the only mandatory early certification. Everything below it is conditional on your background, and everything above it is conditional on your direction.
  • Intermediate certs pay twice: once in hiring filters, and once as a one-year waiver toward the CISSP experience requirement.
  • CISSP is a five-year clock you start by getting hired, not by enrolling. Buy exams in the order the clock needs.

Run the ladder against your own work history, and your Traecta career roadmap will show which rungs you can skip and which exam belongs in your next 90 days.

Frequently asked questions

Career guides, every two weeks

New articles on switching careers and building your roadmap — delivered to your inbox twice a month. No spam; unsubscribe anytime.

Related articles