A Cyber Security Certification Roadmap

Certifications are a map, not the territory. Here is which ones move the needle.

July 7, 2026

Certifications do three different jobs, and confusing them is why people waste money. Some get you past a resume filter. Some teach you something. Some prove you can actually do the work.

Very few do all three.

What Certifications Are Actually For

The honest first purpose is getting through automated resume screening and human resources filters. That is a real and legitimate benefit, and it is the main value of the entry level ones.

The second purpose is structured learning. A certification syllabus is a curriculum somebody designed, which is useful when you do not know what you do not know.

The third is proof of ability, and only the practical, lab based exams do this. A multiple choice exam proves you can recognize a correct answer.

Starting Out

CompTIA Security+ is the standard first certification. It is broad, it is recognized by human resources departments almost everywhere, and it appears in United States government requirements. It will not teach you to do the job and it will get your resume read.

CompTIA Network+ is worth considering first if your networking is weak, because everything else assumes it. Alternatively, do the networking work properly in a course such as the mentorship foundations and skip the certificate.

Cloud fundamentals such as AWS Cloud Practitioner or Microsoft AZ-900 are cheap, quick, and increasingly expected.

Flow diagram of a certification sequence: one broad entry certification, then demonstrated hands on work, then one practical certification, with management certifications later.
An Order That Works

Defensive Track

CompTIA CySA+ and the Blue Team Level 1 certification from Security Blue Team both aim at SOC analyst work, and the latter is more hands on.

GIAC certifications from SANS, such as GCIH for incident handling and GCIA for intrusion analysis, are widely respected and very expensive. They are usually employer funded rather than self funded.

Vendor certifications matter here more than people expect. If your target employer runs Splunk or Microsoft Sentinel, the relevant vendor certification is a direct signal. See SIEM and Splunk explained.

Offensive Track

CEH is recognized broadly, appears in job listings and some government requirements, and is a multiple choice exam. It is good for filters and for structured coverage of the field.

OSCP from OffSec is the practical benchmark. The exam is a real lab with a time limit and a report to write, and passing it means something specific to hiring managers.

Hack The Box and TryHackMe both now offer practical certifications that cost less than OSCP and are gaining recognition. They are a reasonable stepping stone.

Cloud and Systems

AWS Certified Security Specialty, Microsoft SC-200 for security operations and AZ-500 for Azure security, and Google Professional Cloud Security Engineer are all worth real money in the market because cloud security demand consistently exceeds supply.

On the systems side, RHCSA and RHCE are entirely practical exams. They are not security certifications and they prove something valuable, which is that you can actually run the systems you claim to defend.

Later, With Experience

CISSP requires five years of documented experience and is the standard credential for senior and management roles. Taking the exam without the experience gives you Associate status, which is a reasonable move but not the same thing.

CISM is aimed at security management, and CISA at audit. Both fit people moving toward leadership or GRC.

What Nobody Tells Beginners

A stack of certifications with no demonstrated work is a recognizable pattern to hiring managers, and not a good one. It reads as someone who studied instead of doing.

One certification plus a portfolio of things you actually did beats four certifications and nothing else, reliably.

Certifications also expire and require continuing education credits and annual fees, which is a cost people forget when planning.

The order that works for most people is: one broad entry certification, then real hands on work you can talk about, then one practical certification in your chosen direction. See building a home lab.

Learn This at HackRange

Week 13 of the mentorship covers this in detail, including which certifications your target employers in South West Florida actually ask for.