Most cybersecurity certification roadmaps you will find are a wall chart with sixty logos on it, sorted by vendor. That is a catalogue, not a roadmap. It tells you what exists. It does not tell you what to sit next.
Here is the short version. Start with ISC2 CC or CompTIA Security+, depending on whether you have any IT background. Spend a year in a job. Then pick one branch, defensive, offensive, cloud or governance, and take the one certification that proves it. Senior credentials like CISSP and CISM come after you have the experience they require, not before, because both will hold your certificate hostage until you do.
The sequencing matters more than the logos. What follows is the order that works, the experience gates that decide when you are allowed to move, and the four things that changed in 2026 and quietly invalidated most of the advice still ranking on this topic.
What changed in the cybersecurity certification roadmap in 2026
Four changes this year matter enough to redraw the map.
ISC2 CC is no longer free. This is the big one, and almost every roadmap still says otherwise. New enrolments in the One Million Certified in Cybersecurity programme closed on 20 May 2026. If you received a free voucher before that date you can still sit the exam up to 31 December 2026. Everyone starting now pays $199 for the exam plus a $50 annual maintenance fee. The "just take CC, it costs nothing" advice is a year out of date.
The CC exam outline changed on 1 September 2026. It is the first substantial content update since the certification launched in 2022, and it threads foundational AI topics through the whole outline. Study material written before September is describing a different exam.
CySA+ has two live versions right now. CS0-004 launched on 23 June 2026 and CS0-003 retires on 22 December 2026. Until that date you can sit either one and your certificate says "CompTIA CySA+" regardless. After it, only CS0-004 exists. If you are mid-study on CS0-003, finish it. If you are starting now, start on CS0-004.
The CISSP experience waiver was cut. ISC2 tightened which certifications buy you a year off the five-year experience requirement. If you were banking on an older credential to shorten the gate, check it before you plan around it. We covered the detail in what the CISSP experience waiver change means for CEH, CISA and OSCP holders.
One change that has not happened yet, despite widespread reporting: Security+ SY0-801. Training vendors and instructor forums point to a November 2026 release, but CompTIA has not officially confirmed a launch date. SY0-701 is the live exam today. Do not stall a study plan waiting for a version that has no confirmed date, which is the argument we made in full in SY0-801 vs SY0-701.
Tier 1: where to actually start
Two certifications belong at the entry point, and which one you take depends on a single question: do you already work in IT?
ISC2 CC, if you are coming from outside IT
CC is 100 multiple-choice questions in 120 minutes, with a pass mark of 700 out of 1000. The five domains are Security Principles (26%), Network Security (24%), Access Controls (22%), Security Operations (18%), and Business Continuity, Disaster Recovery and Incident Response (10%).
It assumes no prior experience and no prerequisites. That makes it the right first exam for career changers, helpdesk staff moving sideways, and students. It will not get you hired on its own. It gets you literate enough that the Security+ material stops looking like a foreign language.
CompTIA Security+, if you have a year or two of IT behind you
Security+ SY0-701 runs up to 90 questions in 90 minutes with a pass mark of 750 on a scale of 100 to 900. It is the baseline credential that appears in more junior security job adverts than anything else, and it satisfies the DoD 8140 requirements for several work roles.
If you already hold A+ or Network+, or you have done a couple of years on a service desk, skip CC and go straight here. Taking CC first in that situation costs you $199 and six weeks to prove something your CV already proves.
Exam Tip: Both exams reward the same study pattern, which is timed practice questions from week one rather than reading cover to cover and testing at the end. People who leave practice questions until the final fortnight discover their recognition of a term does not survive contact with a scenario.
The full comparison, including who each one actually suits, is in ISC2 CC vs CompTIA Security+.
Tier 2: pick one branch and prove it
This is where roadmaps usually fail people. They present tier two as a menu of eight certifications and imply you should collect them. You should take one. Employers hire for a role, and a second lateral certification at the same level reads as avoidance of the first job.
Choose the branch that matches the job you want, not the one with the best-looking badge.
| Branch | Take this | Format | Who it suits |
|---|---|---|---|
| Defensive / SOC | CompTIA CySA+ (CS0-004) | Up to 85 questions, 165 minutes, 750/900 | Alert triage, detection engineering, incident response |
| Offensive | CompTIA PenTest+ (PT0-003) | Up to 90 questions, 165 minutes, 750/900 | Testing, red team, vulnerability assessment |
| Cloud security | Microsoft SC-200 or a cloud-native equivalent | Vendor-specific | Anyone whose estate is Azure, AWS or GCP first |
| Governance and risk | ISACA CRISC or CISA | 150 questions, 240 minutes | Audit, risk, compliance, GRC analyst roles |
CySA+ is the most common tier-two step because defensive roles are the most common tier-two jobs. It is analyst work made examinable: log analysis, threat intelligence, vulnerability management and incident response, tested partly through performance-based questions rather than recall. The version question is settled in CySA+ CS0-004 vs CS0-003.
PenTest+ (PT0-003) launched in December 2024 and assumes three to four years in a testing role. It is a genuine step up in expected hands-on ability, not a sideways move from Security+.
If your target is specifically a SOC seat, the branch has its own sequencing considerations now that tier-one triage is increasingly automated, which we worked through in the SOC analyst certification path for 2026.
Tier 3: the senior certifications, and the gates on them
Both flagship senior credentials have experience requirements that are enforced at certification, not at the exam. You can sit and pass either one with no experience at all. You simply do not become certified. ISC2 calls that status an Associate, and you hold it until you can evidence the years.
CISSP is a computer-adaptive exam of 125 to 175 questions in 240 minutes, passing at 700 out of 1000. The gate is five years of paid work across at least two of the eight domains. A four-year degree waives one of those years. CISSP is the credential that appears in more senior security job adverts than any other, and it is the reason most people build a roadmap in the first place.
CISM is 150 questions in 240 minutes, passing at 450 on a 200 to 800 scale. The gate is five years total with at least three specifically in information security management across three or more of its domains. Its content outline changes on 3 November 2026. CISM is the management credential: less technical breadth than CISSP, far more emphasis on running a programme, governance and incident management as a leadership function.
CCSP sits alongside rather than above these, for cloud security specialists. Its exam outline was revised effective 1 August 2026, so pre-August study material is stale.
The practical implication of the gates is that tier three is a two to five year problem, not a next-quarter one. Passing CISSP in year two of your career gets you an Associate status and a renewal fee. It does not get you the letters after your name. Plan tier three around when you will have the experience, and use the intervening time on tier two and on the job that generates the years.
The AI security tier, and whether you need it yet
A genuinely new layer appeared in 2026 and no roadmap written before this year contains it.
CompTIA SecAI+ (CY0-001) launched on 17 February 2026 at around $425. It has no hard prerequisites, but CompTIA recommends three to four years of IT experience, at least two years hands-on in security, and Security+, CySA+ or PenTest+ first. It sits parallel to tier two rather than replacing it.
ISACA AAISM is 100 questions in 120 minutes, passing at 450 on a 200 to 800 scale, priced at $459 for members and $599 for non-members. It has a hard prerequisite: an active CISM or CISSP at the time of application. That places it firmly above tier three, not inside it.
The honest answer on timing is that neither belongs in your first three certifications. Both assume you already hold the security fundamentals they build on, and AAISM structurally cannot be your entry point. If you are choosing between them later, SecAI+ vs AAISM sets out which suits which role.
The full cybersecurity certification roadmap at a glance
| Tier | Certification | Experience gate | Typical timing |
|---|---|---|---|
| 1 | ISC2 CC | None | Month 0, no IT background |
| 1 | CompTIA Security+ | None enforced | Month 0 to 6, some IT background |
| 2 | CySA+, PenTest+, SC-200, CRISC or CISA | Role dependent, none enforced | Year 1 to 2 |
| 2.5 | CompTIA SecAI+ | None enforced, security fundamentals assumed | Year 2 onwards |
| 3 | CISSP | 5 years across 2 of 8 domains | Year 5 |
| 3 | CISM | 5 years, 3 in security management | Year 5 |
| 3 | CCSP | 5 years, 3 in infosec, 1 in a cloud domain | Year 5 |
| 4 | ISACA AAISM | Active CISM or CISSP required | Post-CISSP or post-CISM |
Three mistakes that stall people on this roadmap
Collecting tier-one certifications. CC, then Security+, then a vendor fundamentals badge, then a free course certificate. Four credentials, all proving the same level of knowledge. One tier-one certification and a job beats four tier-one certifications and none.
Sitting CISSP too early. The exam does not check your experience. The certification does. People pass, receive Associate status, pay the maintenance fee for three years, and gain nothing they could not have gained by taking the exam later with the experience already banked.
Studying a retired or superseded objective set. This year alone that risk applies to CC (outline changed 1 September), CySA+ (CS0-003 retires 22 December), CCSP (outline revised 1 August) and CISM (outline changes 3 November). Check the version code on your study material against the version code on the exam you have booked. It is a two-minute check that prevents a wasted eight weeks.
Frequently Asked Questions
What is the best certification path for cybersecurity?
Start with ISC2 CC if you have no IT background, or CompTIA Security+ if you have one to two years of IT experience. Work in the field for a year, then take one tier-two certification matching your chosen branch, most commonly CySA+ for defensive roles. Take CISSP or CISM at around the five-year mark when you can satisfy their experience requirements.
What is the best first certificate for cybersecurity?
For career changers with no IT experience, ISC2 CC is the best first certificate because it assumes no prior knowledge and has no prerequisites. For anyone already working in IT, CompTIA Security+ is the better first certificate, since it carries far more weight in job adverts and you already have the background to handle it.
What is the easiest cyber security certification to get?
ISC2 CC is the easiest recognised security certification, with 100 multiple-choice questions, no performance-based questions and no experience requirement. It is no longer free, however, following the closure of new One Million Certified in Cybersecurity enrolments on 20 May 2026. It now costs $199 plus a $50 annual maintenance fee.
Can I make $200,000 a year in cyber security?
It is achievable, but not through certifications alone. Salaries at that level generally sit with senior architects, principal engineers and security leadership in high-cost markets or specialised sectors such as finance. CISSP and CISM appear frequently in those job adverts, but they act as a filter you have to pass rather than the reason for the salary. The experience behind them is what is being paid for.
Is 40 too old to get into cyber security?
No. Career changers entering at 40 usually arrive with something a graduate does not have, whether that is systems administration, networking, audit, project management or industry domain knowledge. Security roles draw heavily on that context. The roadmap is the same, though the entry point often is not: people with an existing IT background should generally start at Security+ rather than CC.
Ready to Start Practising?
Every certification on this roadmap is passed the same way, which is timed practice against exam-style questions until the scenarios stop surprising you. Reading alone produces recognition. Questions produce recall under time pressure, and only one of those is tested on exam day.
CertCrush has full practice question banks for the certifications on every tier of this roadmap, including ISC2 CC, CompTIA Security+, CompTIA CySA+ CS0-004, CompTIA PenTest+, CISSP, CISM and CCSP.
Work out which tier you are on, pick the one certification that moves you to the next, and start practising. Create a free CertCrush account and begin with the exam you have actually booked.
