If you search for a SOC analyst certification path, most of what you find was written for a job that no longer exists in quite the same form. The advice is usually some version of "get Security+, apply for Tier 1, work your way up". That route worked reliably until about 2024. In 2026 it does not, because the entry-level rung it depends on has been partly automated away.
This guide gives you the SOC analyst certification path as it actually works now: which certifications employers screen for, what order to take them in, what each one costs, and which ones are a waste of your money. It is written for someone aiming at a first or second security operations role, and it is honest about the fact that a single entry-level cert no longer clears the bar.
What Changed: AI Ate Tier 1 Triage
The reason the old advice fails is structural, not cyclical.
Gartner projected that roughly half of all Tier 1 SOC analyst positions would be eliminated or fundamentally transformed by automation. That prediction has largely played out. Detection and response vendors now claim their platforms handle the overwhelming majority of routine alert enrichment, categorisation and initial containment without a human touching it. Treat the vendor numbers with scepticism, but the direction is not in dispute: the repetitive queue-clearing work that used to be an entire junior job description is now mostly machine work.
Three consequences follow, and each one changes what you should study.
Employers raised the floor. More than 70% of SOC job postings now ask for two or more years of experience. When the easy tickets are automated, the remaining human work is the judgement-heavy part, so the job description drifts upward and the "entry-level" label stops meaning what it says.
AI fluency became a screening filter. Over 64% of cybersecurity job listings in 2026 require AI, machine learning or automation skills. That is not a niche preference any more. It is a keyword filter your CV either passes or fails.
The senior end got hotter, not colder. Demand for senior analysts and threat hunters is projected to grow by around 40% over the next three years. The pipeline problem is real: organisations still need Tier 3 people, but the training ground that used to produce them is thinner.
Reality check: The SOC analyst career is not disappearing. The unskilled version of it is. Certifications that prove you can investigate, reason about an adversary and work a modern detection platform are worth more than they were three years ago. Certifications that only prove you memorised vocabulary are worth less.
The 2026 SOC Analyst Certification Path at a Glance
Here is the full path with current pricing and the role level each certification realistically supports.
| Stage | Certification | Cost (USD) | Format | What it proves |
|---|---|---|---|---|
| Foundation | ISC2 CC | $199 | 100 to 125 items, CAT, 2 hours | Baseline security vocabulary, no experience needed |
| Baseline | CompTIA Security+ (SY0-701) | $439 | Max 90 questions, PBQs included | The cert HR filters on, DoD 8140 baseline |
| Core | CompTIA CySA+ (CS0-004) | $439 | Max 85 questions, 165 minutes | Detection, triage, vulnerability management, IR |
| Platform | Microsoft SC-200 | About $165 | 40 to 60 questions, 100 minutes | Sentinel, KQL and Defender, the tools you use daily |
| Differentiator | CompTIA SecAI+ (CY0-001) | $359 | Max 60 questions, PBQs included | Securing and working alongside AI systems |
| Practical | BTL1 or HTB CDSA | $490 / about $210 | Hands-on practical exam | You can actually run an investigation |
Prices are the direct vendor list price at the time of writing and exclude taxes, retakes and training bundles. CompTIA raised Security+ pricing to $439 as of 1 June 2026.
Stage 1: ISC2 CC, and the Free Ride That Ended
The ISC2 Certified in Cybersecurity is the sensible first step if you are coming from a help desk, a different industry, or nothing at all. It requires no work experience, which makes it genuinely open.
The exam is a computerised adaptive test of 100 to 125 items over two hours, with a scaled passing score of 700 out of 1000. The five domains are Security Principles (26%), Access Controls Concepts (22%), Network Security (24%), Security Operations (18%) and Business Continuity, Disaster Recovery and Incident Response (10%).
One important change: the ISC2 One Million Certified in Cybersecurity programme stopped accepting new enrolments on 20 May 2026. CC is no longer free for new candidates. The exam now costs $199 plus a $50 annual maintenance fee. If you enrolled before the cutoff and hold an unexpired code, you can still schedule and sit the exam until 31 December 2026. A lot of the advice still circulating online has not caught up with this.
Exam Tip: The ISC2 CC objectives are being refreshed on 1 September 2026. If you are studying now, check which version your exam date falls under before you buy a study guide.
Verdict: Worth it if you have no security background and need something on the CV inside a month. Skip it if you are already committed to Security+, because CC will not add much on top. We compared the two directly in ISC2 CC vs CompTIA Security+.
Stage 2: CompTIA Security+, Still the Filter You Have to Pass
Security+ is not the certification that gets you the SOC job. It is the certification that stops your CV being binned before a human reads it. That distinction matters, and it is why the cert still sits on this path despite being over-supplied.
Security+ remains the baseline credential most employers expect on a Tier 1 application, and it satisfies DoD 8140 baseline requirements for several cyber work roles, which makes it non-negotiable for anyone targeting defence or federal contractors. Our DoD 8140 guide maps which certification qualifies you for which work role.
The current SY0-701 exam has a maximum of 90 questions including performance-based questions, with a passing score of 750 on a scale of 100 to 900.
Version timing matters right now. CompTIA has signalled that SY0-801 will release on 17 November 2026, with a preview window in late October. CompTIA has historically let announced dates slip by three to six months, so treat that as provisional. If you plan to sit before the end of 2026, take SY0-701 and stop worrying about it. If your study runway pushes you into 2027, aim at SY0-801 instead.
Verdict: Mandatory, but understand what you are buying. Security+ on its own is now a floor, not a differentiator. Roughly everyone applying to the same Tier 1 posting has it.
Stage 3: CompTIA CySA+, the Actual SOC Analyst Certification
If you only take one certification from this list, take this one. CySA+ is the closest mainstream credential to the day job of a security operations analyst: log analysis, behavioural detection, threat intelligence, incident response and vulnerability triage.
The CS0-004 version launched on 23 June 2026 and replaced CS0-003. It has a maximum of 85 questions across 165 minutes, with a passing score of 750 on the 100 to 900 scale. The four domains and their weights are:
- Security Operations, 34%. The largest domain, covering detection, log analysis and threat hunting.
- Vulnerability Management, 26%. Scanning, prioritisation and remediation workflows.
- Incident Response and Management, 24%. Containment, eradication, recovery and forensics fundamentals.
- Reporting and Communication, 16%. Writing findings up for people who do not read packet captures.
CompTIA rewrote the objectives for CS0-004 to reflect how security teams actually operate in 2026: more cloud, more automation, more AI tooling and far more hybrid infrastructure. That is precisely the shift this article is about, and it is why CySA+ has aged better than its peers. We broke the changes down in CySA+ CS0-004 vs CS0-003.
CompTIA recommends around four years of hands-on experience in a SOC or vulnerability analyst role before sitting it. Very few candidates have that, and CompTIA does not enforce it. Do not let the recommendation put you off, but do expect the performance-based questions to punish pure memorisation.
Exam Tip: The Reporting and Communication domain is the one candidates skip and then fail on. It is 16% of the exam, which is more marks than most people lose anywhere else. Practise writing the finding, not just spotting it.
Verdict: The single highest-return certification on this path for a working or aspiring analyst. If you are deciding between this and going deeper on Security+, take CySA+. See CySA+ vs Security+ for the full comparison, and the CySA+ CS0-004 8-week study plan when you are ready to start.
Stage 4: Microsoft SC-200, Because Employers Buy Platforms, Not Concepts
Here is the gap in most SOC analyst certification roadmaps. They stack vendor-neutral certs on top of each other and never address the fact that on day one you will be sat in front of a specific SIEM, writing queries in a specific language.
For a very large share of organisations, that platform is Microsoft Sentinel. SC-200 is the certification that proves you can drive it.
The exam costs around $165 USD depending on region and requires a scaled score of 700 out of 1000 to pass. Expect roughly 40 to 60 questions in a 100-minute session. The weighting tells you everything about where to spend your study time:
- Mitigate threats using Microsoft Sentinel: 50 to 55%
- Mitigate threats using Microsoft Defender XDR: 25 to 30%
- Mitigate threats using Microsoft Defender for Cloud: 20 to 25%
Over half the exam is Sentinel, and a substantial part of that is KQL. If you can write Kusto queries confidently you will pass, and more importantly you will interview well, because interviewers ask candidates to talk through a query.
Verdict: The highest-leverage vendor certification on this path, and the one that most visibly separates two otherwise identical CVs. Pair it with CySA+ rather than choosing between them. Our SC-200 8-week study plan covers the current objectives.
Stage 5: CompTIA SecAI+, the 2026 Differentiator
This is the stage that did not exist on any roadmap two years ago, and it is the reason to revisit your plan if you built it before this year.
With over 64% of 2026 cybersecurity listings asking for AI, machine learning or automation skills, an AI security credential has moved from novelty to screening advantage. CompTIA SecAI+ (CY0-001) launched on 17 February 2026 as the first mainstream AI security certification from a major vendor-neutral body.
The exam costs $359, has a maximum of 60 questions including performance-based items, and requires a scaled score of 600 on the 100 to 900 range. There are no hard prerequisites, though CompTIA recommends three to four years in IT with at least two in cybersecurity, and suggests Security+, CySA+ or PenTest+ as useful background.
What makes it relevant to a SOC analyst specifically: the content covers securing AI systems, recognising AI-specific attack patterns such as prompt injection and model poisoning, and working effectively alongside automated triage rather than being replaced by it. That last point is the career argument in a single certification.
Verdict: Take it after CySA+, not before. It is a differentiator, and a differentiator only works when the fundamentals underneath it are solid. Read what jobs SecAI+ actually unlocks and the full domain and cost breakdown before committing.
Stage 6: Prove You Can Do the Job, Not Just Describe It
Multiple-choice certifications tell an employer you studied. Practical certifications tell them you can work an incident. Now that the easy tickets are automated, the second signal is worth far more than it used to be.
Blue Team Level 1 (BTL1)
$490 including the training material, labs and two exam attempts, finishing with a 24-hour hands-on practical. It is the best value practical blue-team certification available and it is widely recognised by hiring managers who have actually run a SOC. Start with the BTL1 study plan.
HTB Certified Defensive Security Analyst (CDSA)
Around $210 alongside an HTB Academy subscription, with a seven-day practical assessment and a written report. Harder than BTL1 and more respected in technical interviews, partly because the reporting requirement mirrors the real job. See the CDSA study plan.
The Alternatives, Honestly Assessed
| Certification | Cost | Verdict |
|---|---|---|
| ISACA CCOA | Mid-range | Strong, SOC-specific and gaining traction fast. A credible CySA+ alternative if you prefer ISACA. See our CCOA breakdown. |
| GIAC GSEC | High (SANS pricing) | Excellent content, but SANS courses routinely run $5,000 to $8,000. Only sensible if an employer is paying. |
| GIAC GCIH | High (SANS pricing) | The gold standard for incident handling and worth it on someone else's budget. GCIH study plan. |
| EC-Council CSA | Mid-range | Ranks well in search results, but carries less weight with hiring managers than CySA+ at a similar price. Skip unless an employer specifically asks. |
| Vendor SOC certs (Splunk, QRadar) | Varies | Take the one your target employer actually runs. Otherwise premature. |
The Order to Take Them In
If you are starting from zero and want a concrete sequence:
- ISC2 CC (optional, one month) if you have no security background at all.
- CompTIA Security+ (two to three months) to clear the CV filter.
- CompTIA CySA+ CS0-004 (two months) to prove analyst-level capability.
- Microsoft SC-200 (six to eight weeks) to prove platform capability.
- BTL1 or HTB CDSA (six to eight weeks) to prove you can run an investigation.
- CompTIA SecAI+ (four to six weeks) to differentiate on the skill everyone is now hiring for.
If you already work in IT and have Security+, skip straight to step 3 and treat steps 3, 4 and 5 as your priority. That combination, a vendor-neutral analyst cert plus a platform cert plus a practical, is what a modern SOC hiring manager is actually looking for.
And a warning worth repeating: certifications open doors, they do not walk you through them. We wrote about this at length in The Certification Trap. Build a home lab, write up investigations, and be able to talk through a real detection you tuned. The certificate gets you the interview. The evidence gets you the offer.
What SOC Analysts Actually Earn in 2026
Salary data varies wildly by source and methodology, so treat these as ranges rather than promises. Aggregators put the overall average for a SOC analyst in the United States at roughly $105,000 per year, with a typical tier breakdown of:
- Tier 1: approximately $70,000 to $95,000
- Tier 2: approximately $85,000 to $130,000
- Tier 3 and threat hunting: approximately $110,000 to $160,000
The compression at the bottom and the growth at the top is the automation story showing up in the pay data. The certifications in stages 3 to 6 above are the ones that move you out of the compressed band.
Frequently Asked Questions
Which certification is best for SOC analysts?
CompTIA CySA+ (CS0-004) is the best single certification for a SOC analyst, because its four domains map almost directly onto the job: detection and log analysis, vulnerability management, incident response, and reporting. If your target employer runs Microsoft Sentinel, pair it with SC-200 for the platform skills. Security+ is still needed to pass CV screening, but it is a baseline rather than a differentiator.
Is a certified SOC analyst worth it?
Yes, but the return depends heavily on which certification you pick. A vendor-neutral analyst certification plus a platform certification plus one hands-on practical is the combination that measurably improves interview rates in 2026. Stacking three overlapping multiple-choice certs at the same level is where people waste money, because employers cannot tell them apart.
How to become a SOC analyst?
Build foundational networking and operating-system knowledge, take Security+ to clear the automated CV filters, then add CySA+ for analyst-level detection and response skills. Learn one SIEM properly, which for most organisations means Microsoft Sentinel and KQL, and prove it with SC-200. Finish with a practical certification such as BTL1 or HTB CDSA, and keep a written record of investigations you have run in a home lab.
Is SOC an entry-level job?
It used to be the standard entry point into cybersecurity, but that has changed. More than 70% of SOC job postings now require two or more years of experience, because AI-driven triage has absorbed much of the repetitive Tier 1 workload. Roles still exist for newcomers, but you need to arrive with demonstrable hands-on capability rather than a single foundational certification.
How much does the SOC analyst certification path cost?
Following the full sequence in this guide costs roughly $1,500 to $2,000 in exam fees alone, spread across twelve to eighteen months. You can cut that substantially by skipping ISC2 CC if you already have IT experience, and by choosing HTB CDSA over BTL1 for the practical stage. Avoid SANS and GIAC options unless an employer is funding them.
Ready to Start Practising?
Reading objectives is not studying. The candidates who pass these exams are the ones who work through hundreds of realistic questions and, crucially, the performance-based questions that decide most CySA+ and SecAI+ results.
CertCrush has full practice exam banks, flashcards and PBQs for every certification on this path, including ISC2 CC, CompTIA Security+, CySA+ CS0-004, Microsoft SC-200 and CompTIA SecAI+. Every question comes with a detailed explanation of why the right answer is right and why the plausible-looking wrong ones are wrong, which is the part that actually moves your score.
Pick the stage you are on, and start there.
Create your free CertCrush account and start practising today.
