Skip to content
Career Roadmaps

Cybersecurity Certification Roadmap

A structured, role-based progression guide for cybersecurity certifications.

Pros

  • Clear, structured progression from Beginner to Expert
  • Aligns certifications with specific cybersecurity roles
  • Prioritizes practical, hands-on exams

Cons

  • Certifications alone do not guarantee jobs
  • Hands-on certifications require significant lab time
Sponsored Link

Certification Roadmap

Legend: Theory Practical HR Filter
Certification Organisation Type
ISC2 CC ISC2 Theory
CompTIA Network+ CompTIA Practical + HR
CompTIA Security+ CompTIA Practical + HR

Role-Based Paths

Penetration Tester

eJPT PNPT OSCP OSEP

SOC Analyst

Security+ CySA+ BTL1 GCIH

Incident Responder

CySA+ BTL1 GCIH GCFA

Cloud Security

Security+ Azure AWS CCSP

DevSecOps Engineer

Security+ AWS/Azure CKS CSSLP

GRC / Auditor

Security+ CISA CRISC CISM

Security Engineer

Security+ CySA+ Cloud CISSP

Minimum Certifications to Get a Job Fast

The shortest defensible route from zero to a first role — with the caveat that a certification gets you read, not hired.

Security+

CompTIA

Pass HR filters for entry-level

BTL1

SBT

SOC Analyst job-ready fast

OSCP

OffSec

Offensive role benchmark

SC-200

Microsoft

Microsoft SOC skills

AWS Security

AWS

Cloud security roles

Certifications to Avoid

CEH

Expensive, largely multiple-choice, and thin on hands-on. Still passes HR filters in some regions and is mandated for certain government roles, so check the job adverts you are actually targeting before dismissing it

Beginner cert stacking

Three entry certificates prove the same thing three times. The second one adds almost nothing a hiring manager can use

Vendor-overlap certs

Overlapping badges from one cloud provider are diminishing returns, and each carries its own renewal cycle and fee

Practical Decision Matrix

Want a job fast? Security+, then OSCP
Weak foundation? Partner Training + Vendor Exam
Low budget? Self-Study + Direct Exam
Want hands-on? OffSec / GIAC / BTL1
Want HR filtering? ISC2 / CompTIA / ISACA

Common Mistakes

  • Collecting certificates with no lab hours behind them — it shows in the first technical interview
  • Treating a multiple-choice pass as evidence of competence
  • Attempting advanced exams before the networking and systems fundamentals are solid
  • Stacking beginner certificates that cover the same ground
  • Expecting a certificate to produce a job — it produces an interview, at best

Best Practices

  • Favour hands-on, lab-based exams; they are harder to pass and harder to fake
  • Read ten job adverts you would actually apply for, then buy what they ask for
  • Build a home lab and break it — isolated from your home network
  • One foundational certificate, then move up rather than sideways
  • Write up what you built. A portfolio someone can read beats a badge they cannot verify

Maintaining Certs (CPEs)

  • Track expiration dates! Certs expire every 3 years.
  • Earn Continuing Professional Education (CPE) credits.
  • Attend security conferences (BlackHat, DefCon, B-Sides).
  • Complete free vendor webinars for easy credits.
  • Write security articles or blog posts for CPEs.

Core Rule: Always Choose Official Vendors

If it is not issued by a recognised body, count it as learning rather than a credential — worth your time, worth nothing to the filter. The screening step is usually automated and matches the issuing organisation, which is the whole reason this rule exists rather than any judgement about course quality.

ISC2CompTIAOffSecGIACISACA
Sponsored Links

Share article

Subscribe to my newsletter

Receive my case study and the latest articles on my WhatsApp Channel.

Warning

Ask CyberROX AI