Skip to content
Breaking into cybersecurity

Best cybersecurity certifications for beginners, and the order to take them

The best cybersecurity certifications for beginners, in the order to take them: Security+ first, a foundation if you need one, then a specialist exam.

LearnCyber editorial team, reviewed by Hackrowd Technology’s penetration testers · · 8 min read

For most beginners the best first cybersecurity certification is CompTIA Security+, taken after you are comfortable with basic networking, and followed by one specialist exam that matches the job you want. That is the whole answer in one line; the rest of this post is about the order, the exceptions, and how to avoid spending a year collecting credentials that nobody asked for.

One thing before the list. A certification is an exam-based credential issued by a certifying body such as CompTIA or ISC2, usually with a renewal requirement. A certificate shows you finished a course. Both have their place, but they are not the same thing on a CV, and recruiters know the difference. We cover that properly in Certificate vs certification: what employers actually check.

What certifications do I need for cyber security as a beginner?

You need fewer than you think. For an entry-level role, one recognised baseline certification plus visible hands-on work (a home lab, write-ups, a small project on GitHub) will usually get you further than three certifications and nothing to show.

Here is the short list worth knowing, grouped by what they prove.

Stage Certification Issuer What it proves Who it suits
Foundation (optional) Network+ (N10-009) CompTIA You understand how networks actually work: addressing, routing, ports, common services, troubleshooting Anyone who cannot yet explain what happens when they type a URL
Foundation (optional) Certified in Cybersecurity (CC) ISC2 Broad security vocabulary across five domains People who want a gentle, structured first exam
Baseline Security+ (SY0-701) CompTIA Core security knowledge across five domains, with hands-on performance-based questions Almost every beginner, whatever the target role
Specialist: defence CySA+ CompTIA Detection, analysis and response work a SOC analyst does Aspiring SOC and blue-team analysts
Specialist: offence PenTest+ (PT0-003) CompTIA Planning, running and reporting a penetration test Aspiring penetration testers
Specialist: governance None yet (see Exception 2) Various Audit, risk and control frameworks People heading into GRC (see below)

Why Security+ sits in the middle of almost every roadmap

Security+ is broad by design. The SY0-701 exam has five domains: General Security Concepts (12%), Threats, Vulnerabilities and Mitigations (22%), Security Architecture (18%), Security Operations (28%), and Security Program Management and Oversight (20%). It is up to 90 questions in 90 minutes, and the passing score is 750 on a 100–900 scale. That breadth is the point: it gives you the shared language every later specialism assumes.

It also includes performance-based questions (PBQs), short simulations where you configure or analyse something rather than pick a letter. CompTIA’s own PBQ explainer lists Security+ among the exams that use simulation PBQs. That makes it a reasonable proxy for “can this person do basic things”, which is why it appears in so many job adverts.

A timing note: CompTIA’s Security+ page says the next version, Security+ V8, is expected to launch on or around 17 November 2026. SY0-701 stays available for a period after that; check the same page for its retirement date before you book, and make sure your study materials match the version on your voucher.

In what order should you take cybersecurity certifications?

There is no single correct order, but there is a sensible default, and three common exceptions.

The default order

  1. Get networking right first. Either take Network+ or study to its level without sitting the exam. If you are not sure whether you need it, read Security+ vs Network+: which should you take first?.
  2. Take Security+. Our SY0-701 study guide walks through the objectives and a plan.
  3. Spend three to six months building and documenting. Home lab, write-ups, a CTF or two, notes on GitHub. This is the step most people skip, and it is the one interviewers ask about.
  4. Take one specialist exam that matches the job you are applying for: CySA+ for SOC work, PenTest+ for offensive work.
  5. Stop and get a job. Later certifications make far more sense once your employer’s needs tell you which one.

Exception 1: you already work in IT

If you have spent a year or two on a helpdesk, in networking or as a sysadmin, skip the foundation stage. Go straight to Security+, then to the specialist exam. Your work history already shows the fundamentals.

Exception 2: you are heading for governance, risk and compliance

If you come from audit, legal, banking or compliance, Security+ is still a good baseline because GRC analysts need to understand the controls they assess. After that, frameworks matter more than technical exams: learn NIST’s Cybersecurity Framework 2.0 and the structure of ISO/IEC 27001 before chasing a GRC certification. Many of the well-known GRC certifications expect several years of relevant experience, so check the issuer’s eligibility rules first.

Exception 3: you want to be a penetration tester

Security+ still comes first; offensive work without fundamentals is guesswork. After it, PenTest+ (PT0-003) is a structured route that covers scoping, legal considerations and reporting as well as attacks. Some testers also take hands-on practical exams from other providers later. Whatever you choose, the practical habit matters more than the logo: lots of lab time on deliberately vulnerable machines, and every session written up.

A quick self-check: are you ready for Security+ yet?

Here is a test you can run today. Open a terminal on any Linux machine (a free virtual machine is fine) and run these:

ip -brief address
ip route
dig +short example.com
ss -tulpn

Plausible output on a home-lab VM looks like this:

lo               UNKNOWN        127.0.0.1/8 ::1/128
eth0             UP             192.168.56.10/24 fe80::a00:27ff:fe4e:66a1/64
default via 192.168.56.1 dev eth0
192.168.56.0/24 dev eth0 proto kernel scope link src 192.168.56.10
93.184.215.14
Netid State  Recv-Q Send-Q Local Address:Port  Peer Address:Port Process
udp   UNCONN 0      0      127.0.0.53%lo:53         0.0.0.0:*     users:((“systemd-resolve”,pid=512,fd=13))
tcp   LISTEN 0      128          0.0.0.0:22         0.0.0.0:*     users:((“sshd”,pid=801,fd=3))

(The address dig returns for example.com may differ when you run it; that is expected.)

Now answer, without searching:

  • What does /24 mean, and how many usable host addresses does it give?
  • What is the default gateway, and what happens to a packet bound for 8.8.8.8?
  • Why is something listening on 127.0.0.53 port 53?
  • Port 22 is open on 0.0.0.0. Who can reach it, and what would you check next?

If you can answer all four comfortably, you are ready to start Security+ study. If two or more stumped you, spend a few weeks on networking first. That is not a setback; it is the cheapest time you will ever spend on your career, because every later topic (firewalls, VPNs, segmentation, log analysis) assumes it.

Are entry-level certifications like ISC2 CC worth it?

ISC2’s Certified in Cybersecurity is a genuine certification, requires no work experience, and covers five domains: Security Principles, Security Governance, Identity and Access Management Concepts, Networking and Cloud Security Concepts, and Security Operations and Incident Response.

It is a useful first exam if you want structure and a confidence boost. It is lighter than Security+, though, and fewer job adverts name it. Note that ISC2’s free “One Million Certified in Cybersecurity” programme has closed to new enrolments; the course and exam are now paid like ISC2’s other exams. If you were already enrolled, existing exam codes must be used by 31 December 2026, per ISC2.

Our view: CC is fine as a stepping stone, but don’t let it delay Security+ by months. If budget forces a choice, Security+ is usually the better use of money.

Which certifications should beginners skip, at least for now?

Some well-known credentials are poor first choices, not because they are bad, but because they are aimed at someone else.

  • Advanced management certifications that require years of experience. You may pass the exam but not be able to hold the credential until you meet the experience rule. Read the eligibility page before you buy anything.
  • Vendor product certifications for tools you have never used at work. They make sense when an employer runs that product.
  • Stacks of short-course certificates. A course certificate can be a fine way to learn, but five of them do not add up to one certification, and none of them replaces a lab write-up.
  • Anything you are tempted to pass with “dumps”. Brain-dump sites sell leaked exam content. Using them breaches exam agreements and can get your certification revoked; see Exam dumps: why they can cost you your certification.

How to plan the money and the time

We won’t quote prices here because they change and vary by country; check CompTIA’s exam page for the current price in your region, and the issuer’s page for anything else. A few planning points hold everywhere:

  • Budget for one attempt and a contingency. Plan as if you might need a retake, then aim not to.
  • Renewals exist. CompTIA certifications are valid for three years and renew through continuing education. Factor in that you will keep learning anyway.
  • Pace yourself by hours, not weeks. A rough starting point many learners use is a fixed number of study hours per week, protected like a work shift. Track what you actually do; adjust the plan after a fortnight with real data.
  • Book the exam once you are scoring consistently well on fresh practice questions, not when a calendar date arrives.

Illustrative example, not a real student: a bank operations officer with no IT background spends six weeks on networking basics, studies Security+ over the following three months while building a small home lab, passes, then spends three months documenting lab projects before applying for SOC and GRC analyst roles. A specialist exam comes later, chosen to match the role they land.

What employers actually look at alongside certifications

Certifications get your CV past filters. What gets you hired is evidence that you can do the work:

  • A short portfolio: three to five lab write-ups explaining what you did, what you found and what you would fix.
  • Honest familiarity with the tools in the job advert (a SIEM, a vulnerability scanner, Wireshark, Nmap).
  • The ability to explain a concept simply in an interview. Practise explaining “what is a VPN” to a non-technical friend.
  • Professional habits: you mention scope and permission without being asked. Only test systems you own or have written permission to test.

If you are still working out which direction suits you, start with How to get into cybersecurity with no experience: a practical roadmap and come back to this list once you have picked a lane.

Questions

Is Security+ enough to get a job?

On its own it rarely is, and no certification guarantees a job. Security+ plus hands-on evidence and good interview answers is a strong combination for entry-level roles.

Should I take Network+ before Security+?

Only if your networking is weak. Run the self-check above. If you passed it, go straight to Security+.

Should I wait for Security+ V8?

If you are already well into SY0-701 study, finish and sit it while it is available. If you are starting from zero close to the launch date, check CompTIA's page and pick the version your study materials cover.

Is a Google or Coursera cybersecurity certificate a certification?

No. It is a course certificate. It can be good learning, but list it under training, not certifications.

How many certifications should a beginner have?

One baseline and, after some hands-on time, one specialist. Then let your job shape the rest.