Skip to content
Cyber Security Firms

Cyber Security Certifications: What Employers Ask For

Every certification body ranks its own credential first. This is the same eight certifications laid out side by side, with what each one costs, what it demands before you can hold it, and which jobs actually ask for it.

Beginner12 min readUpdated
Cyber Security Certifications: What Employers Ask For

Search this term and the first three results are CompTIA, ISC2 and Google, each listing its own catalog and none of them showing a price. That is the problem with the question: the people best placed to answer it are all selling something.

What follows is the eight certifications employers name in job ads, in one table, with the experience each demands and the cost each carries, taken from the issuing body's own pages. Then the part the vendors do not write: whether any of it gets you hired.

What Are Cyber Security Certifications?

A certification is a credential from an independent body saying you passed its exam and, for most of them, that you have done the job for a stated number of years. Nobody is legally required to hold one. Employers use them as a filter because there is no license for this work, so the issuer's name is the closest thing to a standard.

Which issuer matters more than which topic. Six organizations account for almost every certification in a US job posting: CompTIA, ISC2, ISACA, EC-Council, OffSec and GIAC, the certification arm of the SANS Institute. Vendor certifications from Microsoft, Cisco and AWS prove you can run one company's products, which is useful once you know where you are working and premature before that.

Certifications also sit on top of knowledge rather than instead of it. The exams test whether you can apply the controls that make up the working definition of cyber security, which is material you have to learn somewhere first.

Which Cyber Security Certifications Do Employers Ask For?

These eight are the ones that recur in job postings. Everything in the table comes from the issuing body's own page, linked in the sections below.

CertificationIssuerLevelExperience expectedCost
Security+CompTIAEntryNetwork+ and about two years in a security or systems administrator role, recommended not requiredVoucher price not published on CompTIA's site; $150 to renew with CEUs every three years
CySA+CompTIAMidAbout four years as a SOC or vulnerability analystAs above
CEHEC-CouncilMidOfficial training, or two years in an information security role plus a $100 eligibility applicationCourse packages from $1,699
GSEC and other GIACGIACMid to advancedVaries by certificationNot published on giac.org; normally bought with SANS training
CISSPISC2AdvancedFive years across the exam domains$749
CISMISACAAdvancedFive years of security management across three of four domains$575 members, $760 non-members
CCSPISC2AdvancedFive years$599
OSCPOffSecAdvancedNone formally$1,749 including the course and one attempt

Entry Level Cyber Security Certifications

CompTIA Security+ is the default first certification in the United States, and the one you will see named by title in entry level job ads. The current exam is SY0-701, a maximum of 90 multiple choice and performance based questions in 90 minutes. CompTIA recommends Network+ and around two years in a security or systems administrator role first, but that is guidance rather than a gate. It is broad and shallow by design, which is what makes it work as a filter.

ISC2's CC, Certified in Cybersecurity, is the cheapest credible alternative at $199 and requires no work experience. It is newer and less often named in postings, so treat it as a supplement or as a way to test whether the material holds your interest.

The Google Cybersecurity Certificate is a course rather than a certification: $49 a month after a seven day trial, three to six months at five to ten hours a week, no prior experience required. It teaches the ground floor well and is a reasonable way to prepare for Security+, but it is not what a hiring manager means by a certification.

Before any of them, learn how the attacks work. Candidates who cram the acronyms without the mechanism fail on the scenario questions.

Mid Level Cyber Security Certifications

CompTIA CySA+ is Security+ for people already doing the work. The current exam is CS0-004, a maximum of 85 questions in 165 minutes, and CompTIA recommends about four years in a SOC analyst or vulnerability analyst role. It maps more directly to a detection and response job than anything else on this list.

EC-Council's CEH is the best known offensive credential and the most argued about. The knowledge exam is 125 multiple choice questions in four hours, with an optional six hour, 20 challenge practical that upgrades the holder to CEH Master. Eligibility runs two ways: complete EC-Council's official training, whose on-demand packages start at $1,699, or self-study with two years of information security experience plus a $100 non-refundable application. Recruiters recognize it and practitioners dismiss it, on the grounds that a multiple choice exam cannot demonstrate offensive skill. Both are true, which is why it opens doors at companies that screen on keywords and none at companies that test.

GIAC, the certification arm of SANS, runs the most respected exams in the field and the most expensive route to them. GSEC, the general one, is 106 questions in four hours with a 72 percent pass mark. GIAC publishes no price on its own site, because an attempt is normally bought alongside a SANS course priced for employers rather than individuals. If your employer pays, this is the strongest thing at this level. If you pay, it usually is not.

Understanding phishing properly matters more here than it sounds, because social engineering is the entry point in most real incidents and it appears in every one of these exams.

Advanced Cyber Security Certifications

Three of these four cannot be held without five years of experience, which is the single most misunderstood fact about them.

CISSP from ISC2 is the broad standard, an exam across eight domains that costs $749 and requires five years of work experience across those domains. It appears in postings for security leads, architects and managers more than for analysts.

CISM from ISACA is the governance counterpart, aimed at people who run security programs rather than build them. The exam is US$575.00 for members and US$760.00 for non-members, and certification requires five or more years of information security management experience across at least three of the four CISM domains, within the preceding ten years.

CCSP, also from ISC2, is the cloud specialization: $599 and five or more years of experience. Worth it when your work is genuinely cloud-first, redundant when it is not.

OSCP from OffSec is the outlier and the one practitioners respect most. No prerequisites, no multiple choice paper. $1,749 buys 90 days of the PEN-200 course, the labs and one exam attempt, and the exam is 24 hours of proctored hands-on work against three standalone machines and an Active Directory set. Note the naming: OSCP+ expires after three years, while the underlying OSCP does not.

How Much Do Cyber Security Certifications Cost?

The exam fee is the smallest part of the number. Budget for four things: the exam, the training, the retake and the renewal.

Published exam fees run from $199 for CC to $749 for CISSP, with CISM at $575 or $760 and OSCP at $1,749 with the course bundled in. Two of the eight publish no price at all: CompTIA sells vouchers through its own store, whose product pages now redirect back to the certification pages, and GIAC prices attempts through SANS. Assume you will have to ask.

Renewal is the cost people forget. Renewing a CompTIA certification with continuing education units carries a $150 fee per three year cycle, though passing the current exam version instead carries no CE fee. GIAC wants 36 CPEs earned while the certification is active, or a retake. ISC2 and ISACA charge annual maintenance on top of continuing education. Over ten years, upkeep on three certifications exceeds what the exams cost.

A neat stack of plain exam booklets on a flat surface with one booklet pulled halfway out

Will a Cyber Security Certification Get You a First Job?

On its own, usually not, and the Bureau of Labor Statistics is the place to check rather than any vendor.

Read those two lines together, because they are the honest answer. A certification is preferred, not sufficient. The same handbook lists a degree as typical and prior experience in a related occupation as normal, which is why most people arrive in security from help desk, systems administration or networking rather than straight from a course. It is also why the certification is worth more once you can point at the threats you have actually handled.

Myth vs reality
What people believe
Pass Security+ and you are in. The field is desperate for people and there are hundreds of thousands of unfilled jobs.
What actually happens
The shortage is real at the mid and senior levels and almost absent at the entry level, where a single junior posting draws hundreds of applicants. A certification moves you past the keyword filter. What gets you the interview after that is demonstrable work: a home lab, a bug bounty, a help desk job where you handled the phishing reports.

The strongest entry-level combination is a certification, adjacent experience and something you can show. Read this year's breach reports and be able to explain how one of them happened, in order, without notes. That is a better interview than any credential, and it is free.

What Is the Best Cyber Security Certification to Get?

There is no single answer, and any page that gives you one is guessing about your situation. Security+ if you are coming from outside IT, because it is the credential entry level postings name by title and because passing it proves you can learn the vocabulary. CySA+ or a GIAC certification if you already work in IT, since your existing experience is worth more than another broad exam. CISSP or CISM once you clear five years and are heading toward leadership, choosing CISM for governance work and CISSP for technical breadth. OSCP if you want to break things for a living.

The one strategy that consistently fails is collecting certifications instead of experience. Two certifications and two years of doing the job beats five certifications and none, and the people reading your resume know that.

Key takeaways

  • Six issuers matter in the US: CompTIA, ISC2, ISACA, EC-Council, OffSec and GIAC. The issuer's name is what employers screen on.
  • Security+ is the standard first certification. ISC2's CC at $199 is the cheapest credible alternative.
  • CISSP, CISM and CCSP each require five years of experience before you can hold them. They are mid-career credentials, not entry points.
  • OSCP is the offensive standard, judged on a 24 hour hands-on exam, at $1,749 with the course.
  • Published exam fees run from $199 to $749, plus training and renewal. CompTIA charges $150 per three year cycle to renew with CEUs.
  • The BLS lists a bachelor's degree as typical entry level education and says employers prefer certified candidates. Preferred is not sufficient.
  • A certification, adjacent experience and something you can demonstrate is the combination that gets interviews.

Common questions

What is the best cybersecurity certification to get?

It depends where you are starting. Security+ if you are new, CySA+ or a GIAC certification if you already work in IT, CISSP or CISM once you have five years and are heading toward leadership, OSCP for offensive work. Any ranking that names one winner is ignoring your situation.

Which cyber security certification is best for beginners?

CompTIA Security+, because entry level postings name it by title and it has no hard prerequisite. ISC2's CC is a cheaper alternative at $199 with no experience requirement, and the Google Cybersecurity Certificate at $49 a month is a way to learn the material first.

How much do cyber security certifications cost?

Published exam fees range from $199 for ISC2's CC to $749 for CISSP, with CISM at $575 for ISACA members and $760 for non-members, CCSP at $599, and OSCP at $1,749 with the course bundled. CompTIA and GIAC publish no price on their own sites. Add training and renewal.

Do cyber security certifications expire?

Most do. CompTIA certifications run on three year cycles, renewable with continuing education units for $150 or by passing the current exam version. GIAC requires 36 CPEs or a retake. ISC2 and ISACA require continuing education plus annual maintenance. OSCP+ expires after three years; the base OSCP does not.

Can I get a cyber security job with just a certification?

Rarely straight away. The Bureau of Labor Statistics lists a bachelor's degree as typical entry level education for information security analysts and says employers prefer certified candidates, which makes a certification a filter to pass rather than a qualification to hire on. Pair it with adjacent work in IT, support or networking.

Is a certificate in cyber security worth it?

Yes, as one part of a package. It moves your resume past automated screening, it forces structured study, and an employer will often pay for it. It is not a substitute for experience, and collecting several before your first job is the most common way to waste money here.

Can I make $200,000 a year in cyber security?

Some people do, and it is not the norm. The BLS puts the median annual wage for information security analysts at $129,180 in May 2025. Pay above $200,000 exists in senior leadership, specialized offensive work and high cost metros, usually after ten years and often with equity making up the difference.

Is 40 too old for cyber security?

No. Security hires heavily from adjacent careers and values pattern recognition, communication and knowing how organizations actually work, all of which improve with age. What matters is current hands-on capability, which is a question about the last twelve months rather than your age.

Do I need a degree for cyber security?

Not always, but it helps more than certification marketing admits. The BLS lists a bachelor's degree as typical entry level education for information security analysts. Plenty of people get in without one, usually through an IT support or systems role first, and it matters less each year you are working.

CISSP or CISM, which should I take?

CISSP if your work is technically broad and you want the widest recognition, CISM if you run a security program and deal with risk and governance. Both need five years. CISM's requirement is narrower: five years of security management across at least three of its four domains.

On this page
Reviewed by

Daniel Reyes

  • CISSP
  • 12 years in security operations
  • Austin, TX

Daniel Reyes is a CISSP who spent twelve years in security operations, most recently leading a detection and response team for a mid-sized healthcare group in Texas. He reviews every resource and breach report on Cyber Security Firms for technical accuracy before it publishes.

Most of the people he has trained arrived having been told too much: a dozen acronyms, six vendors, and no clear idea which risk was theirs. His approach is to explain what an attack actually does before naming the tool that stops it, on the basis that most breaches start with something a reader could have recognised.

Read the full bio and how we research →