article

Which cybersecurity certification should I get first?

Choose Security+, ISC2 CC, or an IT foundation first based on your experience, target work, cost, and official credential requirements.

Build my personalized career plan

Certification details change. Always confirm final pricing, availability, and credential terms on the official provider page linked in the sources below before you pay for anything.

Last updated 2026-07-23 — the article text's own revision date; dated evidence on this page carries its own check date. See the Citation Ledger at the foot for this page's sources.

The call

The call: Choose by the next gap, not by the loudest credential name. Security+ is the stronger fit when you already have Network+-level knowledge or equivalent hands-on IT and networking experience.

Start with Security+ if you already understand basic systems and networking and need a broad security baseline. Start with ISC2 CC if you are genuinely new and want a no-experience cybersecurity foundation. Start with neither if basic IT and networking operations are still unfamiliar—build those first. Do not start with CISSP.

Key takeaways

  • Choose Security+ when you have IT/networking footing and need its broader operational baseline or your target names it.
  • Choose ISC2 CC when you are genuinely new and want a no-experience cybersecurity foundation.
  • Choose neither yet when systems, networking, identity, and troubleshooting are still unfamiliar.
  • Use guided learning when structure and practice—not a credential screen—is the immediate gap.
  • CySA+ belongs after fundamentals; CISSP is an experience-gated later target.

The short answer

Choose by the next gap, not by the loudest credential name. Security+ is the stronger fit when you already have Network+-level knowledge or equivalent hands-on IT and networking experience. ISC2 CC has no work-experience requirement and fits a true newcomer who wants a first cybersecurity foundation. If systems, networking, identity, and troubleshooting are all new, build those basics before either exam.

Your situationBetter first moveWhy
No IT or networking backgroundIT support and networking practice firstSecurity work assumes systems, networks, identity, and troubleshooting context.
New to cybersecurity but comfortable with basic ITISC2 CCNo work-experience requirement and a lower captured U.S. exam fee than Security+.
Network+-level knowledge or equivalent hands-on experienceSecurity+Broader operational security baseline; CompTIA recommends prior networking and systems/security experience.
Need guided instruction before an examGoogle Cybersecurity or another structured foundationA learning program can build vocabulary and artifacts before a proctored credential.
Already comfortable with logs and triageCySA+ may be a later stepIt is analyst depth, not the first foundation.
Long-term senior security leadershipCISSP laterISC2 has an experience gate; it is not a beginner first move.

If federal, military, or defense-contractor work is the goal, verify the current requirement for the specific work role. Neither credential is job readiness by itself.

Decision matrix by credential type

A learning program, an entry credential, a broad security exam, an analyst-depth exam, and an advanced credential solve different problems.

OptionCategoryUse it first when...Skip or delay it when...
Google Cybersecurity CertificateGuided learning programYou need structure, labs, and a first security vocabulary pass.You need a proctored certification screen now.
ISC2 CCEntry cybersecurity certificationYou want a no-experience credential and the current fee and lifecycle work for you.You already command the fundamentals or your target explicitly requires Security+.
CompTIA A+ or equivalent practiceIT-support foundationYou lack troubleshooting, endpoint, operating-system, and support context.You already have hands-on IT experience.
CompTIA Security+Broad security baselineYou have IT/networking footing and your target work names Security+ or its domains.Networking and systems administration are still new.
CompTIA CySA+Analyst-depth certificationYou already have security fundamentals and want defensive-analysis depth.You are trying to skip fundamentals.
CISSPAdvanced, experience-gated credentialYou are planning a later leadership target and can meet experience requirements.You are choosing a first credential.

Choose the option that closes the next evidence gap and pair it with hands-on proof.

Current official-source facts to verify before paying

These are decision facts, not outcome claims. Fees, versions, and regions can change, so verify the official source before paying.

CredentialCurrent cited factWhat it means for timing
ISC2 CCNo work experience required; current exam is 100-125 items in two hours; captured U.S. fee is $199. ISC2 has announced a new outline effective September 1, 2026.Entry option for newcomers; confirm which outline applies before scheduling.
CompTIA Security+SY0-701; up to 90 mixed-format questions in 90 minutes; captured U.S. voucher is $439. CompTIA recommends Network+ plus about two years of security or systems-administration experience, but does not require it.Direct broad security exam after IT and networking footing.
Google CybersecurityGuided beginner program with labs and portfolio activities; not the same category as a proctored certification.Use when learning structure is the gap.
CompTIA A+Two-exam IT-support foundation.Consider only when basic IT operations are the blocker.
CompTIA CySA+Analyst-depth credential.Later step after fundamentals and hands-on logs or triage.
CISSPISC2 requires relevant paid experience, with waiver and Associate routes.Not a beginner first credential.

The ISC2 One Million Certified program closed new enrollment on May 20, 2026. Do not plan around a free exam unless you already hold a valid unexpired code. Record the official URL, fee and date, exam version, target-work fit, and the hands-on artifact you still need.

Match the first credential to the work

Role evidence keeps the recommendation honest. O*NET's Information Security Analysts tasks include safeguarding files, monitoring malware reports, access-control changes, risk assessments, testing security measures, and updating security files. Those are closer to logs, identity, triage, and documentation than to credential collecting.

Target workFirst credential logicProof beyond the credential
Cybersecurity AnalystSecurity+ or ISC2 CC can organize fundamentals; Google can build starter artifacts.Risk/control note, access-control example, vulnerability summary.
SOC AnalystSecurity+ plus hands-on logs/SIEM is stronger than a credential-only plan.Alert triage note, incident timeline, SIEM search explanation.
IT Security Operations SpecialistSecurity+ helps with security vocabulary; IT and IAM context may matter just as much.Identity review, logging note, vulnerability-management note.
Network Security EngineerNetworking and firewall reasoning usually need depth beyond the first security credential.Network diagram, firewall reasoning, scan explanation.

This is why the same first credential is not right for everyone. A learner with no systems context has a different gap than a help desk technician trying to move into security operations.

Honest bottom line

Security+ is usually the direct first proctored security exam for someone with IT and networking footing. ISC2 CC is the cleaner no-experience credential for a true newcomer. A guided learning program can come first when structure and practice are the gap. Basic IT work should come first when systems and networking are still unfamiliar. CySA+ comes later, and CISSP is an experience-gated long-term target.

Whichever route you choose, build proof beyond the credential: an access review, a risk note, a log search, an incident timeline, or a small network-security lab. No credential here creates employment, interviews, pay, exam outcomes, or a fixed timeline.

Frequently asked questions

Which cybersecurity certification should I get first?

Start with Security+ if you have IT and networking footing. Start with ISC2 CC if you are new and want a no-experience foundation. Build basic IT and networking practice first if those systems are still unfamiliar.

Should I start with ISC2 CC or Security+?

Choose ISC2 CC for the lower formal entry barrier and lower captured exam fee. Choose Security+ when you already have IT/networking background and need its broader operational baseline or your target explicitly names it.

Should I get A+ before Security+?

Only when basic IT support, operating-system, endpoint, and troubleshooting context is the real gap. A+ is not a formal Security+ prerequisite.

Is CISSP a good first cybersecurity certification?

No for most beginners. ISC2 has an experience gate for CISSP, so treat it as a later target after relevant security work.

Related, with the cited detail

Evidence behind this article

RoleMath turns this article into a small decision report: official credential facts, occupation context, and AI workflow evidence.

Mapped roles: IT Security Operations Specialist, Network Security Engineer, Cybersecurity Analyst, SOC Analyst, Help Desk Technician

Pay by metro

IT Security Operations Specialist maps to Information Security Analysts.
MetroMedian payCost-adjusted
San Jose, CA$176,120$159,496
Raleigh, NC$143,640$146,337
Seattle, WA$161,780$145,573
Network Security Engineer maps to Computer Occupations, All Other.
MetroMedian payCost-adjusted
San Jose, CA$184,430$167,021
Denver, CO$160,520$151,746
Lexington Park, MD$144,680$143,589

Occupation-level metro medians only; not credential salary, personal pay, or a placement claim. OEWS 2025-05 + BEA RPP 2024. Sources: U.S. Bureau of Economic Analysis Regional Price Parities, U.S. Bureau of Labor Statistics May 2025 OEWS Current Tables

AI impact context

  • IT Security Operations Specialist: roughly 24% of recorded usage looked like augmentation vs 76% automation-style (Anthropic Economic Index; usage signal, not a job-loss prediction). Sampled AI-language terms include Anthropic, LLM, OpenAI, machine learning. Descriptive Claude usage data, not employment demand, not job loss, and not a personal forecast; CC-BY attribution required.
  • Network Security Engineer: roughly 36% of recorded usage looked like augmentation vs 64% automation-style (Anthropic Economic Index; usage signal, not a job-loss prediction). Sampled AI-language terms include LLM. Descriptive Claude usage data, not employment demand, not job loss, and not a personal forecast; CC-BY attribution required.
  • Cybersecurity Analyst: roughly 24% of recorded usage looked like augmentation vs 76% automation-style (Anthropic Economic Index; usage signal, not a job-loss prediction). Sampled AI-language terms include Anthropic, OpenAI, machine learning. Descriptive Claude usage data, not employment demand, not job loss, and not a personal forecast; CC-BY attribution required.

Sources: Anthropic Economic Index report: Cadences (release 2026-06-26), Canaries in the Coal Mine - recent employment effects of AI (working paper), Felten Raj and Seamans - AI Occupational Exposure (AIOE) index, GPTs are GPTs: An early look at the labor market impact potential of LLMs (Science 2024), OECD Employment Outlook 2023 - Artificial Intelligence and the Labour Market

What we verified about these certifications

Certifications referenced in this evidence packet: CompTIA A+; CompTIA CySA+; CompTIA Network+; CompTIA Security+; ISC2 CC - Certified in Cybersecurity; ISC2 CISSP - Certified Information Systems Security Professional.

No certification shown here is treated as salary, job, ROI, or pass-rate proof. Sources: CompTIA official credential page, CompTIA official credential page, CompTIA official credential page, CompTIA official credential page, ISC2 official credential page

Core source records

This table lists the page’s core content records and their checked dates where recorded. Claim-specific citations appear beside the relevant text and may not be repeated here.

Show all 14 sources
IDSupportsSourceChecked
CIT-01Google Cybersecurity should be framed as a learning program, not the same category as a proctored certification.https://grow.google/certificates/cybersecurity/Date not recorded
CIT-02Google Cybersecurity timing and format should use current Coursera page details.https://www.coursera.org/professional-certificates/google-cybersecurityDate not recorded
CIT-03Google Cybersecurity can be a preparation path for Security+ but is not the same credential.https://www.coursera.org/professional-certificates/google-cybersecurityDate not recorded
CIT-04Security+ exam structure and fee should use official-source official sources.https://www.comptia.org/en-us/certifications/security/2026-07-21
CIT-05A+ should be framed as optional IT-support foundation context, not a cybersecurity requirement.https://www.comptia.org/en-us/certifications/a/core-1-and-2-v15/2026-07-21
CIT-06CySA+ should be treated as later analyst-depth context unless target roles name it.https://www.comptia.org/en-us/certifications/cybersecurity-analyst/v4/2026-07-20
CIT-07ISC2 CC should be framed as an entry credential with dated official-source cost and exam rows.https://www.isc2.org/certifications/cc2026-07-01
CIT-08ISC2 CC pricing should be verified at the official ISC2 exam-pricing page before purchase.https://www.isc2.org/register-for-exam/isc2-exam-pricing2026-07-05
CIT-09CISSP is not a beginner first credential because it has an experience gate.https://www.isc2.org/certifications/cissp/cissp-experience-requirementsDate not recorded
CIT-10CISSP exam cost and structure should be treated as advanced context only.https://www.isc2.org/certifications/cissp/cissp-certification-exam-outline2026-07-05
CIT-11Cybersecurity role-task evidence should come from O*NET.https://www.onetonline.org/link/summary/15-1212.00Date not recorded
CIT-12Network-security depth should be separated from first-credential advice.https://www.onetonline.org/link/summary/15-1299.05Date not recorded
CIT-13ISC2 CC has an announced exam-outline change that affects study-version selection.https://www.isc2.org/certifications/cc/cc-certification-exam-outline2026-07-05
CIT-14The ISC2 One Million Certified program is not open to new enrollment.https://www.isc2.org/landing/1mcc2026-07-10

Ready to turn this decision into a plan?

Start the RoleMath planner