The Certification Market and Its Quality Variation
The cybersecurity certification market has grown alongside the cybersecurity skills shortage, producing a wide range of certifications of widely varying quality, employer recognition, and career value. At one end: certifications from established bodies (ISACA, ISC2, CompTIA, EC-Council, SANS/GIAC, Offensive Security) that are widely recognised in hiring processes and that require demonstrated knowledge through rigorous exams. At the other end: certifications from training platforms (LinkedIn Learning, Coursera, various bootcamp-style programmes) that indicate course completion rather than demonstrated capability and that most employers evaluate accordingly.
The investment of time and money in cybersecurity certifications should be calibrated to the certifications that actually open the career doors the candidate is targeting, rather than to the certifications that are easiest to obtain or most prominently marketed. The hiring manager’s perspective is the most relevant perspective: which certifications do hiring managers in cybersecurity roles actually look for, and which do they pass over without adverse consequence?
The Entry-Level Starting Points
CompTIA Security+ is the most widely recognised entry-level cybersecurity certification in the US, required for many DoD contractor and federal government security roles and commonly listed as a preference or requirement in entry-level security analyst and SOC analyst job postings. It covers security fundamentals broadly (network security, cryptography, threats and vulnerabilities, access control, identity management) rather than deeply, providing the breadth that entry-level security roles benefit from. Cost is approximately $400 for the exam; preparation typically takes 2–4 months of study with available study materials.
CompTIA Network+ and CompTIA A+ provide the networking and IT fundamentals foundation that Security+ builds on; candidates without networking background often benefit from Network+ preparation before Security+. ISC2’s Certified in Cybersecurity (CC) is a newer free-to-take entry-level certification that ISC2 introduced to lower the barrier to entry — it doesn’t carry the same employer recognition as Security+ yet but provides an accessible starting point for career-changers evaluating whether cybersecurity is the right direction.
The Mid-Level Certifications That Move Careers
CompTIA CySA+ (Cybersecurity Analyst) provides the next step after Security+ for analysts focused on threat detection and response. CCNA (Cisco Certified Network Associate) provides networking depth that security professionals working in network security environments need and that Security+ doesn’t fully provide. Certified Ethical Hacker (CEH) from EC-Council has strong name recognition but has faced criticism for depth relative to its cost — it’s widely listed in job postings but less respected by practitioners than Offensive Security’s certifications.
OSCP (Offensive Security Certified Professional) is the certification that penetration tester job postings most consistently require for experienced roles: it requires completing a 24-hour practical exam where candidates must hack a series of machines in a lab environment rather than answering multiple-choice questions. This hands-on examination approach makes OSCP holders demonstrably capable rather than just knowledgeable about concepts. The preparation (PEN-200 course + lab time, approximately $1,499) and the difficulty are significant; the career value for penetration testing roles is correspondingly high.
The Senior and Specialist Certifications
CISSP (ISC2 Certified Information Systems Security Professional) is the most widely recognised senior cybersecurity certification, commonly required for CISO, security management, and senior security architect roles. It requires 5 years of paid work experience in two or more CISSP domains to earn (though the exam can be taken without the experience, yielding ‘Associate of ISC2’ status). The exam covers 8 security domains at a conceptual and managerial level rather than technical depth — CISSP is a management and strategic certification rather than a technical practitioner certification.
GIAC certifications (from SANS) are the most respected technical certifications in specific security domains: GPEN (penetration testing), GWAPT (web application penetration testing), GCIA (intrusion analysis), and GCIH (incident handling) are commonly sought for specialised technical roles. GIAC courses (through SANS) are expensive ($7,000–$8,000+ per course) and are typically employer-funded or sponsored. Self-study options exist but are more challenging without the accompanying course material.
The Study Approach That Produces Better Outcomes Than Certification Alone
Certifications demonstrate knowledge; demonstrated capability is what employers actually want to see. The candidates who stand out in cybersecurity hiring — at entry and experienced levels — combine relevant certifications with practical experience that demonstrates the application of that knowledge: a home lab where they’ve set up and attacked environments (TryHackMe, HackTheBox, PicoCTF for guided practice; home virtualisation lab for independent practice), contributions to open source security tools, CTF (Capture the Flag) competition participation, and a documented history of findings from security research.
The job application that combines a relevant certification with a GitHub repository demonstrating relevant technical work, a TryHackMe or HackTheBox profile showing hands-on practice, and perhaps one publicly disclosed bug found through responsible disclosure is significantly more compelling than the same certification without the practical evidence. Certifications open the resume screening door; practical demonstration of capability closes the interview.




