Security Certifications Roadmap: From Network+ to OSCP and Beyond

Security Certifications Roadmap: From Network+ to OSCP and Beyond

The cybersecurity certification market is worth billions of dollars, and vendors are very good at making you feel like you need every credential they offer. You do not. But the right certifications, earned at the right time, can accelerate your career significantly. The wrong ones waste months of study time and thousands of dollars.

This guide maps out the major certification paths, explains what each exam actually tests, gives you real cost figures, and helps you figure out which credentials are worth pursuing based on your career goals.

The Certification Landscape

graph TD
    subgraph Foundation["Foundation Tier - $300-$400"]
        NPLUS[CompTIA Network+]
        SPLUS[CompTIA Security+]
    end
    subgraph Intermediate["Intermediate Tier - $400-$1,200"]
        CYSA[CompTIA CySA+]
        EJPT[eLearnSecurity eJPT]
        CEH[EC-Council CEH]
        PENPLUS[CompTIA PenTest+]
        SSCP[ISC2 SSCP]
    end
    subgraph Advanced["Advanced Tier - $1,000-$2,500"]
        OSCP[OffSec OSCP]
        GPEN[SANS GPEN]
        CISSP[ISC2 CISSP]
        CISM[ISACA CISM]
        OSWE[OffSec OSWE]
    end
    subgraph Expert["Expert Tier - $1,500+"]
        OSCE3[OffSec OSCE3]
        GXPN[SANS GXPN]
        CCSP[ISC2 CCSP]
    end
    NPLUS --> SPLUS
    SPLUS --> CYSA
    SPLUS --> EJPT
    SPLUS --> CEH
    SPLUS --> PENPLUS
    SPLUS --> SSCP
    CYSA --> CISSP
    CYSA --> CISM
    EJPT --> OSCP
    CEH --> OSCP
    PENPLUS --> OSCP
    SSCP --> CISSP
    OSCP --> OSWE
    OSCP --> OSCE3
    GPEN --> GXPN
    CISSP --> CCSP

Certification progression paths - arrows show common advancement routes, not strict prerequisites

Cybersecurity certifications fall into three broad categories:

Vendor-neutral certifications (CompTIA, ISC2, ISACA) test general knowledge applicable across technologies. These are the most widely recognized and often required for government and defense contractor positions.

Hands-on/practical certifications (OffSec, eLearnSecurity, SANS GIAC) require you to demonstrate skills in lab environments. These carry the most weight with technical hiring managers.

Vendor-specific certifications (AWS Security Specialty, Azure Security Engineer, Cisco CyberOps) prove expertise with particular platforms. Valuable when targeting roles at organizations using those technologies.

Foundation Tier: Network+ and Security+

CompTIA Network+ (N10-009)

What it tests: Network architecture, network operations, network security fundamentals, network troubleshooting. This covers TCP/IP, DNS, DHCP, subnetting, wireless networking, VLANs, firewalls, and basic network monitoring.

Exam format: Up to 90 questions (multiple choice and performance-based), 90 minutes, passing score 720/900.

Cost: $369 for the exam voucher. Study materials range from free (Professor Messer on YouTube) to $300+ for commercial courses.

Study time: 4-8 weeks for someone with basic IT experience. 8-12 weeks for complete beginners.

Is it worth it? If you have no networking background, yes. Network+ forces you to learn the fundamentals that every security role requires. If you already have networking experience or a CCNA, skip it and go straight to Security+.

CompTIA Security+ (SY0-701)

What it tests: General security concepts, threats and vulnerabilities, security architecture, security operations, and security program management. The SY0-701 version emphasizes zero trust, cloud security, and automation more than previous versions.

Exam format: Up to 90 questions (multiple choice and performance-based), 90 minutes, passing score 750/900.

Cost: $404 for the exam voucher.

Study time: 6-10 weeks with networking knowledge. 10-16 weeks without.

Is it worth it? Almost always yes. Security+ is the baseline certification for the industry. It meets DoD 8570/8140 requirements for IAT Level II positions, which means it is required for most government security jobs. The majority of entry-level security job postings mention Security+ specifically.

Security+ does not make you a security professional. It proves you understand the fundamentals - which is exactly what entry-level employers need to see.

Intermediate Tier: CySA+, eJPT, and CEH

CompTIA CySA+ (CS0-003)

What it tests: Security operations, vulnerability management, incident response, and reporting. CySA+ focuses on the defensive/blue team side - analyzing security data, managing vulnerabilities, and handling incidents.

Cost: $404 exam voucher.

Study time: 8-12 weeks after Security+.

Best for: SOC analysts and anyone heading toward defensive security roles. It fills the gap between Security+ and CISSP nicely.

eLearnSecurity Junior Penetration Tester (eJPT)

What it tests: Basic penetration testing methodology in a practical lab environment. You get a letter of engagement and a target network, then have to find and exploit vulnerabilities and submit a report.

Cost: $249 for the exam (includes one retake). The INE training course is available with a subscription (~$50/month).

Study time: 6-10 weeks.

Best for: Anyone who wants to get into penetration testing. The eJPT is the best stepping stone to the OSCP because it uses the same practical exam format at a much easier difficulty level. It teaches you the methodology and lab exam mindset before you tackle the beast that is OSCP.

EC-Council Certified Ethical Hacker (CEH)

What it tests: Broad knowledge of hacking techniques, tools, and methodologies across 20 domains. The exam is multiple choice, though EC-Council now offers a practical component (CEH Practical) separately.

Cost: $1,199 for the exam voucher (or ~$2,000+ through official training). Yes, really.

Study time: 8-12 weeks.

Best for: Checking a box on job descriptions. CEH has name recognition with HR departments and is listed on many government job postings. Among technical practitioners, it has a mixed reputation because the multiple-choice format does not prove practical skill. If your target employer requires it specifically, get it. Otherwise, the eJPT or PenTest+ offer better value.

CompTIA PenTest+ (PT0-003)

What it tests: Penetration testing planning, information gathering, attacks and exploits, reporting and communication. Includes performance-based questions.

Cost: $404 exam voucher.

Study time: 8-10 weeks after Security+.

Best for: A middle ground between CEH (too theoretical) and OSCP (too difficult for early career). Good DoD 8570 compliance option for pen testing roles.

Advanced Tier: OSCP, GPEN, and CISSP

Offensive Security Certified Professional (OSCP)

What it tests: Practical penetration testing skills in a grueling 24-hour exam. You are given a set of target machines in a lab environment and must compromise them, then write a professional penetration testing report. There is no multiple choice - you either hack the machines or you do not.

Cost: $1,749 for 90 days of lab access + one exam attempt. Additional attempts are $249 each.

Study time: 3-6 months of dedicated preparation (many people take longer).

Pass rate: Not officially published, but community estimates range from 40-60% on first attempt.

Best for: Anyone serious about offensive security. OSCP is the gold standard for penetration testing certifications. It carries enormous weight with technical hiring managers because everyone knows you cannot fake your way through the exam. Getting an OSCP tells employers you can actually find and exploit vulnerabilities under pressure.

The OSCP is hard. Prepare extensively with platforms like HackTheBox, TryHackMe, and Proving Grounds before attempting it. Having hands-on tools like the BLEShark Nano helps build familiarity with wireless attack surfaces, protocol analysis, and the kind of creative thinking the OSCP rewards.

Get the BLEShark Nano - $49.99

SANS GIAC Penetration Tester (GPEN)

What it tests: Penetration testing methodology, legal issues, scanning, exploitation, password attacks, and advanced techniques. The GPEN is a proctored multiple-choice exam, but SANS exams are known for being difficult and thorough.

Cost: $979 for the exam alone. The SANS training course (SEC560) that prepares you costs $7,000-$9,000. This makes GPEN one of the most expensive certifications in the field.

Study time: The SEC560 course is 6 days. Additional prep: 4-6 weeks.

Best for: People whose employers will pay for SANS training. The training quality is excellent, but the cost puts it out of reach for self-funded learners. If your company offers it, take it.

ISC2 Certified Information Systems Security Professional (CISSP)

What it tests: Eight domains covering security and risk management, asset security, security architecture, communications and network security, identity and access management, security assessment, security operations, and software development security. CISSP is broad, covering management and technical topics.

Cost: $749 exam fee.

Requirement: 5 years of cumulative, paid work experience in two or more of the eight domains (or 4 years with a relevant degree). You can pass the exam without the experience, but you will be an "Associate of ISC2" until you meet the requirement.

Study time: 8-16 weeks for experienced professionals. Longer for those without broad security experience.

Best for: Security professionals with 5+ years of experience who want to move into management or senior technical roles. CISSP is frequently required for security architect, security director, and CISO positions. Do not pursue it early in your career - the experience requirement exists for a reason, and the content assumes you have real-world context for the material.

Cost Breakdown and Study Time

pie title Certification Cost Comparison (Exam Only)
    "Network+ $369" : 369
    "Security+ $404" : 404
    "CySA+ $404" : 404
    "eJPT $249" : 249
    "CEH $1,199" : 1199
    "OSCP $1,749" : 1749
    "GPEN $979" : 979
    "CISSP $749" : 749

Exam voucher costs only - training materials and lab access are additional

A realistic budget for the most common certification path (Network+ to Security+ to eJPT to OSCP) looks like this:

  • Network+ exam: $369 + study materials (~$50 for a book, free videos): ~$420
  • Security+ exam: $404 + study materials (~$50): ~$454
  • eJPT exam: $249 + INE subscription (~$150 for 3 months): ~$399
  • OSCP: $1,749 (includes lab and exam): $1,749

Total: approximately $3,022 spread over 12-18 months. That is a significant investment, but compared to a college degree, it is remarkably affordable for the career outcomes it enables.

Tips for reducing costs:

  • CompTIA frequently runs sales on exam vouchers (10-15% off)
  • Academic discounts are available for students
  • Many employers have tuition reimbursement programs that cover certifications
  • Professor Messer's free YouTube courses are genuinely sufficient for Network+ and Security+ - you do not need expensive bootcamps
  • Veterans and active military can often get free CompTIA vouchers through DoD programs

What Employers Actually Look For

Different sectors value different certifications. Here is the breakdown:

Government and defense contractors: DoD 8570/8140 compliance drives everything. Security+ is the minimum for most positions. CISSP, CASP+, and CEH are commonly required for higher-level roles. Certifications are often hard requirements that HR will not waive.

Enterprise corporations: Security+ for entry level, CISSP for senior roles. Cloud-specific certs (AWS Security Specialty, Azure Security Engineer) are increasingly valued. Practical certs like OSCP are appreciated but less commonly required.

Consulting firms and pen testing shops: OSCP is the gold standard. Many consulting firms will not consider pen testing candidates without it. CEH meets some compliance requirements but does not carry the same technical credibility.

Startups and tech companies: Generally care less about certifications and more about demonstrable skills. A strong GitHub profile, CTF rankings, or bug bounty track record may matter more than any certificate. That said, OSCP still commands respect universally.

Managed Security Service Providers (MSSPs): Security+ for SOC analyst roles, CySA+ or GCIA for senior analysts, CISSP for management. MSSPs hire in volume and often list certifications as hard requirements.

Study Strategies That Work

For multiple-choice exams (Security+, CySA+, CEH):

  • Watch video courses at 1.5x speed for initial exposure
  • Read one comprehensive textbook (Darril Gibson for Security+, Jason Dion for CySA+)
  • Take practice exams repeatedly until you consistently score 85%+
  • Focus on understanding concepts, not memorizing answers - CompTIA questions are scenario-based
  • Study for 1-2 hours daily rather than weekend cramming sessions

For practical exams (eJPT, OSCP):

  • Practice on HackTheBox, TryHackMe, and Proving Grounds machines daily
  • Take detailed notes on every machine you compromise - methodology, commands, and lessons learned
  • Build a personal cheat sheet of useful commands for enumeration, exploitation, and privilege escalation
  • Practice writing professional reports - the OSCP report is worth a significant portion of your grade
  • Join study groups and Discord communities for accountability and hints when you are stuck

For CISSP:

  • Think like a manager, not a technician - CISSP tests decision-making at an organizational level
  • The "ISC2 way" of thinking is real - learn to choose the most correct answer from a risk management perspective
  • Use the official ISC2 study guide plus one additional resource (Destination Certification on YouTube is excellent)
  • The exam is adaptive - do not panic if questions feel hard, that means you are performing well

Certification Myths Debunked

"Certifications guarantee a job." They do not. Certifications open doors and get you past HR filters, but interviews test your actual knowledge and communication skills. A cert with no practical ability to back it up will be exposed quickly.

"You need certifications to work in cybersecurity." Technically false, practically often true. Many excellent security professionals have no certifications. But for career changers and those without a traditional CS background, certifications provide a structured learning path and a credibility signal that employers trust.

"More certifications are always better." Diminishing returns hit fast. Two or three well-chosen certifications paired with practical experience beat a wall of acronyms after your name. Hiring managers who see 10+ certifications on a resume sometimes view it as a red flag - it suggests the candidate spent more time studying for exams than doing actual work.

"CEH is equivalent to OSCP." It is not. CEH tests knowledge through multiple choice; OSCP tests skill through practical application. They exist at fundamentally different levels despite both being "penetration testing" certifications. Anyone who has held both will tell you the gap is enormous.

"CISSP is for beginners." CISSP requires five years of professional experience for a reason. Studying CISSP material early in your career is fine for learning, but attempting the exam without real-world context makes the questions significantly harder to interpret correctly.

The optimal certification strategy is simple: match your certifications to your career goals, earn them in a logical order, and always pair study with hands-on practice. No certification replaces the ability to actually do the work, but the right credentials at the right time can meaningfully accelerate your progress.

Back to blog

Leave a comment