Cybersecurity is a broad field, and the right certifications depend on which part of it you want to work in. A SOC analyst, a penetration tester, a cloud security engineer and a governance specialist follow different paths. This roadmap groups the most recognised certifications by stage and specialisation.
Stage 1: Foundations (0–2 years)
- Networking and systems: CompTIA Network+ or Cisco CCNA; Linux skills (RHCSA for depth).
- Security basics: CompTIA Security+ (a new version is expected around November 2026) or ISC2 Certified in Cybersecurity.
- Vendor fundamentals: Microsoft SC-900 if you are heading towards Microsoft security tools.
At this stage, hands-on practice in a home lab matters as much as any certificate.
Stage 2: Specialise (2–5 years)
| Path | Typical roles | Certifications to consider |
|---|---|---|
| Security operations (SOC) | SOC analyst, incident responder, threat hunter | Microsoft SC-200, CompTIA CySA+ |
| Cloud security | Cloud security engineer, DevSecOps engineer | Microsoft SC-500, AWS Security – Specialty (SCS-C03), Google Professional Cloud Security Engineer, CKS for Kubernetes |
| Offensive security | Penetration tester, red team member | CEH (with the practical exam), OSCP |
| Identity | Identity and access engineer | Microsoft SC-300 |
| Governance, risk and compliance | GRC analyst, IT auditor | ISACA CISA, ISO 27001 lead implementer or lead auditor |
Stage 3: Senior and leadership (5+ years)
- CISSP: broad senior credential for architects, consultants and leads. Requires five years of experience in at least two of its eight domains.
- CISM: for security managers running a programme. Requires five years of experience, including three in security management.
- CISA: for senior auditors and assurance leaders.
Principles that apply on every path
- Depth beats collection. Two well-chosen certifications backed by experience impress more than ten unrelated ones.
- Check versions. Many security exams changed in 2026; study for the current version.
- Keep learning between exams. Follow advisories from CERT-In and vendor security blogs, and practise on legal training platforms.
- Stay ethical. Only test systems you are authorised to test. Integrity is the foundation of a security career.
For detailed guides to many of these certifications, browse our Security Certifications section.
Leave a Reply